When a system is compromised, attackers often try to disable auditing, in Windows 7; modifications to the audit policy are recorded as entries of Event ID____________.
Hmm, this is a tricky one. Disabling auditing is a classic move by attackers, so we need to know the right Event ID to look for. I'm going with C) 4904 - it just sounds right to me.
Shawn
8 days agoHelene
4 days agoErinn
10 days agoBrandon
16 days ago