| Author | Messages | |
sbradcpa
Posts:496
 | | 02/08/2008 4:10 AM |
| <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type"> </head> <body bgcolor="#ffffff" text="#000000"> SecurityFocus:
<a class="moz-txt-link-freetext" href="http://www.securityfocus.com/archive/88/487752/30/0/threaded">http://www.securityfocus.com/archive/88/487752/30/0/threaded</a>
<a class="moz-txt-link-freetext" href="http://www.securityfocus.com/archive/88/487412/30/0/threaded">http://www.securityfocus.com/archive/88/487412/30/0/threaded</a>
Over on the SecurityFocus listserve one of the questions is "what regulations bind you?"
Similar thread on centralizing logs over there.
<a class="moz-txt-link-abbreviated" href="javascript:window.location.replace('ma'+'ilto:'+'neil.ruston'+'@'+'barclayswealth'+'.com')">neil.ruston@barclayswealth.com</a> wrote: <blockquote cite="mid:66638278BC179F4EBC96C1033FCBD77023B1CB2A9B@GBRPSMMSWM01VA.gbl.barwealth.net" type="cite"> <meta http-equiv="Content-Type" content="text/html; "> <meta name="Generator" content="Microsoft Word 11 (filtered medium)"> <!--[if !mso]> <style> v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style> <![endif]--><o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="PlaceType"> <o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="PlaceName"><o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="place"> <o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="PersonName"><!--[if !mso]> <style> st1\:*{behavior:url(#default#ieooui) } </style> <![endif]--> <style> <!--a:link {mso-style-priority:99;} span.MSOHYPERLINK {mso-style-priority:99;} a:visited {mso-style-priority:99;} span.MSOHYPERLINKFOLLOWED {mso-style-priority:99;} p {mso-style-priority:99;}
/* Font Definitions */ @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0;} @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman";} a:link, span.MsoHyperlink {color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {color:purple; text-decoration:underline;} p {mso-margin-top-alt:auto; margin-right:0cm; mso-margin-bottom-alt:auto; margin-left:0cm; font-size:12.0pt; font-family:"Times New Roman";} span.EmailStyle18 {mso-style-type:personal; font-family:Calibri; color:#002060; font-weight:bold;} span.EmailStyle19 {mso-style-type:personal; font-family:Calibri; color:#1F497D;} span.EmailStyle20 {mso-style-type:personal-reply; font-family:Arial; color:navy;} @page Section1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt;} div.Section1 {page:Section1;} --> </style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext="edit" spidmax="1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext="edit"> <o:idmap v:ext="edit" data="1" /> </o:shapelayout></xml><![endif]--> </o:SmartTagType></o:SmartTagType></o:SmartTagType></o:SmartTagType> <div class="Section1"> <p class="MsoNormal"><font color="navy" face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial; color: navy;">Interesting thread – I guess most of you don’t have banking regulations to consider – lucky you </span></font><font color="navy" face="Wingdings" size="2"><span style="font-size: 10pt; font-family: Wingdings; color: navy;">J</span></font><font color="navy" face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial; color: navy;"><o:p></o:p></span></font></p> <p class="MsoNormal"><font color="navy" face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial; color: navy;"><o:p> </o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"> What tool are you using? <b><span style="font-weight: bold;">Quest Intrust</span></b><o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US">
If <st1:place w:st="on"><st1 laceName w:st="on">System</st1 laceName> <st1 laceType w:st="on">Center</st1 laceType></st1:place> and it was MOM, did you see an improvement in performance/scalability over MOM? <b><span style="font-weight: bold;">MOM is a systems monitoring tool, IMO. I use it but not for collating and reporting on security events. I’m sure it can perform both roles – I prefer to use tools which are fit for purpose. Intrust has security specific aspects which MOM lacks.</span></b><o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"> What auditing do you have enabled? <b><span style="font-weight: bold;">Everything within the AD! Large parts of the file and reg are audited too on servers.