﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 560 - Object Open </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 12:07:22 GMT</lastBuildDate><ttl>20</ttl><item><title>Missing Handle (-) Causing Failure Audit</title><link>http://forum.ultimatewindowssecurity.com/Topic779-36-1.aspx</link><description>I need help with this please...  I am trying to understand if the event is being created by there not being a Handle ID.  This specific person has access to this shared folder and they were able to open the file just fine.  I don't know why it is appearing in the "Failure Audit" category, or is it just "noise".  &lt;P&gt;Sanitized Error:&lt;/P&gt;&lt;P&gt;Event Type: Failure Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Object Access &lt;BR&gt;Event ID: 560&lt;BR&gt;Date:  8/5/2011&lt;BR&gt;Time:  11:14:20 AM&lt;BR&gt;User:  ACMECO\JDOE&lt;BR&gt;Computer: FILESERVERNAME&lt;BR&gt;Description:&lt;BR&gt;Object Open:&lt;BR&gt;  Object Server: Security&lt;BR&gt;  Object Type: File&lt;BR&gt;  Object Name: F:\Generic\Daily\Monthly\2011\Aug 2011.xls&lt;BR&gt;  Handle ID: -&lt;BR&gt;  Operation ID: {1,1562195102}&lt;BR&gt;  Process ID: 4&lt;BR&gt;  Image File Name: &lt;BR&gt;  Primary User Name: FILESERVERNAME$&lt;BR&gt;  Primary Domain: XXXXXXCO&lt;BR&gt;  Primary Logon ID: (0x0,0x3E7)&lt;BR&gt;  Client User Name: JDOE&lt;BR&gt;  Client Domain: XXXXXXCO&lt;BR&gt;  Client Logon ID: (0x1,0x5C7E1B6D)&lt;BR&gt;  Accesses: DELETE &lt;BR&gt;   READ_CONTROL &lt;BR&gt;   ACCESS_SYS_SEC &lt;BR&gt;   ReadData (or ListDirectory) &lt;BR&gt;   ReadEA &lt;BR&gt;   ReadAttributes &lt;BR&gt;   &lt;BR&gt;  Privileges: -&lt;BR&gt;  Restricted Sid Count: 0&lt;BR&gt;  Access Mask: 0x1030089&lt;/P&gt;&lt;P&gt;&lt;BR&gt;For more information, see Help and Support Center at &lt;A href="http://go.microsoft.com/fwlink/events.asp"&gt;http://go.microsoft.com/fwlink/events.asp&lt;/A&gt;.</description><pubDate>Fri, 05 Aug 2011 11:22:18 GMT</pubDate><dc:creator>mjv1975</dc:creator></item><item><title>What is Object Server?</title><link>http://forum.ultimatewindowssecurity.com/Topic699-36-1.aspx</link><description>Exactly what is the Object Server in the 560 message?&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;/font&gt; &lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;Thanks,&lt;/font&gt;&lt;/p&gt;&lt;font size="2"&gt;&lt;p&gt;&lt;br&gt;paul&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;&lt;/font&gt; &lt;/p&gt;&lt;p&gt;&lt;/font&gt; </description><pubDate>Mon, 23 May 2011 13:43:27 GMT</pubDate><dc:creator>pwstoecker</dc:creator></item><item><title>How to track user modifications and accesses to folders and files</title><link>http://forum.ultimatewindowssecurity.com/Topic493-36-1.aspx</link><description>Hi,&lt;br&gt;I have a task to help determine who has moved a particular folder and its subfolder/files to another location.&lt;br&gt;&lt;br&gt;For example: User A has moved 'C:\folder2' to 'C:\folder1\folder2'&lt;br&gt;&lt;br&gt;I've tried searching for related events on 560,567 and 562,which I understand will be generated for such cases, but however,I only see event code 560.&lt;br&gt;&lt;br&gt;Unable to determine much, I searched for the last event time for C:\folder2, which is 13:00hr, and the next event at 14:00 with file location shown in the log is C:\folder1\folder2. Both of these events are code 560, and I am unable to search for a corresponding code 567,562 and handle ID.&lt;br&gt;Thus, am suspecting the movement of the folder happens between 13:00 to 14:00...&lt;br&gt;&lt;br&gt;Please advise?&lt;br&gt;&lt;br&gt;</description><pubDate>Tue, 05 Oct 2010 00:44:59 GMT</pubDate><dc:creator>Jer06</dc:creator></item><item><title>Wmiprvse.exe 560 Errors</title><link>http://forum.ultimatewindowssecurity.com/Topic534-36-1.aspx</link><description>Hello,&lt;br&gt;&lt;br&gt;I need help identifying if the following errors are harmless or not. I am getting the same error on a few different systems.&lt;br&gt;&lt;br&gt;Executable: C:\WINDOWS\wbem\wmiprvse.exe&lt;br&gt;&lt;br&gt;Attempts to access one of the following files: &lt;br&gt;C:\WINDOWS\repair\setup.log&lt;br&gt;C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini&lt;br&gt;C:\WINDOWS\system32\profmap.dll&lt;br&gt;C:\WINDOWS\system32\config\system&lt;br&gt;These errors occur as both administrator and regular user.&lt;br&gt;&lt;br&gt;Any help would be greatly appreciated.