29.04.2014 Views

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Windows</strong> 7<br />

ID Level <strong>Event</strong> <strong>Log</strong> <strong>Event</strong> Source<br />

Account Lockouts 4740 Informational Security Microsoft-<strong>Windows</strong>-Security-Auditing<br />

User Added to 4728, Informational Security Microsoft-<strong>Windows</strong>-Security-Auditing<br />

Privileged Group 4732,<br />

4756<br />

Successful User 4624 Informational Security Microsoft-<strong>Windows</strong>-Security-Auditing<br />

Account <strong>Log</strong>in<br />

Failed User 4625 Informational Security Microsoft-<strong>Windows</strong>-Security-Auditing<br />

Account <strong>Log</strong>in<br />

Account <strong>Log</strong>in <strong>with</strong><br />

Explicit Credentials<br />

4648 Informational Security Microsoft-<strong>Windows</strong>-Security-Auditing<br />

<strong>Windows</strong> XP<br />

Table 16: <strong>Windows</strong> 7 Account Activity <strong>Event</strong>s<br />

ID Type <strong>Event</strong> <strong>Log</strong> <strong>Event</strong> Source<br />

Account Lockouts 644 Success Audit Security Security<br />

Failed <strong>Log</strong>in 529 Failure Audit Security Security<br />

Successful <strong>Log</strong>in 528 Success Audit Security Security<br />

User Initiated <strong>Log</strong>off 551 Success Audit Security Security<br />

Account <strong>Log</strong>in <strong>with</strong> Explicit 552 Success Audit Security Security<br />

Credentials<br />

Successful Network <strong>Log</strong>in 540 Success Audit Security Security<br />

User Account Created 624 Success Audit Security Security<br />

Change Password Attempt 627 Success Audit Security Security<br />

User Added to Privileged Group 632, 636,<br />

660<br />

Success Audit Security Security<br />

Table 17: <strong>Windows</strong> XP Account Activity <strong>Event</strong>s<br />

4.8 Kernel Driver Signing<br />

Introduction of kernel driver signing in <strong>the</strong> 64-bit version of <strong>Windows</strong> Vista significantly improves<br />

defenses against malicious drivers or activities in <strong>the</strong> kernel. Any indication of a protected driver being<br />

altered may indicate malicious activity or a disk error and should warrant investigation.<br />

<strong>Windows</strong> 7<br />

33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!