Commercial Honeypots for Windows?



Does any vendor make a commercial Honeypot for Windows, or one that emulates
Windows 2000? I have a trojan on a DMZ that is spreading itself by SMB to
other machines, and I want to see in detail what files it is grabbing and
replacing. I can of course configure a Windows 2000 host and then use
Sysinternals tools to get the same information, but it's more work than I
want, and I am hoping to find a commercial tool that would save time.

I saw a lot of freeware research tools, but they all looked like they would
take as much time to learn and install and make work as doing things the
hard way using Sysinternals.

--
Will


.



Relevant Pages

  • Re: [Full-disclosure] mac trojan in-the-wild
    ... good and is just spreading FUD. ... No one is suggesting that this the propogation of this malware amoung ... The same gang infects Windows machines as ... just that now they also target macs. ...
    (Full-Disclosure)
  • Re: Fortune:More for your money with Mac
    ... So what FUD is it I'm spreading instead? ... Pretty much anything you say about Windows. ... He's told us the reasons. ...
    (comp.sys.mac.advocacy)
  • Re: mac trojan in-the-wild
    ... good and is just spreading FUD. ... No one is suggesting that this the propogation of this malware amoung ... The same gang infects Windows machines as ... just that now they also target macs. ...
    (Bugtraq)
  • Re: Commercial Honeypots for Windows?
    ... other machines, and I want to see in detail what files it is grabbing and ... I can of course configure a Windows 2000 host and then use ... Sysinternals tools to get the same information, but it's more work than I ... If you can't be bothered to run up a few sysinternal tools, then analysing honeypot information would be of little use to you. ...
    (microsoft.public.security)
  • Re: Fortune:More for your money with Mac
    ... C Lund wrote: ... So what FUD is it I'm spreading instead? ... Pretty much anything you say about Windows. ...
    (comp.sys.mac.advocacy)