RSS Windows Security Logging and Other Esoterica
哪吒推荐该订阅
原站:http://blogs.msdn.com/ericfitz/default.aspx
标签:windows security other logging esoterica
点击立即订阅,“Windows Security Logg...”的内容有更新,哪吒第一时间提醒您
“Windows Security Logging and Other Esoterica”的内容更新
累计:29 篇(自 2008-01-10 起)
更新:约7篇/年,最后更新981 天前
Windows Security Logging and Other Esoterica
i've written twice (here and here) about the relationship between the "old" event ids (5xx-6xx) in ws03 and earlier versions of windows, and between the "new" security event ids (4xxx-5xxx) in vista and beyond.in short, eventid(ws03) + 4096 = eventid(ws08) for almost all security events in ws03.the exceptions are the logon events. the logon success eve... (311 天前)
Windows Security Logging and Other Esoterica
Fadi, Ned and Brian of the auditing team have documented all the auditing events by audit policy category and subcategory for your reference.Check it out in the Knowledge Base.Even better, they documented all the events in spreadsheet format, and that's propagating to the Microsoft Download Center. I'll publish the link when it's online.2008-04-17 UPD... (311 天前)
Windows Security Logging and Other Esoterica
I've written before on noise reduction in the Windows security event log. I've also written to describe how object access auditing works. But, I still get questions on how to reduce noise from object access events. The other day I got that question, specific to Directory Service objects, on an internal discussion list so I thought I'd clean up the answer... (311 天前)
Windows Security Logging and Other Esoterica
I get the question fairly often, how to use the logon events in the audit log to track how long a user was using their computer and when they logged off.As I have written about previously, this method of user activity tracking is unreliable. It works in trivial cases (e.g. single machine where the user doesn't have physical access to the power switch or... (311 天前)
Windows Security Logging and Other Esoterica
I get a lot of questions about how ACS event retention works. So here you go, I'm blogging it so I can just answer with a link :-)There are two DWORD registry values which affect backlog transmission. Both are on the collector machine under HKLM\System\CurrentControlSet\Services\AdtServer\Parameters.EventRetentionPeriod, if present, is expressed in hou... (311 天前)
Windows Security Logging and Other Esoterica
We got several reports recently of a bug in ACS that certain DS Access events, primarily for dnsNode and dnsZone objects, don't properly get looked up.Some background: the event log in Windows prefers to log invariants such as message IDs, parameter message IDs, SIDs (security IDs which represent users and groups, etc.), and GUIDs (globally unique IDs w... (311 天前)
Windows Security Logging and Other Esoterica
A judge in New Zealand declined to convict the admitted (guilty plea) botherder of a million-bot botnet, citing the negative consequences a conviction would have on the young man's future prospects. See the story here.Well duh. The whole theory of crime and punishment is that if you do something bad, you get punished, and punishment is something that is... (311 天前)
订阅者 ( 1 )
yuier
相关订阅源
RSS LiveSino - LiveSide 中文版

LiveSide 中文版,关注 Windows Live, MSN 及微软等相关的产品、技术和文化

标签: livesino live live的产品、技术和文化 windows news

指数 | 151人订阅  

RSS gHacks Technology News | Latest Tech News, Software And Tutorial

A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.

标签: ghacks firefox windows technology software

指数 | 5人订阅  

RSS Windows 7之家(www.win7china.com) 文章类别: 所有文章

Windows 7之家(www.win7china.com) 文章类别: 所有文章

标签: windows win7之家 7之家 windows7 win7

指数 | 9人订阅  

RSS Ed Bott

Windows Expertise (and more)

标签: windows office microsoft live

指数 | 2人订阅  

RSS Sukima Windows Plus

民放で云うと「テレビ東京」的サイトを目指すネタ系ウェップログ&たまに日記

标签: windows sukima plus

指数 | 1人订阅  

我要反馈