RE: Forensic Investigation



Probably not. This is one argument in favour of a fileserver as central
storage. In that case you should be able to audit who was logged-on, and
when, plus the ownership of files will tell you who put them there (but not
who deleted them!)

HST, the event logs in XP Home may give some clue as to who accessed the
computer, and when. Check out event viewer in Control Panel>Computer
Management. This would only be of value if (confidential) passwords were
in-force, of course. Otherwise anyone may have used the ex-employee's logon.

If there is serious doubt about the ex-employee's trustworthiness then I'd
be inclined to do a thorough scan for Trojans, and if there is any doubt
about the results, to reinstall the OS from scratch.

"SteelCadman" wrote:

Ok, I have used a very specific title for the subject of this post, and
rightly so. The company I work for had a tech savy employee leave rather
suddenly. However there was activity on this individuals computer after her
departure. Files were accessed, not remotely as the workstation was
physically disconnected from the network.
Heres the query, what form of access was perfiormed on the files, were they
copied, were they just opened. If they were copied where to? USB, CD-Burner?

Now, if our IT guy was quick, he would have all systems running XP Pro with
Security policies set to Fort Knox Level. However we have XP Home, and now I
have been asked to figure out the answers to the above questions.

My question is, Is it possable after the fact? and if so how?
Ive tried everything I can think of.
.



Relevant Pages

  • Re: Registry Auditing
    ... In the left pane, under Local Policies, click Audit Policy. ... On the Auditing tab, click Add. ... Inspect the Event Logs for any information on the changed ... > "Clark Murray" wrote in message ...
    (microsoft.public.windowsxp.general)
  • RE: Read-Only Table on SQL
    ... Select successfull logins under Audit ... Restart MSSQLServer service. ... Check the NT Application Event logs and/or SQL Errorlogs ...
    (microsoft.public.sqlserver.security)
  • Re: Audit User Access
    ... No nothing appears in any of the event logs. ... > Jonathan is there any thing related to the message box in the event log of ... >> I have set up the AD group policy as instructed but when I try to apply ... >> audit trail to a directory I get a message box saying that the audit ...
    (microsoft.public.win2000.active_directory)
  • Re: Registry Auditing
    ... In the left pane, under Local Policies, click Audit Policy. ... On the Auditing tab, ... Inspect the Event Logs for any information on the changed ...
    (microsoft.public.windowsxp.general)