The Active Directory Administrative Center is another new component introduced by Windows Server 2008 R2. Many admins gave it a glance, thought to themselves "another ADUC, why bother?", and went back to their familiar old tool. If you like acctinfo.dll though, you should like ADAC.
With Win7 RSAT installed and the AD tools enabled (or RDP'ed into your Win2008 R2 servers for AD administration), run DSAC.EXE. You'll see this:
Here is the detail explanation from the expert http://blogs.technet.com/b/askds/archive/2011/04/12/you-probably-don-t-need-acctinfo2-dll.aspx
Thursday, February 26, 2015
Tuesday, October 21, 2014
Tracing User Activities
It would be great if we can have one tool that will be able to tell us what are the user activities or have done on the computer base on date!
May be we can start with this tool.
Name: LastActivityView by Nirsoft
URL: http://www.nirsoft.net/utils/computer_activity_view.htm
Description:
LastActivityView is a tool for Windows operating system that collects information from various sources on a running system, and displays a log of actions made by the user and events occurred on this computer. The activity displayed by LastActivityView includes: Running .exe file, Opening open/save dialog-box, Opening file/folder from Explorer or other software, software installation, system shutdown/start, application or system crash, network connection/disconnection and more...
May be we can start with this tool.
Name: LastActivityView by Nirsoft
URL: http://www.nirsoft.net/utils/computer_activity_view.htm
Description:
LastActivityView is a tool for Windows operating system that collects information from various sources on a running system, and displays a log of actions made by the user and events occurred on this computer. The activity displayed by LastActivityView includes: Running .exe file, Opening open/save dialog-box, Opening file/folder from Explorer or other software, software installation, system shutdown/start, application or system crash, network connection/disconnection and more...
Windows OS: When was a File Deleted?
Can dates of file deletion be obtained? Yes, sometimes.
In a computer forensics examination dates are almost always going to important. Every file on a modern Windows system has numerous dates, from the Created, Modified, Last Written, and Entry Modified dates in the NTFS, to the dates in Link file, registry entries, and folders.
“Was the file deleted before his resignation?”
“Was the file deleted before or after the data preservation order?”
“If the file was deleted on the 1st rather than the 31st, than that means there was a breach of a court order. Can you say when it was deleted?”
All of these questions are asking the same thing: “When was a file deleted?”
NTFS, the standard file system for Windows, does not record a deleted date, however the recycle bin does. When a file is deleted via the recycle bin (i.e when a user clicks delete for a file it is placed in the recycle bin) the recycle bin keeps track of the deletion of the file – when it happend, how big the file was, and where it came from. This information is stored within the INFO2 file of that recycle bin.
Therefore if a file was deleted via the recycle bin the date of deletion can be recovered.
However, if it is not deleted via a recycle bin, this information is not recorded.
Source URL:
http://whereismydata.wordpress.com/2009/04/02/forensics-deleted-dates/
http://whereismydata.wordpress.com/2009/08/16/forensics-when-was-a-file-deleted-part-1/
http://whereismydata.wordpress.com/2009/08/17/forensics-when-was-a-file-deleted-part-2/
In a computer forensics examination dates are almost always going to important. Every file on a modern Windows system has numerous dates, from the Created, Modified, Last Written, and Entry Modified dates in the NTFS, to the dates in Link file, registry entries, and folders.
“Was the file deleted before his resignation?”
“Was the file deleted before or after the data preservation order?”
“If the file was deleted on the 1st rather than the 31st, than that means there was a breach of a court order. Can you say when it was deleted?”
All of these questions are asking the same thing: “When was a file deleted?”
NTFS, the standard file system for Windows, does not record a deleted date, however the recycle bin does. When a file is deleted via the recycle bin (i.e when a user clicks delete for a file it is placed in the recycle bin) the recycle bin keeps track of the deletion of the file – when it happend, how big the file was, and where it came from. This information is stored within the INFO2 file of that recycle bin.
Therefore if a file was deleted via the recycle bin the date of deletion can be recovered.
However, if it is not deleted via a recycle bin, this information is not recorded.
