<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Event Log Managment</title>
	<atom:link href="http://ithompson.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ithompson.wordpress.com</link>
	<description>Logs .. Logs and More Logs</description>
	<lastBuildDate>Thu, 08 Dec 2011 14:23:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ithompson.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Event Log Managment</title>
		<link>http://ithompson.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ithompson.wordpress.com/osd.xml" title="Event Log Managment" />
	<atom:link rel='hub' href='http://ithompson.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Logging, Logging</title>
		<link>http://ithompson.wordpress.com/2011/12/02/logging-logging/</link>
		<comments>http://ithompson.wordpress.com/2011/12/02/logging-logging/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 04:14:16 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audting]]></category>
		<category><![CDATA[Event Log]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Audit Log]]></category>
		<category><![CDATA[Audit Policy]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[detecting a hack attempt]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=193</guid>
		<description><![CDATA[Here lately we’ve been hearing a lot about Stuxnet and Duqu.  Well this week is no different, but there is some insight into how one of these could have been slowed down if not prevented.  In an article released on Nov 30, 2011 at eWeek.com, Duqu Attackers Wiped All Linux CandC Servers to Cover Tracks, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=193&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here lately we’ve been hearing a lot about Stuxnet and Duqu.  Well this week is no different, but there is some insight into how one of these could have been slowed down if not prevented.  In an article released on Nov 30, 2011 at eWeek.com, <a href="http://www.eweek.com/c/a/Security/Duqu-Attackers-Wiped-All-Linux-CC-Servers-to-Cover-Tracks-475981/">Duqu Attackers Wiped All Linux CandC Servers to Cover Tracks</a>, there are some good insights even though it’s almost just a side note.  The article mainly discusses what the Duqu attackers did to help cover their tracks.  The part of the article that caught my eye was the last paragraph.</p>
<blockquote>
<p style="text-align:center;" align="center"><em>Even though there was a possibility of a zero-day, the researchers thought it was more likely that the servers&#8217; root passwords were brute-forced, based on a log of a user attempting to log in as root multiple times over an 8-minute period from an IP address in Singapore before finally succeeding.</em></p>
</blockquote>
<p>It all comes down to logging and then doing something with those logs.  Having a solution (<a href="http://www.logrhythm.com/">www.logrhythm.com</a>) that can help point out these types of items is critical.  Just to have logging turned on gets you nothing, you need to do something with these logs.  Having a solution in place and watching for anomalies like this could have helped to slow Duqu down.  Logs won’t stop the attackers but if we are being proactive and watching (with the correct solution) we would at least slow them down some.</p>
<p>As this also shows that attackers aren’t worried about people logging their activities because they know most organizations/admins aren’t doing anything with the logs until well after the fact.</p>
<p>One of the things that you need to be asking your SIEM/Log Management provider is how would they have picked up on something like this?  Can it be correlated/detected that it was coming from the same IP address and repeated attempts?  Most SIEM/Log Management vendors will tell you “sure we can do that”.  Well my next question would be: What if this was across multiple Operating Systems, could you detect it then?  Now for my shameless plug, with LogRhythm the answer is yes.  Some vendors expect you to be a subject matter expert across all Operating Systems, network devices and applications.  With LogRhythm you don’t need to be, our normalization handles that for you.  We can take being proactive to the next level with <a href="http://blog.logrhythm.com/tags/advanced-correlation/">advanced correlation</a> and <a href="http://www.logrhythm.com/Products/SmartRemediation.aspx">Smart<strong>Remediation</strong></a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/193/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=193&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2011/12/02/logging-logging/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Event Triggers</title>
		<link>http://ithompson.wordpress.com/2011/05/31/event-triggers/</link>
		<comments>http://ithompson.wordpress.com/2011/05/31/event-triggers/#comments</comments>
		<pubDate>Tue, 31 May 2011 15:32:20 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Event Log]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[event log alarms]]></category>
