Solved

Can you tell what files are touched during a RDP session on SBS2003?

Posted on 2010-11-23
2
318 Views
Last Modified: 2012-05-10
I have a server that i know was hacked through the rdp. I was able to use network probe to trace the ip traffic to an ip address in south korea. I also know that the session lasted approx 2.5 hours and 390 meg of data was transmitted. My question is - How can i find out WHAT data was taken or copied? I have crawled through all the event logs and they are of no use, i did a search on any files that would have been created or modified during the time period but nothing interesting came up. Any suggestions? Is there a hidden log somewhere that tells when files are copied?
0
Comment
Question by:rrcarlisle
2 Comments
 
LVL 8

Accepted Solution

by:
ShareefHuddle earned 500 total points
ID: 34201455
If auditing was setup but by default no not really.
0
 

Author Comment

by:rrcarlisle
ID: 34225650
will auditing tell me what files are touched (copied, opened, etc) by what user? How does one activate this feature?
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The related questions "How do I recover the passwords for my Q-See DVR" and "How can I reset my Q-See DVR to eliminate a password" are seen several times a week.  Here we discuss the grim reality of the situation.
OnPage: Incident management and secure messaging on your smartphone
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

697 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question