Track user/computer/ip by Caller Logon ID

Track user/computer/ip by Caller Logon ID

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Track user/computer/ip by Caller Logon ID PanTzeR 04-28-2008
Posted by =?Utf-8?B?UGFuVHplUg==?= on April 28, 2008, 1:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Greetings All,

I got a situation where account was deleted from AD using domain admin
account and would like to track it to IP or Computer that was done from. I
did a bit of investigation and located event that was logged on a Domain
Controller when that happened. It shows a bit of details, such as time,
username etc:

----------------------------------------------
Event Type:        Success Audit
Event Source:        Security
Event Category:        Account Management
Event ID:        647
Date:                24/04/2008
Time:                10:20:41 AM
User:                MYDOMAIN\domadmin
Computer:        DOMAINDC14
Description:
Computer Account Deleted:
        Target Account Name:        COMPUTER462$
        Target Domain:        MYDOMAIN
        Target Account ID:        COMPUTER462
DEL:feb4cabb-34d2-46e3-a84f-9092685d2452
        Caller User Name:        domadmin
        Caller Domain:        MYDOMAIN
        Caller Logon ID:        (0x0,0x4D53D30)
        Privileges:        -
----------------------------------------------

As I understand that was done from the DC14 (probably RDP connection).
Unfortunately, Account Logon Events were not recorder during that time. That
probably could have helped a bit (is there loggin for RDP elsewhere?).

The questions that I keep chasing in my mind are:
1)        What is Caller Logon ID property? I’ve googled that for some time, but
have not found really nice and detailed explanation.
2)        Is it possible to use information that I have to track the deletion
further (ideally to IP or ComputerName)?”.

WBR,
PanTzeR

Similar ThreadsPosted
Disks filling up - how to track it July 20, 2005, 10:00 pm
track netbios to ip addres May 14, 2007, 9:29 pm
Best Way to Track Service Being Turned On? April 26, 2008, 8:06 pm
Failure Audits 529 & 680: How to track the IP address? July 13, 2005, 3:48 pm
missing key/value in registry of w2k server - hot to track it? June 12, 2005, 10:19 pm
0x80070569: Logon failure: the user has not been granted the requested logon type at this computer. December 22, 2005, 9:06 am
Possible to track user's file system usage? March 20, 2006, 11:44 am
Track transfer of files from desktop system September 7, 2007, 2:42 pm
Logon failure: the user has not been granted the requested logon t October 3, 2006, 1:54 am
Is Acitve Directory keeping track of old account names? June 29, 2006, 7:28 am

The site map in XML format XML site map

Contact Us | Privacy Policy