(CISA, SSCP, Security MVP)
, , (event IDs) Windows. , “” . . .
,
, . event id, , . – . 10 Windows.
Event ID — () —
1)
675 4771
( )
675/4771 Kerberos . , , . Kerberos .
2)
676, Failed 672 4768
( )
676/4768 . Kerberos .
: Windows 2003 Server 672 676.
3)
681 Failed 680 4776
( )
681/4776
NTLM . , .
NTLM .
: Windows 2003 Server 680 681.
4)
642 4738
( )
642/4738 , . .
5)
632 4728; 636 4732; 660 4756
( )
, . (Global), (Local) (Universal) ID.
6)
624 4720
( )
7)
644 4740
( )
8)
517 1102
( )
(Logon/Logoff)
Event Id —
528 4624 —
529 4625 — –
530 4625 –
531 4625 — –
532 4625 — –
533 4625 — –
534 4625 5461 — –
535 4625 — –
539 4625 — –
540 4624 — ( Windows 2000, XP, 2003)
(Logon Types)
—
2 — ( )
3 — (, IIS — 528 Windows Server 2000 . . 540)
4 — (batch) (, )
5 — ( )
7 — (, )
8 — NetworkCleartext ( (credentials), . IIS “ ”)
9 — NewCredentials
10 — RemoteInteractive ( , )
11 — CachedInteractive ( , , , )
Kerberos
—
6 —
12 — ;
18 — ,
23 —
24 — ;
32 — . ,
37 —
NTLM
( ) — (16- ) —
3221225572 — C0000064 —
3221225578 — C000006A — ,
3221226036 — C0000234 —
3221225586 — C0000072 —
3221225583 — C000006F — ( )
3221225584 — C0000070 —
3221225875 — C0000193 —
3221225585 — C0000071 —
3221226020 — C0000224 —
www.ultimatewindowssecurity.com/securitylog/quickref/Default.aspx. , .
P.S. ? NetWrix Event Log Manager 4.0, , . , . 10 100 .