</span></b><o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"> What is your event volume like? <b><span style="font-weight: bold;">10 million security events per day from DCs alone. We plan to add Exchange and file servers to the scope this year.</span></b><o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"> How long do you retain the events? (I.e. 30 days then they get purged) <b><span style="font-weight: bold;">I have no plan to ever purge the Intrust repository. I only retain 30 days of online data however. [I’ll let you read up on the architecture used by Intrust rather than explain here </span></b></span></font><b><font color="#1f497d" face="Wingdings" size="2"><span style="font-size: 11pt; font-family: Wingdings; color: rgb(31, 73, 125); font-weight: bold;" lang="EN-US">J</span></font></b><b><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125); font-weight: bold;" lang="EN-US">]<o:p></o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125); font-weight: bold;" lang="EN-US"><o:p> </o:p></span></font></b></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US">neil<o:p></o:p></span></font></p> <p class="MsoNormal"><font color="navy" face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial; color: navy;"><o:p> </o:p></span></font></p> <div> <div class="MsoNormal" style="text-align: center;" align="center"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US"> <hr tabindex="-1" align="center" size="2" width="100%"></span></font></div> <p class="MsoNormal"><b><font face="Tahoma" size="2"><span style="font-size: 10pt; font-family: Tahoma; font-weight: bold;" lang="EN-US">From:</span></font></b><font face="Tahoma" size="2"><span style="font-size: 10pt; font-family: Tahoma;" lang="EN-US"> <a class="moz-txt-link-abbreviated" href="javascript:window.location.replace('ma'+'ilto:'+'ActiveDir-owner'+'@'+'mail'+'.activedir')".org">ActiveDir-owner@mail.activedir.org</a> [<a class="moz-txt-link-freetext" href="javascript:window.location.replace('ma'+'ilto:'+'ActiveDir-owner'+'@'+'mail'+'.activedir')".org">mailto:ActiveDir-owner@mail.activedir.org</a>] <b><span style="font-weight: bold;">On Behalf Of </span></b>Lucas, Bryan
<b><span style="font-weight: bold;">Sent:</span></b> 08 February 2008 01:06
<b><span style="font-weight: bold;">To:</span></b> <st1 ersonName w:st="on"><a class="moz-txt-link-abbreviated" href="javascript:window.location.replace('ma'+'ilto:'+'ActiveDir'+'@'+'mail'+'.activedir')".org">ActiveDir@mail.activedir.org</a></st1 ersonName>
<b><span style="font-weight: bold;">Subject:</span></b> How to collect logs - was RE: [ActiveDir] Event Log Entries...</span></font><span lang="EN-US"><o:p></o:p></span></p> </div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;"><o:p> </o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US">For those of collecting AD logs… <o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"> What tool are you using?<o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US">
If <st1:place w:st="on"><st1 laceName w:st="on">System</st1 laceName> <st1 laceType w:st="on">Center</st1 laceType></st1:place> and it was MOM, did you see an improvement in performance/scalability over MOM?<o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"> What auditing do you have enabled?<o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"> What is your event volume like?<o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"> How long do you retain the events? (I.e. 30 days then they get purged)<o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"><o:p> </o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US">Even with selective logging, we’re generating 2.6 million total security events per day from our DC’s. The tools I’ve tried can’t handle that volume, so I was considering trying <st1:place w:st="on"><st1 laceName w:st="on">System</st1 laceName> <st1 laceType w:st="on">Center</st1 laceType></st1:place>.