Skip to main content

CommandLineUtility Data Collector

The CommandLineUtility Data Collector lets you remotely spawn, execute, and extract data provided by a Microsoft native or third-party command line utility. It lets you execute a command line utility and capture its output as Enterprise Auditor data. This data collector is a core component of Enterprise Auditor and is available with all Enterprise Auditor licenses.

Protocols

  • Remote Registry
  • RPC

Ports

  • TCP 135-139
  • Randomly allocated high TCP ports

Permissions

  • Member of the local Administrators group

CommandLineUtility Query Configuration

The CommandLineUtility Data Collector executes a command line utility and captures the output. Configure it through the Command Line Utility Data Collector Wizard, which contains the following pages:

Command Line Utility Data Collector Wizard Welcome page

To hide the Welcome page, select the Don't display this page the next time checkbox while the wizard is open, and save the configuration settings.