Using event logging to reveal network activity

Two computers' files were deleted remotely by another computer. How can we track down the source computer that logged into these two computer and deleted the files?
I'm not sure which version(s) of Windows you're running, but if you have security and system event logging enabled to track logins, network connections, etc. that may be your only source to track things down. See this Microsoft article for details on event logging. Also, consider any VPN, firewall, and router logs that may have recorded such events. Good luck in finding the perpetrator!

View questions and answers from all of our Windows security experts here.

This was first published in May 2006

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.