<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Event Log Managment</title>
	<atom:link href="http://ithompson.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ithompson.wordpress.com</link>
	<description>Event Log Managment</description>
	<lastBuildDate>Mon, 23 Nov 2009 21:06:52 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='ithompson.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/a080cdeee8577d11f594a892bb530e3d?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Event Log Managment</title>
		<link>http://ithompson.wordpress.com</link>
	</image>
			<item>
		<title>Directory Services Auditing</title>
		<link>http://ithompson.wordpress.com/2009/11/23/directory-services-auditing/</link>
		<comments>http://ithompson.wordpress.com/2009/11/23/directory-services-auditing/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 21:06:52 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Active Directory auditing]]></category>
		<category><![CDATA[directory services auditing]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=99</guid>
		<description><![CDATA[I&#8217;ve been asked by a customer to take a look at their level of Directory Services Auditing.  I&#8217;m not able to share their screen shots but can scrub an email that I sent to them and post it here.
When it comes to Directory Services Auditing I always tell people less is more, if you already [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=99&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;ve been asked by a customer to take a look at their level of Directory Services Auditing.  I&#8217;m not able to share their screen shots but can scrub an email that I sent to them and post it here.</p>
<p>When it comes to Directory Services Auditing I always tell people less is more, if you already understand what the other audit policies give you then you can get 85% to 90% of what you need from those.  There are somethings that you will have to get via Directory Services Auditing there&#8217;s just no getting around it.  But just as with the case of Object Access be very carefull what you turn on or you will flood yourself with junk noise events.  The major pain is that all events generated by Directory Services use the same event id no matter what action you are doing and are very cryptic.</p>
<p>Here is the email:</p>
<blockquote><p>&#8220; As we talked about on the phone today there is a lot of auditing turned on where Microsoft hasn’t given very much information about what it generates and even some that are currently not used.  Example: Intellimirror-Group is used by remote boot legacy for managing groups of server machines and is currently not used.   Based on the screen shot you sent me I can see that the objects are currently being monitored which are generating a lot of noise events for you.  You might be better suited to audit the properties instead of the objects.  Example, if you want to know when a user has been given access to someone else’s inbox you need to monitor for changes to the property: msExchMailboxSecurityDescriptor; or if you want to know who made a GPO change then you need to monitor for changes to the properties: gpLink and gPOptions.  Most of the information that you can find via MSDN in regards to these audit objects is related to developers and not what the audit trail will give you.  Keep in mind that Microsoft considers the Directory Services auditing a low level audit, so the events that are generated are pretty cryptic in nature and all use the same event id. </p></blockquote>
<blockquote><p> There are a few of the objects that you would want to monitor to help get a more full picture of what is happening such as: Computer, User, OU, Shares, Group objects.  Monitoring these will give you things such as what OU a user was created in, where the Account Mgmt auditing does not give you this.  Also Account Mgmt auditing does not give you OU auditing (as again Microsoft considers this to be a low level object).</p></blockquote>
<blockquote><p> In most companies it’s easy to turn on Auditing but very difficult to get it turned off and this is where Admins get themselves and others into a painful spot.  How to prove what is not needed when Microsoft doesn’t document what the auditing does or doesn’t do.</p></blockquote>
<blockquote><p> Other examples:</p>
<p>msSFU30MailAliases – represents UNIX mail file data</p>
<p>nisMap – contains the generic abstraction of an NIS map</p>
<p>oncRpc – represents an abstraction of the Open Network Computing (ONC) Remote Procedure Call (RPC) binding</p>
<p>msRTCSIP-EdgeProxy – this attribute is reserved for future use</p>
<p>msRTCSIP-TrustedWebComponentsServerData – this attribute is reserved for future use&#8221;</p></blockquote>
<p>Here are a few of the links where I pulled this data from:</p>
<p><a href="http://msdn.microsoft.com/en-us/library/ms680938(VS.85).aspx" target="_blank">http://msdn.microsoft.com/en-us/library/ms680938(VS.85).aspx</a></p>
<p><a href="http://msdn.microsoft.com/en-us/library/ms985886(EXCHG.65).aspx" target="_blank">http://msdn.microsoft.com/en-us/library/ms985886(EXCHG.65).aspx</a></p>
<p><a href="http://technet.microsoft.com/en-us/library/bb663647.aspx" target="_blank">http://technet.microsoft.com/en-us/library/bb663647.aspx</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/99/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=99&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/11/23/directory-services-auditing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Audit Account Logon vs Audit Logon/Logoff</title>
		<link>http://ithompson.wordpress.com/2009/10/05/audit-account-logon-vs-audit-logonlogoff/</link>
		<comments>http://ithompson.wordpress.com/2009/10/05/audit-account-logon-vs-audit-logonlogoff/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 15:00:39 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audit Account Logon]]></category>
		<category><![CDATA[Audit Logon/Logoff]]></category>
		<category><![CDATA[Audit Policy]]></category>
		<category><![CDATA[Audting]]></category>
		<category><![CDATA[Event Log]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Account Logon]]></category>
		<category><![CDATA[Audit Log]]></category>
		<category><![CDATA[Logon/Logoff events]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=94</guid>
