Analysis and Evaluation of the Windows Event Log - Bill Buchanan
Analysis and Evaluation of the Windows Event Log - Bill Buchanan
Analysis and Evaluation of the Windows Event Log - Bill Buchanan
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
CO42019 – Project 4<br />
These modifiactions were <strong>the</strong>n saved to disc <strong>and</strong> directory snoop was refreshed, this <strong>the</strong>n<br />
showed that <strong>the</strong> data on <strong>the</strong> drive had been modified, however when <strong>the</strong> event viewer was<br />
opened up it did not show any changes. This must mean that it does not read from <strong>the</strong><br />
file after it has loaded up.<br />
The system was <strong>the</strong>n restarted.<br />
Directory Snoop was opened up <strong>and</strong> pointed towards <strong>the</strong> Sec<strong>Event</strong>.Evt file, this showed<br />
that <strong>the</strong> time <strong>and</strong> date had been set back to <strong>the</strong>ir original value. This was varified with<br />
opening up <strong>the</strong> event viewer.<br />
Perhaps it only stores ‘new events’ in memory. That is events that have happened after<br />
<strong>the</strong> system was started.<br />
So once again <strong>the</strong> Hex editor was used to modify <strong>the</strong> time <strong>and</strong> date <strong>of</strong> ‘old events’ <strong>and</strong><br />
this was verified as being changed on <strong>the</strong> hard drive using directory snoop.<br />
The system was <strong>the</strong>n restarted.<br />
A quick look with <strong>the</strong> event viewer shows that <strong>the</strong> times <strong>of</strong> <strong>the</strong> events have been set back<br />
to <strong>the</strong>ir original value.<br />
System Starts<br />
<strong>Event</strong> Service opens log<br />
file into memory<br />
<strong>Event</strong> Service monitors<br />
<strong>and</strong> updates memory<br />
with new events<br />
Is system<br />
shutting<br />
down<br />
No<br />
Yes<br />
<strong>Event</strong> Service writes<br />
memory to file<br />
System Stops<br />
Project – Week 5.doc Page 8 <strong>of</strong> 8