29.04.2014 Views

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The <strong>Event</strong> Delivery Optimization options shown in Figure 3 permits <strong>the</strong> collection of event logs in 15<br />

minutes (Normal), 6 hours (Minimize Bandwidth), or 30 seconds intervals (Minimize Latency). [12] A<br />

custom interval can be set using <strong>the</strong> wecutil command line utility.<br />

Figure 3: <strong>Event</strong> Delivery Optimization<br />

Configuration<br />

Figure 4: Completed Subscription<br />

Custom Subscriptions<br />

The general approach to creating subscriptions using <strong>the</strong> graphical user interface lacks flexibility for<br />

custom configuration. It may be desirable to customize <strong>the</strong> frequency of event delivery and <strong>the</strong> batch<br />

amount of a subscription. A detailed description of <strong>the</strong> subscription schema is found in <strong>the</strong> Subscription<br />

section of <strong>the</strong> Appendix.<br />

Customization of subscriptions depends on <strong>the</strong> administrator’s needs and requirements. Several<br />

subscriptions have been created and provided in <strong>the</strong> Subscriptions section of <strong>the</strong> Appendix. These<br />

subscriptions collect events that an enterprise may be interested in collecting from domain computers.<br />

The following tables summarize <strong>the</strong> event IDs and <strong>the</strong> category <strong>the</strong>y represent for each recommended<br />

subscriptions. The Recommended <strong>Event</strong>s to Collect section discusses <strong>the</strong>se events in more detail.<br />

Each subscription focuses on account activity, application and computer failures, computer and<br />

applications modification, and security notifications.<br />

<strong>Windows</strong> Vista and above <strong>Event</strong>s<br />

12 http://technet.microsoft.com/en-us/library/cc749167.aspx<br />

8

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!