G
Guest
Hi,
We have a windows 2000 domain and I see a lot of event ID 644 and 539
(account lockouts) on each of our domain controller security logs. Many are
from users which we suspect is fat finger syndrome but I also see quite a few
that say the administrator account is locked out. I use the administrator
account all day long and never get notified that it is locked out. Is there a
way to determine if this is malicious activity or something like a service
running with an old password?
Thanks,
Pete
We have a windows 2000 domain and I see a lot of event ID 644 and 539
(account lockouts) on each of our domain controller security logs. Many are
from users which we suspect is fat finger syndrome but I also see quite a few
that say the administrator account is locked out. I use the administrator
account all day long and never get notified that it is locked out. Is there a
way to determine if this is malicious activity or something like a service
running with an old password?
Thanks,
Pete