Source URL:
http://whereismydata.wordpress.com/2009/04/02/forensics-deleted-dates/
http://whereismydata.wordpress.com/2009/08/16/forensics-when-was-a-file-deleted-part-1/
http://whereismydata.wordpress.com/2009/08/17/forensics-when-was-a-file-deleted-part-2/
Wednesday, July 9, 2014
Windows Share Folder Auditing Setting
If you want to setup Windows share folder Auditing policy, check out this link http://blog.windowsnt.lv/2011/11/15/tracking-user-activity-english/
Wednesday, June 4, 2014
Windows Registry Hives
A hive is a logical group of keys, subkeys, and values in the registry that has a set of supporting files containing backups of its data.
Most of the supporting files for the hives are in the %SystemRoot%\System32\Config directory. These files are updated each time a user logs on.
Registry hive Supporting files
HKEY_CURRENT_CONFIG System, System.alt, System.log, System.sav
HKEY_CURRENT_USER Ntuser.dat, Ntuser.dat.log
HKEY_LOCAL_MACHINE\SAM Sam, Sam.log, Sam.sav
HKEY_LOCAL_MACHINE\Security Security, Security.log, Security.sav
HKEY_LOCAL_MACHINE\Software Software, Software.log, Software.sav
HKEY_LOCAL_MACHINE\System System, System.alt, System.log, System.sav
HKEY_USERS\.DEFAULT Default, Default.log, Default.sav
Detail URL: http://msdn.microsoft.com/en-us/library/windows/desktop/ms724877%28v=vs.85%29.aspx
Most of the supporting files for the hives are in the %SystemRoot%\System32\Config directory. These files are updated each time a user logs on.
Registry hive Supporting files
HKEY_CURRENT_CONFIG System, System.alt, System.log, System.sav
HKEY_CURRENT_USER Ntuser.dat, Ntuser.dat.log
HKEY_LOCAL_MACHINE\SAM Sam, Sam.log, Sam.sav
HKEY_LOCAL_MACHINE\Security Security, Security.log, Security.sav
HKEY_LOCAL_MACHINE\Software Software, Software.log, Software.sav
HKEY_LOCAL_MACHINE\System System, System.alt, System.log, System.sav
HKEY_USERS\.DEFAULT Default, Default.log, Default.sav
Detail URL: http://msdn.microsoft.com/en-us/library/windows/desktop/ms724877%28v=vs.85%29.aspx
Thursday, May 22, 2014
Powershell: Get FQDN of local or remote computer
To get FQDN of local computer:
PS C:\> [System.Net.Dns]::GetHostByName(($env:computerName))
To get FQDN of Remote computer:
PS C:\> [System.Net.Dns]::GetHostByName("notebook01")
Note:
System.Net.DNS class has a few other useful methods using which you can get FDQN and IP address details.
Refer to http://msdn.microsoft.com/en-us/library/system.net.dns.aspx for more details.
PS C:\> [System.Net.Dns] | Get-Member -Static
PS C:\> [System.Net.Dns]::GetHostByName(($env:computerName))
To get FQDN of Remote computer:
PS C:\> [System.Net.Dns]::GetHostByName("notebook01")
Note:
System.Net.DNS class has a few other useful methods using which you can get FDQN and IP address details.
Refer to http://msdn.microsoft.com/en-us/library/system.net.dns.aspx for more details.
PS C:\> [System.Net.Dns] | Get-Member -Static
Friday, May 2, 2014
How to Use the Cipher Security Tool to Overwrite Deleted Data
To overwrite deleted data on a volume by using Cipher.exe, use the /w switch with the cipher command. Use the following steps:
C:>Users\user_name\> cipher /w:C:\ and then press ENTER.
To overwrite deleted data on folder
C:>Users\user_name\> cipher /w:C:\your_folder_name and then press ENTER.
Note: Specify the drive and the folder that identifies the volume that contains the deleted data that you want to overwrite. Data that is not allocated to files or folders will be overwritten. This permanently removes the data. This can take a long time if you are overwriting a large space.
Detail URL: http://support.microsoft.com/kb/315672
- Quit all programs.
- Click Start, click Run, type cmd, and then press ENTER.
- Type cipher /w:driveletter:\foldername, and then press ENTER.
C:>Users\user_name\> cipher /w:C:\ and then press ENTER.
To overwrite deleted data on folder
C:>Users\user_name\> cipher /w:C:\your_folder_name and then press ENTER.
Note: Specify the drive and the folder that identifies the volume that contains the deleted data that you want to overwrite. Data that is not allocated to files or folders will be overwritten. This permanently removes the data. This can take a long time if you are overwriting a large space.
Detail URL: http://support.microsoft.com/kb/315672
Subscribe to:
Posts (Atom)