New Article: Incident Response Tools For Unix, Part Two

From: Dan Hanson (dhanson_at_securityfocus.com)
Date: 10/16/03

  • Next message: Jeffrey Denton: "Re: New Rootkit?"
    Date: Thu, 16 Oct 2003 11:31:39 -0600 (MDT)
    To: incidents@securityfocus.com
    
    

    Because, in the past, I have received questions asking where part 1 of a
    series is located, if you read the article, at the bottom in the section
    about the author, there is a link to all the other articles on
    SecurityFocus that were authored by Holt.

    =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

    Incident Response Tools For Unix, Part Two: File-System Tools
    Feature Article by Holt Sorenson Oct 16, 2003

    This article is the second in a three-part series on tools that are useful
    during incident response and investigation after a compromise has occurred
    on a OpenBSD, Linux, or Solaris system. This installment will focus on
    file system tools.

    http://www.securityfocus.com/infocus/1738

    ---------------------------------------------------------------------------
    FREE Whitepaper: Better Management for Network Security

    Looking for a better way to manage your IP security?
    Learn how Solsoft can help you:
    - Ensure robust IP security through policy-based management
    - Make firewall, VPN, and NAT rules interoperable across heterogeneous
    networks
    - Quickly respond to network events from a central console

    Download our FREE whitepaper at:
    http://www.securityfocus.com/sponsor/Solsoft_incidents_031015
    ----------------------------------------------------------------------------


  • Next message: Jeffrey Denton: "Re: New Rootkit?"

    Relevant Pages

    • RE: Auditing enabled but Logon Failures not showing up
      ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Focus-Microsoft)
    • RE: Auditing enabled but Logon Failures not showing up
      ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Focus-Microsoft)
    • Re: Terminal Services Auditing?
      ... Read Special Ops and mount an assault to eradicate network negligence today. ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Focus-Microsoft)
    • RE: Alternatives to sftp?
      ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Security-Basics)
    • RE: Alternatives to sftp?
      ... FREE Whitepaper: Better Management for Network Security ... Ensure robust IP security through policy-based management ...
      (Security-Basics)