ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™

  • ID: DT099
  • Created: 04th August 2024
  • Updated: 04th August 2024
  • Platform: Windows
  • Contributor: Khaled A. Mohamed

Windows Event Log, Audit Removable Storage

With Group Policy it is possible to enable object access auditing in regards to removeable storage events.

 

Go to Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> Audit Policies -> Object Access.
Double click Audit Removable Storage and check both Success and Failures
 

Monitor Event ID 4663 (An attempt was made to access an object) and/or 4656 (A handle to an object was requested). This can be used to detect events where a user account is attempting to use removable storage devices on a system.