03. 07. 2014 MarinovMihail Service Management

Monitoring USB Ports with Safed

Sometimes, especially for security reasons, it is important to know if the USB ports of a server have been used and what kind of operation has been carried out. Well, with the new version 1.7.0 of the Safed agent it is possible to monitor the USB ports for Windows Vista 2008 and later versions. Now the agent is able to receive WMI event notifications concerning the target instance “Win32_PnPEntity”. All events of classes “__InstanceCreationEvent”, “__InstanceDeletionEvent” and “__InstanceModificationEvent” will be intercepted, filtered (using the usual Safed objective filters) and sent to the syslog collector for further analysis, correlation with other events and storing.

Configuring Safed in order to track USB port usage is simple:

Step 1 – Enable USB monitoring: From the left side menu select “Network Configuration”, then check the “Enable active USB auditing” box. (Img. 1).

Step 1 – Enable USB monitoring

Step 2 – Add a new “EventLog Objective Configuration”: Select “USB Event” from the “Identify the high level event” list (Img. 2) and, if desired, insert a regular-expression-based filter in the “General Search Term” field. A simple example is to filter only “USB Mass Storage Device” for insert, removal or modification.

Step 2 – Add a new “EventLog Objective Configuration”

Once the configuration has been applied, Safed will intercept and filter USB events identifying them with an event ID (18 for USB inserted, 19 for USB removed, and 20 for USB modified) and will send them to the syslog collector (Img. 3.)

Syslog Collector

MarinovMihail

MarinovMihail

Developer at Würth Phoenix
“Hi guys! I’m Mihail and since the university years I has been fascinated by distributed systems and measurements on them. Now when I join the Neteye project I get the possibility to continue with this passion and this is great. My free time is completely dedicated to my wife and my daughters, I simply love them.”

Author

MarinovMihail

“Hi guys! I’m Mihail and since the university years I has been fascinated by distributed systems and measurements on them. Now when I join the Neteye project I get the possibility to continue with this passion and this is great. My free time is completely dedicated to my wife and my daughters, I simply love them.”

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive