Google
Search WWW Search msexchangetips.blogspot.com

Sunday, August 20, 2006

Windows: Audit Changes Made to File Folders or Registry

Summary: This article will delve into auditing changes such as: Changing attributes, writing to, deleting, moving so it can be traced back to a process or user...

To track a Process or User that may be making modifications to a File Folders and Registry, perform the task below.


Caution: This degree of auditing will put a performance hit on the box.



To set up the local policy to Audit Process Tracking:
=====================================
1) Click Start then Run then type
"gpedit.msc" (without the quotes)
2) This will execute the Group Policy Object
3) Expand the following:
+Computer Configuration
+Windows Settings
+Security Settings
+Local Policies
+Audit Process Tracking
4) Under 'Audit these attempts' place a check on
- Failure
- Success
5) Once the policy has been set, run the following command to apply the policy
For Windows 2000: Secedit /refreshpolicy
For Windows XP or 2003: Gpupdate.exe



To set up the local policy to Audit Object access:
=====================================
1) Click Start then Run then type
"gpedit.msc" (without the quotes)
2) This will execute the Group Policy Object
3) Expand the following:
+Computer Configuration
+Windows Settings
+Security Settings
+Local Policies
+Audit Policy
4) Under 'Audit Policy' doubleclick 'Audit Object Access'
5) Under 'Audit these attempts" place a check on
- Failure
- Success



Auditing the registry
=====================================
1) Call up Regedt32 and browse to the key you want to audit
2) Windows 2000: Click the 'Security' menu and select 'Permissions'
Windows 2003/XP Click the 'Edit' menu and select 'Permissions'
3) Click the 'Advanced' button
4) Select the 'Auditing' tab and click the 'Add' button
5) Add the 'Everyone' group and click 'OK'
6) The resulting "Auditing Entry for " dialog box appears
7) In the "Apply onto" drop menu, select "This key and subkeys"
8) Choose the actions you want to audit for... commonly we want to track
changes to the registry... so we'll want to place a check on the following:
'Set Value' Successful and Failed
'Create Subkey' Successful and Failed
'Delete' Successful and Failed
9) Click OK
10) Clear the checkbox on "Allow inheritable auditing entries from parent to propagate to this object"
11) Click OK then OK again to exit
Auditing files or folders



=====================================
1) In Explorer.exe browse to the file or folder you want to audit
2) Click the 'Security' menu
3) Click the 'Advanced' button
4) Select the 'Auditing' tab and click the 'Add' button
5) Add the 'Everyone' group and click 'OK'
6) The resulting "Auditing Entry for " dialog box appears
7) In the "Apply onto" drop menu, select "This folder, subfolders and files"
8) Choose the actions you want to audit for...
For example, if attributes are being changed or files are being deleted
Place check marks under the following:
'Write Attributes' Successful
'Write Extended Attributes' Successful
'Delete Subfolders and Files' Successful
'Delete' Successful
'Change Permissions' Successful
9) Click OK
10) Clear the checkbox on "Allow inheritable auditing entries from parent to propagate to this object"
11) Click OK then OK again to exit



The Security Event log will reflect the following:
=====================================
Event ID of 560 and 562 detailing User audits
Event ID of 592 and 593 detailing Process audits



James Chong
MCSE M+, S+, MCTS, Security+
msexchangetips.blogspot.com


How useful was this article? Want to see a tip not listed? Please leave a comment.

10 Comments:

Anonymous Frank Dowson said...

This way each time you need to browse countless eventlog and search for necessary event. I think it's very complicated. Have you heard about special reporting tools that can trace all such changes ? I can suggest you implement enterprise security reporter. I use this tool very frequently for reporting on enterprise permissions, security, policies, group ownership, registry or files changes and many other things.

7:25 AM  
Blogger marry said...

Blogs are so informative where we get lots of information on any topic. Nice job keep it up!!
_____________________________

Dissertation Help

3:01 AM  
Anonymous Anonymous said...

It seems that every time I opened the Sunday paper, there will be several flyers advertising sales on the scarpe Hogan of different kinds. I suggest you look online to compare prices and have a good idea of what type of hogan donna will best suit your needs. There are certain types of Hogan scarpe uomo in general, and there should be a good idea of what you need to buy more. For those who are running the road or running in all different types of weather the best type of Hogan uomo is the way of the shoe which will give you a combination of stability and durability and excellent traction.

6:02 PM  
Anonymous oem software legal said...

Big to you thanks for the help in this question. I did not know it.

2:24 AM  
Blogger michel jon said...