		<category><![CDATA[event log alerts]]></category>
		<category><![CDATA[event triggers]]></category>
		<category><![CDATA[Event Viewer]]></category>
		<category><![CDATA[EventViewer]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=173</guid>
		<description><![CDATA[I have been asked this question several times so I thought it would be a good time to answer it via a blog post for everyone to use. &#8220;How can I set the Windows Event Viewer to trigger when a certain event happens?&#8221;  Well if you want to set a trigger for something very simple [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=173&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I have been asked this question several times so I thought it would be a good time to answer it via a blog post for everyone to use.</p>
<p>&#8220;How can I set the Windows Event Viewer to trigger when a certain event happens?&#8221; </p>
<p>Well if you want to set a trigger for something very simple such as &#8216;when anyone logs in&#8217; or &#8216;when an account gets created&#8217; that is very simple.  Just right click on the event in the EventViewer and select &#8220;Attach Task to This Event&#8230;&#8221;, then select if you want Windows to launch a program, send an email or display a message. </p>
<p><a href="http://ithompson.files.wordpress.com/2011/05/eventtrigger.jpg"><img class="alignleft size-medium wp-image-175" title="EventTrigger" src="http://ithompson.files.wordpress.com/2011/05/eventtrigger.jpg?w=300&#038;h=204" alt="" width="300" height="204" /></a></p>
<p><a href="http://ithompson.files.wordpress.com/2011/05/eventtrigger-action.jpg"><img class="alignleft size-medium wp-image-176" title="EventTrigger Action" src="http://ithompson.files.wordpress.com/2011/05/eventtrigger-action.jpg?w=300&#038;h=205" alt="" width="300" height="205" /></a></p>
<p>It&#8217;s that quick and easy if you want to look for something simple.  Now the question &#8220;when anyone logs in&#8221; is not quite so easy.  Becuase if you recall from an earlier blog post, there are different <a title="Windows Logon Types" href="http://ithompson.wordpress.com/2008/06/06/windows-logon-types/" target="_blank">types of logins</a>.  So if we just look for logins we will be flooded with triggers because of all the network (type 3) and service (type 5) logins that happen all day everyday. </p>
<p> The question that arrises most often is &#8220;Can event viewer let me know when someone does a remote desktop to one of my servers?&#8221;  The answer to that is no.  Take the following screen shot for example.</p>
<p><a href="http://ithompson.files.wordpress.com/2011/05/eventtrigger-callout.jpg"><img class="alignleft size-medium wp-image-177" title="eventtrigger - callout" src="http://ithompson.files.wordpress.com/2011/05/eventtrigger-callout.jpg?w=300&#038;h=204" alt="" width="300" height="204" /></a></p>
<p>Microsoft doesn&#8217;t give us the ability to look for anything in the event message body, such as the logon type.   But wait you say, EventViewer can do a trigger that will launch a program or script, we can just do it that way.  Not so fast, the program option doesn&#8217;t pass the event to the program or script.  So we are unable to parse the message for our logon type or other information.</p>
<p>So the next question comes, how can we trigger (alarm/alert) for specific information that is located in the event message.  Well you have 2 options, 1st is to write your own script (or get one from the internet) that will parse the Event Log and look for your information.  2nd would be to use a SIEM/Log Management tool such as <a title="LogRhythm" href="http://www.logrhythm.com" target="_blank">LogRhythm</a>.   Having done manual log management (and via scripts) for many years this could be a painful option.  I&#8217;ve been in the SIEM/Log Management business since 2004, I can tell you that many Admins have benefited from letting someone else doing all the heavy lifting of gathering the logs and then setting up alarms very quickly to do just what people have been asking me.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/173/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=173&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2011/05/31/event-triggers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>

		<media:content url="http://ithompson.files.wordpress.com/2011/05/eventtrigger.jpg?w=300" medium="image">
			<media:title type="html">EventTrigger</media:title>
		</media:content>

		<media:content url="http://ithompson.files.wordpress.com/2011/05/eventtrigger-action.jpg?w=300" medium="image">
			<media:title type="html">EventTrigger Action</media:title>
		</media:content>

		<media:content url="http://ithompson.files.wordpress.com/2011/05/eventtrigger-callout.jpg?w=300" medium="image">
			<media:title type="html">eventtrigger - callout</media:title>
		</media:content>
	</item>
		<item>
		<title>Webinar and Training Video links</title>