		<description><![CDATA[Over the past several years I&#8217;ve been explaining the diffence between these two audit polices.  One is for logon/logoff events the other (Account Logon) is for authentication events.  In the past few months I have had several people ask me to put together a blog entry covering these 2 audit polices.  But I&#8217;ve found it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=94&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Over the past several years I&#8217;ve been explaining the diffence between these two audit polices.  One is for logon/logoff events the other (Account Logon) is for authentication events.  In the past few months I have had several people ask me to put together a blog entry covering these 2 audit polices.  But I&#8217;ve found it rather painfull to put into a blog.   Then a few weeks ago I found out that my employeer (Prism Microsystems) was hosting a webinar with <a href="http://www.ultimatewindowssecurity.com" target="_blank">Randy F. Smith</a> and I was going to also be presenting.   Well the webinar went smoothly today and so I have decided that instead of me doing a long lengthly blog entry I would just post a link to the <a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=72" target="_blank">recorded webinar</a>.  Enjoy and I hope you are able to gain more insight into these 2 Audit Policies.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=94&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/10/05/audit-account-logon-vs-audit-logonlogoff/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Micorsoft Patch Research Site</title>
		<link>http://ithompson.wordpress.com/2009/09/16/micorsoft-patch-research-site/</link>
		<comments>http://ithompson.wordpress.com/2009/09/16/micorsoft-patch-research-site/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 16:17:33 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Microsoft Patches]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=90</guid>
		<description><![CDATA[I was watching a Randy F. Smith webinar today and he showed a section of his website that he uses to track the Microsoft patches.  So I thought this would be good information to share.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=90&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I was watching a Randy F. Smith webinar today and he showed a section of his website that he uses to <a href="http://www.ultimatewindowssecurity.com/patchanalysis/research.aspx" target="_blank">track the Microsoft patches</a>.  So I thought this would be good information to share.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/90/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=90&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/09/16/micorsoft-patch-research-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>More Info on Tracking Down File Deletes</title>
		<link>http://ithompson.wordpress.com/2009/08/05/more-info-on-tracking-down-file-deletes/</link>
		<comments>http://ithompson.wordpress.com/2009/08/05/more-info-on-tracking-down-file-deletes/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 20:52:01 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audit Policy]]></category>
		<category><![CDATA[Event Log]]></category>
		<category><![CDATA[File Deletes]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Object Access]]></category>
		<category><![CDATA[event id 4656]]></category>
		<category><![CDATA[event id 560]]></category>
		<category><![CDATA[File Delete]]></category>
		<category><![CDATA[Object Access Auditing]]></category>
		<category><![CDATA[track file changes]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=85</guid>
		<description><![CDATA[Quite awhile ago I wrote a blog entry on Tracking Down File Deletes, it continues to be one of my most read blogs.  I came across another blog entry that does a good job of explaining the same thing.  The author is Ned Pyle, in his post he covers not only the Windows 2003 but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=85&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Quite awhile ago I wrote a blog entry on <a href="http://ithompson.wordpress.com/2007/09/06/tracking-down-file-deletes/" target="_blank">Tracking Down File Deletes</a>, it continues to be one of my most read blogs.  I came across another blog entry that does a good job of explaining the same thing.  The author is Ned Pyle, in his <a href="http://blogs.technet.com/askds/archive/2009/08/04/tracking-a-remote-file-deletion-back-to-the-source.aspx" target="_blank">post</a> he covers not only the Windows 2003 but also the Windows 2008 auditing so I thought I would share it with you.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/85/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=85&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/08/05/more-info-on-tracking-down-file-deletes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Recommended Windows 2008 Audit Policy</title>
		<link>http://ithompson.wordpress.com/2009/05/27/recommended-windows-2008-audit-policy/</link>
		<comments>http://ithompson.wordpress.com/2009/05/27/recommended-windows-2008-audit-policy/#comments</comments>
		<pubDate>Wed, 27 May 2009 18:24:36 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audit Policy]]></category>
		<category><![CDATA[Windows 2008]]></category>
		<category><![CDATA[Windows 2008 Audit Policy]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=81</guid>
		<description><![CDATA[Randy F. Smith has a good resource for the Windows 2008 Audit Policy.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=81&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Randy F. Smith has a good resource for the <a href="http://www.ultimatewindowssecurity.com/wiki/WindowsSecuritySettings/Recommended-Baseline-Audit-Policy-for-Windows-Server-2008?Keywords=recommended+audit" target="_blank">Windows 2008 Audit Policy</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/81/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=81&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/05/27/recommended-windows-2008-audit-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>IIS status code</title>
		<link>http://ithompson.wordpress.com/2009/05/21/iis-status-code/</link>
		<comments>http://ithompson.wordpress.com/2009/05/21/iis-status-code/#comments</comments>
		<pubDate>Thu, 21 May 2009 14:46:35 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[IIS]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[IIS status code]]></category>
		<category><![CDATA[IIS sub-status codes]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=79</guid>
		<description><![CDATA[Here is a link to some good information about the IIS status / sub-status codes for IIS 5 and 6.
