RE: Looking for Host Based IDS

From: Matt.Carpenter@alticor.com
Date: 12/17/01


To: GuyF@xpert.com
From: Matt.Carpenter@alticor.com
Date: Mon, 17 Dec 2001 14:45:06 -0500


Tripwire is pretty much an OpenSource default for *nix. Windows has many
and varied. I've heard good things about ISS's software as well as
PacketStorm.
 Check out Freshmeat if you want other options (www.freshmeat.net) for
*nix

                                                                                                                   
                    Guy Fighel
                    <GuyF@xpert.c To: "'Matt.Carpenter@alticor.com'" <Matt.Carpenter@alticor.com>
                    om> cc:
                                         Subject: RE: Looking for Host Based IDS
                    12/17/2001
                    12:39 PM
                                                                                                                   
                                                                                                                   

Microsoft and *NIX

-----Original Message-----
From: Matt.Carpenter@alticor.com [mailto:Matt.Carpenter@alticor.com]
Sent: Monday, December 17, 2001 7:37 PM
To: GuyF@xpert.com
Subject: Re: Looking for Host Based IDS

What OS are you looking for?

                    Guy Fighel

                    <GuyF@xpert.c To:
focus-ids@securityfocus.com

                    om> cc:

                                         Subject: Looking for Host
Based
IDS
                    12/17/2001

                    10:34 AM

Hello,

Can someone recommend about a good Host Based IDS that looks for suspicious
operating system processes?
I need the ability to write a specific policy for specific system processes
and need that the IDS will report about any modifications.

I would appreciate your help,

Guy.


Quantcast