Re: diagnose compromise on NT

From: Patrick Andry (pandry@wolverinefreight.ca)
Date: 07/22/02


Date: Mon, 22 Jul 2002 11:05:20 -0400
From: Patrick Andry <pandry@wolverinefreight.ca>
To: "Ingersoll, Jared" <jared@cswv.com>

Ingersoll, Jared wrote:
> Does anyone know of any good tools that can be used on an NT 4.0 box to
> (help) diagnose a system compromise? I've been playing around with inzider
> with limited results.
>
> Thanks,
>
> Jared
>
> ----------------------------------------------------------------------------
> This list is provided by the SecurityFocus ARIS analyzer service.
> For more information on this free incident handling, management
> and tracking system please see: http://aris.securityfocus.com

What type of system compromise?
Did event log/web logs show any activity?

PStools from sysinternals is usually a good set of raw tools to use, but you
have to know what you are looking for in order for them to be of any use.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • RE: A small quandary
    ... This list is provided by the SecurityFocus ARIS analyzer service. ... and tracking system please see: http://aris.securityfocus.com ... For more information on this free incident handling, management ...
    (Incidents)
  • RE: Anyone seen this before?
    ... The answer to this is, in task manager, you can right click on any app ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: Code Red - A Possible Origin?
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: Code Red - A Possible Origin?
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: fbi.gov weirdness?
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)