{"id":31289,"date":"2019-10-31T21:40:29","date_gmt":"2019-10-31T18:40:29","guid":{"rendered":"https:\/\/prohoster.info\/blog\/chto-poleznogo-mozhno-vytashhit-iz-logov-rabochej-stantsii-na-baze-os-windows\/"},"modified":"2019-10-31T21:40:29","modified_gmt":"2019-10-31T18:40:29","slug":"chto-poleznogo-mozhno-vytashhit-iz-logov-rabochej-stantsii-na-baze-os-windows","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-poleznogo-mozhno-vytashhit-iz-logov-rabochej-stantsii-na-baze-os-windows","title":{"rendered":"\u00c7far\u00eb informacioni t\u00eb dobish\u00ebm mund t\u00eb nxjerrim nga log\u00ebt e stacionit t\u00eb pun\u00ebs n\u00eb sistemin operativ Windows","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Stacioni i p\u00ebrdoruesit \u00ebsht\u00eb vendi m\u00eb i vuneruesh\u00ebm n\u00eb infrastruktur\u00ebn e siguris\u00eb informacionit. P\u00ebrdoruesit mund t\u00eb marrin nj\u00eb email n\u00eb pun\u00eb q\u00eb duket se vjen nga nj\u00eb burim i sigurt, por me nj\u00eb lidhje n\u00eb nj\u00eb faqe t\u00eb infektuar. Mund t\u00eb ndodh\u00eb q\u00eb dikush t\u00eb shkarkoj\u00eb nj\u00eb mjet t\u00eb dobish\u00ebm p\u00ebr pun\u00eb nga nj\u00eb vend i paqart\u00eb. Mund t\u00eb mendojm\u00eb p\u00ebr nj\u00eb num\u00ebr t\u00eb madh rastesh se si malware mund t\u00eb dep\u00ebrtoj\u00eb n\u00eb burimet intra-korporative p\u00ebrmes p\u00ebrdoruesve. Prandaj, stacionet e pun\u00ebs k\u00ebrkojn\u00eb v\u00ebmendje t\u00eb shtuar, dhe n\u00eb k\u00ebt\u00eb artikull do t\u00eb flasim p\u00ebr nga cilat ngjarje mund t\u00eb p\u00ebrfitojm\u00eb p\u00ebr t\u00eb ndjekur sulmet.<\/p>\n<p><img decoding=\"async\" alt=\"\u00c7far\u00eb informacioni t\u00eb dobish\u00ebm mund t\u00eb nxjerrim nga log\u00ebt e stacionit t\u00eb pun\u00ebs n\u00eb sistemin operativ Windows\" src=\"\/wp-content\/uploads\/2019\/04\/6e0eddfc90ae158b3d532a6b7a069177.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>P\u00ebr t\u00eb identifikuar nj\u00eb sulm n\u00eb faz\u00ebn e tij m\u00eb t\u00eb hershme, n\u00eb sistemin operativ Windows ka tri burime t\u00eb dobishme ngjarjesh: regjistri i ngjarjeve t\u00eb siguris\u00eb, regjistri i monitorimit t\u00eb sistemit dhe regjistrat e Power Shell.<\/p>\n<h2>Regjistri i ngjarjeve t\u00eb siguris\u00eb (Security Log)<\/h2>\n<p>\nKy \u00ebsht\u00eb vendi kryesor p\u00ebr ruajtjen e regjistrave sistemor\u00eb t\u00eb siguris\u00eb. K\u00ebtu grumbullohen ngjarjet e hyrjes\/daljes s\u00eb p\u00ebrdoruesve, aksesit n\u00eb objekte, ndryshimeve t\u00eb politikave dhe aktiviteteve t\u00eb tjera q\u00eb lidhen me sigurin\u00eb. Sigurisht, n\u00ebse \u00ebsht\u00eb vendosur politika p\u00ebrkat\u00ebse.<\/p>\n<p><img decoding=\"async\" alt=\"\u00c7far\u00eb informacioni t\u00eb dobish\u00ebm mund t\u00eb nxjerrim nga log\u00ebt e stacionit t\u00eb pun\u00ebs n\u00eb sistemin operativ Windows\" src=\"\/wp-content\/uploads\/2019\/04\/82e59ad17a09a8211dc6fe9737208fd7.