Detections
- Home
- - Detections
- -DT099
- ID: DT099
- Created: 04th August 2024
- Updated: 04th August 2024
- Platform: Windows
- Contributor: Khaled A. Mohamed
Windows Event Log, Audit Removable Storage
With Group Policy it is possible to enable object access auditing in regards to removeable storage events.
Go to Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> Audit Policies -> Object Access
.
Double click Audit Removable Storage and check both Success and Failures
Monitor Event ID 4663 (An attempt was made to access an object) and/or 4656 (A handle to an object was requested). This can be used to detect events where a user account is attempting to use removable storage devices on a system.