Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: User creation audit trail |
|---|---|
| Date: | Thu, 24 Aug 2006 10:00:53 -0400 |
Do you use GFI event log watcher for all your workstations? Or just servers? -----Original Message----- From: Greg Merideth [mailto:gmerideth@uclnj.com] Sent: Wednesday, August 23, 2006 12:47 PM To: Lee Clemens; focus-ms@securityfocus.com Subject: RE: User creation audit trail I believe event ID 645 is the creation of a user account in the domain. I use the GFI event log watcher and track that event on the network. -----Original Message----- From: Lee Clemens [mailto:lee@leeclemens.net] Sent: Tuesday, August 22, 2006 9:26 PM To: focus-ms@securityfocus.com Subject: User creation audit trail Hello all, I am trying to find a way to verify and when and by whom a user was created on a Domain computer. The account was created on the local machine, so I'm wondering if it is captured in the event log somewhere. And perhaps what the event ID is for that, or anywhere else I could find out?? Thanks in advance, Lee Clemens ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ --- ------------------------------------------------------------------------ --- _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ NOTICE: This email is business confidential. If received in error, please destroy this email and notify sender immediately. Sender does not waive confidentiality, or privilege and use is prohibited. --------------------------------------------------------------------------- ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Whole disk encryption, Erik Anderson |
|---|---|
| Next by Date: | RE: Whole disk encryption, Michael Mooney |
| Previous by Thread: | RE: User creation audit trail, Greg Merideth |
| Next by Thread: | RE: User creation audit trail, Greg Merideth |
| Indexes: | [Date] [Thread] [Top] [All Lists] |