track SAM modifications

  • Thread starter Marc Ochsenmeier
  • Start date
M

Marc Ochsenmeier

Hi,

I know that, when turned on, Windows entries in the events log when someone
changes the SAM.

My question is: is there any notification mechanism proper to the SAM that
can be registered in order to capture these events?

Thanks
Marc Ochsenmeier
______________________________________________________

(e-mail address removed) HP Customer Support R&D
Network Services
tel: +49 (7031) 14-7503 Schickardstraße 25
fax: +49 (7031) 14-4987 D - 71034 Böblingen
 
J

Jean-Baptiste Marchand

Marc said:
I know that, when turned on, Windows entries in the events log when someone
changes the SAM.

Yes, when the _Audit object access_ auditing category is set (for
success and/or failures) in the security auditing policy, 560 events
related to SAM objects appear in the security eventlog.

This is because SAM objects have by default a SACL (see the following
thread for more details):

http://www.securityfocus.com/archive/116/327320/2003-06-30/2003-07-06/1
My question is: is there any notification mechanism proper to the SAM that
can be registered in order to capture these events?

Not that I know of. But you can modify the SACL on SAM objects using the
samacl tool:

http://razor.bindview.com/tools/desc/acltools1.0-readme.html


Of course, a 560 event does not actually mean that an object was
effectively accessed but only that access was given to an object, with
the intent to do something with it.


Jean-Baptiste Marchand
 
E

Eric Fitzgerald [MSFT]

Better still, enable "Account Management", the events are more clear.

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
M

Marc Ochsenmeier

Hi,

this is was I did! I did enable the auditing of "Account management". From
this point, I receive the event 518 in the log events.
This event tells me how someone has been trying to modify the SAM.

....but what I am really looking for is a mechanism that allow me to
(programmatically) register a component (dll?) that will enable me to catch
these events additionally to log events. My goal is to collect the SAM
specific audit events in another application.

Thanks in advance.

Marc Ochsenmeier
www.ochsenmeier.com



Eric Fitzgerald said:
Better still, enable "Account Management", the events are more clear.

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
M

Marc Ochsenmeier

Hi,

this is was I did! I did enable the auditing of "Account management". From
this point, I receive the event 518 in the log events.
This event tells me how someone has been trying to modify the SAM.

....but what I am really looking for is a mechanism that allow me to
(programmatically) register a component (dll?) that will enable me to catch
these events additionally to log events. My goal is to collect the SAM
specific audit events in another application.

Thanks in advance.

Marc Ochsenmeier
www.ochsenmeier.com



Eric Fitzgerald said:
Better still, enable "Account Management", the events are more clear.

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
M

Marc Ochsenmeier

Hi,

this is was I did! I did enable the auditing of "Account management". From
this point, I receive the event 518 in the log events.
This event tells me how someone has been trying to modify the SAM.

....but what I am really looking for is a mechanism that allow me to
(programmatically) register a component (dll?) that will enable me to catch
these events additionally to log events. My goal is to collect the SAM
specific audit events in another application.

Thanks in advance.

Marc Ochsenmeier
www.ochsenmeier.com



Eric Fitzgerald said:
Better still, enable "Account Management", the events are more clear.

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
M

Marc Ochsenmeier

Hi,

this is was I did! I did enable the auditing of "Account management". From
this point, I receive the event 518 in the log events.
This event tells me how someone has been trying to modify the SAM.

....but what I am really looking for is a mechanism that allow me to
(programmatically) register a component (dll?) that will enable me to catch
these events additionally to log events. My goal is to collect the SAM
specific audit events in another application.

Thanks in advance.

Marc Ochsenmeier
www.ochsenmeier.com



Eric Fitzgerald said:
Better still, enable "Account Management", the events are more clear.

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
M

Marc Ochsenmeier

Hi,

this is was I did! I did enable the auditing of "Account management". From
this point, I receive the event 518 in the log events.
This event tells me how someone has been trying to modify the SAM.

....but what I am really looking for is a mechanism that allow me to
(programmatically) register a component (dll?) that will enable me to catch
these events additionally to log events. My goal is to collect the SAM
specific audit events in another application.

Thanks in advance.

Marc Ochsenmeier
www.ochsenmeier.com



Eric Fitzgerald said:
Better still, enable "Account Management", the events are more clear.

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
M

Marc Ochsenmeier

Hi,

this is was I did! I did enable the auditing of "Account management". From
this point, I receive the event 518 in the log events.
This event tells me how someone has been trying to modify the SAM.

....but what I am really looking for is a mechanism that allow me to
(programmatically) register a component (dll?) that will enable me to catch
these events additionally to log events. My goal is to collect the SAM
specific audit events in another application.

Thanks in advance.

Marc Ochsenmeier
www.ochsenmeier.com

Eric Fitzgerald said:
Better still, enable "Account Management", the events are more clear.

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
M

Marc Ochsenmeier

sorry about this multiple answer!
I don't know what happend, the server had a problem....


Eric Fitzgerald said:
Better still, enable "Account Management", the events are more clear.

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
R

Roger Abell [MVP]

You may want to look into using WMI to get a notification
set up on the event log entries of interest.

Marc Ochsenmeier said:
Hi,

this is was I did! I did enable the auditing of "Account management". From
this point, I receive the event 518 in the log events.
This event tells me how someone has been trying to modify the SAM.

...but what I am really looking for is a mechanism that allow me to
(programmatically) register a component (dll?) that will enable me to catch
these events additionally to log events. My goal is to collect the SAM
specific audit events in another application.

Thanks in advance.

Marc Ochsenmeier
www.ochsenmeier.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top