<o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"><o:p> </o:p></span></font></p> <div> <p class="MsoNormal"><font color="#1f497d" face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial; color: rgb(31, 73, 125);" lang="EN-US">Bryan Lucas<o:p></o:p></span></font></p> <p class="MsoNormal"><font color="#1f497d" face="Arial" size="1"><span style="font-size: 7.5pt; font-family: Arial; color: rgb(31, 73, 125);" lang="EN-US">Director of Technical Services<o:p></o:p></span></font></p> <p class="MsoNormal"><st1:place w:st="on"><st1 laceName w:st="on"><font color="#1f497d" face="Arial" size="1"><span style="font-size: 7.5pt; font-family: Arial; color: rgb(31, 73, 125);" lang="EN-US">Texas</span></font></st1 laceName><font color="#1f497d" face="Arial" size="1"><span style="font-size: 7.5pt; font-family: Arial; color: rgb(31, 73, 125);" lang="EN-US"> <st1 laceName w:st="on">Christian</st1 laceName> <st1 laceName w:st="on">University</st1 laceName></span></font></st1:place><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"><o:p></o:p></span></font></p> </div> <p class="MsoNormal"><font color="#1f497d" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(31, 73, 125);" lang="EN-US"><o:p> </o:p></span></font></p> <div> <div style="border-style: solid none none; border-color: rgb(181, 196, 223) -moz-use-text-color -moz-use-text-color; border-width: 1pt medium medium; padding: 3pt 0cm 0cm;"> <p class="MsoNormal"><b><font face="Tahoma" size="2"><span style="font-size: 10pt; font-family: Tahoma; font-weight: bold;" lang="EN-US">From:</span></font></b><font face="Tahoma" size="2"><span style="font-size: 10pt; font-family: Tahoma;" lang="EN-US"> <a class="moz-txt-link-abbreviated" href="javascript:window.location.replace('ma'+'ilto:'+'ActiveDir-owner'+'@'+'mail'+'.activedir')".org">ActiveDir-owner@mail.activedir.org</a> [<a class="moz-txt-link-freetext" href="javascript:window.location.replace('ma'+'ilto:'+'ActiveDir-owner'+'@'+'mail'+'.activedir')".org">mailto:ActiveDir-owner@mail.activedir.org</a>] <b><span style="font-weight: bold;">On Behalf Of </span></b>Brian Desmond
<b><span style="font-weight: bold;">Sent:</span></b> Thursday, February 07, 2008 2:54 PM
<b><span style="font-weight: bold;">To:</span></b> <st1 ersonName w:st="on"><a class="moz-txt-link-abbreviated" href="javascript:window.location.replace('ma'+'ilto:'+'ActiveDir'+'@'+'mail'+'.activedir')".org">ActiveDir@mail.activedir.org</a></st1 ersonName>
<b><span style="font-weight: bold;">Subject:</span></b> RE: [ActiveDir] Event Log Entries...<o:p></o:p></span></font></p> </div> </div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US"><o:p> </o:p></span></font></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US">I have a standard set of MOM rules I use for customers that traps changes to all the builtin admin groups as well as account management events on the builtin admin account.<o:p></o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US"><o:p> </o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US">There are two KB articles titled to the tune of “Windows 2000 security event descriptions part 1” and part 2. I usually use that as a reference.<o:p></o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US"><o:p> </o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US">Thanks,<o:p></o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US">Brian Desmond<o:p></o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US"><a class="moz-txt-link-abbreviated" href="javascript:window.location.replace('ma'+'ilto:'+'brian'+'@'+'briandesmond'+'.com')">brian@briandesmond.com</a><o:p></o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US"><o:p> </o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US">c - 312.731.3132<o:p></o:p></span></font></b></p> <p class="MsoNormal"><b><font color="#002060" face="Calibri" size="2"><span style="font-size: 11pt; font-family: Calibri; color: rgb(0, 32, 96); font-weight: bold;" lang="EN-US"><o:p> </o:p></span></font></b></p> <div style="border-style: solid none none; border-color: rgb(181, 196, 223) -moz-use-text-color -moz-use-text-color; border-width: 1pt medium medium; padding: 3pt 0cm 0cm;"> <p class="MsoNormal"><b><font face="Tahoma" size="2"><span style="font-size: 10pt; font-family: Tahoma; font-weight: bold;" lang="EN-US">From:</span></font></b><font face="Tahoma" size="2"><span style="font-size: 10pt; font-family: Tahoma;" lang="EN-US"> <a class="moz-txt-link-abbreviated" href="javascript:window.location.replace('ma'+'ilto:'+'ActiveDir-owner'+'@'+'mail'+'.activedir')".org">ActiveDir-owner@mail.activedir.org</a> [<a class="moz-txt-link-freetext" href="javascript:window.location.replace('ma'+'ilto:'+'ActiveDir-owner'+'@'+'mail'+'.activedir')".org">mailto:ActiveDir-owner@mail.activedir.org</a>] <b><span style="font-weight: bold;">On Behalf Of </span></b>Frank Abagnale
