Direct Inward Dialing: +1 408 916 9892
What will you do if you want to find out what changes a certain help desk technician made in Active Directory over a week’s time? Or, extract a change audit trail for a certain user as a part of a security incident investigation?
PowerShell can help but will certainly require a great deal of effort to offer the kind of visibility and correlation required for an investigation, which is exactly what ADAudit Plus packs into its search utility.
ADAudit Plus provides you a search capability which enables you to instantly trace the footsteps of a specified user in the Active Directory. Simple and straightforward to use, this search takes three inputs –username for which you require an audit trail, domain, and time period – and instantly provides the following consolidated summary:
Every detail presented in the consolidated summary is a link, which further unfurls into an elaborate report. For example, while perusing the results for administrator activity over a week’s time, you can click open the GPO Modified report for a closer look, maybe for comparing old and new values.
From an incident investigation standpoint, this search capability strings together all the vital pieces of forensic information namely
When pieced and analyzed together, such information provides better context, thereby enabling you to connect the dots easily or even steer the investigation in the right direction. For example, assume that you suspect user A to have tampered with Active Directory. You use the audit trail search to investigate.
Deleted account’s permissions have been inappropriately elevated by a help desk technician (HDT). |
Indicates involvement of the HDT as an accomplice. |
Deleted account logged into and operated from computer Y. Also, it remotely accessed several other computers. |
Helps you quickly isolate computer Y from where the deleted account made changes in Active Directory. Sets you on a hunt for telltale signs of data theft and other kinds of invasions in the remotely accessed computers. |
A summary of all the Active Directory objects affected by this deleted account. |
Enables you to undo or readjust the AD security configurations to neutralize the attack. |
That’s the potential of ADAudit Plus’s Consolidated Audit Trail.