|
|
|
XPath to generate a list of NTLM authentications on Windows Vista or Later |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : Hi Everyone, Sas sent me an email complaining that I am not posting as often as I should- sorry about that. I am working on a different project now but I am still in close touch with the auditing team and I'll try to do better. Anyway a question that I hear regularly is, how do I find all the NTLM authentications on my network Other than running a network trace, the best way I have found ok invented - to do this is to look at the logon events in the audit log. One of the changes we made to the logon events in Windows Vista and therefore subsequent releases of Windows was to include the NTLM protocol level in the logon events, if the NTLM auth package was used. Now, with the new EventLog ecosystem, it's easy to generate some XPath to find just these events. Here's the query System Provider Name 'Microsoft-Windows-Security-Auditing' and Task 12544 and band Keywords,9007199254740992 and EventID 4624 and EventData Data Name 'LmPackageName' '-' To use this in Event Viewer 1. Find the Security log under Windows Logs in the tree pane. 2. Right-click the Security log, and choose Filter Current Log... 3. Select the XML tab. 4. Check the Edit query manually box. 5. Replace the default query , or everything in the element , with the text in the box above. I've formatted it for readability. 6. Click OK The event view will now be filtered and you'll only see NTLM logon events. Additionally, each filtered event will contain a Detailed Authentication Information section containing the protocol level e.g. LM, NTLM, NTLM V2 in the Package Name field, and the session key length, if one was negotiated. Detailed Authentication Information Logon Process NtLmSsp Authentication Package NTLM Transited Services - Package Name NTLM only NTLM V2 Key Length 128
Les mots clés de la revue de presse pour cet article : windows vista Les videos sur SecuObs pour les mots clés : windows vista Les mots clés pour les articles publiés sur SecuObs : windows vista Les éléments de la revue Twitter pour les mots clé : windows vista
Les derniers articles du site "Windows Security Logging and Other Esoterica" :
- XPath to generate a list of NTLM authentications on Windows Vista or Later - Auditing system impact on performance - Mapping pre-Vista Security Event IDs to Security Event IDs in Vista+ - List of Windows Server 2003 Events - Why does Windows XP generate so many logon failure events? - I always wondered who Björn was... - ACS Tidbits - You learn something new every day- Logon Type 0 - ACS Event Transformation Demystified - Shameless Self-Promotion
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|