Detecting Who Executed RuntimeBroker.exe and Enabling Tracking
Detecting Who Executed RuntimeBroker.exe and Enabling Tracking
RuntimeBroker.exe and Enabling Tracking1. Purpose
2. Key Event IDs
3. Detecting Who Executed RuntimeBroker.exe
RuntimeBroker.exeThe process C:\Windows\System32\RuntimeBroker.exe (DD) initiated the power off of computer DD on behalf of user DD\Administrator.
4. Enabling Required Audit Policies
5. Optional: Collect Process Creation Details
6. Using PowerShell for Live Detection
7. Optional: Use Sysinternals Process Explorer
8. Best Practices
Summary
Last updated