SIEMENS. Sven Lehmberg. ZT IK 3, Siemens CERT. Siemens AG 2000 Siemens CERT Team / 1



Similar documents
Microsoft Auditing Events for Windows 2000/2003 Active Directory. By Ed Ziots Version 1.6 9/20/2005

Symantec Enterprise Security Manager Baseline Policy Manual for CIS Benchmark

User Rights vjj 1

Windows Server 2008/2012 Server Hardening

About Microsoft Windows Server 2003

Objectives. At the end of this chapter students should be able to:

Symantec Enterprise Security Manager Baseline Policy Manual for CIS Benchmark. For Windows Server 2008 (Domain Member Servers and Domain Controllers)

Windows NT Server Operating System Security Features Carol A. Siegel Payoff

Web. Security Options Comparison

Exam Ref Implementing an Advanced Server Infrastructure. Steve Suehring

Log Management and Intrusion Detection

Introduction to Computer Security

Contents. Supported Platforms. Event Viewer. User Identification Using the Domain Controller Security Log. SonicOS

Microsoft Windows NT. Securing Windows NT Installation. October 23, Microsoft Corporation. Contents. Abstract

PATCHING WINDOWS SERVER 2012 DOMAIN CONTROLLERS. Prepared By: Sainath K.E.V MVP Directory Services

APPENDIX I Basic Windows NT Server 4.0 Installation and Configuration

ExhIBIT 1 User Manager and Users Group

NETWRIX IDENTITY MANAGEMENT SUITE

Security Options... 1

Walton Centre. Document History Date Version Author Changes 01/10/ A Cobain L Wyatt 31/03/ L Wyatt Update to procedure

Defense Security Service Office of the Designated Approving Authority Standardization of Baseline Technical Security Configurations

PREPARED BY: AUDIT PROGRAM Author: Lance M. Turcato. APPROVED BY: Logical Security Operating Systems - Generic. Audit Date:

Managing and Maintaining a Windows Server 2003 Network Environment

Achieving PCI COMPLIANCE with the 2020 Audit & Control Suite.

Security. Ausgewählte Betriebssysteme Institut Betriebssysteme Fakultät Informatik. Copyright Hermann Härtig, Ronald Aigner

Ecora Enterprise Auditor Instructional Whitepaper. Who Made Change

MCSE TestPrep: Windows NT Server 4, Second Edition Managing Resources

Migration Strategies and Tools for the HP Print Server Appliance

Managing and Securing Windows Service Accounts. Bob McCoy, MCSE, CISSP/ISSAP Technical Account Manager Microsoft Corporation

3 Setting up Databases on a Microsoft SQL 7.0 Server

NETWRIX ACCOUNT LOCKOUT EXAMINER

Windows Operating Systems. Basic Security

NETWRIX EVENT LOG MANAGER

The Institute of Internal Auditors Detroit Chapter Presents


VERITAS Backup Exec 9.1 for Windows Servers Quick Installation Guide

Advanced Audit Policy Configurations for LT Auditor+ Reference Guide

How to monitor AD security with MOM

Understand Troubleshooting Methodology

Xcalibur. Foundation. Administrator Guide. Software Version 3.0

Vyapin Office 365 Management Suite

Directory Backup and Restore

- 1 - SmartStor Cloud Web Admin Manual

Introduction. Before you begin. Installing efax from our CD-ROM. Installing efax after downloading from the internet

Windows 2000/Active Directory Security

Windows Advanced Audit Policy Configuration

SB34: Event Logs Don t Lie: Step-by-Step Security. Rick Simonds, Sage Data Security

Server Manager Performance Monitor. Server Manager Diagnostics Page. . Information. . Audit Success. . Audit Failure

Dell InTrust Auditing and Monitoring Microsoft Windows

UserLock advanced documentation

Integrating LANGuardian with Active Directory

SECURITY BEST PRACTICES FOR CISCO PERSONAL ASSISTANT (1.4X)

PowerLink for Blackboard Vista and Campus Edition Install Guide

Find the Who, What, Where and When of Your Active Directory

Events Forensic Tools for Microsoft Windows

Windows 2000/XP DSS Auditing Written by: Darren Bennett - CISSP Originally Written 08/04/04 Last Updated 08/07/04

qliqdirect Active Directory Guide

How To - Implement Single Sign On Authentication with Active Directory

Move a VM 3.0 with AD Integration to a new server. Creation date: 17/06/2008 Last Review: 26/06/2008 Revision number: 1

Installing Windows Server Update Services (WSUS) on Windows Server 2012 R2 Essentials

Module 10: Maintaining Active Directory

SECURITY SUBSYSTEM IN WINDOWS

DameWare Development. DameWare NT Utilities Mini Remote Control Help Manual. Brought to you by Optrics Engineering, a division of Optrics Inc.

