You can turn on event auditing, through the group policy editor to log every instance of a program being run and then filter the results from the system log using a third-party tool. The exact event you would be looking for is "Audit process tracking," which tracks all executables. Be sure to turn this on for both failure and success to get the most comprehensive logging possible.
This was first published in June 2003
Join the conversationComment
Share
Comments
Results
Contribute to the conversation