		<link>http://ithompson.wordpress.com/2010/07/01/webinar-and-training-video-links/</link>
		<comments>http://ithompson.wordpress.com/2010/07/01/webinar-and-training-video-links/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 16:58:54 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Webinars]]></category>
		<category><![CDATA[training videos]]></category>
		<category><![CDATA[webinars]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=113</guid>
		<description><![CDATA[A few days ago I was asked by a customer if I had links to all of the webinars and training videos that I put togther or been apart off.  So I have started to put together that list.  The first group is for webinars hosted on the LogRhythm website; the 2nd group are webinars that I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=113&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A few days ago I was asked by a customer if I had links to all of the webinars and training videos that I put togther or been apart off.  So I have started to put together that list.  The first group is for webinars hosted on the LogRhythm website; the 2nd group are webinars that I have conducted with Randy F. Smith and hosted at UltimateWindowsSecurity.com; the last group is a webinar I did for WhiteHat World.  As I conduct more webinars and training sessions I will add them to the list.</p>
<p><strong>LogRhythm</strong></p>
<p>Sept 15, 2011</p>
<p><a title="HIPAA &amp; HITECH Act" href="http://ecrm.logrhythm.com/HIPAAHITECHActwithLockstepTechnologyGroup.html" target="_blank">HIPAA &amp; HITECH Act | Get ready for Tougher Privacy, Security Rules and Enforcement<br />
</a></p>
<p><strong>Prism Microsystems</strong></p>
<p>**Feb 14, 2011; Do to some unforseen issues at Prism I can no longer in good faith promote their product or services and I have removed all links to their website.</p>
<p><strong>Ultimate Windows Security</strong></p>
<p>Hosted By Randy F. Smith</p>
<p>December 2, 2010</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=116">5 Real World Ways to Use Anomaly Detection with Security Logs </a></p>
<p>November 11, 2010</p>
<p><a href="https://www.ultimatewindowssecurity.com/webinars/register.aspx?id=114">Auditing IIS with the Windows Security Log </a></p>
<p>October 14, 2010</p>
<p><a href="/webinars/register.aspx?id=111">Building a Security Dashboard for Your Senior Executives </a></p>
<p>June 30, 2010</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=101">Taming SharePoint Audit Logs with LOGbinder SP and EventTracker </a></p>
<p>June 23, 2010</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=100">Top 5 Daily Reports for Monitoring Windows Servers </a></p>
<p>May 6, 2010</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=91">Configuring Windows Audit Policy to Minimize Noise: Provide Compliance, Support Forensics and Detect Intrusions </a></p>
<p>March 4, 2010</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=84">Security Log Exposed: Auditing Changes, Deletions and Creations in Active Directory </a></p>
<p>February 4, 2010</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=80">Insider Gone Bad: Tracking Their Steps and Building Your Case with the Security Log </a></p>
<p>October 1, 2009</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=72">Security Log Exposed: What is the Difference Between “Account Logon” and “Logon/Logoff” Events? </a></p>
<p>July 23, 2009</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=62">Using Windows Server 2008&#8242;s New Log Management Features: Archival, Forwarding, Views and Triggers </a></p>
<p>May 14, 2009</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=53">Top 9 Ways to Detect Insider Abuse with the Security Log </a></p>
<p>March 19, 2009</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=50">Leveraging the XP and Vista Security Logs to Ensure Workstation Security and Compliance </a></p>
<p>January 20, 2009</p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=32">Anatomy of a Hack: Tracking an Intruder with Security Logs </a></p>
<p><strong>WhiteHat World</strong></p>
<p>February 10, 2009</p>
<p><a href="https://whitehatworldevents.webex.com/ec0605lb/eventcenter/recording/recordAction.do?theAction=poprecord&amp;actname=%2Feventcenter%2Fframe%2Fg.do&amp;actappname=ec0605lb&amp;renewticket=0&amp;renewticket=0&amp;apiname=lsr.php&amp;entappname=url0107lb&amp;needFilter=false&amp;&amp;isurlact=t">Security Beyond the Windows Event Log – Monitoring Ten Critical Conditions</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=113&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2010/07/01/webinar-and-training-video-links/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Inside and Outside Hack Attempts</title>
		<link>http://ithompson.wordpress.com/2010/03/03/inside-and-outside-hack-attempts/</link>
		<comments>http://ithompson.wordpress.com/2010/03/03/inside-and-outside-hack-attempts/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 16:48:01 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audit Policy]]></category>
