Get history of file operations in Windows?

Posted on

QUESTION :

Is there a way to get a history of file operations in Windodws, like which folders were moved where, last renamed file, what was deleted, etc.?

ANSWER :

Process Monitor by SysInternals can monitor and log all file, registry and network operations.

procmon.exe

You have to be careful though. In the screenshot above, even though it says CreateFile all access is read-only (libraries (DLLs) being loaded).

There is no such log by default.


On a Windows NT system, an administrator can enable auditing of file operations:

Auditing settings for a directory

However:

  1. For this to work, “Audit object access” must be enabled in secpol.msc:

    Secpol: Auditing

    The moment you turn it on, you will get flooded by miscellaneous object access logs.

  2. Audit logs of the entire filesystem will fill up the Security log really fast. I’m not going to talk about performance hits.

Leave a Reply

Your email address will not be published.