Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Best Practice for auditing Active Directory

Status
Not open for further replies.

snootalope

IS-IT--Management
Jun 28, 2001
1,706
US
Anyone know if there's a guide, or information that's apart of another guide, that sets the best practices for what and where to audit events in active directory?

I currently audit success and failure logon events of course, but I'd like to see what's recommend to see if I should be capturing privileged use, privileged escalation attempts, and so forth..

Thanks for any info!
 
Check out SANS. They have a lot of resources on auditing in general. [URL unfurl="true"]http://www.sans.org/reading_room/whitepapers/auditing/[/url]

The SANS organization is closely linked with the CISSP certification.

PSC

Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top