Slide 23
Slide 23 text
23
• What was our DB server doing during this time?
• SQL ERRORLOG
• Plain text (FINALLY!), can be opened by ${insert_your_fav_text_editor}
• Tracks startup, shutdown, login, logout, authentication success/failures
• Oddly enough, not just errors..
• Can be removed from a system and preserved forensically
• Examined later on a separate, analysis system
The Investigation
Analysis (cont.)