Menu

#2857 Add security relevant event logging via Windows event log

KeePass
open
nobody
None
5
2024-01-08
2023-12-30
Al Ex
No

Adding security relevant event logging (like unlocking, editing and autofill actions) via Windows event log would offer the possibility to detect credential stealing (e.g. many different credentials opened in a short timeframe) in the central logging infrastructure.

Discussion

  • Paul

    Paul - 2023-12-31

    That is not the sort of thing you need / want in a personal, portable password manager. In a shared / enterprise manager you want more robust auditing.
    More importantly, a single export is all you need to steal all data and that is hardly going to make bells ring when checking the event log.

    cheers, Paul

     
    • Al Ex

      Al Ex - 2024-01-08

      Thanks for your answer, Paul!
      On https://keepass.info/help/kb/trust.html it is stated that KeePass 'is installed by default on all PCs of the federal administration of Switzerland.' and that in France it is recommended for use in the public sector. That somehow makes it an enterprise manager, doesn't it?
      I guess the main use case is replacing the web browser's password storage.

       
  • Paul

    Paul - 2024-01-08

    No, it is not an enterprise manager, it is a personal manager installed on a lot of machines.
    An enterprise manager would be centrally managed with multiple user accounts, like Bitwarden, Pleasant or LastPass.

    I use KeePass to store a lot more than just website credentials. It has credit card, car, computer, insurance, passport....
    A single central location for all my important stuff, that I can carry on my phone as well.

    cheers, Paul

     

Log in to post a comment.