mailing list archives
Re: [PEN-TEST] Audit package
From: H Carvey <keydet89 () YAHOO COM>
Date: Wed, 27 Sep 2000 17:14:16 -0000
I'd like to throw a couple of other tools into the mix,
specifically regarding NT...
NTObjectives has NTLast, which might also be
Of course, using Perl is a great answer. I've written
several scripts that pull the EventLogs from NT
systems...all that needs to be done is the proper
However, keep in mind...regardless of what system
you're on, no sort or parsing tool will work if the
information isn't being logged. For much of what
you're looking for on NT, you need to pay attention not
only to the EventLog settings, but ACLs, as well.