Delete Auditing: How to Determine Who Deleted a File In Windows Server

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 ต.ค. 2024

ความคิดเห็น • 12

  • @sharp615
    @sharp615 ปีที่แล้ว

    Awesome and very thorough video.

    • @URTechDotCa
      @URTechDotCa  ปีที่แล้ว

      Yep. Dell has streamlined their manufacturing process and unless you're a corporate and want to order dozens of machines you pretty much have to take what they give you these days

  • @waiwai5690
    @waiwai5690 6 หลายเดือนก่อน

    Thanks for this awesome video and very useful, may i know about how to separate (move/rename) from the list but remain the delete action?

  • @Illasera
    @Illasera 4 หลายเดือนก่อน

    Great video, Thank you, one question, any idea how to store such a specific event log in a different volume / drive? in case of an SSD usage, i assume this auditing policy is going to write like a mother.
    symlink won't help here (I assume).

  • @mohammedafeef7301
    @mohammedafeef7301 2 ปีที่แล้ว

    Wow... That's awesome.. Only the best video on this topic....thank you, in this example you've set on folder, so I can set on volume if I need on all folders under it right?.... Liked and subscribe d.. :) I need more topics on servers, firewall,... Relevant it topics..thanks again

  • @oluchristianfarinloye4804
    @oluchristianfarinloye4804 2 ปีที่แล้ว

    Is there a way to (1) find out who deleted, even though the policy in this video wasn't set up? (2) Recover the deleted document/file from registry

  • @xbriskx
    @xbriskx ปีที่แล้ว

    But how to search event viewer for the file name? I have so many events EVent Viewer doesn't load them it takes forever.

  • @PhillcoAmaru
    @PhillcoAmaru ปีที่แล้ว

    Does this work when a resource is shared over a network? I mean, users are not part of any Windows Server user group. They are "external users". I hope you can understand me. 😅

  • @grix25
    @grix25 ปีที่แล้ว

    Tnx aloooot :)

  • @johnkill2k
    @johnkill2k ปีที่แล้ว

    if the computer/user deleted the file is not a domain user, still there will be log?

  • @calvinnguyen1699
    @calvinnguyen1699 7 หลายเดือนก่อน

    nice video

  • @IT-AEA
    @IT-AEA ปีที่แล้ว

    windows has built-in command cipher /W:yourDriver