Someone logged me off how can i find who and did what

Posted on 2007-09-28
Last Modified: 2011-09-20

I had Ctrl Alt Del my machine and out of office.Some one restarted my machine and logged in as the Domain Administrator and logged of the system.I want to find what they did after logging in to my machine.
Did they delete any file ,Copy,Move,Editted any files etc.Is there  a way to find this.

Question by:bsharath
    LVL 6

    Expert Comment

    you can find out who did log you out from the security log in the event viewer or computer management.

    however for the files, if auditing is enabled and group policy has been enabled for "Audit Object access", then only you can find out what files have changed...

    else try to find out the modified files by date/time
    LVL 16

    Assisted Solution


    I think we have beaten this up pretty bad ealrlier...

    If you had enabled Files Access Audits on your NTFS drives, you can find out.. what files were accessed..

    If not.. i dont see a better way!
    LVL 6

    Accepted Solution

    by default auditing is disabled.

    for enabling it, you need to set auditing on the folders you want to monitor. Secondly you need to enable auditing from the group policy.

    after enabling this, events are logged in the event viewer if any changes are made to the files/folders...

    also, you can choose what events to log like read/delete...etc.

    Featured Post

    How does your email signature look on mobiles?

    Do your employees use mobile devices to reply to emails? With mobile becoming increasingly important to the business world, it is in your best interest to make sure that your email signature looks great across all types of devices.

    Join & Write a Comment

    Some time ago I faced the need to use a uniform folder structure that spanned across numerous sites of an enterprise to be used as a common repository for the Software packages of the Configuration Manager 2007 infrastructure. Because the procedu…
    This is a little timesaver I have been using for setting up Microsoft Small Business Server (SBS) in the simplest possible way. It may not be appropriate for every customer. However, when you get a situation where the person who owns the server is i…
    This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
    Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…

    729 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now