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>Kontrolli i p\u00ebrdoruesve dhe grupeve (ngjarjet 4798 dhe 4799).<\/b> Malware n\u00eb fillim t\u00eb sulmit shpesh kontrollon llogarit\u00eb lokale t\u00eb p\u00ebrdoruesve dhe grupet lokale n\u00eb stacionin e pun\u00ebs p\u00ebr t\u00eb gjetur kredencialet p\u00ebr veprat e tij t\u00eb zeza. K\u00ebto ngjarje do t\u00eb ndihmojn\u00eb n\u00eb zb\u53d1\u73b0jen e kodit t\u00eb keq para se ai t\u00eb p\u00ebrparoj\u00eb m\u00eb tej dhe, duke p\u00ebrdorur t\u00eb dh\u00ebnat e grumbulluara, t\u00eb p\u00ebrhapen n\u00eb sisteme t\u00eb tjera.<\/p>\n<p><b>Krijimi i nj\u00eb llogarie lokale dhe ndryshime n\u00eb grupet lokale (ngjarjet 4720, 4722\u20134726, 4738, 4740, 4767, 4780, 4781, 4794, 5376 dhe 5377).<\/b> Nj\u00eb sulm gjithashtu mund t\u00eb filloj\u00eb, p\u00ebr shembull, me shtimin e nj\u00eb p\u00ebrdoruesi t\u00eb ri n\u00eb grupin e administrator\u00ebve lokal\u00eb.<\/p>\n<p><b>P\u00ebrpjekjet p\u00ebr t\u00eb hyr\u00eb me nj\u00eb llogari lokale (ngjarja 4624).<\/b> P\u00ebrdoruesit e ndersh\u00ebm hyjn\u00eb me nj\u00eb llogari domene dhe identifikimi i hyrjes me nj\u00eb llogari lokale mund t\u00eb n\u00ebnkuptoj\u00eb fillimin e nj\u00eb sulmi. Ngjarja 4624 p\u00ebrfshin gjithashtu hyrjet me llogari domene, prandaj gjat\u00eb p\u00ebrpunimit t\u00eb ngjarjeve duhet t\u00eb filtrohen ngjarjet, ku domene ndryshon nga emri i stacionit t\u00eb pun\u00ebs.<\/p>\n<p><b>P\u00ebrpjekja p\u00ebr t\u00eb hyr\u00eb me nj\u00eb llogari t\u00eb caktuar (ngjarja 4648).<\/b> Kjo ndodh kur procesi ekzekutohet n\u00eb modin 'Ekzekutim si' (run as). N\u00eb nj\u00eb mod normal t\u00eb funksionimit t\u00eb sistemeve, kjo nuk duhet t\u00eb ndodh\u00eb, prandaj k\u00ebto ngjarje duhet t\u00eb jen\u00eb n\u00ebn kontroll.<\/p>\n<p><b>Bllokimi\/ribllokimi i stacionit t\u00eb pun\u00ebs (ngjarjet 4800-4803).<\/b> Kategoris\u00eb s\u00eb ngjarjeve t\u00eb dyshimta mund t'i p\u00ebrkasin \u00e7do veprim q\u00eb ndodhi n\u00eb nj\u00eb stacion pune t\u00eb bllokuar.<\/p>\n<p><b>Ndryshimet n\u00eb konfigurimin e firewall-it (ngjarjet 4944-4958).<\/b> E qart\u00eb \u00ebsht\u00eb se, gjat\u00eb instalimit t\u00eb softuer\u00ebve t\u00eb rinj, konfigurimi i firewall-it mund t\u00eb ndryshoj\u00eb, \u00e7ka do t\u00eb sjell\u00eb sinjale t\u00eb false. N\u00eb shumic\u00ebn e rasteve, nuk ka nevoj\u00eb t\u00eb monitorohen k\u00ebto ndryshime, por \u00ebsht\u00eb gjithmon\u00eb mir\u00eb t\u00eb jesh i vet\u00ebdijsh\u00ebm p\u00ebr to.<\/p>\n<p><b>Lidhjet e pajisjeve Plug\u2019n\u2019play (ngjarja 6416 dhe vet\u00ebm p\u00ebr Windows 10).<\/b> Kjo \u00ebsht\u00eb e r\u00ebnd\u00ebsishme p\u00ebr t'u ndjekur, n\u00ebse p\u00ebrdoruesit zakonisht nuk lidhin pajisje t\u00eb reja n\u00eb stacionin e pun\u00ebs, dhe papritur lidhin nj\u00eb.