		<category><![CDATA[Audting]]></category>
		<category><![CDATA[Event Log]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Audit Log]]></category>
		<category><![CDATA[detecting a hack attempt]]></category>
		<category><![CDATA[insider hacks]]></category>
		<category><![CDATA[insider threats]]></category>
		<category><![CDATA[outside hacks]]></category>
		<category><![CDATA[windows audit policy]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=109</guid>
		<description><![CDATA[Over the last several years I have conducted quite a few webinars with Randy F. Smith on a variety of topics that relate to Windows Audit Policies and Log Management.  Two of these truly drive home the point about why you need to be looking at your logs (not just Windows but all sources; *NIX and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=109&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Over the last several years I have conducted quite a few webinars with <a href="http://www.ultimatewindowssecurity.com" target="_blank">Randy F. Smith</a> on a variety of topics that relate to Windows Audit Policies and Log Management.  Two of these truly drive home the point about why you need to be looking at your logs (not just Windows but all sources; *NIX and Network Devices as well).  The first of these was conducted on Jan 20, 2009 entitled &#8220;<a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=32" target="_blank">Anatomy of a Hack: Tracking an Intruder with Security Logs</a>&#8221; and most recently on Feb 4, 2010 entitled &#8220;<a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=80" target="_blank">Insider Gone Bad: Tracking Their Steps and Building Your Case with the Security Log </a>&#8220;.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/109/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/109/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/109/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=109&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2010/03/03/inside-and-outside-hack-attempts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>New Website: Security Scoreboard</title>
		<link>http://ithompson.wordpress.com/2010/02/23/new-website-security-scoreboard/</link>
		<comments>http://ithompson.wordpress.com/2010/02/23/new-website-security-scoreboard/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 16:14:02 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=107</guid>
		<description><![CDATA[For those of us who are on a constant lookout for security tools a new website has been started, Security Scoreboard. From the About page Security Scoreboard was launched in 2010 for CISOs, CIOs, IT managers, and anyone with IT security challenges. It helps busy IT security professionals cut through the flood of press releases when [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=107&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>For those of us who are on a constant lookout for security tools a new website has been started, <a href="http://www.securityscoreboard.com/" target="_blank">Security Scoreboard</a>.</p>
<p>From the About page</p>
<blockquote><p>Security Scoreboard was launched in 2010 for CISOs, CIOs, IT managers, and anyone with IT security challenges. It helps busy IT security professionals cut through the flood of press releases when researching a security vendor online. By providing a central resource to start researching IT security vendors, Security Scoreboard aims to provide a vital resource for anyone starting to research information security solutions for their organization.</p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/107/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/107/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/107/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=107&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2010/02/23/new-website-security-scoreboard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Tracking RDP Logons</title>
		<link>http://ithompson.wordpress.com/2009/12/01/tracking-rdp-logons/</link>
		<comments>http://ithompson.wordpress.com/2009/12/01/tracking-rdp-logons/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 19:35:21 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audit Logon/Logoff]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[event id 682]]></category>
		<category><![CDATA[event id 683]]></category>
		<category><![CDATA[RDP Logons]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=102</guid>
		<description><![CDATA[Earlier this week a customer asked me the following question: We came across a scenario where one of our sessions that we need to track events on, recorded only 683 events (rdp logoff) but zero 682 events (rdp logon). I put together a detailed email explaining to him why/what was really happening and thought it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=102&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Earlier this week a customer asked me the following question:</p>
