Honeypots mailing list archives

Sebek options for read/write/listen?


From: Jon Andersen <janderse () umich edu>
Date: Wed, 7 Jun 2006 11:10:06 -0400

Hi,

I'm using Sebek for Windows under VMware. The socket open/close/read/write/listen calls are what I'm most interested in, and yet it appears that Sebek is only recording the socket opens. I only see packets with "call=3" and "proto=6" when network traffic happens. Is there some way to configure/build Sebek to give more information than just socket opens, including read/write/listen on sockets? Or is there some other tool the community has found that records those calls on Windows?

-Jon Andersen
Graduate Student
734-763-4521 (work)
734-763-8428 (home)
Computer Science & Engineering - Rm 4917
University of Michigan


Current thread: