25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CO42019 – Project 4<br />

These modifiactions were <strong>the</strong>n saved to disc <strong>and</strong> directory snoop was refreshed, this <strong>the</strong>n<br />

showed that <strong>the</strong> data on <strong>the</strong> drive had been modified, however when <strong>the</strong> event viewer was<br />

opened up it did not show any changes. This must mean that it does not read from <strong>the</strong><br />

file after it has loaded up.<br />

The system was <strong>the</strong>n restarted.<br />

Directory Snoop was opened up <strong>and</strong> pointed towards <strong>the</strong> Sec<strong>Event</strong>.Evt file, this showed<br />

that <strong>the</strong> time <strong>and</strong> date had been set back to <strong>the</strong>ir original value. This was varified with<br />

opening up <strong>the</strong> event viewer.<br />

Perhaps it only stores ‘new events’ in memory. That is events that have happened after<br />

<strong>the</strong> system was started.<br />

So once again <strong>the</strong> Hex editor was used to modify <strong>the</strong> time <strong>and</strong> date <strong>of</strong> ‘old events’ <strong>and</strong><br />

this was verified as being changed on <strong>the</strong> hard drive using directory snoop.<br />

The system was <strong>the</strong>n restarted.<br />

A quick look with <strong>the</strong> event viewer shows that <strong>the</strong> times <strong>of</strong> <strong>the</strong> events have been set back<br />

to <strong>the</strong>ir original value.<br />

System Starts<br />

<strong>Event</strong> Service opens log<br />

file into memory<br />

<strong>Event</strong> Service monitors<br />

<strong>and</strong> updates memory<br />

with new events<br />

Is system<br />

shutting<br />

down<br />

No<br />

Yes<br />

<strong>Event</strong> Service writes<br />

memory to file<br />

System Stops<br />

Project – Week 5.doc Page 8 <strong>of</strong> 8

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!