How to detect hackers on your web server

cmd.exe, ftp.exe, net.exe, ping.exe and tftp.exe. The auditing tab To enable object access auditing to log each time the SYSTEM account and Internet guest account attempt to run cmd.exe: 1. Right-click on cmd.exe and select Properties 2. Next select the Security tab and click on Advanced 3. Select the Auditing tab and click on Add 4. ................
................