Nice Post, thanks for sharing these steps to audit changes made to file and folders. I found good information about this from http://www.lepide.com/file-server-audit/ which helps to audit file and folders access like who made, what changes and where. This tool track unauthorized access and critical modification occurred in a network and get real time alerts on every access to files and folders on windows file servers.

4:42 AM  
Blogger oakleyses said...

louis vuitton outlet, oakley sunglasses, michael kors handbags, cheap jordans, prada handbags, uggs outlet, michael kors outlet, oakley sunglasses, uggs on sale, ray ban sunglasses, burberry outlet, tiffany jewelry, uggs on sale, kate spade, gucci handbags, ray ban sunglasses, prada outlet, longchamp outlet, louboutin uk, burberry factory outlet, tory burch outlet, nike air max, tiffany jewelry, christian louboutin, louboutin shoes, oakley sunglasses, cheap oakley sunglasses, chanel handbags, michael kors outlet store, louis vuitton outlet, nike outlet, ralph lauren polo, louis vuitton, christian louboutin, michael kors outlet online, longchamp outlet, uggs outlet, michael kors outlet online, nike air max, longchamp bags, replica watches, ralph lauren outlet, oakley sunglasses, ray ban sunglasses, louis vuitton outlet online, nike free, michael kors

6:30 PM  
Blogger oakleyses said...

burberry pas cher, lunette oakley pas cher, coach outlet, kate spade outlet, true religion jeans, converse, coach outlet, longchamp soldes, north face uk, michael kors, louboutin pas cher, new balance, lululemon outlet, coach purses, nike air max, hermes pas cher, nike tn pas cher, vans pas cher, coach outlet store online, mulberry uk, lunette ray ban pas cher, nike air max uk, sac guess pas cher, nike air force, nike roshe run pas cher, longchamp pas cher, north face pas cher, nike air max pas cher, ray ban uk, true religion outlet, abercrombie and fitch, polo lacoste pas cher, true religion outlet, michael kors, jordan pas cher, nike free, polo ralph lauren uk, vanessa bruno pas cher, true religion outlet, hogan sito ufficiale, ralph lauren pas cher, michael kors outlet online, nike free pas cher, nike roshe uk, abercrombie and fitch UK, nike blazer pas cher, hollister uk

6:31 PM  
Blogger oakleyses said...

converse shoes outlet, salvatore ferragamo, timberland boots, softball bats, herve leger, ray ban, hollister, louboutin, gucci, nike roshe run, iphone cases, beats by dre, mcm handbags, oakley, p90x workout, insanity workout, wedding dresses, abercrombie and fitch, abercrombie, nike air max, mac cosmetics, babyliss pro, valentino shoes, bottega veneta, mont blanc, converse, jimmy choo outlet, hollister clothing, nike air max, north face outlet, new balance shoes, north face outlet, instyler ionic styler, soccer shoes, lululemon outlet, asics running shoes, ghd hair, giuseppe zanotti, soccer jerseys, nfl jerseys, longchamp uk, reebok outlet, nike air huarache, chi flat iron, hermes handbags, vans outlet, polo ralph lauren, celine handbags, nike trainers uk, vans scarpe

6:33 PM  
Blogger oakleyses said...

toms shoes, supra shoes, montre pas cher, ugg uk, juicy couture outlet, moncler, lancel, michael kors outlet online, ugg pas cher, michael kors handbags, barbour, doke & gabbana, michael kors outlet, coach outlet, louis vuitton uk, canada goose jackets, pandora charms, moncler, ugg,ugg australia,ugg italia, links of london uk, moncler jackets, hollister, juicy couture outlet, canada goose outlet, swarovski uk, pandora jewelry, canada goose pas cher, canada goose outlet, marc jacobs, moncler pas cher, thomas sabo uk, swarovski jewelry, karen millen uk, louis vuitton, moncler, moncler uk, sac louis vuitton, canada goose, moncler outlet, louis vuitton, canada goose, wedding dresses uk, ugg,uggs,uggs canada, canada goose uk, sac louis vuitton, moncler, replica watches, barbour jackets uk, bottes ugg pas cher, canada goose jackets

6:34 PM  
Blogger Minko Chen said...

kobe 9
nhl jerseys
nike air max
air max 90
mcm backpack
ugg outlet online
hermes belt for sale
ugg outlet store
ralph lauren outlet
louis vuitton outlet store
ralph lauren uk
juicy couture tracksuit
coach outlet
lacoste shirts
abercrombie and fitch
snow boots
true religion jeans
longchamp handbags
hermes outlet store
cheap nike shoes
1128MINKO

6:40 PM  

Post a Comment

<< Home

xml:lang="en" lang="en"> MS Exchange Tips: Windows: Audit Changes Made to File Folders or Registry