Difference between revisions of "Windows"

From Mesopoly 3.0
Jump to navigation Jump to search
Line 1: Line 1:
*[http://www.microsoft.com/technet/archive/community/columns/security/askus/aus1101.mspx Microsoft about Auditing]
+
*You have windows network and you would like monitor user login / logoff.
 +
*You have already searched the web and usenet trying to find suitable recipies but found none to concise
 +
** Windows 2003 server came with heaps of new auditing features and many of those are published but silent fact remains, that simple logon / logoff monitoring is not part of default reports.
  
"Event Comb" from Microsoft
+
*FIRST you have to start logon / logoff loging on machines monitored. Those are events 528 (540?) for logon and 538 for logoff.
 
+
** you can start logging of these either locally or via group policy
or
 
 
 
[url]http://www.microsoft.com/technet/security/guidance/secmod144.mspx[/url]
 
[url]http://www.sysinternals.com/ntw2k/freeware/psloglist.shtml[/url] -- PsLogList
 
[url]http://www.gfi.com/lanselm/[/url] -- LanGuard S.E.L.M. -- trial download
 
  
 
Audit Logon/Logoff success events. The logon (528/540) and logoff (538
 
Audit Logon/Logoff success events. The logon (528/540) and logoff (538

Revision as of 12:50, 24 March 2006

  • You have windows network and you would like monitor user login / logoff.
  • You have already searched the web and usenet trying to find suitable recipies but found none to concise
    • Windows 2003 server came with heaps of new auditing features and many of those are published but silent fact remains, that simple logon / logoff monitoring is not part of default reports.
  • FIRST you have to start logon / logoff loging on machines monitored. Those are events 528 (540?) for logon and 538 for logoff.
    • you can start logging of these either locally or via group policy

Audit Logon/Logoff success events. The logon (528/540) and logoff (538