Auditing %SystemRoot%\system32 or c:\windows\system32 Files

Posted on 2009-07-06
Medium Priority
Last Modified: 2012-05-07
I have two questions for this subject:

1.  What is the difference between the SystemRoot location and the "windows" location?

2.  If I need to set auditing for specific files within the \system32 directory, does it matter if I set it through SystemRoot or in the \system32 directory?
Question by:myoutback
  • 2
LVL 10

Accepted Solution

PlusIT earned 500 total points
ID: 24784982
1.  the difference is that the SystemRoot is a variable poointing to your windows installation.  Not everyone installs c:\windows by using for example %systemroot%\system32 you are sure you can browse to the system32 folder even if your windows is not installed in C.
Try this by opening a cmd shell and echo the variable with the command: echo %SYSTEMROOT%

2.  try to use variables as much as you can.

Author Comment

ID: 24793821
Thanks for the explanation.

If I wanted to set auditing to %SystemRoot%\system32\activeds.dll from the cmd shell, what would it look like?
LVL 10

Assisted Solution

PlusIT earned 500 total points
ID: 24801766
i'm not sure tbh never done it myself this maybe can help you:

Featured Post

WEBINAR: GDPR Implemented - Tips & Lessons Learned

Join the WatchGuard team on Thursday, March 29th as we recount some valuable lessons learned in weighing the needs of a business against the new regulatory environment, look ahead at the two months left before implementation, and help you understand the steps you can take today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
Nuance's PaperPort may display this error message: PaperPort appears to be running Windows XP Compatibility Mode which may result in errors. We recommend disabling Compatibility Mode for the PaprPort.exe program, see Technote 6629. This articl…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
This video tutorial shows you the steps to go through to set up what I believe to be the best email app on the android platform to read Exchange mail.  Get the app on your phone: The first step is to make sure you have the Samsung Email app on your …

619 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question