Sign in
Windows Security Logging and Other Esoterica
thoughts from the Windows auditing team
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
ACS
Descriptions
HowTo
Laws
Malware
News
Previews
Privacy
Rants
SEM
Tips
Tools
Unicode
Archive
Archives
June 2012
(1)
August 2011
(1)
May 2011
(1)
April 2011
(1)
July 2010
(1)
May 2010
(1)
August 2009
(1)
June 2009
(1)
September 2008
(1)
August 2008
(1)
July 2008
(4)
April 2008
(2)
March 2008
(1)
February 2008
(3)
January 2008
(1)
November 2007
(1)
October 2007
(2)
August 2007
(5)
July 2007
(3)
June 2007
(2)
May 2007
(3)
April 2007
(1)
February 2007
(3)
October 2006
(1)
September 2006
(2)
August 2006
(2)
June 2006
(1)
May 2006
(2)
March 2006
(3)
December 2005
(6)
November 2005
(2)
September 2005
(3)
August 2005
(11)
January 2005
(1)
December 2004
(2)
October 2004
(1)
MSDN Blogs
>
Windows Security Logging and Other Esoterica
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Windows Security Logging and Other Esoterica
Farewell for now...
Posted
11 months ago
by
Eric Fitzgerald
0
Comments
I have resigned from Microsoft and am moving to another company. I hope my blog has been helpful to you all! Feel free to contact me at my hotmail address (eric_fitzgerald). I'll be up and blogging somewhere else soon. Best regards, Eric
Windows Security Logging and Other Esoterica
Off Topic: Unicode Right-to-Left Override character used by malware
Posted
over 2 years ago
by
Eric Fitzgerald
1
Comments
Here's an interesting thing for you security types to be aware of. Many of you probably are careful to screen attachment types to make sure that you don't unintentionally execute code that might be malicious. Malware authors have discovered that by...
Windows Security Logging and Other Esoterica
An interesting logging regulation that doesn't apply to Windows event logs...
Posted
over 2 years ago
by
Eric Fitzgerald
3
Comments
I was browsing around looking for logging regulations and stumbled across this . It's the United State's federal regulation on EDRs - Event Data Recorders - installed in automobiles. EDRs are little log engines, like the "black box" flight data recorders...
Windows Security Logging and Other Esoterica
Decoding UAC Flags Values in events 4720, 4738, 4741, and 4742
Posted
over 2 years ago
by
Eric Fitzgerald
0
Comments
In Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2, there are four events that contain a user account control (UAC) flags value: 4720 - user account creation 4738 - user account change 4741 - computer account creation...
Windows Security Logging and Other Esoterica
Auditing Changes to Audit Policy
Posted
over 3 years ago
by
Eric Fitzgerald
10
Comments
Mitsuru, one of our support engineers in Japan, actually did some excellent research recently into exactly what our behavior is for auditing audit policy and I wanted to share that with you. In Windows, we've always had auditing for changes to security...
Windows Security Logging and Other Esoterica
XPath to generate a list of NTLM authentications on Windows Vista or Later
Posted
over 3 years ago
by
Eric Fitzgerald
0
Comments
Hi Everyone, Sas sent me an email complaining that I am not posting as often as I should- sorry about that. I am working on a different project now but I am still in close touch with the auditing team and I'll try to do better. Anyway a question...
Windows Security Logging and Other Esoterica
Auditing system impact on performance
Posted
over 4 years ago
by
Eric Fitzgerald
0
Comments
UPDATE 2010-06-06 (EricF) - Fixed Vista+ architecture image; link was broken on migration to new blog platform I get questions from time to time, such as my recent offline question from Steve, about what performance impact auditing has on the system...
Windows Security Logging and Other Esoterica
Mapping pre-Vista Security Event IDs to Security Event IDs in Vista+
Posted
over 4 years ago
by
Eric Fitzgerald
1
Comments
I've written twice ( here and here ) about the relationship between the "old" event IDs (5xx-6xx) in WS03 and earlier versions of Windows, and between the "new" security event IDs (4xxx-5xxx) in Vista and beyond. In short, EventID(WS03) + 4096 = EventID...
Windows Security Logging and Other Esoterica
Minimizing Directory Service Audit Event Noise
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
I've written before on noise reduction in the Windows security event log. I've also written to describe how object access auditing works . But, I still get questions on how to reduce noise from object access events. The other day I got that question,...
Windows Security Logging and Other Esoterica
Tracking User Logon Activity Using Logon Events
Posted
over 5 years ago
by
Eric Fitzgerald
5
Comments
I get the question fairly often, how to use the logon events in the audit log to track how long a user was using their computer and when they logged off. As I have written about previously, this method of user activity tracking is unreliable . It works...
