Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISSForum] Logon_with_admin_privileges on Server Sensor |
|---|---|
| Date: | Wed, 19 Oct 2005 10:43:39 +0400 |
Hi list. I've submitted enhancements request containing the following: Logon_with_admin_privileges signature is VERY useful, but now it can't be used, because it's triggered for system accounts (machine_name$) as well. In many cases it's this event is not interesting for system accounts, but they can't be filtered because SS can't filter events. I understand that to teaching SS to filter events is may needs great development, so I propose to make to different signatures for USER accounts logons with admin privileges and for SYSTEM accounts logon. Now because of VERY great number of Logon_with_admin_privileges (so it's impossible to find something in that events) I have to switch it off. And receive a very interesting answer - that I have to create validation script on TCL... and if I can't do this by myself ISS could provide me with the script at the price of one day consulting. Thinking in this way we can make a conclusion that because EVERY Windows eventlog event and EVERY text log event can be made by hands, there is no necessity for ISS to provide these events at all :-) So, dear list, maybe someone already solved described problem and already has such validation script for server sensor? Thank you. --- Best regards, Sergey V. Soldatov. Information security department. tel/fax +7 095 745 89 50 tel +7 095 777 77 07 (1613) _______________________________________________ ISSForum mailing list ISSForum@iss.net TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to mod-issforum@iss.net The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISSForum] Testing of ISS Products, Weiss, Mark \(M.A.\) |
|---|---|
| Next by Date: | Re: [ISSForum] Testing of ISS Products, Caulk,Mark A |
| Previous by Thread: | [ISSForum] Testing of ISS Products, Weiss, Mark \(M.A.\) |
| Next by Thread: | Re: [ISSForum] Logon_with_admin_privileges on Server Sensor, John Zeigler |
| Indexes: | [Date] [Thread] [Top] [All Lists] |