RE: Idea: A Comprehensive List

From: Mike Gilles (mike.gillesat_private)
Date: Wed Mar 20 2002 - 07:09:38 PST

  • Next message: Meritt James: "Re: Suggestions for research"

    Links to all these tools and/or organizations might be something to
    consider.  Makes the list more practical.   
    
    My $0.02 
    
    Thanks
    
    -MG
    
    Here's some:
    
    Nessus
    http://www.nessus.org/
    
    SNORT
    http://www.snort.org/
    
    Nmap
    http://www.nmap.org/
    
    TCPDump
    http://www.tcpdump.org/
    
    Ethereal
    http://www.ethereal.com/
    
    Trafshow (one of many DL links)
    http://www.tuxfinder.com/thematic/tree.php3?category=8&offset=2
    
    
    -----Original Message-----
    From: Matthew.Brownat_private [mailto:Matthew.Brownat_private]
    Sent: Sunday, March 17, 2002 8:17 PM
    To: forensicsat_private
    Subject: Idea: A Comprehensive List
    
    
    Folks
    
            I'd like to create a list of resources to respond to future 
    inquiries on this list.  I will maintain this list to keep from adding to 
    the moderator's existing workload.  I suggest listing tools and services 
    in the following areas. I've added a few to get us started below my 
    signature block.
    
            This might also help in determining a scope for forensics labs and 
    field kits. Many tools have moved through this list and it is a shame we 
    haven't been keeping track of them. There are plenty of web sites, but I 
    think with the expertise we have on this list, we could also provide some 
    feedback on these tools once a list has been compiled.  Feedback and 
    participation is welcome.
    
    Thanks,
    Matthew Brown, CISSP
    Principal Consultant
    
    
    
    
    Sandbox tools (To Trap):
            snort
            trafshow
            ethereal
            tcpdump
            nmap
    
    IDS (To Detect):  (These are the tools that create evidence we end up 
    examining during incidents afterall)
            Cisco Host Based
            VigilEnt Security Agents
            Dragon
            Network Flight Recorder
            snort
            RealSecure
            Netranger
            Netprowler
            BlackIce
            Intruder Alert
    
    Evidence Capturing - Software:
            EnCase (www.GuidanceSoftware.com)
            dd (Comes with *nix)
            netcat (nc)
    
    Evidence Capturing - Hardware:
            ImageMaster Solo2 - Hardware duplicator
            F.R.E.D. and his brothers - Hardware
    
    Evidence Examination:
            Coroner's Toolkit (TCT)
            EnCase
            SATAN
            NTI
    
    Data Recovery:
            OnTrack's Easy Recovery
            Norton Utilities
            NTI
    
    Certifications - Organizations that certify in the areas of Digital 
    Forensics, Incident Response, or Digital Investigations:
            HTCN
            SANS
    
    Training - Organizations that train in the areas of Digital Forensics, 
    Incident Response, or Digital Investigations:
            SANS & SANSfire
            Guidance Software
            NTI
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Mar 21 2002 - 07:26:17 PST