This is a lightweight PowerShell script that collects security events with the ID 4740 (which referes to account lockouts) and references them against an array of users that has been specified. This information is emailed to a set of recipients with key information from the event
- Powershell (A recent version will be ok, 4 or higher)
- Active Directory Powershell Module
To get a local copy up and running follow these simple steps.
This script requires the Active Directory PowerShell Module to be installed. Instructions can be found here
-
Clone the repo (or download)
git clone https://github.com/harrisoncattell/Active-Directory-Account-Lockout-Monitor.git
-
Please move script file to suitable location
-
Locate and change the following
$VerbosePath
$OUPath
$recipients = @("TEST <TEST@testemail.com>")
$Sender = @("TEST <TEST@testemail.com>")
You may also want to change how the events are collected, this can be found in the line $SecurityEvents = Get-WinEvent -FilterHashtable @{LogName='ForwardedEvents';ID='4740'} -MaxEvents 50
- Create the Task Scheduler task for this script, the interval can be set to how ever long you want (Please make the variable
$TimeSpan
match) If you don't know how to do this, please follow this guide
This project can be used in local AD security monitoring. This was created in reponse to the need of transparency around what administrator accounts were getting locked out and from where without relying on delayed notification from a SIEM supplier
Contributions are what make the open source community such an amazing place to be learn, inspire, and create. Any contributions you make are greatly appreciated.
- Fork the Project
- Create your Feature Branch (
git checkout -b feature/AmazingFeature
) - Commit your Changes (
git commit -m 'Add some AmazingFeature'
) - Push to the Branch (
git push origin feature/AmazingFeature
) - Open a Pull Request
Name: Harrison Cattell
Linkedin: https://www.linkedin.com/in/harrisoncattell/
Project Link: https://github.com/harrisoncattell/Active-Directory-Account-Lockout-Monitor