RE: Sniffer information to track LSASS activity.

From: Bill-MT (BillMT_at_discussions.microsoft.com)
Date: 04/11/05

  • Next message: ML: "RE: Disk Full Prompt While save from A Applications from Remote"
    Date: Sun, 10 Apr 2005 19:37:02 -0700
    
    

    First, Thanks to all of you for responding.

    Per your recommendations I have done the following.
    - Enabled specific auditing of failures for certain events on the DC in
    question.
    - Downloaded and tried both Process Explorer and TcpView.
    - -Examined/modified my capture filter by selecting on specific MS TCP/UDP
    ports.

    Yesterday (Saturday) I rebooted the DC in question. So far (Sunday night)
    more than 24hours later the unusual CPU activity associated with this event
    has not re-occurred (which tells me that this event is not caused by any
    systems normally running on the weekend (i.e. the 24x7 systems) so I have not
    been able to use any of your advice yet.

    Although at this point I have nothing to report per your recommendations
    above, I do have an one additional question at this time. Per the response I
    got to my original posting on this issue, do any of you believe it is good
    practice to install Anti Virus software on a Domain Controller. And if yes,
    are there any caveats to doing so.

    Thanks again for your suggestions. - bill


  • Next message: ML: "RE: Disk Full Prompt While save from A Applications from Remote"

    Relevant Pages

    • Re: [SLE] 9.1 Personal and lack of Gnome
      ... I think this is the perfect place to share that opinion, ... >recommendations for when you understand the point you're responding to. ... Please read the FAQs: suse-linux-e-faq@suse.com ...
      (SuSE)
    • Re: Do you carry a gun while out on a ride?
      ... they are responding to. ... So get a newsreader that can filter on message content as well as ... Recommendations? ... Time flys when you're having fun. ...
      (uk.rec.cycling)
    • Re: OT Union Thugs force the Dims to outlaw secret ballot
      ... President says that being unionized will prevent the TSA from ... responding to changes brought about by new intelligence and other ... commissions's recommendations and stopping the flood of illegal immigrant ...
      (alt.autos.toyota)
    • Recommended CF Card for Olympus Evolt 500
      ... Purchased this camera new, and I am looking for a quick responding CF card. ... Any recommendations? ...
      (rec.photo.digital)