25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Ano<strong>the</strong>r look at <strong>the</strong> ‘c:\windows\system32\config’ folder shows that quite a bit <strong>of</strong><br />

information has been written to <strong>the</strong> log file, it has increased in size by 74Kb.<br />

And ano<strong>the</strong>r look at <strong>the</strong> Security <strong>Log</strong> reveals that it now contains 492 events.<br />

It is also noted that it has continued to write to <strong>the</strong> log file as if nothing has happened.<br />

There will probably be an event that signifies that <strong>the</strong> <strong>Event</strong> Service has been stopped <strong>and</strong><br />

started. This will require fur<strong>the</strong>r investigation.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!