25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CO42019 – Project 4<br />

And <strong>the</strong>n restarted <strong>the</strong> event service<br />

Initial Diagnosis:<br />

<strong>Event</strong> log started with no problems or errors<br />

One point to note is that <strong>the</strong> PC2 usernames are now identifiable <strong>and</strong> <strong>the</strong> PC1 usernames<br />

have been changed to ANONYMOUS LOGON. Also, <strong>the</strong> log file has maintained <strong>the</strong><br />

computer name <strong>of</strong> PC1 in <strong>the</strong> column on <strong>the</strong> right h<strong>and</strong> side.<br />

PC2 was <strong>the</strong>n rebooted <strong>and</strong> its security log examined again… The log was still exactly<br />

<strong>the</strong> same as before, this has presented a problem for fur<strong>the</strong>r analysis, as no new events<br />

have been logged.<br />

Project – Week 4.doc Page 6 <strong>of</strong> 14

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!