question

Doria avatar image
0 Votes"
Doria asked NK-KP answered

Net Statistics Server.

Hi everyone!

May someone share any material about permission and password violations? I would like to track the process and discover what is causing those numbers. Look:

34374-untitled.png


Thanks.


windows-server-security
untitled.png (17.5 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

udara avatar image
0 Votes"
udara answered

Hi Doria,

You can audit logon failure(4625 event in Security events)

Check following for further details.
https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625

(Don't forget to Accept as answer if this is helpful)



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered

Could be hacking attempts. May need to do some network captures.

--please don't forget to Accept as answer if the reply is helpful--


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

SethWH avatar image
0 Votes"
SethWH answered

Could be nefarious, or could be a lot of users type in their passwords incorrectly (it happens) . You normally see these high password violation numbers on domain controllers and the file servers will have high permissions violations. Your server has both. What is the function of this particular server?

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Doria avatar image
0 Votes"
Doria answered SethWH commented

File server.

What tools and which OS log can I get more information?

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

You could start with auditing logon events (failed) and object access for file/folder shares. These events will be reported in the Event Viewer and you can filter there or dump the logs into a service like Splunk or Elk stack.

0 Votes 0 ·
VickyWang-MFST avatar image
0 Votes"
VickyWang-MFST answered

Hi,
 
Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
 
Best Regards,
Vicky

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Doria avatar image
0 Votes"
Doria answered

Yes, the information helped!

I will capture the events and analyze! I will open a new thread about this.



Regards

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

VickyWang-MFST avatar image
0 Votes"
VickyWang-MFST answered

Hi,
I am glad to hear that your issue was successfully resolved.
If there is anything else we can do for you, please feel free to post in the forum.
Have a nice day!

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

NK-KP avatar image
0 Votes"
NK-KP answered

Could be other misconfigured servers in the network trying to attach/reach it.
Try turning off NetBIOS (over TCP/IP, in your network adapter settings) in your server, and those numbers may go down.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.