PaulDotCom mailing list archives
HIDS advice?
From: rgula at tenablesecurity.com (Ron Gula)
Date: Tue, 18 Aug 2009 22:22:14 -0400
I'm curious how many people enable process accounting on UNIX or Windows and feed these to their SIM? When you start seeing tcpdump being run by user 'www' at 2:00 am, things can get interesting. Ron Christopher Rimondi wrote:
I have used OSSEC for the past three years and believe it is an excellent IDS. The rule set is expansive and flexible. It also encrypts all communication between the agents and the server. Also, check out the WUI. It has got pretty decent search functionality. Not on the order of Splunk but, it gets the job done. Thanks, Chris Rimondi ------------------------------------------------------------------------ _______________________________________________ Pauldotcom mailing list Pauldotcom at mail.pauldotcom.com http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom Main Web Site: http://pauldotcom.com
-- Ron Gula, CEO Tenable Network Security
Current thread:
- HIDS advice? lists at truthisfreedom.org.uk (Aug 17)
- HIDS advice? Erik Harrison (Aug 17)
- HIDS advice? Jason Wood (Aug 17)
- <Possible follow-ups>
- HIDS advice? Christopher Rimondi (Aug 18)
- HIDS advice? Ron Gula (Aug 18)
- HIDS advice? Joe Magee (Aug 19)
- HIDS advice? Ron Gula (Aug 20)
- HIDS advice? Dale Stirling (Aug 20)
- HIDS advice? Ron Gula (Aug 18)
- HIDS advice? Mike Patterson (Aug 19)