Re: filesystem watcher and more



"hugomind" <hugomind@xxxxxxxxx> wrote in message news:519f23e1-317e-47f8-9f3a-d17bd071e349@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,

I need to catch the domainname/username as additional information when
the Filesystemwatcher throws en event ?
If someone is creating, deleting or changing perms of a file I would
need to know who it was.

Could some give me a hint how to accomplish this ?

thnx,
Hugo


Turn on file auditing (Access - Successful ) for the "Authenticated Users" on the File and/or Directories you care about, an event will be written to the security log provided you did enable "Object Access" Auditing in the Local Policies.
The security log entry will tell you who's did what on the FS object.
Even with a FS filter driver it's not possible to get at this info, you are to low in the IO stack to get at this info, which is only accessible by the security subsystem system in the kernel.

Willy.


.



Relevant Pages

  • Re: Event ID 560 Problem
    ... >Error 560s usually refer to object access. ... >whenever a user makes a connection to something out on ... >> this repeated event in my security log that I can't ... Whenever someone log off their workstation, ...
    (microsoft.public.win2000.security)
  • Re: a forensic question
    ... Would anyone gain anything by deleting ... like this turn out to be user error, though without auditing logs all you've ... But she discovered that some important files on her workstation ... >> security log of the PDC? ...
    (microsoft.public.win2000.security)
  • Re: a forensic question
    ... Would anyone gain anything by deleting ... like this turn out to be user error, though without auditing logs all you've ... But she discovered that some important files on her workstation ... >> security log of the PDC? ...
    (comp.security.misc)
  • Re: Help!Am I being hacked?
    ... That is entirely normal to be seen in the security log for access to the local sam by ... NT AUTHORITY\SYSTEM when object access is enabled. ... for the administrator account. ... account can not be locked out to console logon. ...
    (microsoft.public.win2000.security)
  • Re: Data access and security permissions
    ... protection" to "low" and see if this continues. ... >Category: Object Access ... Access databases ... security log to fill up ...
    (microsoft.public.inetserver.iis.security)