Active Ports 1.4 ZoneLog. Active Ports Overview What it does Where to get it Why use it How to use...
-
Upload
vernon-adams -
Category
Documents
-
view
216 -
download
0
Transcript of Active Ports 1.4 ZoneLog. Active Ports Overview What it does Where to get it Why use it How to use...
Active Ports Overview What it does Where to get it Why use it How to use it Screen Shots Observations Lessons Learned
What Active Ports Does Monitor TCP/UDP activity Maps processes to specific ports Easy to kill processes
Observations Simple and easy to use Not very robust Little documentation Doesn’t always find the remote IP
ZoneLog Overview What it does Where to get it Why use it How to use it Screen Shots Observations Lessons Learned
What it does Incident Response Helps interpret Zone Alarm log file Gives information on data being
blocked
How to use it Download VB6 runtime files Download application Find ZAlog.txt C:\WINDOWS\Internet Logs
Observations Not all data about attack is true Not all features are useful
Activity graph Good documentation