﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 564 - Object Deleted </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 12:04:28 GMT</lastBuildDate><ttl>20</ttl><item><title>How to determine and correlate events that a file has been deleted?</title><link>http://forum.ultimatewindowssecurity.com/Topic550-40-1.aspx</link><description>Hi all,&lt;br&gt;I am trying to track a particular folder,where any deletion of files under that folder will be reported.&lt;br&gt;&lt;br&gt;I did a sample test and realize that a file deletion process consist of the event 560,564 and then 562.&lt;br&gt;&lt;br&gt;So event 564 is straightforward and tells you that something has been deleted by a user,but it doesn't tells you what has been deleted!?Therefore I am trying to correlate and tied this event 564 to event 560 because it contains the details of the file.I'm trying to do this by looking at the handle ID and the User field.&lt;br&gt;&lt;br&gt;However,there can be scenarios where a user accesses a file now and generates event 560,few hours later then the user decides to delete off the file that will generate event 564.In between this period there can be multiple events of 560 generated by this user.&lt;br&gt;&lt;br&gt;So I appreciate if anyone can provide some advice on how to determine that a file has been deleted and how can I accurately determine what is the file that has been deleted and the user?&lt;br&gt;&lt;br&gt;I am trying to correlate and tied event 564 to the corresponding 560 but am not confident that it is correct...&lt;br&gt;&lt;br&gt;Thanks in advanced.</description><pubDate>Fri, 14 Jan 2011 04:27:13 GMT</pubDate><dc:creator>Jer06</dc:creator></item><item><title>Logging for workstations in a Windows domain</title><link>http://forum.ultimatewindowssecurity.com/Topic478-40-1.aspx</link><description>We want to monitor access to secure files on workstations. We'll be looking for attempts to delete objects as well as attempts to open them. &lt;/P&gt;&lt;P&gt;If the file is on a workstation that is part of a domain, do the object access atempts and object deleted messages show up on the domain controller or will they only show up on the workstation? &lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Amy (altoflyer)</description><pubDate>Mon, 27 Sep 2010 14:07:44 GMT</pubDate><dc:creator>altoflyer</dc:creator></item><item><title>Object Created</title><link>http://forum.ultimatewindowssecurity.com/Topic397-40-1.aspx</link><description>Randy,&lt;br&gt;&lt;br&gt;Is there an Object Created EVID?&lt;br&gt;&lt;br&gt;Thx,&lt;br&gt;Jeff</description><pubDate>Mon, 28 Jun 2010 17:19:38 GMT</pubDate><dc:creator>jwalzer</dc:creator></item></channel></rss>
