Applied Incident Response by Steve Anson
Author:Steve Anson [Anson, Steve]
Language: eng
Format: epub
ISBN: 9781119560319
Publisher: Wiley
Published: 2020-02-26T00:00:00+00:00
Object Access
Whether you’re dealing with an insider threat or a remote attacker who has gained access to your systems, determining what data was accessed by an adversary is frequently necessary during an incident response. Windows provides auditing capabilities to answer this question, but only if they are explicitly enabled before an incident occurs. Attackers frequently leverage valid credentials to remotely access data in user‐created shared folders or administrative shares (shares that are created by the system and designated by a dollar sign at the end of the share name). Doing so will generate Account Logon and Logon events as mentioned earlier, but additional logging can also be enabled in the Group Policy Management Console by navigating to Computer Configuration ➪ Policies ➪ Windows Settings ➪ Security Settings ➪ Advanced Audit Policy Configuration ➪ Audit Policies ➪ Object Access ➪ Audit File Share. Once enabled, the event IDs described in Table 8.7 are logged in the Security log of the local system.
Table 8.7: Network share event IDs
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Sass and Compass in Action by Wynn Netherland Nathan Weizenbaum Chris Eppstein Brandon Mathis(7783)
Grails in Action by Glen Smith Peter Ledbrook(7697)
Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 by Chris Gill(6575)
Azure Containers Explained by Wesley Haakman & Richard Hooper(6565)
Running Windows Containers on AWS by Marcio Morales(6096)
Kotlin in Action by Dmitry Jemerov(5067)
Microsoft 365 Identity and Services Exam Guide MS-100 by Aaron Guilmette(4922)
Combating Crime on the Dark Web by Nearchos Nearchou(4502)
Management Strategies for the Cloud Revolution: How Cloud Computing Is Transforming Business and Why You Can't Afford to Be Left Behind by Charles Babcock(4414)
Microsoft Cybersecurity Architect Exam Ref SC-100 by Dwayne Natwick(4348)
The Ruby Workshop by Akshat Paul Peter Philips Dániel Szabó and Cheyne Wallace(4177)
The Age of Surveillance Capitalism by Shoshana Zuboff(3959)
Python for Security and Networking - Third Edition by José Manuel Ortega(3745)
Learn Windows PowerShell in a Month of Lunches by Don Jones(3509)
The Ultimate Docker Container Book by Schenker Gabriel N.;(3412)
Mastering Python for Networking and Security by José Manuel Ortega(3345)
Mastering Azure Security by Mustafa Toroman and Tom Janetscheck(3332)
Blockchain Basics by Daniel Drescher(3298)
Learn Wireshark by Lisa Bock(3268)
