Sign In
Windows Security Logging and Other Esoterica
thoughts from the Windows auditing team
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
ACS
Descriptions
HowTo
Laws
Malware
News
Previews
Privacy
Rants
SEM
Tips
Tools
Unicode
Archive
Archives
August 2011
(1)
May 2011
(1)
April 2011
(1)
July 2010
(1)
May 2010
(1)
August 2009
(1)
June 2009
(1)
September 2008
(1)
August 2008
(1)
July 2008
(4)
April 2008
(2)
March 2008
(1)
February 2008
(3)
January 2008
(1)
November 2007
(1)
October 2007
(2)
August 2007
(5)
July 2007
(3)
June 2007
(2)
May 2007
(3)
April 2007
(1)
February 2007
(3)
October 2006
(1)
September 2006
(2)
August 2006
(2)
June 2006
(1)
May 2006
(2)
March 2006
(3)
December 2005
(6)
November 2005
(2)
September 2005
(3)
August 2005
(11)
January 2005
(1)
December 2004
(2)
October 2004
(1)
August, 2005
MSDN Blogs
>
Windows Security Logging and Other Esoterica
>
August, 2005
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Windows Security Logging and Other Esoterica
Multiple Events for Successful Account Creation
Posted
over 7 years ago
by
Eric Fitzgerald
0
Comments
Here is the pattern you should expect to see when creating a local account. For domain accounts, you may also see some DS Access events as the account is created and the various properties are set. 560 SAM_DOMAIN handle open for CreateUser access 632...
Windows Security Logging and Other Esoterica
Multiple Events for Failed Account Creation
Posted
over 7 years ago
by
Eric Fitzgerald
1
Comments
When you create a local user account on Windows, and you have enabled account management auditing, you will see multiple events that map into this single occurrence. I was actually going to file a change request on this, but I'm not sure that that is...
Windows Security Logging and Other Esoterica
Logs and the Rules of Evidence
Posted
over 7 years ago
by
Eric Fitzgerald
1
Comments
I quite frequently hear these questions: 1. My logs/log collection database aren't digitally signed, can I still use them in court? 2. My logs are in a text file that an admin can write to, can I still use them in court? Our legal department...
Windows Security Logging and Other Esoterica
Delegating Access to the Security Log
Posted
over 7 years ago
by
Eric Fitzgerald
1
Comments
I often get the question, how do I allow a group of auditors read access to my security logs without making them admins and without letting them clear the logs? To answer this, first you need to know, for what version of Windows? Prior to Windows Server...
Windows Security Logging and Other Esoterica
COMMENT MY BLOG, PLEASE!
Posted
over 7 years ago
by
Eric Fitzgerald
1
Comments
If you have auditing questions (as opposed to general security questions), please feel free to comment my blog or send me email. I read it all and respond (eventually), and I love to post on new topics. I just want to make sure that this is useful stuff...
Windows Security Logging and Other Esoterica
Another culprit causes too many object access events.
Posted
over 7 years ago
by
Eric Fitzgerald
1
Comments
I encountered this in the course of investigating another report of "too many object access events". Evidently Exchange 2000 Server can cause a large number of handle close events with no corresponding handle open events. The KB article explains how to...
Windows Security Logging and Other Esoterica
A Voice of Sanity from SANS
Posted
over 7 years ago
by
Eric Fitzgerald
0
Comments
I was reading SANS NewsBites , a weekly email newsletter describing significant news around information security. I came across this article summary about a "security researcher" who got a light jail sentence after hacking into several organizations'...
Windows Security Logging and Other Esoterica
Why don't I see the workstation name in logon events?
Posted
over 7 years ago
by
Eric Fitzgerald
0
Comments
Top reasons: 1. In NTLM logons, it's subject to spoofing. There exist hacking tools which improperly populate the workstation field of the logon request. I don't know if this is intentional or not. 2. There is no way to carry this information in...
Windows Security Logging and Other Esoterica
Monitoring Active Directory Schema Changes
Posted
over 7 years ago
by
Eric Fitzgerald
1
Comments
As a follow-on to my last post, I want to relate how to monitor for Active Directory schema changes. First you need to put SACLs on the schema. Remember to replace any existing SACLs, disable propagaion of the SACL from the parent, and force propagation...
Windows Security Logging and Other Esoterica
Monitoring Group Policy Changes with Windows Auditing
Posted
over 7 years ago
by
Eric Fitzgerald
6
Comments
I spent some time a while back analyzing logs, figuring out what you can do with group policy auditing on Windows Server 2003. I did not test Windows 2000; I suspect that much of this applies but YMMV. GP editing does leave an auditable trail of directory...
Windows Security Logging and Other Esoterica
Deciphering Account Logon Events
Posted
over 7 years ago
by
Eric Fitzgerald
7
Comments
One of the most common questions that I get about Windows Auditing is, how come you guys were so @#%! stupid that you put in two logon categories? The answer is actually pretty simple- we're bad at choosing names. "Account Logon" isn't really about...
Page 1 of 1 (11 items)