Re: Monitor User Remotely.

From: Steven L Umbach (sumbach55_at_ameritech.net)
Date: 11/26/03


Date: Wed, 26 Nov 2003 18:28:20 GMT

There are various things that you can do. A keyboard logger will record
activity [check legal and personel first], auditing of process tracking on
the computer may be helpful but will generate a lot of events in the
security log in Event Viewer that are not the easiest to interpret, viewing
temporary files/temporary internet files and history folder can be done
remotely via administrator share, and folder files have creation timestamps
and ownership information.

Having said that, I have to wonder if this user needs to be a power user or
administrator on his computer. Making him a regular user may stop a lot of
that. I would also enable auditing of logon events on his computer so that
you can track his usage and other users time on his computer. If he is a
local administrator however, he can clear the security log. You may want to
give him a pristine installation and then back it up to have as evidence or
proof that at a particular point in time the computer was clean. That along
with the security log files will help you build a case against him. ---
Steve

"Tom (Tom)" <webmaster@takenet.com> wrote in message
news:3fc4b78c.184865502@news.btclick.com...
> I have 1 user, who keeps installing priate sofwtare, virused software,
> or trojans..
>
> We keep telling him the restrictions of business systems.
>
> Is there any way we can remotely monitor him, without him seeing that
> we are watching ??
>
> All staff are advised that the Pc could be monitored, so we have no
> problems with permission or privacy..
>
> Ideally, we don't want him to know that we are monitoring him..
>
> Any IDEAS >>???



Relevant Pages

  • Re: Server 2003 updates fail
    ... Some how the administrators was removed from Manage auditing and security log in the local security setting. ... > Please verify permissions on the following rights include the built-in ... I was log on as the administrator when getting ...
    (microsoft.public.windowsupdate)
  • Re: Unable to access Security Event Log Windows 2003 Stand alone
    ... The error that get loged is Windows error code: ... > administrator has the Manage auditing and security log right. ...
    (microsoft.public.security)
  • Re: Monitor the Adminstrator
    ... You can't realistically restrict an administrator. ... and a malicious administrator could modify the security log. ... See the link below on auditing. ... For starts it is a good idea to at least audit ...
    (microsoft.public.win2000.security)
  • Re: Authentication Auditing
    ... > only show in the security log of the domain computer itself - not the ... > it indeed does show that auditing of logon events is enabled for success ... It is enabled but the effective setting dispalys as "No Auditing". ...
    (microsoft.public.win2000.security)
  • Re: Audit Failures/READ_CONTROL SYNCHRONIZE
    ... You're auditing File and Object Access; you've enabled Auditing on the files ... and you're complaining about audit events ... You can't mask events out of the security log in Event Viewer. ... > Client Domain: HEX21 ...
    (comp.os.ms-windows.nt.admin.security)