<\/p>\n<p>Windows p\u00ebrmban 9 kategorit\u00eb e auditimit dhe 50 n\u00ebnkategorit\u00eb p\u00ebr konfigurimin e holl\u00ebsish\u00ebm. Grupi minimal i n\u00ebnkategorive q\u00eb duhet t\u00eb aktivizohen n\u00eb cil\u00ebsimet \u00ebsht\u00eb:<\/p>\n<p><b>Hyrje\/Ndalim<\/b><\/p>\n<ul>\n<li>Hyrja;<\/li>\n<li>Dalja;<\/li>\n<li>Bllokimi i Llogaris\u00eb;<\/li>\n<li>Ngjarjet e tjera t\u00eb Hyrjes\/Ndalimit.<\/li>\n<\/ul>\n<p>\n<b>Menaxhimi i Llogarive<\/b><\/p>\n<ul>\n<li>Menaxhimi i Llogarive t\u00eb P\u00ebrdoruesve;<\/li>\n<li>Menaxhimi i Grupeve t\u00eb Siguris\u00eb.<\/li>\n<\/ul>\n<p>\n<b>Ndryshimi i Politika<\/b><\/p>\n<ul>\n<li>Ndryshimi i Politikave t\u00eb Auditimit;<\/li>\n<li>Ndryshimi i Politikave t\u00eb Autentikimit;<\/li>\n<li>Ndryshimi i Politikave t\u00eb Autorizimit.<\/li>\n<\/ul>\n<p><\/p>\n<h2>Monitori i Sistem\u00ebve (Sysmon)<\/h2>\n<p>\nSysmon \u00ebsht\u00eb nj\u00eb mjet i integruar n\u00eb Windows, i cili mund t\u00eb regjistroj\u00eb ngjarje n\u00eb regjistrin e sistemit. Zakonisht k\u00ebrkohet t\u00eb instalohet ve\u00e7mas.<\/p>\n<p><img decoding=\"async\" alt=\"\u00c7far\u00eb informacioni t\u00eb dobish\u00ebm mund t\u00eb nxjerrim nga log\u00ebt e stacionit t\u00eb pun\u00ebs n\u00eb sistemin operativ Windows\" src=\"\/wp-content\/uploads\/2019\/04\/0b1e14fb9ba4d63a4d9d94bd9d62d112.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nK\u00ebto ngjarje n\u00eb thelb mund t\u00eb gjenden gjithashtu n\u00eb regjistrin e siguris\u00eb (duke aktivizuar politik\u00ebn e duhur t\u00eb auditimit), por Sysmon ofron m\u00eb shum\u00eb detaje. Cilat ngjarje mund t\u00eb merren nga Sysmon?<\/p>\n<p><b>Krijimi i procesit (ID e ngjarjes 1).<\/b> Regjistri i ngjarjeve t\u00eb siguris\u00eb s\u00eb sistemit gjithashtu mund t\u00eb tregoj\u00eb se kur \u00ebsht\u00eb nisur ndonj\u00eb *.exe dhe madje do t\u00eb tregoj\u00eb emrin dhe rrug\u00ebn e nisjes. Por, ndryshe nga Sysmon, nuk do t\u00eb mund t\u00eb tregoj\u00eb hash-in e aplikacionit. Softueri i d\u00ebmsh\u00ebm mund t\u00eb quhet madje edhe si notepad.exe i pad\u00ebmsh\u00ebm, por hash-i do ta nxjerr\u00eb at\u00eb n\u00eb drit\u00eb.<\/p>\n<p><b>Koneksionet n\u00eb rrjet (ID e ngjarjes 3).<\/b> E qart\u00eb \u00ebsht\u00eb se ka shum\u00eb koneksione n\u00eb rrjet, dhe nuk \u00ebsht\u00eb e leht\u00eb t\u00eb monitorohen t\u00eb gjitha. Por \u00ebsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb merret parasysh se Sysmon, ndryshe nga Regjistri i Siguris\u00eb, mund t\u00eb lidh\u00eb koneksionin n\u00eb rrjet me fushat ProcessID dhe ProcessGUID, duke treguar portin dhe <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/lir\/ipv4\/\"   title=\"Adresa IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"622\">Adresa IP<\/a> burimin dhe marr\u00ebsin.<\/p>\n<p><b>Ndryshimet n\u00eb regjistrin e sistemit (ID e ngjarjes 12-14).<\/b> M\u00ebnyra m\u00eb e thjesht\u00eb p\u00ebr t\u00eb shtuar veten n\u00eb autostart \u00ebsht\u00eb t\u00eb regjistrohesh n\u00eb regjistrin. Security Log e b\u00ebn k\u00ebt\u00eb, por Sysmon tregon se kush b\u00ebri ndryshimin, kur, nga ku, ID e procesit dhe vler\u00ebn e m\u00ebparshme t\u00eb \u00e7el\u00ebsit.