SecurityFocus Article Announcement: Incident Response Tools For Unix, Part One: System Tools

From: Dan Hanson (dhanson@securityfocus.com)
Date: 03/28/03

  • Next message: Klayton Monroe: "FTimes 3.2.1 Release (Includes Dig, HashDig, and Map Tools)"
    Date: Thu, 27 Mar 2003 16:24:24 -0700 (MST)
    From: Dan Hanson <dhanson@securityfocus.com>
    To: incidents@securityfocus.com
    
    

    Hey incidents subscribers, many times posters to this list have questions
    about odd behaviour on a host and the answer is usually to run some
    investigative tools. The following series will hopefully help people
    investigating potential breaches on Unix or Linux systems.

    =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

    Incident Response Tools For Unix, Part One: System Tools

    By Holt Sorensen

    This article is the first in a three-part series on tools that are useful
    during incident response and investigation after a compromise has occurred
    on a OpenBSD, Linux, or Solaris system. This installment will focus on
    system tools, the second part will discuss file-system tools, and the
    concluding article will look at network tools.

    http://www.securityfocus.com/infocus/1679

    ----------------------------------------------------------------------------
    Powerful Anti-Spam Management and More...
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.surfcontrol.com/go/zsfihl1


  • Next message: Klayton Monroe: "FTimes 3.2.1 Release (Includes Dig, HashDig, and Map Tools)"

    Relevant Pages

    • Re: Major Update On Jeff Hardy, Escorted Off Plane, WWE Comments
      ... WWE has acknowledged the incident though with the following statement to ... are currently investigating the situation and will take appropriate ... Jeff Hardy = Scott Hall 2008 ...
      (rec.sport.pro-wrestling)
    • Forest Green Shooting.
      ... I understand that the IPPC are investigating the shooting of Mohammed ... Kahar in this incident. ...
      (uk.politics.misc)
    • Re: EMT Woe
      ... HMRI would be investigating this ... incident and they have the power to obtain this information, ...
      (uk.railway)
    • Re: NEW YORK TIMES investigates Palin as mayor and governor.
      ... the three politicos driving the ... with the incident because he would not do her political will is ... and has final and ultimate authority over the State Police. ... They are investigating "abuse of power" so your bullshit statements ...
      (rec.music.artists.springsteen)
    • Re: Horrific accident on the Ashton Canal
      ... Even in the earliest reports, we hear than BW and the HSE are ... What is there for the HSE to investigate? ... "We are investigating the incident which we are ...
      (uk.rec.waterways)