<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security e Virtualization Blog di Feliciano Intini (e il suo team PCfSV2) : Security Monitoring and Auditing</title><link>http://blogs.technet.com/feliciano_intini/archive/tags/Security+Monitoring+and+Auditing/default.aspx</link><description>Tags: Security Monitoring and Auditing</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Security News da Mark Russinovich</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/09/09/security-news-da-mark-russinovich.aspx</link><pubDate>Tue, 09 Sep 2008 12:03:24 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3121410</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3121410.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3121410</wfw:commentRss><description>E' da un po' che Mark non si faceva sentire, ma a giudicare da tutto quello in cui &amp;#232; impegnato come dargli torto? Tra le notizie che ha fornito nel suo ultimo post ci sono alcuni spunti in area security: La pagina web dedicata al libro Windows Internals...(&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/09/09/security-news-da-mark-russinovich.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3121410" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/3.0+Operating+System+Security/default.aspx">3.0 Operating System Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Vista+Security/default.aspx">Windows Vista Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2008+Security/default.aspx">Windows Server 2008 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Tools/default.aspx">Security Tools</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Monitoring+and+Auditing/default.aspx">Security Monitoring and Auditing</category></item><item><title>Alcune risorse utili sul Security Auditing in Windows Vista e Windows Server 2008</title><link>http://blogs.technet.com/feliciano_intini/archive/2008/04/21/alcune-risorse-utili-sul-security-auditing-in-windows-vista-e-windows-server-2008.aspx</link><pubDate>Mon, 21 Apr 2008 14:40:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3041526</guid><dc:creator>Feliciano Intini</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/feliciano_intini/comments/3041526.aspx</comments><wfw:commentRss>http://blogs.technet.com/feliciano_intini/commentrss.aspx?PostID=3041526</wfw:commentRss><description>&lt;p&gt;&lt;font face="Calibri" size="3"&gt;Quando vi ho parlato della nuova proposizione strategica di Microsoft, &amp;quot;&lt;a href="http://blogs.technet.com/feliciano_intini/archive/2008/04/14/l-evoluzione-del-trustworthy-computing-end-to-end-trust-e2e.aspx" target="_blank"&gt;&lt;strong&gt;End to End Trust&lt;/strong&gt;&lt;/a&gt;&amp;quot;, vi ho riportato i due concetti cardine: maggiore &lt;strong&gt;Autenticazione&lt;/strong&gt; e miglior &lt;strong&gt;Audit&lt;/strong&gt;. L'ambito dell'Audit, se lo iniziamo ad osservare dal punto di vista tecnologico, &amp;#232; uno di quelli su cui la piattaforma Windows sta facendo i maggiori progressi rispetto agli albori. All'inizio (ai tempi di Windows NT) la generazione degli eventi di auditing in Windows non &amp;#232; stata pensata per essere esattamente uno strumento a supporto del professionista di sicurezza: l'obiettivo reale era quello di poter tracciare con il maggior livello di dettaglio il comportamento del sistema operativo per poter risolvere i suoi eventuali malfunzionamenti. Solo dopo si &amp;#232; compreso che era necessario modificare alcuni aspetti del meccanismo di &lt;em&gt;event logging&lt;/em&gt; anche a favore di una fruibilit&amp;#224; in area sicurezza, per realizzare un vero e proprio &lt;em&gt;security auditing&lt;/em&gt;. &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;&lt;strong&gt;Windows Vista&lt;/strong&gt; e &lt;strong&gt;Windows Server 2008&lt;/strong&gt; rappresentano le versioni su cui questa evoluzione ha raggiunto un livello, tanto atteso, di vera maturit&amp;#224;. A questo proposito, quindi, potrebbero interessarvi i riferimenti informativi che stanno gi&amp;#224; illustrando queste novit&amp;#224;:&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Il blog &amp;quot;&lt;a href="http://blogs.msdn.com/ericfitz/default.aspx"&gt;Windows Security Logging and Other Esoterica&lt;/a&gt;&amp;quot; del team di Windows Auditing&lt;/font&gt;&lt;/li&gt;    &lt;li&gt;&lt;font face="Calibri" size="3"&gt;Il blog &amp;quot;&lt;/font&gt;&lt;a href="http://blogs.technet.com/askds/default.aspx"&gt;&lt;font face="Calibri" size="3"&gt;Ask the Directory Services Team&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;&amp;quot; del team Directory Services&lt;/font&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Ultima risorsa &lt;a href="http://blogs.technet.com/askds/archive/2008/03/27/one-stop-shop-for-auditing-in-windows-server-2008-and-windows-vista.aspx" target="_blank"&gt;segnalata&lt;/a&gt; &amp;#232; un utilissimo &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;947226" target="_blank"&gt;articolo di KB&lt;/a&gt; e un &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=82e6d48f-e843-40ed-8b10-b3b716f6b51b&amp;amp;DisplayLang=en" target="_blank"&gt;foglio Excel&lt;/a&gt; in cui sono &lt;u&gt;documentati tutti i circa 360 eventi di sicurezza di Windows Vista e Windows Server 2008&lt;/u&gt;.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;Buona consultazione!&lt;/font&gt;&lt;/p&gt; &lt;span class="sbmLink"&gt;   &lt;table cellspacing="1" cellpadding="1"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td class="sbmText"&gt;Share this post : &lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to del.icio.us" onmouseout="mOut(this)" href="http://del.icio.us/post?url=http://blogs.technet.com/feliciano_intini/archive/2008/04/21/alcune-risorse-utili-sul-security-auditing-in-windows-vista-e-windows-server-2008.aspx&amp;amp;;title=Alcune risorse utili sul Security Auditing in Windows Vista e Windows Server 2008" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/deliciou4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to digg" onmouseout="mOut(this)" href="http://digg.com/submit?phase=2&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/04/21/alcune-risorse-utili-sul-security-auditing-in-windows-vista-e-windows-server-2008.aspx&amp;amp;title=Alcune risorse utili sul Security Auditing in Windows Vista e Windows Server 2008" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/digg14.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to live" onmouseout="mOut(this)" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;amp;mkt=en-us&amp;amp;url=http://blogs.technet.com/feliciano_intini/archive/2008/04/21/alcune-risorse-utili-sul-security-auditing-in-windows-vista-e-windows-server-2008.aspx&amp;amp;title=Alcune risorse utili sul Security Auditing in Windows Vista e Windows Server 2008" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/live4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to technorati!" onmouseout="mOut(this)" href="http://technorati.com/faves/?add=http://blogs.technet.com/feliciano_intini/archive/2008/04/21/alcune-risorse-utili-sul-security-auditing-in-windows-vista-e-windows-server-2008.aspx&amp;amp;title=Alcune risorse utili sul Security Auditing in Windows Vista e Windows Server 2008" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/technora4.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;          &lt;td class="sbmDim" onmouseover="mOvr(this)" onmouseout="mOut(this)"&gt;&lt;a class="sbmDim" onmouseover="mOvr(this)" title="Post it to yahoo!" onmouseout="mOut(this)" href="http://myweb.yahoo.com/myresults/bookmarklet?u=http://blogs.technet.com/feliciano_intini/archive/2008/04/21/alcune-risorse-utili-sul-security-auditing-in-windows-vista-e-windows-server-2008.aspx&amp;amp;t=Alcune risorse utili sul Security Auditing in Windows Vista e Windows Server 2008" target="_blank"&gt;&lt;img src="http://blogs.msdn.com/blogfiles/rahulso/WindowsLiveWriter/IconsfordifferentSocialBookmarkingSites_B387/yahoo9.png" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/span&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3041526" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/3.0+Operating+System+Security/default.aspx">3.0 Operating System Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Vista+Security/default.aspx">Windows Vista Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Windows+Server+2008+Security/default.aspx">Windows Server 2008 Security</category><category domain="http://blogs.technet.com/feliciano_intini/archive/tags/Security+Monitoring+and+Auditing/default.aspx">Security Monitoring and Auditing</category></item></channel></rss>