GPEN · Question #293
John works as a professional Ethical Hacker. He is assigned a project to test the security of placed a backdoor in the network. Now, he wants to clear all event logs related to previous hacking…
The correct answer is C. elsave.exe D. WinZapper. Two tools capable of clearing Windows 2000 event logs are elsave.exe and WinZapper, both used by attackers to erase evidence of intrusion from Windows NT/2000 systems.
Question
John works as a professional Ethical Hacker. He is assigned a project to test the security of placed a backdoor in the network. Now, he wants to clear all event logs related to previous hacking attempts. Which of the following tools can John use if we-are-secure.com is using the Windows 2000 server? Each correct answer represents a complete solution. Choose two.
Options
- AAuditPol
- BBlindside
- Celsave.exe
- DWinZapper
How the community answered
(25 responses)- A4% (1)
- B12% (3)
- C84% (21)
Why each option
Two tools capable of clearing Windows 2000 event logs are elsave.exe and WinZapper, both used by attackers to erase evidence of intrusion from Windows NT/2000 systems.
AuditPol is a command-line utility for configuring Windows audit policies - enabling or disabling which events are audited - not for deleting or clearing existing event log entries.
Blindside is not a recognized Windows event log clearing tool and has no established function related to event log manipulation on Windows 2000 servers.
elsave.exe is a command-line utility designed to save and clear Windows NT/2000 event logs including the security, system, and application logs, making it directly effective for removing traces of unauthorized activity. Its targeted log-clearing capability makes it a practical tool for covering attacker tracks on a Windows 2000 server.
WinZapper is a tool specifically built to delete individual records from Windows NT/2000 event logs, allowing attackers to selectively remove only the entries that reveal hacking activity rather than wiping all logs. This selective deletion is more covert because completely empty logs can themselves appear suspicious to investigators.
Concept tested: Windows event log clearing tools for intrusion cover
Topics
Community Discussion
No community discussion yet for this question.