Re: Shared Folder Forensics

From: Olaf Engelke [MVP Windows Server] (oenews01_at_mvps.org)
Date: 11/14/05

  • Next message: Olaf Engelke [MVP Windows Server]: "Re: dir | more command is killing the command window"
    Date: Mon, 14 Nov 2005 23:10:38 +0100
    
    

    Hi Bruce,
    Bruce Wayne wrote:
    > Does the NET USE command leave any sort of evidence? We have a user
    > suspected of connecting to a certain shared folder she should not
    > have been allowed to access (this was prior to tightening the
    > permissions on the folder and enabling auditing). Is there any way to
    > check the history of NET USE on a client computer, to see whether the
    > user actually did access the confidential shared folder?
    >

    there is not very much you can do. You could dig through the
    HKEY/Current_USER of this account to see, if there are remains in the
    registry from files in sensitive pathes, which may have opened with
    applications like MS Office.
    But since already some time is gone, the chances are reduced again.
    Best greetings from Germany
    Olaf


  • Next message: Olaf Engelke [MVP Windows Server]: "Re: dir | more command is killing the command window"

    Relevant Pages

    • Re: Folder contents not in alphabetical order
      ... workstation, when a shared folder on the server is opened either in ... You can sort the column items in the ... file type, modified date, file size. ...
      (microsoft.public.windowsxp.general)
    • Sort by MODIFIED
      ... for some reason My Shared Folder just reverted to where I can't sort ... and My Videos, and I need to find out how I can get it back to the normal 4. ...
      (microsoft.public.windowsxp.help_and_support)
    • Shared folder called address
      ... I have found a shared folder on my root directory called Address. ... has some sub folders, in the subfolders there are some dll's, the dll's ... I assume that this is some sort of address book publishing but not sure. ...
      (microsoft.public.exchange.admin)
    • Shared Folder Forensics
      ... Does the NET USE command leave any sort of evidence? ... suspected of connecting to a certain shared folder she should not have been ...
      (microsoft.public.security)
    • Shared Folder Forensics
      ... Does the NET USE command leave any sort of evidence? ... suspected of connecting to a certain shared folder she should not have been ...
      (microsoft.public.windowsxp.security_admin)