Chris Crowe&#8217;s blog on IIS.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=79&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Here is a link to some good information about the <a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;318380" target="_blank">IIS status / sub-status codes for IIS 5 and 6.</a></p>
<p><a href="http://blog.crowe.co.nz/archive/2005/08/26/231.aspx" target="_blank">Chris Crowe&#8217;s blog</a> on IIS.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/79/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=79&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/05/21/iis-status-code/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Monitoring Network Shares</title>
		<link>http://ithompson.wordpress.com/2009/05/20/monitoring-network-shares/</link>
		<comments>http://ithompson.wordpress.com/2009/05/20/monitoring-network-shares/#comments</comments>
		<pubDate>Wed, 20 May 2009 19:37:36 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audting]]></category>
		<category><![CDATA[Event Log]]></category>
		<category><![CDATA[Object Access]]></category>
		<category><![CDATA[event id 560]]></category>
		<category><![CDATA[monitoring network shares]]></category>
		<category><![CDATA[network shares]]></category>
		<category><![CDATA[Object Access Auditing]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=72</guid>
		<description><![CDATA[I had a discussion today with a customer who was trying to monitor when their users tried to access network shares and failed.  He had all the correct accesses setup, removed &#8220;Everyone&#8221; and gave access to only those groups that needed access.  He even turned on the correct Object Access auditing, but his problem was that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=72&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I had a discussion today with a customer who was trying to monitor when their users tried to access network shares and failed.  He had all the correct accesses setup, removed &#8220;Everyone&#8221; and gave access to only those groups that needed access.  He even turned on the correct Object Access auditing, but his problem was that when anyone outside the correct groups tried to access the folder they got the message that &#8221;  \\&lt;server name&gt;\&lt;share&gt; was not accessable.  You might not have permission &#8230; &#8221; but the Audit Failure 560 events (his server is W2k3) were not being generated. </p>
<p>This is something that I&#8217;ve seen quite often, the issue comes from the  Share Permissions that have been set.  Because he removed the Everyone group from the Share Permission the Audit Failure events for 560 (Object Access Auditing) were not being generated. </p>
<p>So if you need to be able to track when unauthorized users are attempting to access shares for which they do not have access, leave the Everyone group with Read permission under the Share Permissions tab on the folder (as seen in the screen shot below). </p>
<p><img class="aligncenter size-full wp-image-74" title="Share Permission" src="http://ithompson.files.wordpress.com/2009/05/sharepermission1.jpg?w=375&#038;h=519" alt="Share Permission" width="375" height="519" /></p>
<p> </p>
<p>Now on the Security tab make sure that you turn on the correct Object Access auditing  (stay away from FULL CONTROL; you will flood yourself with noise events).  Now since in this example we want to track when people fail to open the network share, goto the Security tab, then click on the Advanced button, then the Auditing tab.  Click the add button and set this auditing for Everyone and check Traverse Folder and List Folder boxes under the Failed column.</p>
<p><img class="aligncenter size-full wp-image-75" title="Audit Settings" src="http://ithompson.files.wordpress.com/2009/05/audit-settings.jpg?w=425&#038;h=536" alt="Audit Settings" width="425" height="536" /></p>
<p>Now when users attempt to open this network share event id 560 Audit Failure event will be generated telling you who, what, when.  Now the from where is not going to be listed in the 560 event but can be tracked down by looking at the Client Logon ID hex code listed in the event description.</p>
<p>Looking at the Object Name will tell you what file/folder the user was trying to access.  If the Image File Name is blank then you know they were attempting to access the resource from the network, if this field has a value then they used the program listed to access the resource locally.  Client User Name will tell you who the user was if they accessed remotely (if they are accessesing locally then look at the Primary User Name).  The Client Logon ID (or Primary Logon ID) will help you link back to the logon event (528 or 540 in the case of W2k3 and older OS).  Looking at the Accesses list we can see the ReadData/ListDirectory which is what we are auditing for.</p>
<p><img class="aligncenter size-full wp-image-76" title="560 Failure" src="http://ithompson.files.wordpress.com/2009/05/560-failure.jpg?w=401&#038;h=610" alt="560 Failure" width="401" height="610" /></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/72/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=72&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/05/20/monitoring-network-shares/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>

		<media:content url="http://ithompson.files.wordpress.com/2009/05/sharepermission1.jpg" medium="image">
			<media:title type="html">Share Permission</media:title>
		</media:content>

		<media:content url="http://ithompson.files.wordpress.com/2009/05/audit-settings.jpg" medium="image">
			<media:title type="html">Audit Settings</media:title>
		</media:content>

		<media:content url="http://ithompson.files.wordpress.com/2009/05/560-failure.jpg" medium="image">
			<media:title type="html">560 Failure</media:title>
		</media:content>
	</item>
		<item>
		<title>Detecting Insider Threats</title>
		<link>http://ithompson.wordpress.com/2009/04/29/detecting-insider-threats/</link>
		<comments>http://ithompson.wordpress.com/2009/04/29/detecting-insider-threats/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 18:29:07 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audting]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[insider hacks]]></category>
		<category><![CDATA[insider threats]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=64</guid>
		<description><![CDATA[Over the last few weeks I have been putting together a whitepaper on detecting insider threats (on a Windows network).  The paper is finished and is available here.  In the next few days I will be setting up a webinar that will cover this topic watch www.prismmicrosys.com for a link to the webinar.
