The most trusted source for computer security training, certification and research.



select a course
San Jose, CA - April 23 - 25, 2007
Global Information Assurance Certification

This is the best group of instructors I've ever been exposed to.
-Mark Jeanmougin, 53.com


Additional Course Offerings: Additional courses are available in San Jose on April 25th. Please visit the WhatWorks in Log Management Summit 2007 page for more information.

SPECIAL

Uncovering Secrets from the Windows Security Log

Wednesday, April 25, 2007 : 1pm - 4pm
Randy Smith, Ultimate Windows Security
3 CPE Credits Per Day
The Windows security log is extremely important to monitoring all aspects of Windows security. But it is also the most poorly documented area of Windows 2000 and Windows Server 2003. For most events, Microsoft documentation simply restates the static text of the event's description. Where information exists, it is riddled with inaccuracies. More importantly, Microsoft provides almost no guidance and very little background information for individual events much less events in context with other events. In addition, the security log event IDs and codes change from one version of Windows to the next, which makes security log knowledge even more arcane and complicates the design of programs that monitor the security log. In this half-day seminar, you will gain essential knowledge for leveraging the Windows security log. The seminar includes live demonstrations on Windows Server 2003 and time for Q&A. You will learn the meaning and value of all 9 audit categories how to centrally monitor logon events for your entire domain to track user access to files and folders to monitor programs executed by users why it is crucial to monitor member server logs in addition to domain controllers the meaning of the security logs many cryptic codes the truth about the impact on performance of auditing and other misconceptions.

I learned more at this conference than 2 other training conferences I have attended combined.
-Steve Farmer, LANL