<\/p>\n<p><b>Krijimi i skedarit (ID e ngjarjes 11).<\/b> Sysmon, ndryshe nga Security Log, do t\u00eb tregoj\u00eb jo vet\u00ebm vendndodhjen e skedarit, por edhe emrin e tij. \u00cbsht\u00eb e qart\u00eb q\u00eb nuk mund t\u00eb ndiqni gjith\u00e7ka, por mund t\u00eb b\u00ebni auditimin e drejtorive t\u00eb caktuara.<\/p>\n<p>Dhe tani ajo q\u00eb nuk ndodhet n\u00eb politikat e Security Log, por ndodhet n\u00eb Sysmon:<\/p>\n<p><b>Ndryshimi i koh\u00ebs s\u00eb krijimit t\u00eb skedarit (ID e ngjarjes 2).<\/b> Disa malware mund t\u00eb ndryshoj\u00eb dat\u00ebn e krijimit t\u00eb skedarit p\u00ebr ta fshehur at\u00eb nga raportet me skedar\u00ebt e sapokrijuar.<\/p>\n<p><b>Ngarkimi i drejtuesve dhe bibliotekave dinamike (ID e ngjarjeve 6-7).<\/b> Ndjekja e ngarkes\u00ebs n\u00eb kujtes\u00eb t\u00eb DLL-ve dhe drejtuesve t\u00eb pajisjeve, kontrollimi i n\u00ebnshkrimit digjital dhe vlefshm\u00ebria e tij.<\/p>\n<p><b>Krijimi i nj\u00eb rrjedhe n\u00eb procesin e ekzekutimit (ID e ngjarjes 8).<\/b> Nj\u00eb nga llojet e sulmeve, p\u00ebr t\u00eb cil\u00ebn gjithashtu duhet t\u00eb jeni t\u00eb v\u00ebmendsh\u00ebm.<\/p>\n<p><b>Ngjarjet RawAccessRead (ID e ngjarjes 9).<\/b> Operacionet e leximit nga disku n\u00ebp\u00ebrmjet 'dot'. N\u00eb shumic\u00ebn d\u00ebrrmuese t\u00eb rasteve, nj\u00eb aktivitet i till\u00eb duhet t\u00eb konsiderohet anormal.<\/p>\n<p><b>Krijimi i nj\u00eb rrjedhe t\u00eb em\u00ebruar t\u00eb skedarit (ID e ngjarjes 15).<\/b> Ngjarja regjistrohet kur krijohet nj\u00eb rrjedh\u00eb e em\u00ebruar skedari, e cila gjeneron ngjarje me hash-in e p\u00ebrmbajtjes s\u00eb skedarit.<\/p>\n<p><b>Krijimi i nj\u00eb pipe t\u00eb em\u00ebruar dhe lidhjeve (ID e ngjarjeve 17-18).<\/b> Ndjekja e kodit t\u00eb d\u00ebmsh\u00ebm q\u00eb komunikon me komponent\u00ebt e tjer\u00eb p\u00ebrmes pipes t\u00eb em\u00ebruara.<\/p>\n<p><b>Aktiviteti p\u00ebr WMI (ID e ngjarjes 19).<\/b> Regjistrimi i ngjarjeve q\u00eb shkaktohen kur qaseni n\u00eb sistem p\u00ebrmes protokollit WMI.<\/p>\n<p>P\u00ebr t\u00eb mbrojtur vet\u00eb Sysmon, duhet t\u00eb ndiqni ngjarjet me ID 4 (ndalimi dhe nisja e Sysmon) dhe ID 16 (ndryshimi i konfigurimit t\u00eb Sysmon).<\/p>\n<h2>Ditar\u00ebt e Power Shell.<\/h2>\n<p>\nPower Shell \u00ebsht\u00eb nj\u00eb mjet i fuqish\u00ebm p\u00ebr menaxhimin e infrastruktur\u00ebs Windows, prandaj ka shanse t\u00eb m\u00ebdha q\u00eb sulmuesi ta zgjedh\u00eb at\u00eb. P\u00ebr t\u00eb marr\u00eb t\u00eb dh\u00ebna mbi ngjarjet e Power Shell, mund t\u00eb p\u00ebrdoren dy burime: Windows PowerShell log dhe Microsoft-WindowsPowerShell \/ Operational log.<\/p>\n<h4>Windows PowerShell log.<\/h4>\n<p>\n<img decoding=\"async\" alt=\"\u00c7far\u00eb informacioni t\u00eb dobish\u00ebm mund t\u00eb nxjerrim nga log\u00ebt e stacionit t\u00eb pun\u00ebs n\u00eb sistemin operativ Windows\" src=\"\/wp-content\/uploads\/2019\/04\/03d830871fc2c47ceeb8f0822f3f20e0.