Audit success in event log from not administrator IP - is that immediately a hack success indicator?
Posted
by
Valentin Kuzub
on Server Fault
See other posts from Server Fault
or by Valentin Kuzub
Published on 2011-11-20T23:22:22Z
Indexed on
2011/11/21
1:54 UTC
Read the original article
Hit count: 505
I checked event log today and between mass of failed audit events I found some successes which originated from not my country. However they look a little weird and no process is specified, while when I logon using RDP it says winlogon.exe
I am wondering whether that means my system was compromised or there are good variants and it doesnt mean its all that bad.
I am using a VPS solution if thats useful.
© Server Fault or respective owner