Monitor Suspicious Activity
If you use Windows Firewall, you can configure it to keep a record of rejected connection attempts. Here’s how:
1. Log on using a Computer Administrator account and go to the Start screen. If you don’t have a keyboard, open the Search charm.
2. Type the word firewall, at the right select Settings, then select Windows Firewall. Select Advanced Settings.
3. Right-click Windows Firewall with Advanced Security in the left pane and select Properties. Select one of the available profile tabs (Private Profile, in most cases) and click the Customize button within the Logging area. Set Log Dropped Packets to Yes.
4. Take note of the location of the log file, and then click OK. By default, the log file is \windows\system32\LogFiles\Firewall\pfirewall.log ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access