Re: Checking - will this Windows audit-tool be useful?



I would try it out.

On 6/13/06, Marcos Marrero <mmarrero@xxxxxxxxxxxxxxxxx> wrote:
I believe that you application would be of great help. I too audit AD
environments fairly regularly and this tool would help tremendously...



-----Original Message-----
From: Petr.Kazil@xxxxxx [mailto:Petr.Kazil@xxxxxx]
Sent: Tuesday, June 13, 2006 11:45 AM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: Checking - will this Windows audit-tool be useful?


I'm working on a Windows audit tool. I will probably build it anyway,
because I can use it myself and it's a fun project. But to be sure, I
would
like to check if it's not already out there somewhere.

A longish explanation:

I do a lot of Windows / Active Directory audits. Until now I used the
traditional tools like Dumpsec, Hyena, pstools and a lot of the built in
Windows commands.

But a lot of the information that I need, is already present in one
single
file. If I run "csvde -f outputfile.txt" then I have the core data of
Active Directory in my hands. Almost all the data in Dumpsec (and much
more) is present in the csvde-file.

The charm of using this file, is that you don't need to run any tools on
the client's infrastructure. In a few cases an admin was willing to send
the (strongly encrypted) file by e-mail and I could start my audit right
away without taking much of his time.

I have written a set of scripts in VBScript that parse and analyze the
csvde file and produce interesting data like: statistics, "dead"
accounts,
administrator groups and memberships, OU-trees and policies, domain
policies, computer OS-versions, account settings, etc.

At the moment I'm rewriting the scripts into a decent application in
Visual
Basic 2005, as an exercise with this language.

My question:

Do you think anyone will be interested in this tool when I'm finished?

I know I'm reinventing the wheel a bit - but I've successfully used
csvde-file data in the past, so I hope others might be interested too.

This email has been scanned for all viruses by the MessageLabs SkyScan
service.

**********************************************************************
This Email is intended for the exclusive use of the addressee only.
If you are not the intended recipient, you should not use the
contents nor disclose them to any other person and you should
immediately notify the sender and delete the Email.

Lloyds TSB Bank plc is registered in England and Wales Number: 2065.
Registered office: 25 Gresham Street, London EC2V 7HN.

**********************************************************************


This email has been scanned for all viruses by the MessageLabs SkyScan
service.

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------



------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------



Relevant Pages

  • RE: Unix auditing tools - Windows based.
    ... audit Unix/linux. ... Concerned about Web Application Security? ... to go with a managed service or an enterprise ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • RE: [lists] How tos in Hacking AS400
    ... In 15 minutes I made the $40K I charged for the audit. ... If you spend more on coffee than on IT security, ... Download FREE whitepaper on how a managed service can help ...
    (Pen-Test)
  • RE: Licensed Penetration Tester LPT
    ... Subject: Licensed Penetration Tester LPT ... Download FREE whitepaper on how a managed service can ... now for a limited time we can do a FREE audit for you to confirm your ...
    (Pen-Test)
  • Re: Sniff telnet connections
    ... but server that i need to audit it is out of my lan. ... As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. ... You have an option to go with a managed service or an enterprise software. ... Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. ...
    (Pen-Test)
  • Client-Side Caching - Windows XP
    ... caching directory under Windows. ... As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. ... You have an option to go with a managed service or an enterprise software. ... Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. ...
    (Pen-Test)