Active ports 1 4 zonelog
This presentation is the property of its rightful owner.
Sponsored Links
1 / 38

Active Ports 1.4 ZoneLog PowerPoint PPT Presentation


  • 96 Views
  • Uploaded on
  • Presentation posted in: General

Active Ports 1.4 ZoneLog. Active Ports Overview. What it does Where to get it Why use it How to use it Screen Shots Observations Lessons Learned. What Active Ports Does. Monitor TCP/UDP activity Maps processes to specific ports Easy to kill processes. Where to get it.

Download Presentation

Active Ports 1.4 ZoneLog

An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.


- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -

Presentation Transcript


Active ports 1 4 zonelog

Active Ports 1.4ZoneLog


Active ports overview

Active Ports Overview

  • What it does

  • Where to get it

  • Why use it

  • How to use it

  • Screen Shots

  • Observations

  • Lessons Learned


What active ports does

What Active Ports Does

  • Monitor TCP/UDP activity

  • Maps processes to specific ports

  • Easy to kill processes


Where to get it

Where to get it

  • http://www.ntutility.com/freeware.html

  • http://www.download.com


Why use it

Why use it

  • Live analysis

  • Monitor what systems access the Internet

  • Detect Trojans and other malware


How to use it

How To Use It

  • Setup and Go


Observations

Observations

  • Simple and easy to use

  • Not very robust

  • Little documentation

  • Doesn’t always find the remote IP


Lessons learned

Lessons Learned

  • Simple tool for live analysis

  • Must know what should be open


Zonelog

ZoneLog


Zonelog overview

ZoneLog Overview

  • What it does

  • Where to get it

  • Why use it

  • How to use it

  • Screen Shots

  • Observations

  • Lessons Learned


Where to get it1

Where to get it

  • http://zonelog.co.uk/


Why use it1

Why use it

  • Zone Alarm does not have a good log viewer

  • Get a lot more info than Zone Alarm offers


What it does

What it does

  • Incident Response

  • Helps interpret Zone Alarm log file

  • Gives information on data being blocked


How to use it1

How to use it

  • Download VB6 runtime files

  • Download application

  • Find ZAlog.txt

  • C:\WINDOWS\Internet Logs


Observations1

Observations

  • Not all data about attack is true

  • Not all features are useful

    • Activity graph

  • Good documentation


Lessons learned1

Lessons Learned

  • Lots of harmless traffic

  • Big improvement over ZA log viewer


  • Login