<blockquote><p><em>We came across a scenario where one of our sessions that we need to track events on, recorded only 683 events (rdp logoff) but zero 682 events (rdp logon).</em></p></blockquote>
<p>I put together a detailed email explaining to him why/what was really happening and thought it would be good to share.</p>
<blockquote><p>I want to clarify event id 682 for you, it’s not a RDP Logon event, it’s a Session Reconnected event.  That’s why you see 683 events without any 682 events.</p>
<p> If you want to track when someone logs onto a system via RDP you need to look for event id 528 with a logon type of 10.</p>
<p> So here is what you can expect to see in the logs (all of these events are in the Security log on the system SERVER1):</p>
<p> At 9:22 am Isaac remotes into Server1:</p>
<p>Event ID: 528</p>
<p> Successful Logon:<br />
  User Name: isaac<br />
  Domain: XXXXXXXX<br />
  Logon ID: (0&#215;0,0x<span style="color:#3366ff;">2505AC69</span>)<br />
  <span style="color:#ffff00;">Logon Type: 10</span><br />
  Logon Process: User32<br />
  Authentication Package: Negotiate<br />
  Workstation Name: SERVER1<br />
  Logon GUID: {f9c49597-2dcc-19cb-32cb-89a0e776ec9c}<br />
  Caller User Name: SERVER1$<br />
  Caller Domain: XXXXXXXX<br />
  Caller Logon ID: (0&#215;0,0x3E7)<br />
  Caller Process ID: 2380<br />
  Transited Services: -<br />
  Source Network Address: xxx.xxx.xxx.145<br />
  Source Port: 18573</p>
<p> Then at 9:42:06 am Isaac clicks the “X” in the upper corner of the RDP session (does not logout, but disconnects)</p>
<p>Event ID: 683</p>
<p> Session disconnected from winstation:<br />
  User Name: isaac<br />
  Domain: XXXXXXXX<br />
  Logon ID: (0&#215;0,0x<span style="color:#3366ff;">2505AC69</span>)<br />
  Session Name: RDP-Tcp#1<br />
  Client Name: Workstation1<br />
  Client Address: xxx.xxx.xxx.145</p>
<p> Then at 9:42:37 am Isaac re-connects to the RDP session on Server1</p>
<p>Event ID: 682</p>
<p> Session reconnected to winstation:<br />
  User Name: isaac<br />
  Domain: XXXXXXXX<br />
  Logon ID: (0&#215;0,0x<span style="color:#3366ff;">2505AC69</span>)<br />
  Session Name: RDP-Tcp#2<br />
  Client Name: Workstation1<br />
  Client Address: xxx.xxx.xxx.145</p>
<p> Then at 11:56 am Isaac logs off the RDP session</p>
<p>Event ID: 551</p>
<p> User initiated logoff:<br />
  User Name: isaac<br />
  Domain: XXXXXXXX<br />
  Logon ID: (0&#215;0,0x<span style="color:#3366ff;">2505ac69</span>)</p>
<p> Now let’s analyze how we tie all these together.  The 1<sup>st</sup> event the 528 tells us how the connection was established, Logon Type: 10 (highlighted in yellow) which is a RemoteInteractive (aka RDP or Terminal Session) (for other logon types see this <a href="http://ithompson.wordpress.com/2008/06/06/windows-logon-types/" target="_blank">list</a>).  This event also confirms that the RDP session was done to a system called Server1 (noted in the Workstation Name line), it also tells us from which system the RDP session was done xxx.xxx.xxx.145 (the Source Network Address line).  We also get the Logon ID which is a HEX code (highlighted in blue).  This Logon ID allows us to connect all of the activity that Isaac does while the RDP session is active (with the right auditing turned on), we can track what files/folders were touched, what processes were launched, etc.  It also allows us to tell if he disconnects (683) or logs off (551) the RDP session.  If he disconnects we can then also track when he reconnects (682).</p></blockquote>
<p>Hope this helps.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/102/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=102&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/12/01/tracking-rdp-logons/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Directory Services Auditing</title>
		<link>http://ithompson.wordpress.com/2009/11/23/directory-services-auditing/</link>
		<comments>http://ithompson.wordpress.com/2009/11/23/directory-services-auditing/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 21:06:52 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Directory Services]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Active Directory auditing]]></category>
		<category><![CDATA[directory services auditing]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=99</guid>
		<description><![CDATA[I&#8217;ve been asked by a customer to take a look at their level of Directory Services Auditing.  I&#8217;m not able to share their screen shots but can scrub an email that I sent to them and post it here. When it comes to Directory Services Auditing I always tell people less is more, if you [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=99&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been asked by a customer to take a look at their level of Directory Services Auditing.  I&#8217;m not able to share their screen shots but can scrub an email that I sent to them and post it here.</p>
<p>When it comes to Directory Services Auditing I always tell people less is more, if you already understand what the other audit policies give you then you can get 85% to 90% of what you need from those.  There are somethings that you will have to get via Directory Services Auditing there&#8217;s just no getting around it.  But just as with the case of Object Access be very carefull what you turn on or you will flood yourself with junk noise events.  The major pain is that all events generated by Directory Services use the same event id no matter what action you are doing and are very cryptic.</p>
<p>Here is the email:</p>
<blockquote><p>&#8220; As we talked about on the phone today there is a lot of auditing turned on where Microsoft hasn’t given very much information about what it generates and even some that are currently not used.  Example: Intellimirror-Group is used by remote boot legacy for managing groups of server machines and is currently not used.   Based on the screen shot you sent me I can see that the objects are currently being monitored which are generating a lot of noise events for you.  You might be better suited to audit the properties instead of the objects.  Example, if you want to know when a user has been given access to someone else’s inbox you need to monitor for changes to the property: msExchMailboxSecurityDescriptor; or if you want to know who made a GPO change then you need to monitor for changes to the properties: gpLink and gPOptions.  Most of the information that you can find via MSDN in regards to these audit objects is related to developers and not what the audit trail will give you.  Keep in mind that Microsoft considers the Directory Services auditing a low level audit, so the events that are generated are pretty cryptic in nature and all use the same event id. </p></blockquote>
<blockquote><p> There are a few of the objects that you would want to monitor to help get a more full picture of what is happening such as: Computer, User, OU, Shares, Group objects.  Monitoring these will give you things such as what OU a user was created in, where the Account Mgmt auditing does not give you this.  Also Account Mgmt auditing does not give you OU auditing (as again Microsoft considers this to be a low level object).</p></blockquote>
<blockquote><p> In most companies it’s easy to turn on Auditing but very difficult to get it turned off and this is where Admins get themselves and others into a painful spot.  How to prove what is not needed when Microsoft doesn’t document what the auditing does or doesn’t do.</p></blockquote>
<blockquote><p> Other examples:</p>
<p>msSFU30MailAliases – represents UNIX mail file data</p>
<p>nisMap – contains the generic abstraction of an NIS map</p>
<p>oncRpc – represents an abstraction of the Open Network Computing (ONC) Remote Procedure Call (RPC) binding</p>
<p>msRTCSIP-EdgeProxy – this attribute is reserved for future use</p>
<p>msRTCSIP-TrustedWebComponentsServerData – this attribute is reserved for future use&#8221;</p></blockquote>
<p>Here are a few of the links where I pulled this data from:</p>
<p><a href="http://msdn.microsoft.com/en-us/library/ms680938(VS.85).aspx" target="_blank">http://msdn.microsoft.com/en-us/library/ms680938(VS.85).aspx</a></p>
<p><a href="http://msdn.microsoft.com/en-us/library/ms985886(EXCHG.65).aspx" target="_blank">http://msdn.microsoft.com/en-us/library/ms985886(EXCHG.65).aspx</a></p>
<p><a href="http://technet.microsoft.com/en-us/library/bb663647.aspx" target="_blank">http://technet.microsoft.com/en-us/library/bb663647.aspx</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/99/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=99&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/11/23/directory-services-auditing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Audit Account Logon vs Audit Logon/Logoff</title>
		<link>http://ithompson.wordpress.com/2009/10/05/audit-account-logon-vs-audit-logonlogoff/</link>
		<comments>http://ithompson.wordpress.com/2009/10/05/audit-account-logon-vs-audit-logonlogoff/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 15:00:39 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audit Account Logon]]></category>
		<category><![CDATA[Audit Logon/Logoff]]></category>
		<category><![CDATA[Audit Policy]]></category>
		<category><![CDATA[Audting]]></category>
		<category><![CDATA[Event Log]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Account Logon]]></category>
		<category><![CDATA[Audit Log]]></category>
		<category><![CDATA[Logon/Logoff events]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=94</guid>
