Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: 4656 event log with FIM on windows 7 machine filter

$
0
0

Thoughts here? This is a user workstation. Same event log id (4656), but for a directory recursive monitor by FIM (PCI template)

 

Event FieldInformation
Event NameFileAuditFailure
EventInfoFile open failed "C:\Windows\System32\mfc42u.dll" user "XXXXXXXX$"
InsertionIPXXXXXXXXXX
ManagerLEM
DetectionIPXXXXXXXX
InsertionTime15:50:27 Wed May 04 2016
DetectionTime15:50:12 Wed May 04 2016
Severity3
ToolAliasVista Security
InferenceRule
ProviderSIDMicrosoft-Windows-Security-Auditing 4656
ExtraneousInfoProcessName: C:\Windows\System32\services.exe
SourceAccountXXXXXXXXXX
SourceDomainZZZ
SourceLogonID0x3e7
DestinationAccount
DestinationDomain
DestinationLogonId
AccessRequestedREAD_CONTROL     WRITE_DAC
PrivilegesExercised0x60000
FileNameC:\Windows\System32\mfc42u.dll
FileHandleID0x0
OperationID0
ServingProcess0x21c
AccessPropertiesMask: READ_CONTROL: Granted by D:(A;;0x1200a9;;;BA)     WRITE_DAC: Not granted
OperationTypeFileOpenFailure

Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>