Skip to content

Instantly share code, notes, and snippets.

@jebbster88
Last active January 23, 2018 11:58
Show Gist options
  • Select an option

  • Save jebbster88/2048766f17d987a634f790a0d5b60148 to your computer and use it in GitHub Desktop.

Select an option

Save jebbster88/2048766f17d987a634f790a0d5b60148 to your computer and use it in GitHub Desktop.
get logon/off/lock events to determine activity
$events = Get-EventLog security -source microsoft-windows-security-auditing -ComputerName $computername |
where-object {
($_.instanceID -eq 4624 -and $_.replacementstrings[5] -eq $username -and $_.replacementstrings[8] -eq 2) -or #Local Logon
($_.instanceID -eq 4634 -and $_.replacementstrings[5] -eq $username -and $_.replacementstrings[8] -eq 2) -or #Local Logoff
($_.instanceID -eq 4647 -and $_.replacementstrings[1] -eq $username) -or #Local Logoff 2
($_.instanceID -eq 4778 -and $_.replacementstrings[0] -eq $username) -or #RDP Logon
($_.instanceID -eq 4779 -and $_.replacementstrings[0] -eq $username) -or #RDP Logoff
($_.instanceID -eq 4800 -and $_.replacementstrings[1] -eq $username) -or #Lock
($_.instanceID -eq 4801 -and $_.replacementstrings[1] -eq $username) #Unlock
} | select Index, TimeGenerated, InstanceID,
@{Name="Label";Expression={
$session = $_.replacementstrings[3]
switch($_.InstanceID){
4624 {"Local Logon"}
4634 {"Local Logoff"}
4647 {"Logoff"}
4778 {"Session Connect $session"}
4779 {"Session Disconnect $session"}
4800 {"Lock Screen"}
4801 {"Unlock Screen"}
}
}},
@{Name="Active";Expression={if(([int64]4624,[int64]4778,[int64]4801).Contains($_.InstanceID)){1}else{0}}}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment