Information
This policy setting determines which users can use Windows performance monitoring tools to monitor the performance of system processes.
The recommended state for this setting is: Administrators, NT SERVICE\WdiServiceHost.
Threat actors with this user right could monitor a computer's performance to help identify critical processes that they might wish to attack directly. Threat actors may also be able to determine what processes are active on the computer so that they could identify countermeasures that they may need to avoid, such as antivirus software or an intrusion detection system.
Solution
To establish the recommended configuration via GP, set the following UI path to Administrators, NT SERVICE\WdiServiceHost :
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Profile system performance
Impact:
None - this is the default behavior.