Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

After reviewing how we manage looking for who deleted what files and updating a few things I wondered how others did it?

 

We have 2 file servers that are a dfsr copy of each other. We are now using event forwarding to forward events to another server, using the filter in the event subscription section so we only recieve deleted events, this massivley cuts down the events received to just the ones we are interested, getting round the limitation of having to audit all file access events creating which creates a massive log file and takes ages to search. Also smaller log files mean we can retain deletion logs longer. Forwarding the events means we can have smaller log file sizes and shorter retention times on the actual file servers themselves as information we need from them has been forwarded elsewhere, no more deleting old auto archived security eventlog files.

 

The filter we use is:-


 
   
*[system[(EventID=4663)]]
and
*[EventData[Data[@Name='AccessMask'] and (Data='0x10000')]]
   
   
*[system[(EventID=4659)]]
and
*[EventData[Data[@Name='AccessMask'] and (Data='0x10080')]]
   
   
*[EventData[Data[@Name='ProcessName'] and (Data='C:\Windows\System32\dfsrs.exe')]]
or
*[EventData[Data[@Name='ProcessName'] and (Data='C:\Windows\System32\svchost.exe')]]
   
 

 

Originally we were just using the standard event of 4663 and access mask of 0x10000, however I noticed that it didnt seem to be catching all events. Adding in event 4659 (intent to delete) with mask of 0x10080 (Delete+read permissions) caught the rest. Im guessing this is either to do with shadow copies or dfsr. I exclude the dfsrs and svchost services as I am only really interested in users deleteing files.

Posted
From what ive read the filter uses a subset of XPath 1.0, and doesnt support wildcards or start/end/mid. I wanted to include a filter to ignore .tmp files and ~ files, I dont think its possible though.
Posted
Once you have the log though you can just do a find against the log, in the eventviewer gui, putting in the path eg. "D:\Sharename", but as above I havent found a way to limit it to just logging that path.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...