Re: Win2k Audit Logs - What happened here?

From: H C (keydet89@yahoo.com)
Date: 12/16/02

  • Next message: James-lists: "fswserv.html ????"
    Date: Mon, 16 Dec 2002 13:41:32 -0800 (PST)
    From: H C <keydet89@yahoo.com>
    To: incidents@securityfocus.com
    
    

     
    > We turned on windows 2000 auditing for a particular
    > user on our file server(SERVER1) and found a very
    > interesting audit events, but we don't know what
    > action actually trigered all the events. We noticed
    > that a folder (Group1) and all of its subfolders has
    > been accessed within a 3 econds. Yes just within a
    > few
    > seconds. We though the user(user2) might has been
    > browsing through the folders and subfolders, but it
    > just sound impossible to browser all the folders in
    > less than 3 seconds !!. We also though of the user
    > (user2) might have copy the whole folders and paste
    > it
    > some where... This will sound more logic to do in 3
    > seconds...

    Have you thought of asking the user? Also, since the
    events you posted are all success events, it would
    seem that the user is performing authorized
    activities...so, what's the point?

    > So, what you guyz think? .

    Honestly? You really need to put more thought into
    what auditing you enable.

    __________________________________________________
    Do you Yahoo!?
    Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
    http://mailplus.yahoo.com

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Auditing on a folder
      ... I have been trying to set up Auditing on a member server. ... who has been moving folders around within the share. ... 'Delete Subfolders and Files' Successful, ...
      (microsoft.public.windows.server.general)
    • Re: RFI - Moving files between folders in doc libraries - any improvements in this behavior?
      ... > and folders (subfolders) to organize content. ... SharePoint is a new creation. ... users did not have document libraries into which they can upload ...
      (microsoft.public.sharepoint.portalserver)
    • Re: Help-How do I import my Yahoo Folders to Gmail?
      ... Where are those folders you never mention so it could be folders shown in the message store for Outlook or folders defined in the webmail service at Yahoo and Gmail. ...
      (microsoft.public.outlook)
    • Re: folderLastAccessed script
      ... It will consider nothing other than the subfolders of ... I would like to get the last time all the folders were last accessed. ... Dim WshShell ... Dim fs, f, s, strfolder ...
      (microsoft.public.scripting.vbscript)
    • Re: Permissions for shared folders
      ... bottom folders, since the propagation occurrs. ... Be aware of such of tricky securty settings.. ... >You would enable Auditing to track file access. ... >must both enable logging in the overall computer policy ...
      (microsoft.public.win2000.security)