CSCv7|8.8

Title

Enable Command-line Audit Logging

Description

Enable command-line audit logging for command shells, such as Microsoft Powershell and Bash.

Reference Item Details

Category: Malware Defenses

Audit Items

View all Reference Audit Items

NamePluginAudit Name
18.8.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'WindowsCIS Windows Server 2012 R2 DC L1 v2.6.0
18.8.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'WindowsCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS
18.8.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'WindowsCIS Windows Server 2012 MS L1 v2.4.0
18.8.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'WindowsCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DC
18.8.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'WindowsCIS Windows Server 2012 R2 MS L1 v2.6.0
18.8.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled' - DisabledWindowsCIS Windows Server 2012 DC L1 v2.4.0
18.9.100.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1
18.9.100.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.0
18.9.100.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Windows Server 2012 DC L1 v2.4.0
18.9.100.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MS
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL + NG
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows 10 EMS Gateway v2.0.0 L1
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1 + BL
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + NG
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2022 v2.0.0 L1 MS
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2016 DC L1 v2.0.0
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2019 MS L1 v2.0.0
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL + NG
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + NG
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2016 MS L1 v2.0.0
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2022 v2.0.0 L1 DC
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1 + BL
18.10.87.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2019 DC L1 v2.0.0
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1 + BL
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL + NG
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL + NG
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1 + BL
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 EMS Gateway v2.0.0 L1
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + NG
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + NG
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1
18.10.87.2 Ensure 'Turn on PowerShell Transcription' is set to 'Enabled' - DisabledWindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1
18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1
18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1 + BL + NG
18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1 + BL
18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1 + NG
18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1 + BL
18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1 + NG
18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 11 v2.0.0 L1 + BL + NG
18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'WindowsCIS Microsoft Intune for Windows 10 v2.0.0 L1