Record and evaluate DNS queries Sysmon (System Monitor) is a system service and driver at the same time, which always remains active after installation. Sysmon monitors all system activities and [...]Continue reading "
How does a client in a domain find its logon server? Based on the article Allocation of Logon Server, I will now add 2 diagrams. How does a [...]Continue reading "
Which login server is responsible? How does a client in a domain find its logon server? If a client has just joined a domain, it asks during […]Continue reading "
WIN32: 1722 RPC_S_SERVER_UNAVAILABLE A classic in IT 😉 This error message is just annoying. There are a lot of ways to check whether the port […]Continue reading "
Monitor system and performance indicators The SysGauge tool is a real extension to Task Manager. Why is my computer constantly at risk? SysGauge provides information about the […]Continue reading "
PKTMON Network Sniffer With the Windows 10 on-board tool “pktmon.exe” to be found under C: \ Windows \ System32 you are able to record the network activities. The tool can be […]Continue reading "
LDAP requests MaxPoolThreads The problem that can arise from this can be explained as follows. If the DC receives a request for name resolution, it needs the […]Continue reading "
Where do we check which networks we were connected to? To answer this question, just look at the registration. In this document I go […]Continue reading "
Sysinternals - Sysmon with DNS logging The new event ID for DNS queries is 22. As soon as a process executes a DNS query, it is entered as an event in the LOG […]Continue reading "