		<description><![CDATA[Over the past several years I&#8217;ve been explaining the diffence between these two audit polices.  One is for logon/logoff events the other (Account Logon) is for authentication events.  In the past few months I have had several people ask me to put together a blog entry covering these 2 audit polices.  But I&#8217;ve found it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=94&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Over the past several years I&#8217;ve been explaining the diffence between these two audit polices.  One is for logon/logoff events the other (Account Logon) is for authentication events.  In the past few months I have had several people ask me to put together a blog entry covering these 2 audit polices.  But I&#8217;ve found it rather painfull to put into a blog.   Then a few weeks ago I found out that my employeer (Prism Microsystems) was hosting a webinar with <a href="http://www.ultimatewindowssecurity.com" target="_blank">Randy F. Smith</a> and I was going to also be presenting.   Well the webinar went smoothly today and so I have decided that instead of me doing a long lengthly blog entry I would just post a link to the <a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=72" target="_blank">recorded webinar</a>.  Enjoy and I hope you are able to gain more insight into these 2 Audit Policies.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=94&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/10/05/audit-account-logon-vs-audit-logonlogoff/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>Micorsoft Patch Research Site</title>
		<link>http://ithompson.wordpress.com/2009/09/16/micorsoft-patch-research-site/</link>
		<comments>http://ithompson.wordpress.com/2009/09/16/micorsoft-patch-research-site/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 16:17:33 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Microsoft Patches]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=90</guid>
		<description><![CDATA[I was watching a Randy F. Smith webinar today and he showed a section of his website that he uses to track the Microsoft patches.  So I thought this would be good information to share.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=90&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I was watching a Randy F. Smith webinar today and he showed a section of his website that he uses to <a href="http://www.ultimatewindowssecurity.com/patchanalysis/research.aspx" target="_blank">track the Microsoft patches</a>.  So I thought this would be good information to share.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/90/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=90&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/09/16/micorsoft-patch-research-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
		<item>
		<title>More Info on Tracking Down File Deletes</title>
		<link>http://ithompson.wordpress.com/2009/08/05/more-info-on-tracking-down-file-deletes/</link>
		<comments>http://ithompson.wordpress.com/2009/08/05/more-info-on-tracking-down-file-deletes/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 20:52:01 +0000</pubDate>
		<dc:creator>ithompson</dc:creator>
				<category><![CDATA[Audit Policy]]></category>
		<category><![CDATA[Event Log]]></category>
		<category><![CDATA[File Deletes]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Object Access]]></category>
		<category><![CDATA[event id 4656]]></category>
		<category><![CDATA[event id 560]]></category>
		<category><![CDATA[File Delete]]></category>
		<category><![CDATA[Object Access Auditing]]></category>
		<category><![CDATA[track file changes]]></category>

		<guid isPermaLink="false">http://ithompson.wordpress.com/?p=85</guid>
		<description><![CDATA[Quite awhile ago I wrote a blog entry on Tracking Down File Deletes, it continues to be one of my most read blogs.  I came across another blog entry that does a good job of explaining the same thing.  The author is Ned Pyle, in his post he covers not only the Windows 2003 but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=85&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Quite awhile ago I wrote a blog entry on <a href="http://ithompson.wordpress.com/2007/09/06/tracking-down-file-deletes/" target="_blank">Tracking Down File Deletes</a>, it continues to be one of my most read blogs.  I came across another blog entry that does a good job of explaining the same thing.  The author is Ned Pyle, in his <a href="http://blogs.technet.com/askds/archive/2009/08/04/tracking-a-remote-file-deletion-back-to-the-source.aspx" target="_blank">post</a> he covers not only the Windows 2003 but also the Windows 2008 auditing so I thought I would share it with you.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ithompson.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ithompson.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ithompson.wordpress.com/85/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ithompson.wordpress.com&amp;blog=1623620&amp;post=85&amp;subd=ithompson&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ithompson.wordpress.com/2009/08/05/more-info-on-tracking-down-file-deletes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/af2e777cec8d7f268682b00e48455d99?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ithompson</media:title>
		</media:content>
	</item>
	</channel>
</rss>
