Best Way to Track Service Being Turned On?

Best Way to Track Service Being Turned On?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Best Way to Track Service Being Turned On? Will 04-26-2008
Posted by Will on April 26, 2008, 8:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a strange situation on a firewall I need help with. The server is
Windows 2000 running ISA Server 2004. For reasons I cannot determine yet,
the Internet Connection Sharing (ICS) service keeps getting set to
Automatic. I set it manually to disable, and I have verified that
nothing in group policy should be turning it on. A few days go by, and
then I login and see the service set to Automatic, and sometimes turned on.
I don't believe the other operator of that particular server has enough
knowledge to make this change, nor do I believe he would be malevant enough
to do it. So I have a problem.

What is the best method to get an email alert at the moment that:

1) A particular service has its service status changed to Automatic?

2) The service is started?

I assume there is a third party tool that would monitor services and do the
notification for me. I would appreciate pointers to the best tools of this
type.

--
Will



Posted by Will on April 28, 2008, 2:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
>> I would like other things, like the process id that started the service,
>> the
>> user name /security context, name of program running in that process etc.
>>
>> We have programmers who could write this program, or we could go with a
>> script, but I'm trying to find something off the shelf first.
>
> I sort of doubt you are going to find all of that off-the-shelf Will.
> The reason is that you imply reading into the security log, as the
> history of who started / altered the service is not kept by the SCM
> so querying the SCM state will not show process that started etc.
> Also, just how much other than "service xyz entered started state"
> sort of event messages depends on OS version.
> You might want to think about guaranteeing sufficent items are
> logged to event logs, and then have a little monitoring service
> that uses eventing to subscribe to event log messages of interest.
> When a service transitions it could at least snapshot what is
> running on the system.

Roger, running with this idea, what level of Windows event auditing is
required to capture start and stop information for a service?

Will any audit setting guarantee an eventviewer message showing change of
the service start status from - for example - Disabled to Automatic?

--
Will



Similar ThreadsPosted
SMTP Service when turned on is spamming other SMTP servers. June 25, 2007, 1:09 pm
No firewall turned on. January 29, 2008, 1:22 am
windows security alert says kaspersky is turned off August 24, 2007, 10:10 pm
Windows Firewall and Norton 360 both report that they are turned o May 10, 2008, 4:55 pm
Disks filling up - how to track it July 20, 2005, 10:00 pm
track netbios to ip addres May 14, 2007, 9:29 pm
Failure Audits 529 & 680: How to track the IP address? July 13, 2005, 3:48 pm
missing key/value in registry of w2k server - hot to track it? June 12, 2005, 10:19 pm
XP Firewall turned off by default - Norton Internet Security 2006 February 16, 2006, 4:18 pm
EMAIL Scanning Error/Turned Off in Norton Internet Security (NIS) October 29, 2006, 10:52 am

The site map in XML format XML site map

Contact Us | Privacy Policy