-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathLogon Notification.vbs
More file actions
139 lines (115 loc) · 4.08 KB
/
Copy pathLogon Notification.vbs
File metadata and controls
139 lines (115 loc) · 4.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
'******************************************************************************
'
' This script uses an asynchronous WMI query to monitor for specific logons
' across a set of systems. Adapted from a script found at the ScriptCenter
' at Microsoft.com/technet/scriptcenter
'
' Shawn Stugart
' 11-18-2005
'
'******************************************************************************
Option Explicit
Dim arrComputers(), oFSO, oInputFile, sInputFile
Dim sComputer, oWMI, colSystems, oSystem
Dim sUserName, sAsyncQuery, SINK, intSize
Dim hostname, iHelp, oShell, sQuery, colLogons
Dim oLogon, sError, iError
CheckCScript
sUserName = "Classnet\Administrator" 'Name of account to monitor
sInputFile = "C:\Clients.txt" 'List of systems to monitor
Set oFSO = CreateObject("Scripting.FileSystemObject")
Set oInputFile = oFSO.OpenTextFile(sInputFile,1)
Set SINK = WScript.CreateObject("WbemScripting.SWbemSink","SINK_")
intSize = 0
Do Until oInputFile.AtEndOfStream
Redim Preserve arrComputers(intSize)
arrComputers(intSize) = oInputFile.ReadLine
sComputer = arrComputers(intSize)
WScript.Echo vbCrLf & "Host: " & UCase(sComputer) & vbCrLf
iError = ShowLogons(sComputer)
If iError = 0 Then
TrapLogons(sComputer)
End If
intSize = intSize + 1
Loop
WScript.Echo vbCrLf & vbCrLf & "*************** MONITORING MODE ***************" & vbCrLf
Do
WScript.Sleep 1000
Loop
'***************************************************************************
Function ShowLogons(sHost)
On Error Resume Next
sQuery = "SELECT * FROM Win32_ComputerSystem"
Set oWMI = GetObject("winmgmts:" _
& "{impersonationLevel=impersonate}!\\" & sHost & "\root\cimv2")
If Err = 0 Then
Set colLogons = oWMI.ExecQuery(sQuery)
For each oLogon in colLogons
If LCase(oLogon.UserName) = LCase(sUserName) Then
WScript.Echo vbTab & sUserName & " is currently logged " _
& "on to " & oLogon.Name & "!"
End If
Next
ShowLogons = 0
Else
HandleError(sComputer)
WScript.Echo " Unable to monitor logons on " & sComputer
ShowLogons = 1
End If
End Function
'***************************************************************************
Sub TrapLogons(sHost)
On Error Resume Next
sAsyncQuery = "SELECT * FROM __InstanceModificationEvent WITHIN 1 " & _
"WHERE TargetInstance ISA 'Win32_ComputerSystem'"
Set oWMI = GetObject("winmgmts:" _
& "{impersonationLevel=impersonate}!\\" & sHost & "\root\cimv2")
If Err = 0 Then
oWMI.ExecNotificationQueryAsync SINK, sAsyncQuery
If Err = 0 Then
WScript.Echo vbCrLf
Else
HandleError(sHost)
WScript.Echo " Unable to monitor logons."
End If
Else
HandleError(sHost)
WScript.Echo " Unable to monitor logons."
End If
End Sub
'******************************************************************************
Sub SINK_OnObjectReady(objLatestEvent, objAsyncContext)
If LCase(objLatestEvent.TargetInstance.UserName) = LCase(sUserName) Then
Wscript.Echo VbCrLf & "User: " & objLatestEvent.TargetInstance.UserName
Wscript.Echo " Logged On To: " & objLatestEvent.TargetInstance.Name
Wscript.Echo " Time: " & Now
End If
End Sub
'******************************************************************************
Sub HandleError(sHost)
sError = VbCrLf & " ERROR on " & sHost & VbCrLf & _
" Number: " & Err.Number & VbCrLf & _
" Description: " & Err.Description & VbCrLf & _
" Source: " & Err.Source
WScript.Echo sError
Err.Clear
End Sub
'******************************************************************************
Sub CheckCScript()
hostname = lcase(right(WSCript.Fullname, 11))
If hostname = "wscript.exe" Then
WScript.Echo "This script requires cscript.exe"
iHelp = MsgBox("At a command line, run " & Chr(34) _
& "cscript " & WScript.ScriptFullName & Chr(34) _
& vbCrLf & vbCrLf & "Do you want help?", vbYesNo)
If iHelp = vbYes Then
Set oShell = CreateObject("WScript.Shell")
oShell.Run("cmd.exe")
WScript.Sleep 500
oShell.SendKeys "cscript.exe " & Chr(34) & WScript.ScriptFullName & Chr(34)
WScript.Quit
Else
WScript.Quit
End If
End If
End Sub