Microsoft Solutions for Security and Compliance. Windows Server 2003 Security Guide

BestSync Tutorial. Synchronize with a FTP Server. This tutorial demonstrates how to setup a task to synchronize with a folder in FTP server.

Installing, Configuring, and Managing a Microsoft Active Directory

NetIQ Advanced Authentication Framework - Client. User's Guide. Version 5.1.0

Microsoft Corporation. Project Server 2010 Installation Guide

How To - Implement Clientless Single Sign On Authentication with Active Directory

Guide to deploy MyUSBOnly via Windows Logon Script Revision 1.1. Menu

Quick Setup Guide. 2 System requirements and licensing Kerio Technologies s.r.o. All rights reserved.

Analyst 1.6 Software. Laboratory Director s Guide

Symantec Backup Exec 12.5 for Windows Servers. Quick Installation Guide

Session 17 Windows 7 Professional DNS & Active Directory(Part 2)

IIS SECURE ACCESS FILTER 1.3

Deep Freeze Enterprise - Advanced Maintenance & Autologon

Univention Corporate Server. Operation of a Samba domain based on Windows NT domain services

CRYPTOLogon Agent. for Windows Domain Logon Authentication. Deployment Guide. Copyright , CRYPTOCard Corporation, All Rights Reserved.

Table Of Contents. - Microsoft Windows - WINDOWS XP - IMPLEMENTING & SUPPORTING MICROSOFT WINDOWS XP PROFESSIONAL...10

Networking Best Practices Guide. Version 6.5

Audit Policy Subcategories

Binding an OS X computer to Active Directory at NEIU (Existing User)

MCTS Guide to Microsoft Windows 7. Chapter 7 Windows 7 Security Features

Symantec Backup Exec TM 11d for Windows Servers. Quick Installation Guide

WhatsUp Gold v16.1 Installation and Configuration Guide

How To Audit A Windows Active Directory System

Implementing HIPAA Compliance with ScriptLogic

PLANNING AND DESIGNING GROUP POLICY, PART 1

Using Windows Administrative Tools on VNX

MCSA Security + Certification Program

Hands-On Microsoft Windows Server 2008

Windows security for n00bs part 1 Security architecture & Access Control

RSA Authentication Manager 7.1 Basic Exercises

Chapter. Managing Group Policy MICROSOFT EXAM OBJECTIVES COVERED IN THIS CHAPTER:

McAfee One Time Password

Module 5: Implementing Group Policy

Standard: Event Monitoring

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Microsoft Virtual Labs. Active Directory New User Interface

Service Desk R11.2 Upgrade Procedure - Resetting USD passwords and unlocking accounts in etrust Web Admin

Transcription:

Sven Lehmberg / 1

Agenda Event Viewer and User Manager Analyzing Audit Logs Tools / 2

Auditing Step by Step Two important programs in NT 4.0 Event Viewer and User Manager User Manager for Domains / 3

/ 4

Event Viewer / 5

/ 6

HOWTO Enable Auditing? / 7

What to Audit? / 8

Logon and Logoff / 9

Interactive Logon / 10

Logon Type and Processes Logon Type: 2 : Interactive 3 : Network 4 : Batch 5 : Service 6 : Proxy 7 : Unlock Workstation Authentication Package: MICROSOFT_AUTHENTIC ATION_PACKAGE_V1_0 Logon Process: KSecDD User32 or WinLogon\MSGina SCMgr LAN Manager Workstation Service advapi MS.RADIUS / 11

Logon over the Network / 12

Event Detail No Logon Right over Network / 13

File and Object Access / 14

File And Registry Auditing / 15

Event Detail Object Access: File / 16

File System Access Types Full control Modify Read&Execute, List folders Read Write Traverse folder / Execute file x x x List folder / Read data x x x x Read attributes x x x x Read extended attributes x x x x Create files / Write data x x x Create folders / Append data x x x Write attributes x x x Write extended attributes x x x Delete subfolders and files x Delete x x Read permissions (READ_CONTROL) x x x x x Change permissions (WRITE_DAC) x Take ownership (WRITE_OWNER) x Synchronize x x x x x / 17

Registry Access Types Query Value Set Value Create Subkey Enumerate Subkeys Notify Create Link Delete Write DAC Read Control / 18