Windows Security Logging and Other Esoterica
ACS Event Retention Mechanism
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
I get a lot of questions about how ACS event retention works. So here you go, I'm blogging it so I can just answer with a link :-) There are two DWORD registry values which affect backlog transmission. Both are on the collector machine under HKLM\System...
Windows Security Logging and Other Esoterica
ACS' first bug from being too performant
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
We got several reports recently of a bug in ACS that certain DS Access events, primarily for dnsNode and dnsZone objects, don't properly get looked up. Some background: the event log in Windows prefers to log invariants such as message IDs, parameter...
Windows Security Logging and Other Esoterica
If you're gonna herd bots, do it from New Zealand!
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
A judge in New Zealand declined to convict the admitted (guilty plea) botherder of a million-bot botnet, citing the negative consequences a conviction would have on the young man's future prospects. See the story here . Well duh. The whole theory of...
Windows Security Logging and Other Esoterica
WEvtUtil Scripting
Posted
over 5 years ago
by
Eric Fitzgerald
4
Comments
If you haven't used wevtutil.exe to script event log tasks in Windows Vista or Windows Server 2008, you're missing out. The new tool makes getting events out of the log pretty easy, but the main thing is that it doesn't suffer from any of the drawbacks...
Windows Security Logging and Other Esoterica
Ned on Auditing
Posted
over 5 years ago
by
Eric Fitzgerald
1
Comments
I often talk about Ned, who is the current subject matter expert in Microsoft product support for the auditing feature in the US (Fadi is your guy in the Middle East and we have a couple of guys in Europe). Well, Ned has a blog and I thought I'd point...
Windows Security Logging and Other Esoterica
Windows Server 2008 Security Events Posted
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
Fadi, Ned and Brian of the auditing team have documented all the auditing events by audit policy category and subcategory for your reference. Check it out in the Knowledge Base . Even better, they documented all the events in spreadsheet format...
Windows Security Logging and Other Esoterica
Shameless Self-Promotion
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
There's one topic that I know is on everyone's mind- no, not American Idol - it's "What's new in Auditing in Windows Server 2008?" Well, funny that you brought that up. My friend Jesper Johanssen just wrote a new book, the Windows Server 2008 Security...
Windows Security Logging and Other Esoterica
ACS Event Transformation Demystified
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
I've decided to start dumping my knowledge of ACS for posterity's sake. My first installment is here, and it's an excerpt from an external email I put together which describes how event transformation works on ACS. Transformation is performed on...
Windows Security Logging and Other Esoterica
You learn something new every day- Logon Type 0
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
Today I encountered something new in the logon event- I thought that was old hat and I knew all there was to know about that but I guess I was wrong. The logon event ( 528/540 prior to Windows Vista, 4624 in Vista and Windows Server 2008) has a field...
Windows Security Logging and Other Esoterica
ACS Tidbits
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
Well there has been a lot happening on my old project, ACS (Audit Collection Services, a feature of SystemCenter Operations Manager 2007 ). Two more of our partners, Enterprise Certified and NetPro , have released compliance solutions on top of ACS...
Windows Security Logging and Other Esoterica
I always wondered who Björn was...
Posted
over 5 years ago
by
Eric Fitzgerald
1
Comments
OK here's something I just remembered today. I may be the last person who remembers this so it's important that I record this somewhere. In the RTM bits of Windows NT 4.0, for the German language release only, someone snuck in a string resource into...
Windows Security Logging and Other Esoterica
Why does Windows XP generate so many logon failure events?
Posted
over 6 years ago
by
Eric Fitzgerald
2
Comments
I got the question last week, why there are so many logon failure events on Windows XP when it is not domain joined. The short answer is, by design. (Yes, bad design.) The longer answer is that the shell team is working around the fact that there...
Windows Security Logging and Other Esoterica
List of Windows Server 2003 Events
Posted
over 6 years ago
by
Eric Fitzgerald
3
Comments
So a long time ago, back in my days of providing technical support for Windows NT 4.0, I published " Security Event Descriptions ". This article was the "schema" so to speak, for the Windows NT 4.0 security event log events. Technically Windows events...
Windows Security Logging and Other Esoterica
German court bans retention of logged IP addresses
Posted
over 6 years ago
by
Eric Fitzgerald
1
Comments
A German court has ruled that a government web site may not retain IP addresses and other personally identifiable information (PII) in their logs for any longer than the user is actually using the site. The judges pointed out that in many cases it...
Windows Security Logging and Other Esoterica
Ensuring that there's no useful data in your logs...
Posted
over 6 years ago
by
Eric Fitzgerald
0
Comments
As I wrote about earlier, TorrentSpy, a file-sharing search engine, was ordered by a U.S. magistrate to enable logging on its servers and to subsequently make those logs available to the MPAA, the plaintiff in an illegal file-sharing lawsuit against TorrentSpy...
Page 1 of 4 (78 items)
1
2
3
4