Notifications
Clear all

log file analysis

8 Posts
2 Users
0 Reactions
395 Views
chinigami
(@chinigami)
Active Member
Joined: 18 years ago
Posts: 17
Topic starter  

hello,

generally log files are under windows(system root) directory but there are some logs under system32\config directory likesecurity.log,sam.log, system.log,userdiff.log,tempkey.log and software.log. these logs can't be accessed and they contain important informations about users authentications and activities.
i tried some software to open these logs but they don't worked(specialised only on server log analysis)
(i think that we can open these logs by using a live cd but i haven't tried yet)
so do u know some software that can analyse these special logs??

thanks for the help


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

> they contain important informations about users authentications and activities.

Such as…?


   
ReplyQuote
chinigami
(@chinigami)
Active Member
Joined: 18 years ago
Posts: 17
Topic starter  

hashes of user's password (sam.log), time of authentication and access to a machine and information about user (such as name, id…) and the system.log doesn't trace user activity in system,isn't it ? ?
correct me if am saying false things cause that 's what i find while doing some research ! !
thanks for the question D


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

> hashes of user's password (sam.log), time of authentication and access to a
> machine and information about user (such as name, id…)

Actually, that's not the case at all. The SAM stores all of that information.

A simple Google search revealed the following
http//www.hsc.fr/ressources/articles/win_log_files/index.html.en

This file says that the sam.log file records account lockout related info (I haven't verified this).

> …cause that 's what i find while doing some research

I'm curious to know what you mean by "research"…


   
ReplyQuote
chinigami
(@chinigami)
Active Member
Joined: 18 years ago
Posts: 17
Topic starter  

thanks for the help ) …and i won't tell you the meaning of research just try to do a research in arabic (wich is my mother tongue) and then u will understand how easy is doing research in a different language wink


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

> …and i won't tell you the meaning of research

Well, I'm not sure you understand what I was asking.

You had said, "….cause that 's what i find while doing some research"; I was asking what it was you'd done when doing this research. Clearly, you apparently hadn't done a fairly trivial search via Google, so I was curious what you *had* done, as maybe assisting you with your research methodology would help you find things during future research.


   
ReplyQuote
chinigami
(@chinigami)
Active Member
Joined: 18 years ago
Posts: 17
Topic starter  

sorry if i misunderstood u oops(that is a demonstration that i don't understand all what i read ) ) …and really thanks for the site that u told me to visit wink
thanks for the help and sorry again


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Okay, so you're not going to actually *answer* my question???


   
ReplyQuote
Share: