I
I
iCaesar2011-01-27 16:12:42
Monitoring
iCaesar, 2011-01-27 16:12:42

File actions log

Hello, dear Khabrovites and Khabrovites!
There was a need for a program that analyzes the folders specified by it for user actions and writes everything to a log.
The idea has kind of turned into reality. I wrote in C# because it's so convenient for me. Understood with FileSystemWatcher'om. When creating a file, I look along the path of the SID of the owner of the file and everything seems to be fine - I found out who created the file, wrote it to the log.
But here a snag arose. How to find out the SID of the person who deleted or wrote to the file?

Answer the question

In order to leave comments, you need to log in

3 answer(s)
M
mitnlag, 2011-01-27
@mitnlag

Why did you invent bicycles. You need to look in the event audit, hang policies. And then some script to aggregate the system log.

A
Alexander, 2011-01-27
@Alexx_ps

The Secret Net program and the like. Can be purchased without hardware. It limits access by the mandatory method, monitors everything you say, checks for integrity, protects against changes.
www.securitycode.ru/products/secret_net/
The new version 6 is probably expensive, the old 5.1 is no worse for your tasks.

K
Kirill Mamaev, 2011-01-28
@r00tGER

I can't give you an exact answer either.
But! The technology that antiviruses work on comes to mind. How to proxy any access to the file system.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question