Registry Tip #26: CrashOnAuditFail - Forensics |
Hits: Failed to execute CGI : Win32 Error Code = 3
|
Hive: HKEY_LOCAL_MACHINE
Key: SYSTEM\CurrentControlSet\Control\LSA
Name: CrashOnAuditFail
Type: REG_DWORD
Value: 1
Q140058 - How To Prevent Auditable Activities When Security Log Is Full
Q178208 - CrashOnAuditFail with Logon/Logoff Auditing Causes Blue Screen
Q155076 - Only Administrators May Log in After Applying C2 Security
Q149393 - Auditing of ProcessTracking interaction
Q232564 - STOP 0xC0000244 When Security Log Full - Dah
Q233214 - STOP Error Occurs Even If CrashOnAuditFail Is Disabled
Frank Heyne has made available a Windows NT Eventlog FAQ .
A must have for NT administrators in corporate or governmental organizations or anyone being audited by a large outside audit firm.
It is not a secrets type guide but it has excellent sound advice and its used by PriceWaterhouse's auditors as a guide.