nerdexam
GIAC

GPEN · Question #293

John works as a professional Ethical Hacker. He is assigned a project to test the security of placed a backdoor in the network. Now, he wants to clear all event logs related to previous hacking…

The correct answer is C. elsave.exe D. WinZapper. Two tools capable of clearing Windows 2000 event logs are elsave.exe and WinZapper, both used by attackers to erase evidence of intrusion from Windows NT/2000 systems.

Exploitation & Post-Exploitation Techniques

Question

John works as a professional Ethical Hacker. He is assigned a project to test the security of placed a backdoor in the network. Now, he wants to clear all event logs related to previous hacking attempts. Which of the following tools can John use if we-are-secure.com is using the Windows 2000 server? Each correct answer represents a complete solution. Choose two.

Options

  • AAuditPol
  • BBlindside
  • Celsave.exe
  • DWinZapper

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    12% (3)
  • C
    84% (21)

Why each option

Two tools capable of clearing Windows 2000 event logs are elsave.exe and WinZapper, both used by attackers to erase evidence of intrusion from Windows NT/2000 systems.

AAuditPol

AuditPol is a command-line utility for configuring Windows audit policies - enabling or disabling which events are audited - not for deleting or clearing existing event log entries.

BBlindside

Blindside is not a recognized Windows event log clearing tool and has no established function related to event log manipulation on Windows 2000 servers.

Celsave.exeCorrect

elsave.exe is a command-line utility designed to save and clear Windows NT/2000 event logs including the security, system, and application logs, making it directly effective for removing traces of unauthorized activity. Its targeted log-clearing capability makes it a practical tool for covering attacker tracks on a Windows 2000 server.

DWinZapperCorrect

WinZapper is a tool specifically built to delete individual records from Windows NT/2000 event logs, allowing attackers to selectively remove only the entries that reveal hacking activity rather than wiping all logs. This selective deletion is more covert because completely empty logs can themselves appear suspicious to investigators.

Concept tested: Windows event log clearing tools for intrusion cover

Topics

#log clearing#Windows event logs#covering tracks#elsave WinZapper

Community Discussion

No community discussion yet for this question.

Full GPEN Practice