<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3ASystem_Auditing_-_Beginner</id>
	<title>Draft:System Auditing - Beginner - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3ASystem_Auditing_-_Beginner"/>
	<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:System_Auditing_-_Beginner&amp;action=history"/>
	<updated>2026-09-24T04:43:38Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:System_Auditing_-_Beginner&amp;diff=190&amp;oldid=prev</id>
		<title>MigrationBot: Backfill (v3.0 review queue): added to the review queue</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:System_Auditing_-_Beginner&amp;diff=190&amp;oldid=prev"/>
		<updated>2026-09-22T05:42:58Z</updated>

		<summary type="html">&lt;p&gt;Backfill (v3.0 review queue): added to the review queue&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:42, 22 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l49&quot;&gt;Line 49:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 49:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows System Auditing|007]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows System Auditing|007]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Pending review]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wikicyber:diff:1.41:old-110:rev-190:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:System_Auditing_-_Beginner&amp;diff=110&amp;oldid=prev</id>
		<title>MigrationBot: Import from cypat.guide: docs/windows/system_auditing/system_auditing_beginner.md</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:System_Auditing_-_Beginner&amp;diff=110&amp;oldid=prev"/>
		<updated>2026-09-18T17:06:46Z</updated>

		<summary type="html">&lt;p&gt;Import from cypat.guide: docs/windows/system_auditing/system_auditing_beginner.md&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Submit}}&lt;br /&gt;
&amp;lt;!-- Migrated from https://cypat.guide/docs/windows/system_auditing/system_auditing_beginner (source: docs/windows/system_auditing/system_auditing_beginner.md) --&amp;gt;&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
Author(s): LOWERCASEinuppercase&lt;br /&gt;
&lt;br /&gt;
Last Updated: 06-10-2025&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! Recommended Prerequisites (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
* None&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What Is Auditing? ==&lt;br /&gt;
&lt;br /&gt;
System auditing is the process of tracking and logging certain events on a system. This can include things like login and logoff, attempting to access a certain file or folder, or modifying system settings. These logs can help system administrators identify suspicious activity or system issues. In Windows, system auditing is configured through the &amp;#039;&amp;#039;&amp;#039;Audit Policy&amp;#039;&amp;#039;&amp;#039; settings, which logs selected events to the &amp;#039;&amp;#039;&amp;#039;Event Log&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
When deciding audit policies, it&amp;#039;s important to consider what might be beneficial to record, and adjust settings accordingly. For example, one use-case for auditing would be monitoring to see if anyone is attempting to access a user&amp;#039;s account or brute-force their password. In that case, it may be useful to audit something like logon failures. In general it is considered best practice to audit as much as possible, though it&amp;#039;s important to note that some policies will generate a lot of unnecessary diagnostic events that will quickly clog up the event log.&lt;br /&gt;
&lt;br /&gt;
== Configuring Audit Policy ==&lt;br /&gt;
&lt;br /&gt;
Audit policy on a system is typically configured through either basic audit policy or advanced audit policy. Both of these can be configured through the &amp;#039;&amp;#039;&amp;#039;Local Security Policy&amp;#039;&amp;#039;&amp;#039;, also known as secpol.msc. To open Local Security Policy, go to the Windows search bar and type in either &amp;amp;quot;local security policy&amp;amp;quot; or &amp;amp;quot;secpol.msc&amp;amp;quot; and press enter. Let&amp;#039;s take a look at how to configure audit policy in both ways.&lt;br /&gt;
&lt;br /&gt;
=== Basic Audit Policy ===&lt;br /&gt;
&lt;br /&gt;
Basic audit policy can be configured by navigating to &amp;lt;code&amp;gt;Local Policies &amp;amp;gt; Audit Policy&amp;lt;/code&amp;gt;. Listed here are 9 broad categories of events that the system can audit. By double-clicking any one of them, you can configure whether the system will audit success and/or failure events in each category.&lt;br /&gt;
&lt;br /&gt;
=== Advanced Audit Policy ===&lt;br /&gt;
&lt;br /&gt;
Advanced audit policy can be configured by navigating to the subcategories under &amp;lt;code&amp;gt;Advanced Audit Policy Configuration &amp;amp;gt; System Audit Policies - Local Group Policy Object&amp;lt;/code&amp;gt;. These subcategories are similar to the ones available with a basic audit policy, but they allow for more granularity with the available settings.&lt;br /&gt;
&lt;br /&gt;
For example, under the &amp;lt;code&amp;gt;Logon/Logoff&amp;lt;/code&amp;gt; category, there are multiple specific settings which can be individually configured. Setting &amp;lt;code&amp;gt;Audit account logon events&amp;lt;/code&amp;gt; to a given option in the basic audit policy would be equivalent to applying that option to every subcategory under the &amp;lt;code&amp;gt;Logon/Logoff category&amp;lt;/code&amp;gt; in the advanced audit policy. Using an advanced audit policy gives you the choice to have different settings between those subcategories.&lt;br /&gt;
&lt;br /&gt;
=== Command Prompt ===&lt;br /&gt;
&lt;br /&gt;
The audit policy can also be configured through the command prompt using the &amp;lt;code&amp;gt;auditpol.exe&amp;lt;/code&amp;gt; command line utility (also just referred to as &amp;lt;code&amp;gt;auditpol&amp;lt;/code&amp;gt;). First, open the command prompt by typing &amp;amp;quot;cmd&amp;amp;quot; into the Windows search bar. Now, in order to get all of the current system audit policies, enter &amp;lt;code&amp;gt;auditpol /get /category:*&amp;lt;/code&amp;gt; at the prompt. This should display a list of auditing categories and subcategories (which should mirror those in the advanced audit policy) and their current settings. To enable auditing for one of these subcategories, you can run &amp;lt;code&amp;gt;auditpol /set /subcategory:&amp;amp;quot;Subcategory Name Here&amp;amp;quot; /success:enable /failure:enable&amp;lt;/code&amp;gt;. To disable auditing for a subcategory, you can run the same command but replacing the &amp;lt;code&amp;gt;enable&amp;lt;/code&amp;gt; with &amp;lt;code&amp;gt;disable&amp;lt;/code&amp;gt; for the &amp;lt;code&amp;gt;/success&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;/failure&amp;lt;/code&amp;gt; options.&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
=== References &amp;amp;amp; Further Reading ===&lt;br /&gt;
&lt;br /&gt;
* https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/advanced-security-auditing-faq&lt;br /&gt;
* https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol&lt;br /&gt;
&lt;br /&gt;
[[Category:Windows System Auditing|007]]&lt;br /&gt;
[[Category:Migrated from cypat.guide]]&lt;/div&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
</feed>