When a system is compromised, attackers often try to disable auditing, in Windows 7; modifications to the audit policy are recorded as entries of Event ID____________.
Hmm, this is a tricky one. Disabling auditing is a classic move by attackers, so we need to know the right Event ID to look for. I'm going with C) 4904 - it just sounds right to me.
Shawn
7 days agoHelene
3 days agoErinn
9 days agoBrandon
15 days ago