Sign in
Windows Security Logging and Other Esoterica
thoughts from the Windows auditing team
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
ACS
Descriptions
HowTo
Laws
Malware
News
Previews
Privacy
Rants
SEM
Tips
Tools
Unicode
Archive
Archives
June 2012
(1)
August 2011
(1)
May 2011
(1)
April 2011
(1)
July 2010
(1)
May 2010
(1)
August 2009
(1)
June 2009
(1)
September 2008
(1)
August 2008
(1)
July 2008
(4)
April 2008
(2)
March 2008
(1)
February 2008
(3)
January 2008
(1)
November 2007
(1)
October 2007
(2)
August 2007
(5)
July 2007
(3)
June 2007
(2)
May 2007
(3)
April 2007
(1)
February 2007
(3)
October 2006
(1)
September 2006
(2)
August 2006
(2)
June 2006
(1)
May 2006
(2)
March 2006
(3)
December 2005
(6)
November 2005
(2)
September 2005
(3)
August 2005
(11)
January 2005
(1)
December 2004
(2)
October 2004
(1)
MSDN Blogs
>
Windows Security Logging and Other Esoterica
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Windows Security Logging and Other Esoterica
Tracking User Logon Activity Using Logon Events
Posted
over 5 years ago
by
Eric Fitzgerald
5
Comments
I get the question fairly often, how to use the logon events in the audit log to track how long a user was using their computer and when they logged off. As I have written about previously, this method of user activity tracking is unreliable . It works...
Windows Security Logging and Other Esoterica
Monitoring Group Policy Changes with Windows Auditing
Posted
over 8 years ago
by
Eric Fitzgerald
6
Comments
I spent some time a while back analyzing logs, figuring out what you can do with group policy auditing on Windows Server 2003. I did not test Windows 2000; I suspect that much of this applies but YMMV. GP editing does leave an auditable trail of directory...
Windows Security Logging and Other Esoterica
List of Windows Server 2003 Events
Posted
over 6 years ago
by
Eric Fitzgerald
3
Comments
So a long time ago, back in my days of providing technical support for Windows NT 4.0, I published " Security Event Descriptions ". This article was the "schema" so to speak, for the Windows NT 4.0 security event log events. Technically Windows events...
Windows Security Logging and Other Esoterica
Default ACLs on Windows Event Logs
Posted
over 7 years ago
by
Eric Fitzgerald
4
Comments
A question I get asked frequently: what are the default ACLs on Windows event logs? Here's the answer, straight from the source code with only a little formatting help from me, and in more detail than you probably care to know. Windows 2000: ...
Windows Security Logging and Other Esoterica
Deciphering Account Logon Events
Posted
over 8 years ago
by
Eric Fitzgerald
7
Comments
One of the most common questions that I get about Windows Auditing is, how come you guys were so @#%! stupid that you put in two logon categories? The answer is actually pretty simple- we're bad at choosing names. "Account Logon" isn't really about...
Windows Security Logging and Other Esoterica
Keeping the noise down in your security log
Posted
over 8 years ago
by
Eric Fitzgerald
16
Comments
[2011-04-11] This post was updated to indicate the interaction between these recommendations and the granular audit policy settings which are available in Windows Vista and subsequent releases. EF I commonly hear the complaint that "there's too much...
Windows Security Logging and Other Esoterica
Events 528 and 540
Posted
over 9 years ago
by
Eric Fitzgerald
4
Comments
Logon events. Event 528 and Event 540 are the Logon events. Event 528 is for all logons except "network" logons. "Network" logons are SMB/Microsoft-DS logons (i.e. connecting to a share). RDP, IIS, FTP logons, etc., are event 528 even though credentials...
Windows Security Logging and Other Esoterica
WEvtUtil Scripting
Posted
over 5 years ago
by
Eric Fitzgerald
4
Comments
If you haven't used wevtutil.exe to script event log tasks in Windows Vista or Windows Server 2008, you're missing out. The new tool makes getting events out of the log pretty easy, but the main thing is that it doesn't suffer from any of the drawbacks...
Windows Security Logging and Other Esoterica
Auditing Changes in Windows Server 2003 SP1
Posted
over 9 years ago
by
Eric Fitzgerald
15
Comments
DISCLAIMER: To the best of my knowledge the information here is correct. However the lawyers make me say, that this information is provided "AS-IS" with no warranty, and confers no rights. In other words, if this stuff isn't in SP1, you can't sue us,...
Windows Security Logging and Other Esoterica
The Trouble With Logoff Events
Posted
over 6 years ago
by
Eric Fitzgerald
2
Comments
A lot of you guys probably are using your SEM/SEIM systems to record logon and logoff activity without much of a second thought. I just thought I'd bring one problem to your attention. Logoff events are not strictly reliable. From an engineering...
Windows Security Logging and Other Esoterica
Quick Overview of Object Access Auditing in Windows
Posted
over 7 years ago
by
Eric Fitzgerald
1
Comments
A lot of people are unhappy with object access auditing on Windows, because what they want to know is "who touched the object and what did that person do", but what Windows auditing tells you is actually "who touched the object and what did they ask for...
Windows Security Logging and Other Esoterica
How are object access events generated?
Posted
over 7 years ago
by
Eric Fitzgerald
6
Comments
I wrote this as an answer for Tom, who emailed me, but I thought I'd share it with everyone. There are 7 events associated with object access auditing in Windows: 560 is the "open handle" event. It is logged when an app asks for access to...
Windows Security Logging and Other Esoterica
Windows Server 2008 Security Events Posted
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
Fadi, Ned and Brian of the auditing team have documented all the auditing events by audit policy category and subcategory for your reference. Check it out in the Knowledge Base . Even better, they documented all the events in spreadsheet format...
Windows Security Logging and Other Esoterica
Auditing Changes to Audit Policy
Posted
over 3 years ago
by
Eric Fitzgerald
10
Comments
Mitsuru, one of our support engineers in Japan, actually did some excellent research recently into exactly what our behavior is for auditing audit policy and I wanted to share that with you. In Windows, we've always had auditing for changes to security...
Windows Security Logging and Other Esoterica
ACS Event Transformation Demystified
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
I've decided to start dumping my knowledge of ACS for posterity's sake. My first installment is here, and it's an excerpt from an external email I put together which describes how event transformation works on ACS. Transformation is performed on...
Windows Security Logging and Other Esoterica
Minimizing Directory Service Audit Event Noise
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
I've written before on noise reduction in the Windows security event log. I've also written to describe how object access auditing works . But, I still get questions on how to reduce noise from object access events. The other day I got that question,...
Windows Security Logging and Other Esoterica
You learn something new every day- Logon Type 0
Posted
over 5 years ago
by
Eric Fitzgerald
0
Comments
Today I encountered something new in the logon event- I thought that was old hat and I knew all there was to know about that but I guess I was wrong. The logon event ( 528/540 prior to Windows Vista, 4624 in Vista and Windows Server 2008) has a field...
Windows Security Logging and Other Esoterica
Privilege Use- what do we audit, and when?
Posted
over 8 years ago
by
Eric Fitzgerald
0
Comments
Odd thing today- I got two questions about the obscure " FullPrivilegeAuditing " registry setting- so I thought I'd post my answer. Some of this is not new, I posted on the Windows Server 2003 SP1 changes to auditing a while back. Events ID 577 and...
Windows Security Logging and Other Esoterica
Vista security events get noticed
Posted
over 6 years ago
by
Eric Fitzgerald
5
Comments
Doriansoft noticed that there's a relationship between our pre-Vista security event IDs and our Vista-era security event IDs. For most security events: VistaEventId = PreVistaEventId + 4096 Why is this? We needed to differentiate the Vista events...
Windows Security Logging and Other Esoterica
Documentation on the Windows Vista and Windows Server 2008 Security Events
Posted
over 6 years ago
by
Eric Fitzgerald
4
Comments
I'm hearing lots of complaints that we don't have KB articles on these yet. Doriansoft has a blog post complaining that the " add 4096 " rule doesn't work because we collapsed the logon events into a single success event and failure event (from 2 success...
Windows Security Logging and Other Esoterica
Kickoff post: Windows auditing
Posted
over 9 years ago
by
Eric Fitzgerald
3
Comments
This blog is dedicated to those folks who've Google'd for Windows security event information and found newsgroup posts that I've made in the past. I feel your pain. "Windows Auditing" is what we call the security logging feature of the Windows OS. In...
Windows Security Logging and Other Esoterica
Why does Windows XP generate so many logon failure events?
Posted
over 6 years ago
by
Eric Fitzgerald
2
Comments
I got the question last week, why there are so many logon failure events on Windows XP when it is not domain joined. The short answer is, by design. (Yes, bad design.) The longer answer is that the shell team is working around the fact that there...
Windows Security Logging and Other Esoterica
Help! Someone has deleted events from my Windows event log!
Posted
over 6 years ago
by
Eric Fitzgerald
1
Comments
From time to time I hear this, and it usually turns out not to be the case. I'll begin with a little background. First, The eventlog service does not have (and never did have) any public or private API to delete individual events- there is a log clear...
Windows Security Logging and Other Esoterica
Setting SACLs on Services
Posted
over 8 years ago
by
Eric Fitzgerald
0
Comments
Have you ever wanted a record of admin activity regarding service management? For example, who stopped one of your services? Did you know that you can do this through auditing? It's actually really easy. The "Security Templates" MMC snap-in allows...
Windows Security Logging and Other Esoterica
Delegating Access to the Security Log
Posted
over 8 years ago
by
Eric Fitzgerald
1
Comments
I often get the question, how do I allow a group of auditors read access to my security logs without making them admins and without letting them clear the logs? To answer this, first you need to know, for what version of Windows? Prior to Windows Server...
Page 1 of 4 (78 items)
1
2
3
4