&lt;br&gt;&lt;br&gt;Thank you in advance,&lt;br&gt;Kyle</description><pubDate>Mon, 15 Nov 2010 07:38:42 GMT</pubDate><dc:creator>kblancha82</dc:creator></item><item><title>Root cause of 560 failed object access attempts</title><link>http://forum.ultimatewindowssecurity.com/Topic431-36-1.aspx</link><description>&lt;FONT face=Courier size=2&gt;&lt;FONT face=Courier size=2&gt;&lt;P&gt;I have a question in regard to auditing on XP workstations. We have &lt;BR&gt;object auditing enabled and get lots of 560 events for users accessing &lt;BR&gt;service.exe through the SC_Manager. The problem is user's don't know what &lt;BR&gt;they are doing to generate these events, many happen just logging on. The &lt;BR&gt;information in the actual 560 event is somewhat useless. How can you tell &lt;BR&gt;what program or service is calling SC_Manager to generate the event. I &lt;BR&gt;have been trying off and on for several months and have no clue where to &lt;BR&gt;look or how to find out?&lt;/P&gt;&lt;P&gt;From the event i know:&lt;/P&gt;&lt;P&gt;Object Server: SC Manager&lt;/P&gt;&lt;P&gt;Object Type:   SC_MANAGER OBJECT&lt;/P&gt;&lt;P&gt;Object Name:   ServicesActive&lt;/P&gt;&lt;P&gt;Operation ID, Process ID xxx&lt;/P&gt;&lt;P&gt;Image File name: path to services.exe&lt;/P&gt;&lt;P&gt;login ID, Domain name, User client name etc...what properties are accessed (attempted fail, only monitoring failed access)&lt;/P&gt;&lt;P&gt;What I don't know is what program or process is calling services.exe to cause these events.  How can I investigate this to pin point the cause? Any help would be GREATLY appreciated...&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;</description><pubDate>Thu, 26 Aug 2010 11:02:52 GMT</pubDate><dc:creator>racjen</dc:creator></item><item><title>How to manage Handle ID for event 560, 567 and 562</title><link>http://forum.ultimatewindowssecurity.com/Topic302-36-1.aspx</link><description>Good evening,&lt;/P&gt;&lt;P&gt;i'm trying to correlate more events with ID 560, 567 and 562 using the "Handle ID" but i found that the value assigned to "Handle ID" is not unique because is unique until reboot of the server/machine.&lt;/P&gt;&lt;P&gt;So, after a reboot of the server/machine i can see in event viewer an operation with the same "Handle ID" used before the reboot so i can't define into a database that an operation with a particular "Handle ID" is referred to a particular Username (because the same "Handle ID" can be used for operations of another user after the reboot).&lt;/P&gt;&lt;P&gt;In witch way the operating system determine the "Handle ID"? I noticed that is a numeric code: after witch value it restart to count from 0?&lt;/P&gt;&lt;P&gt;Thanks for help!&lt;/P&gt;&lt;P&gt;Alessandro Rimoldi (Milan, Italy)</description><pubDate>Mon, 25 Jan 2010 12:22:01 GMT</pubDate><dc:creator>AlessandroRimoldi</dc:creator></item><item><title>How to prevent activities generated by SYSTEM user in the security log?</title><link>http://forum.ultimatewindowssecurity.com/Topic423-36-1.aspx</link><description>My security log is full of activities generated by the user "SYSTEM". How to set this user's activites not be in the security log?</description><pubDate>Wed, 04 Aug 2010 14:37:45 GMT</pubDate><dc:creator>mdong@cds.ca</dc:creator></item><item><title>Clarification of 560</title><link>http://forum.ultimatewindowssecurity.com/Topic349-36-1.aspx</link><description>In the case we have at hand on object access failures, the Object Type is SERVICE OBJECT and the Object Name is WinHttpAutoProxySvc. Does this indicate, then, that there is a permissions access problem with the user account trying to access that service? I'm just trying to figure out what has to be changed where to resolve this. (This is the first time I've had the situation where the 560 event is logged consistently. In this case it comes in clusters of 4 events about every 50 minutes.)</description><pubDate>Fri, 09 Apr 2010 10:38:42 GMT</pubDate><dc:creator>richlich</dc:creator></item><item><title>How can you tell when a file was created???</title><link>http://forum.ultimatewindowssecurity.com/Topic93-36-1.aspx</link><description>It seems that event 560 is given for created or modified. Is there may to tell when a file was created???</description><pubDate>Tue, 19 May 2009 08:43:05 GMT</pubDate><dc:creator>mvftw</dc:creator></item></channel></rss>
