Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

Re: audit trails for file access

Subject: Re: audit trails for file access
Date: Mon, 09 Jan 2006 11:16:44 +0100
        Hello,

I was wondering if there are any other file access/modification audit trails
generated apart from the ones which can be set through the security/auditing
tab for a folder's properties.

On a NTFS filesystem, every file has a MAC time
(Modified/Accessed/Created). You should be careful not to modify the
"last accessed" time while investigating an incident (hint: mount the
partition as r/o inside a Linux system).

You can also enable file audit on a file-by-file basis, but be careful
that the system-wide "objet access" audit must be enabled also.


I want to know if there is any kind of logging done by default when a 2003
box is uhh, fresh out of the box.

Audit policy is disabled by default, sorry. If your server has already
been compromised, it is too late.


Also, how can logs be sent to another machine for storage?

As others pointed out : NTSysLog.

Regards,
- Nicolas RUFF

---------------------------------------------------------------------------
---------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>