Use of User Rights / 19

27 User Rights Access this Computer from Network Debug programs SeDebugPrivilege Log on locally Act as part of the operating system - SeTcbPrivilege Add workstation to domain SeMachineAccountPrivilege Backup files and directories SeBackupPrivilege Bypass traverse checking SeChangeNotifyPrivilege Change the system time SeSystemTimePrivilege Create a pagefile SeCreatePagefilePrivilege Create a token object SeCreateTokenPrivilege Create permanent shared objects SeCreate PermanentPrivilege Force shutdown from a remote system SeRemoteShutdownPrivilege Generate security audits SeAuditPrivilege Increase quotas SeIncreaseQuotaPrivilege Increase scheduling priority SeIncreaseBasePriorityPriv. Load and unload device drivers SeLoadDriverPrivilege Lock pages in memory SeLockMemoryPriv. Log on as a batch job SeBatchSID Log on as a Service SeServiceSID Manage auditing and security - SeSecurityPrivilege Modify firmware environment values SeSystemEnvironmentPriv. Profile single process SeProfileSingleProcessPriv. Profile system performance SeSystemProfilePriv. Replace a process level token SeAssignPrimaryTokenPriv. Restore files and directories SeRestorePriv. Shut down the system SeShutdownPriv. Take ownership of files or other objects SeTakeOwnershipPriv. / 20

Event Detail Use of User Rights / 21

User and Group Management / 22

Event Detail User and Group Management / 23

Security Policy Changes / 24

Event Detail - Policy Change / 25

Restart, Shutdown, and System / 26

Event Detail: Restart, Shutdown, and System / 27

Starting NT Authentication and Trusted Logon / 28

Process Tracking / 29

Process Ids II / 30

Process IDs II / 31

Process IDs III Windows 2000 / 32

Process IDs IV Windows 2000 / 33

One Click - Many Security Events Audit Logs for a new user account: Event 632: Global Group Member Added Event 624: User Account Created Event 642: User Account Changed Event 636: Local Group Member Added / 34

Additional Auditing settings Auditing Backup and Restore Activities Key: HKLM\System\CCS\Control\Lsa\ Data: FullPrivilegeAuditing Type: REG_BINARY Value: 1 Base Object Auditing Key: HKLM\System\CCS\Control\Lsa\ Data: AuditBaseObjects Type: REG_DWORD Value: 1 / 35

Account Lockout Event stored on PDC Windows NT 4.0 SP4+ When a user enters too many incorrect passwords in an attempt to log on to a domain, the account is locked out and an event is written to the workstations security logs (if auditing is enabled here). With SP4 this event is also written to the PDC security log. / 36

Audit Policy / 37

Event Log Settings / 38

Lesson learnt You can get a lot of information from the logs Not all infomation is relevant Some information is wrong You can t get too much information about logging from MS / 39

Event IDs SIEMENS Filter Suspicious Events from all Events 512 - Windows NT is starting up 513 - Windows NT is shutting down 517 - The audit log was cleared 528 - Successful logon 529 - Unknown user name or bad password 530 Account logon time restriction violation 531 - Account currently disabled 532 - The specified user account has expired 533 - User not allowed to log on at this computer 534 User has not been granted the requested logon type 535 - The specified account s password has expired 536 The NetLogon component is not active 537 An unexpected error occured during logon 538 User Log off 539 - Account locked out 576 - Special privileges assigned to new logon 608 - User Right Assigned 609 - User Right Removed 612 - Audit Policy Change 624 - User Account Created 643 - Domain Policy Changed / 40

Suspicious Auditing Events Failed Logon Event ID 529 Administrator and Well Known Accounts / 41

Filter Suspicious Events from all Events / 42

Deficiencies of NT Logging Portscans can not be detected ❽ ❽ ❽ ❽ BOF Back Officer Friendly (NFR) http://www.nfr.com Nuke Nabber 2.9a (Dynamsol) http://www.dynamsol.com/puppet/ NetMonitor v0.90 (LeechSoftware) http://www.leechsoftware.com BlackICE http://advide.networkice.com Workstation logs are kept locally ❽ See next slide / 43

Logging Host EvntSLog 2.0 NTSlog 1.02, 2.0 NTOLog CERT / 44

Further Tools Lservers (NT Objectives, Inc.) NPList (NT Objectives, Inc.) WDumpEvt 1.2 ELDump 0.12 ELSaveClr NTLast Tripwire 2.1 for Windows NT / 45

Literature etc. MS Knowledgebase: Q174073, Auditing User Authentication Q174074, Security Event Descriptions Q163905, Auditing User Right Assignment Changes Q101366, Definition and List of Windows NT Advanced User Rights et al. found at http://support.microsoft.com/support/search/c.asp Books etc.: Microsoft Windows NT 4.0 Security, Audit and Control Microsoft Press Microsoft Technical ReferenceWindows NT Windows NT Server Resource Kit 4.0 Visual C++: winnt.h / 46