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>Kryerja e ofruesit t\u00eb t\u00eb dh\u00ebnave (ID e ngjarjes 600).<\/b> Furnizuesit PowerShell jan\u00eb programe q\u00eb sh\u00ebrbejn\u00eb si burim t\u00eb dh\u00ebnash p\u00ebr PowerShell p\u00ebr t'i shqyrtuar dhe menaxhuar ato. P\u00ebr shembull, furnizuesit e integruar mund t\u00eb jen\u00eb variablat e mjedisit Windows ose regjistri i sistemit. Duhet t\u00eb monitoroni shfaqjen e furnizuesve t\u00eb rinj p\u00ebr t\u00eb identifikuar aktivitete t\u00eb d\u00ebmshme n\u00eb koh\u00eb. P\u00ebr shembull, n\u00ebse shihni q\u00eb mes furnizuesve \u00ebsht\u00eb shfaqur WSMan, at\u00ebher\u00eb ka filluar nj\u00eb seanc\u00eb e larg\u00ebt PowerShell.<\/p>\n<h4>Microsoft-WindowsPowerShell \/ Operational log (ose MicrosoftWindows-PowerShellCore \/ Operational n\u00eb PowerShell 6)<\/h4>\n<p>\n<img decoding=\"async\" alt=\"\u00c7far\u00eb informacioni t\u00eb dobish\u00ebm mund t\u00eb nxjerrim nga log\u00ebt e stacionit t\u00eb pun\u00ebs n\u00eb sistemin operativ Windows\" src=\"\/wp-content\/uploads\/2019\/04\/d0a1a74aad59c7c4f64446b52846429f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>Regjistrimi i moduleve (ID ngjarja 4103).<\/b> N\u00eb ngjarje ruhet informacion rreth \u00e7do komande t\u00eb ekzekutuar dhe parametrave me t\u00eb cilat ajo \u00ebsht\u00eb thirrur.<\/p>\n<p><b>Regjistrimi i bllokimit t\u00eb skripteve (ID ngjarja 4104).<\/b> Regjistrimi i bllokimit t\u00eb skripteve tregon \u00e7do bllok kode PowerShell t\u00eb ekzekutuar. Edhe n\u00ebse nj\u00eb sulmues p\u00ebrpiqet t\u00eb fsheh\u00eb komand\u00ebn, ky lloj ngjarjeje do t\u00eb tregoj\u00eb komand\u00ebn e v\u00ebrtet\u00eb t\u00eb ekzekutuar PowerShell. Po ashtu, n\u00eb k\u00ebt\u00eb lloj ngjarjeje mund t\u00eb regjistrohen disa thirrje t\u00eb ul\u00ebta API, k\u00ebto ngjarje zakonisht regjistrohen si Verbose, por n\u00ebse nj\u00eb komand\u00eb ose skript i dyshimt\u00eb p\u00ebrdoret n\u00eb bllokun e kodit, ai do t\u00eb regjistrohet si me r\u00ebnd\u00ebsi Warning.<\/p>\n<p>Kujdes, pas konfigurimit t\u00eb mjetit p\u00ebr mbledhjen dhe analiz\u00ebn e k\u00ebtyre ngjarjeve, do t\u00eb nevojitet koh\u00eb shtes\u00eb p\u00ebr debugimin p\u00ebr t\u00eb zvog\u00ebluar numrin e false positive-ve.<\/p>\n<p>Na tregoni n\u00eb komentet se cilat regjistra po mbledhni p\u00ebr auditimin e siguris\u00eb informative dhe cilat mjete po p\u00ebrdorni p\u00ebr k\u00ebt\u00eb. Nj\u00eb nga drejtimet tona \u00ebsht\u00eb zgjidhjet p\u00ebr auditimin e ngjarjeve t\u00eb siguris\u00eb informative. P\u00ebr zgjidhjen e detyr\u00ebs s\u00eb mbledhjes dhe analiz\u00ebs s\u00eb regjistrave, mund t\u00eb propozojm\u00eb t\u00eb shqyrtoni <noindex><a rel=\"nofollow\" href=\"https:\/\/www.quest.com\/products\/intrust\/\">Quest InTrust<\/a><\/noindex>, i cili \u00ebsht\u00eb n\u00eb gjendje t\u00eb comprimoj\u00eb t\u00eb dh\u00ebnat e ruajtura me nj\u00eb koeficient 20:1, dhe nj\u00eb instanc\u00eb e instaluar e tij mund t\u00eb p\u00ebrpunoj\u00eb deri n\u00eb 60000 ngjarje n\u00eb sekund\u00eb nga 10000 burime.