RE: Auditing a reboot

From: Brad Judy (judy@colorado.edu)
Date: 04/21/03

  • Next message: Hillensbeck, Preston: "RE: Auditing a reboot"
    From: "Brad Judy" <judy@colorado.edu>
    To: "'Hillensbeck, Preston'" <PHillensbeck@sfbcic.com>, <focus-ms@securityfocus.com>
    Date: Mon, 21 Apr 2003 08:29:54 -0600
    
    

    There are several items that are logged on startup, some of which may
    also be logged at other times. Try the normal first item to be logged -
    an event 6009 that states the basic OS version information. See this KB
    article for more info -
    http://support.microsoft.com/default.aspx?scid=kb;EN-US;196452

    Note that this is an event that occurs on startup regardless of how the
    machine was shut down. Other events may be logged as discussed in the
    article above. If you want something more specific you may have to look
    elsewhere.

    Brad Judy

    Information Technology Services
    University of Colorado at Boulder

    > -----Original Message-----
    > From: Hillensbeck, Preston [mailto:PHillensbeck@sfbcic.com]
    > Sent: Monday, April 21, 2003 7:14 AM
    > To: 'focus-ms@securityfocus.com'
    > Subject: Auditing a reboot
    >
    >
    > How would you go about auditing when a machine is rebooted,
    > domain wise? I have looked high and low for an answer, and I
    > can't seem to find one. This is a Windows 2000 question, and
    > I am running Active Directory. I have tried auditing system
    > events, both successes and failures, but cannot get event
    > viewer to spit out the right information. Thanks in advance.
    >
    >
    >
    > --------------------------------------------------------------
    > ---------------
    > Attend Black Hat Briefings & Training Europe, May 12-15 in
    > Amsterdam, the
    > world's premier event for IT and network security experts.
    > The two-day
    > Training features 6 hand-on courses on May 12-13 taught by
    > professionals.
    > The two-day Briefings on May 14-15 features 24 top speakers
    > with no vendor
    > sales pitches. Deadline for the best rates is April 25.
    > Register today to
    > ensure your place. http://www.securityfocus.com/BlackHat-focus-ms
    > --------------------------------------------------------------
    > ----------------
    >

    -----------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the
    world's premier event for IT and network security experts. The two-day
    Training features 6 hand-on courses on May 12-13 taught by professionals.
    The two-day Briefings on May 14-15 features 24 top speakers with no vendor
    sales pitches. Deadline for the best rates is April 25. Register today to
    ensure your place. http://www.securityfocus.com/BlackHat-focus-ms
    ------------------------------------------------------------------------------


  • Next message: Hillensbeck, Preston: "RE: Auditing a reboot"

    Relevant Pages

    • Re: Log in form
      ... An event to trigger some code to register the logoff on db close ... that will open on db startup, ... Private Sub Form_Open ... Dim rs As DAO.Recordset ...
      (microsoft.public.access.modulesdaovba)
    • Re: HP Tech Support No Help with Pop up
      ... getting a pop up asking to register on line which has been done numerous ... Download AutoRuns from the link in my earlier post, which will show far more start-up locations. ... the culprit may be a program that is not run precisely at startup but is instead called by a different program that is run at startup. ... Even if you can't identify the program causing the pop-up, try the HP forums. ...
      (microsoft.public.windowsxp.general)
    • Re: Executing an application inside a Service
      ... The startup application would register with the service to be ... messages/application startups as the local system. ... > with regards, ...
      (microsoft.public.dotnet.languages.csharp)
    • Re: Ocx Registration Q.
      ... I just have a feeling that I ... Installshields has good capabiliries to register the OCX for you, ... don't have to bother for registering the ocx in the startup of your program. ... In my opinion it's good manner to check for correct installation of the ...
      (microsoft.public.fox.programmer.exchange)
    • Re: edit registry via startup script
      ... script that writes to a text file without On Error Resume Next). ... | I did enable auditing but I don't get any sort log entries that were ... | You mentioned earlier that there could possibly be a startup timing issue. ...
      (microsoft.public.scripting.vbscript)