RE: Windows/Exchange security auditing tool

From: yaakov yehudi (yehudi_at_tehila.gov.il)
Date: 09/02/04

  • Next message: Thor: "Re: XP-SP2 "Feature""
    Date: Thu, 2 Sep 2004 07:44:27 +0200
    To: "Rod Dickerson" <rod.dickerson@us.logicalis.com>, <focus-ms@securityfocus.com>
    
    

    You can improve on the types of info that you get by adding additional security logging options in group policy (even for stand alone machines), this will let you know when a user changes a setting. You can also turn on auditing for "everyone" on your hard drives. There is a small performance loss but it is well worth it in many situations (even for debugging applications).

    For a good backend log processor, you should look a CA's eTrust Security Command Center. It will cost you a lot, but is really great value for money. It can really cut through the data overload you will get if you have all the options I have mentioned enabled.

    Also to enable specific data logging, you could look at WMI scripting. That is cheap and effective.

    Regards, YY

    -----Original Message-----
    From: Rod Dickerson [mailto:rod.dickerson@us.logicalis.com]
    Sent: Wednesday, September 01, 2004 0:36
    To: focus-ms@securityfocus.com
    Subject: Windows/Exchange security auditing tool

    Anyone have experience with 3rd party auditing/monitoring software for Windows/Exchange/SQL/etc? This is needed when the security auditing features of the OS are inadequate. I have found it difficult to find the "middle ground" of auditing on Windows servers; either not enough logged or too much. Also, the logging doesn't seem to be as detailed as needed to show true audit trails, for example "user X changed setting Y on server Z at this time." This may be a holy grail search, I realize that. Any help would be appreciated. Thanks.

    Rod

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Thor: "Re: XP-SP2 "Feature""

    Relevant Pages

    • RE: Error: 0xC00D0FB3
      ... Rod ... > Media Player will not play / copy my music CDs in ... > then I get the same error message (think it's ... > Best Regards, ...
      (microsoft.public.windowsmedia.player)
    • Re: How to move system databases to new SAN drive in cluster serve
      ... Best Regards, ... >> Hi Rod, ... >> database all the time in cluster server, but this time I am talking about ... >> moving system databases those are master, ...
      (microsoft.public.sqlserver.clustering)
    • Re: Restoring Old Files
      ... You're welcome Rod. ... Bert Kinney MS-MVP Shell/User ... >> Regards, ... >>> because the old files where I was a password protected user. ...
      (microsoft.public.windowsxp.help_and_support)
    • Table does not split over muløtiple pages..
      ... bottom margin. ... Why doesn't this table split and how can I fix this problem? ... Rod ...
      (microsoft.public.word.tables)
    • Re: Linux free software auditing
      ... You can use Bastille linux as a security auditing tool. ... regards, Mauro Flores ...
      (Vuln-Dev)