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/galssoftware\/blog\/447522\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f \u0440\u0430\u0431\u043e\u0447\u0430\u044f \u0441\u0442\u0430\u043d\u0446\u0438\u044f \u2014 \u0441\u0430\u043c\u043e\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0435 \u043c\u0435\u0441\u0442\u043e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043f\u043e \u0447\u0430\u0441\u0442\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0439\u0442\u0438 \u043d\u0430 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u043f\u043e\u0447\u0442\u0443 \u043f\u0438\u0441\u044c\u043c\u043e \u0432\u0440\u043e\u0434\u0435 \u0431\u044b \u0438\u0437 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0433\u043e \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0430, \u043d\u043e \u0441\u043e \u0441\u0441\u044b\u043b\u043a\u043e\u0439 \u043d\u0430 \u0437\u0430\u0440\u0430\u0436\u0451\u043d\u043d\u044b\u0439 \u0441\u0430\u0439\u0442. \u0412\u043e\u0437\u043c\u043e\u0436\u043d\u043e, \u043a\u0442\u043e-\u0442\u043e \u0441\u043a\u0430\u0447\u0430\u0435\u0442 \u043f\u043e\u043b\u0435\u0437\u043d\u0443\u044e \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0443\u0442\u0438\u043b\u0438\u0442\u0443 \u0438\u0437 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e \u043a\u0430\u043a\u043e\u0433\u043e \u043c\u0435\u0441\u0442\u0430. \u0414\u0430 \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u0438\u0434\u0443\u043c\u0430\u0442\u044c \u043d\u0435 \u043e\u0434\u0438\u043d \u0434\u0435\u0441\u044f\u0442\u043e\u043a \u043a\u0435\u0439\u0441\u043e\u0432, \u043a\u0430\u043a \u0447\u0435\u0440\u0435\u0437 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u043c\u043e\u0436\u0435\u0442 \u0432\u043d\u0435\u0434\u0440\u0438\u0442\u044c\u0441\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23255,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-31289","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f \u0440\u0430\u0431\u043e\u0447\u0430\u044f \u0441\u0442\u0430\u043d\u0446\u0438\u044f \u2014 \u0441\u0430\u043c\u043e\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0435 \u043c\u0435\u0441\u0442\u043e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043f\u043e \u0447\u0430\u0441\u0442\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-poleznogo-mozhno-vytashhit-iz-logov-rabochej-stantsii-na-baze-os-windows\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0427\u0442\u043e \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0433\u043e \u043c\u043e\u0436\u043d\u043e \u0432\u044b\u0442\u0430\u0449\u0438\u0442\u044c \u0438\u0437 \u043b\u043e\u0433\u043e\u0432 \u0440\u0430\u0431\u043e\u0447\u0435\u0439 \u0441\u0442\u0430\u043d\u0446\u0438\u0438 \u043d\u0430 \u0431\u0430\u0437\u0435 \u041e\u0421 Windows | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f \u0440\u0430\u0431\u043e\u0447\u0430\u044f \u0441\u0442\u0430\u043d\u0446\u0438\u044f \u2014 \u0441\u0430\u043c\u043e\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0435 \u043c\u0435\u0441\u0442\u043e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043f\u043e \u0447\u0430\u0441\u0442\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-poleznogo-mozhno-vytashhit-iz-logov-rabochej-stantsii-na-baze-os-windows\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:40:29+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:40:29+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00c7far\u00eb dobi mund t\u00eb nxirreni nga regjistrat e stacionit t\u00eb pun\u00ebs bazuar n\u00eb sistemin operativ Windows | ProHoster","description":"Stacioni i pun\u00ebs p\u00ebrdorues \u00ebsht\u00eb pika m\u00eb e prekshme e infrastruktur\u00ebs sa i p\u00ebrket siguris\u00eb informative.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-poleznogo-mozhno-vytashhit-iz-logov-rabochej-stantsii-na-baze-os-windows","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0427\u0442\u043e \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0433\u043e \u043c\u043e\u0436\u043d\u043e \u0432\u044b\u0442\u0430\u0449\u0438\u0442\u044c \u0438\u0437 \u043b\u043e\u0433\u043e\u0432 \u0440\u0430\u0431\u043e\u0447\u0435\u0439 \u0441\u0442\u0430\u043d\u0446\u0438\u0438 \u043d\u0430 \u0431\u0430\u0437\u0435 \u041e\u0421 Windows | ProHoster","og:description":"\u041f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f \u0440\u0430\u0431\u043e\u0447\u0430\u044f \u0441\u0442\u0430\u043d\u0446\u0438\u044f \u2014 \u0441\u0430\u043c\u043e\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0435 \u043c\u0435\u0441\u0442\u043e \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043f\u043e \u0447\u0430\u0441\u0442\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-poleznogo-mozhno-vytashhit-iz-logov-rabochej-stantsii-na-baze-os-windows","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:40:29+00:00","article:modified_time":"2019-10-31T18:40:29+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31289","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-08 20:25:31","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:19:49","updated":"2026-02-08 20:25:31","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/31289","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=31289"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/31289\/revisions"}],"predecessor-version":[{"id":157813,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/31289\/revisions\/157813"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/23255"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=31289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=31289"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=31289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}