mobi_khan
Posts: 24
Score: 0
Joined: 16.May2008
Status: offline
|
Hi, I wanted to configure the GFI so that I get alert only in case if the user changes the registry value "Start"=4 under the key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR . I have enabled the auditing and for this registry key and selected the "set value". But I am not getting the alert for this. OK but When I enabled the followling auditing entries: 1. Notify 2. Write DAC 3. Write Owner 4.Enumerate Subkeys I am getting the follwoing alert Object Open: Object Server: Security Object Type: Key Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\USBSTOR Handle ID: 304 Operation ID: {0,1316420437} Process ID: 768 Image File Name: C:\WINDOWS\regedit.exe Primary User Name: mubashir.ismail Primary Domain: SENSYS Primary Logon ID: (0x0,0x346DE) Client User Name: - Client Domain: - Client Logon ID: - Accesses: Enumerate sub-keys Privileges: - Restricted Sid Count: 0 SENSYS\mubashir.ismail SS01-CPU-032 Security 7:18:08 PM Critical SS01-CPU-032 8/6/2008 One thing more that you will see that in the Object name its not the "ControlSet" but its "ControlSet001" why is it so?? I just want that if the value of the "Start" changes form 4 to any other value I get the alert. How I can do that please guide me in this regard.
|