Re: Commercial Honeypots for Windows?
- From: "Will" <westes-usc@xxxxxxxxxxxxxx>
- Date: Sun, 28 Jan 2007 15:21:22 -0800
"Bogwitch" <Bogwitch@xxxxxxxxxxxxxxxxxxx> wrote in message
news:zE9vh.81498$n36.74261@xxxxxxxxxxxxxxxxxxxxxxx
Will wrote:emulates
Does any vendor make a commercial Honeypot for Windows, or one that
toWindows 2000? I have a trojan on a DMZ that is spreading itself by SMB
andother machines, and I want to see in detail what files it is grabbing
Ireplacing. I can of course configure a Windows 2000 host and then use
Sysinternals tools to get the same information, but it's more work than
wouldwant, and I am hoping to find a commercial tool that would save time.
I saw a lot of freeware research tools, but they all looked like they
take as much time to learn and install and make work as doing things the
hard way using Sysinternals.
If you can't be bothered to run up a few sysinternal tools, then
analysing honeypot information would be of little use to you. That said,
I don't know much^wanything about commercial honeypots. I would imagine
they will take as much effort to sort out as the freeware tools.
It's not running them that takes time. It's configuring the filters to
exclude the things that don't matter that takes time. And writing down the
results so you have a clear track of what happened. And coordinating the
inputs of file system, registry, user logins, etc...
It would surely be much easier to have the honeypot summarize all activity
against the system from a single source, in a single log.
--
Will
.
- References:
- Commercial Honeypots for Windows?
- From: Will
- Re: Commercial Honeypots for Windows?
- From: Bogwitch
- Commercial Honeypots for Windows?
- Prev by Date: Re: Commercial Honeypots for Windows?
- Next by Date: Re: Non Disclosure Agreement Requires Removal of IE
- Previous by thread: Re: Commercial Honeypots for Windows?
- Next by thread: Re: Is this the place to post a Q regarding OneCare?
- Index(es):