   [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=64&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Over the last few weeks I have been putting together a whitepaper on detecting insider threats (on a Windows network).  The paper is finished and is available <a title="Detecting Insider Threats Whitepaper" href="http://www.prismmicrosys.com/whitepapers.php?id=272&amp;download=true" target="_blank">here</a>.  In the next few days I will be setting up a webinar that will cover this topic watch <a href="http://www.prismmicrosys.com">www.prismmicrosys.com</a> for a link to the webinar.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/64/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=64&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/04/29/detecting-insider-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Tips on Tracking Down a Hack Attempt</title>
		<link>http://ithompson.wordpress.com/2009/03/20/tips-on-tracking-down-a-hack-attempt/</link>
		<comments>http://ithompson.wordpress.com/2009/03/20/tips-on-tracking-down-a-hack-attempt/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 18:54:46 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[detecting a hack attempt]]></category>
		<category><![CDATA[tracking down a hack]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=53</guid>
		<description><![CDATA[On Tuesday March 17, 2009 I conducted a webinar for Prism Microsystems on how Log Management can help you track down a hack attempt.  Now I know there are multiple ways to hack a network, the purpose of this webinar was to show that if you are collecting the log data from ALL your sources, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=53&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>On Tuesday March 17, 2009 I conducted a webinar for Prism Microsystems on how Log Management can help you track down a hack attempt.  Now I know there are multiple ways to hack a network, the purpose of this webinar was to show that if you are collecting the log data from ALL your sources, network equipment/Unix/Linux/Windows that you can track down these attempts very quickly.  Log Management can also help you become more proactive vs always being reactive.  Here is a link to the recorded version of the <a title="Detecting a Hack Attempt" href="http://www.prismmicrosys.com/webinarDetails.php?id=271&amp;a=view" target="_blank">webinar</a>, here is a link for the <a title="Detecing a Hack Attempt Slides" href="http://www.prismmicrosys.com/documents/Detecting%20a%20Hack.pdf" target="_blank">slides</a> used in the webinar.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/53/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=53&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/03/20/tips-on-tracking-down-a-hack-attempt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8216;Tigger&#8217;/Syzor Trojan</title>
		<link>http://ithompson.wordpress.com/2009/03/06/tiggersyzor-trojan/</link>
		<comments>http://ithompson.wordpress.com/2009/03/06/tiggersyzor-trojan/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 20:25:20 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Misc]]></category>
		<category><![CDATA[tigger trojan; syzor trojan]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=51</guid>
		<description><![CDATA[Good article at darkreading.com about the &#8216;Tigger&#8217;/Syzor Trojan written by Tim Wilson.  In this article he points to a blog by Michael Kassner with more info on &#8216;Tigger&#8217;/Syzor trojan.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=51&subd=ithompson&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Good article at darkreading.com about the <a href="http://www.darkreading.com/security/attacks/showArticle.jhtml;jsessionid=PHCWYQADU3OWEQSNDLRSKHSCJUNN2JVN?articleID=215800583" target="_blank">&#8216;Tigger&#8217;/Syzor Trojan </a>written by Tim Wilson.  In this article he points to a <a href="http://blogs.techrepublic.com.com/security/?p=960" target="_blank">blog</a> by Michael Kassner with more info on &#8216;Tigger&#8217;/Syzor trojan.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/51/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&blog=1623620&post=51&subd=ithompson&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/03/06/tiggersyzor-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
	</channel>
</rss>