Mastering Windows Network Forensics and Investigation, 2nd Edition
by Steven Anson, Steve Bunting, Ryan Johnson, Scott Pearson
Parsing Windows Firewall Logs
In Chapter 9, “Registry Evidence,” we covered the Windows Firewall configuration settings in depth. In Windows 7 and Windows Server 2008, logging for the Windows Firewall is disabled by default. Enabling firewall logging requires one to venture deep into the Windows Firewall with the Advanced Security console and even farther above the head and frustration level of most home users. For this reason, and many more like it, logging in general is not usually present on home-based systems.
In the corporate or office environment, however, the chances are much greater that a security-minded system administrator will have enabled logging, either by individual system configuration or through group policy, which pushes the ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access