<b><span style="font-weight: bold;">Sent:</span></b> Thursday, February 07, 2008 6:27 AM
<b><span style="font-weight: bold;">To:</span></b> Active
<b><span style="font-weight: bold;">Subject:</span></b> [ActiveDir] Event Log Entries...<o:p></o:p></span></font></p> </div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US"><o:p> </o:p></span></font></p> <div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US">I want to set up some MOM alerts for changes to the Administrator account.<o:p></o:p></span></font></p> </div> <div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US"> <o:p></o:p></span></font></p> </div> <div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US">From looking at the event logs, Event ID 628 seems to suggest Password Change.<o:p></o:p></span></font></p> </div> <div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US">Does anyone know of other event log ID's that I should be made aware off?<o:p></o:p></span></font></p> </div> <div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US"> <o:p></o:p></span></font></p> </div> <div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US">thanks<o:p></o:p></span></font></p> </div> <div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US"> <o:p></o:p></span></font></p> </div> <div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US">- Frank<o:p></o:p></span></font></p> </div> <p><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US"> <o:p></o:p></span></font></p> <div class="MsoNormal" style="text-align: center;" align="center"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US"> <hr align="center" size="1" width="100%"></span></font></div> <p class="MsoNormal"><font face="Times New Roman" size="3"><span style="font-size: 12pt;" lang="EN-US">Never miss a thing. <a moz-do-not-send="true" href="http://us.rd.yahoo.com/evt=51438/*http:/www.yahoo.com/r/hs">Make Yahoo your homepage.</a> <o:p></o:p></span></font></p> </div> <p> </p> <hr><font face="Arial" size="1">Barclays Wealth is the wealth management division of Barclays Bank PLC. This email may relate to or be sent from other members of the Barclays Group.</font> <p><font face="Arial" size="1">The availability of products and services may be limited by the applicable laws and regulations in certain jurisdictions. The Barclays Group does not normally accept or offer business instructions via internet email. Any action that you might take upon this message might be at your own risk.</font></p> <p><font face="Arial" size="1">This e-mail and any attachments are confidential and intended solely for the addressee and may also be privileged or exempt from disclosure under applicable law. If you are not the addressee, or have received this e-mail in error, please notify the sender immediately, delete it from your system and do not copy, disclose or otherwise act upon any part of this e-mail or its attachments.</font></p> <p><font face="Arial" size="1">Internet communications are not guaranteed to be secure or virus-free. The Barclays Group does not accept responsibility for any loss arising from unauthorised access to, or interference with, any Internet communications by any third party, or from the transmission of any viruses. Replies to this e-mail may be monitored by the Barclays Group for operational or business reasons.</font></p> <p><font face="Arial" size="1">Any opinion or other information in this e-mail or its attachments that does not relate to the business of the Barclays Group is personal to the sender and is not given or endorsed by the Barclays Group.</font></p> <p><font face="Arial" size="1">Barclays Bank PLC. Registered in England and Wales (registered no. 1026167).
Registered Office: 1 Churchill Place, London, E14 5HP, United Kingdom.</font></p> <p><font face="Arial" size="1">Barclays Bank PLC is authorised and regulated by the Financial Services Authority.</font></p> </blockquote> </body> </html> List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.activedir.org/ma/default.aspx
| | | |
|
|