Security Basics mailing list archives

Re: Log checking programs


From: Scott Warren <sw () shelton org>
Date: Mon, 24 Jul 2006 13:09:15 -0500

Check out the Cisco Security Monitoring, Analysis and Response System (Mars) box, they look pretty impressive! I want one!!

http://www.cisco.com/en/US/products/ps6241/index.html

Its supposed to see a threat and alert you as well as give you all the back-trace info on what happened. Its also supposed to be able to cut off the threat.

-- Scott


On Jul 24, 2006, at 4:47 AM, esecuritydude () googlemail com wrote:

Hi all,

I am looking for some sort of program to check AD security event logs. Something or some way to automate checking the logs on the Domain Controllers and sending reports of suspicious activity to an email or something. e.g. Failed Logins etc...

Suggestions welcome,

Thanks in Advance,
Miguel

---------------------------------------------------------------------- -----
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------- -----




---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: