Skip to main content

stuza1 .'s Library tagged Security   View Popular

18 Oct 09

SecuriTeam - Windows NT Event Log explained

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 5 By default, NT does not log all the events. You have to enable auditing, to do so follow these steps:
 1- From the Start Menu, choose Program and then Administrative Tools (Common). From the Administrative Tools submenu, choose User Manager, which displays the User Manager window. 2- From User Manager Menu Click POLICIES then Click Audit, the Audit policy window appears 3- Select the Radio Box "Audit These Events" 4- Select what you want and Click OK and Close User Manager.
Auditing of Privileges:Certain privileges in the system are not audited by default even when auditing on privilege use is turned on. This is done to control the growth of audit logs. The privileges are:
 1- Bypass traverse checking *** To Everyone ***. Is granted to everyone so is meaningless from auditing perspective 2- Debug programs *** To Administrators ***. Not used in a working system and can be removed from administrators group 3- Create a token object *** To no one ***. Should not be granted to anyone 4- Replace process level token *** To no one ***. Should not be granted to anyone 5- Generate Security Audits *** To no one ***. Should not be granted to anyone 6- Backup files and directories *** To Administrators Backup Operators ***. Used during normal system operations 7- Restore files and directories *** To Administrators Backup Operators ***. Used during normal system operations
To enable auditing of these privileges, add the following keyHive: HKEY_LOCAL_MACHINE\SYSTEMKey: System\CurrentControlSet\Control\LsaName: FullPrivilegeAuditingType: REG_BINARYValue: 1

www.securiteam.com/...ws_NT_Event_Log_explained.html - Preview

Utillog Security HOT Audit

1 - 20 of 946 Next › Last »
Showing 20 items per page

Highlighter, Sticky notes, Tagging, Groups and Network: integrated suite dramatically boosting research productivity. Learn more »

Join Diigo