27.2 Launching Privileged Account Sniffer

Prerequisites

  • You can launch this tool only on Windows computers.

  • You must have Microsoft .NET 4.5 or later installed in the system where you are launching this tool.

  • Ensure that the Windows Remote Registry service is running in the target system.

  • For domain administrative account discovery, run this tool in a computer that is part of the domain.

  • For Windows administrative account discovery, ensure that the WTS communication is open and firewalls are not blocking the remote discovery.

  • For service account discovery, ensure that the following configurations are done in the target system:

    • IIS service account discovery:

      • Privileged Account Sniffer supports IIS version 7 or later.

      • Ensure that the IIS Management Scripts and Tools role service is installed.

    • COMplus service account discovery:

      • Enable the COM+ Remote Administration (DCOM-In) firewall policy to allow remote discovery of COM+ service accounts.

      • Set the remoteaccess enable registry entry value to 1.You can find the registry entry at regedit\hkey local machine\software\microsoft\com3.

To launch Privileged Account Sniffer, perform the following:

  1. Download the privileged_account_sniffer from the NetIQ Downloads website.

    Privileged Account Sniffer is included as a separate downloadable file in Privileged Account Manager.

  2. Extract the contents of the downloaded privileged_account_sniffer.zip file and run the PrivilegedAccountSniffer.exe.

  3. Continue with Configuring Privileged Account Sniffer.