Logging Monitoring: File Integrity Events logging

cruise 331 Reputation points
2021-03-12T07:04:19.553+00:00

Any Creation / Deletion of system-level objects installed by Windows (Almost all system-level objects run with administrator privileges, and some can be abused to gain administrator access to a system.)

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,119 questions
{count} votes

Accepted answer
  1. Teemo Tang 11,336 Reputation points
    2021-03-15T08:47:32.553+00:00

    We can track file/folder creation and deletion in Windows by Enabling Audit Object Access policy and Viewing audit logs in Event Viewer
    Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Audit Policy

    Detailed guide here:
    https://www.manageengine.com/products/active-directory-audit/how-to/track-file-and-folder-creation-deletion-in-windows.html

    -------------------------------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful