Security Basics mailing list archives

Re: RE: Computer forensics to uncover illegal internet use


From: pro_logos () hotmail com
Date: 6 Sep 2005 19:13:27 -0000

If you don't have a proxy server like websense then try and have the IT department dump the firewall logs. In some 
cases firewalls have a separate module that logs http connections and this may be valuable as well. I'm an IT Security 
Auditor and 95% of my clients weren't loggging/reviewing logs on their perimeter systems....so hopefully you will be in 
that 5% that does. You could also try a product called Recover My Files.....I use it all the time and it works well. 
The license is only around $50 or so. Just hope this person wasn't using secure erase to delete his files.....probably 
not...most anti-spyware programs will delete the files but not truely secure delete by random bit overwriting. 


Current thread: