38
Active Ports 1.4 ZoneLog

Active Ports 1.4 ZoneLog

Embed Size (px)

DESCRIPTION

Active Ports 1.4 ZoneLog. Active Ports Overview. What it does Where to get it Why use it How to use it Screen Shots Observations Lessons Learned. What Active Ports Does. Monitor TCP/UDP activity Maps processes to specific ports Easy to kill processes. Where to get it. - PowerPoint PPT Presentation

Citation preview

Page 1: Active Ports 1.4 ZoneLog

Active Ports 1.4ZoneLog

Page 2: Active Ports 1.4 ZoneLog

Active Ports Overview What it does Where to get it Why use it How to use it Screen Shots Observations Lessons Learned

Page 3: Active Ports 1.4 ZoneLog

What Active Ports Does Monitor TCP/UDP activity Maps processes to specific ports Easy to kill processes

Page 4: Active Ports 1.4 ZoneLog

Where to get it http://www.ntutility.com/freeware.ht

ml http://www.download.com

Page 5: Active Ports 1.4 ZoneLog

Why use it Live analysis Monitor what systems access the

Internet Detect Trojans and other malware

Page 6: Active Ports 1.4 ZoneLog

How To Use It Setup and Go

Page 7: Active Ports 1.4 ZoneLog
Page 8: Active Ports 1.4 ZoneLog
Page 9: Active Ports 1.4 ZoneLog
Page 10: Active Ports 1.4 ZoneLog
Page 11: Active Ports 1.4 ZoneLog
Page 12: Active Ports 1.4 ZoneLog

Observations Simple and easy to use Not very robust Little documentation Doesn’t always find the remote IP

Page 13: Active Ports 1.4 ZoneLog

Lessons Learned Simple tool for live analysis Must know what should be open

Page 14: Active Ports 1.4 ZoneLog

ZoneLog

Page 15: Active Ports 1.4 ZoneLog

ZoneLog Overview What it does Where to get it Why use it How to use it Screen Shots Observations Lessons Learned

Page 16: Active Ports 1.4 ZoneLog

Where to get it http://zonelog.co.uk/

Page 17: Active Ports 1.4 ZoneLog

Why use it Zone Alarm does not have a good

log viewer Get a lot more info than Zone Alarm

offers

Page 18: Active Ports 1.4 ZoneLog

What it does Incident Response Helps interpret Zone Alarm log file Gives information on data being

blocked

Page 19: Active Ports 1.4 ZoneLog

How to use it Download VB6 runtime files Download application Find ZAlog.txt C:\WINDOWS\Internet Logs

Page 20: Active Ports 1.4 ZoneLog
Page 21: Active Ports 1.4 ZoneLog
Page 22: Active Ports 1.4 ZoneLog
Page 23: Active Ports 1.4 ZoneLog
Page 24: Active Ports 1.4 ZoneLog
Page 25: Active Ports 1.4 ZoneLog
Page 26: Active Ports 1.4 ZoneLog
Page 27: Active Ports 1.4 ZoneLog
Page 28: Active Ports 1.4 ZoneLog
Page 29: Active Ports 1.4 ZoneLog
Page 30: Active Ports 1.4 ZoneLog
Page 31: Active Ports 1.4 ZoneLog
Page 32: Active Ports 1.4 ZoneLog
Page 33: Active Ports 1.4 ZoneLog
Page 34: Active Ports 1.4 ZoneLog
Page 35: Active Ports 1.4 ZoneLog
Page 36: Active Ports 1.4 ZoneLog
Page 37: Active Ports 1.4 ZoneLog

Observations Not all data about attack is true Not all features are useful

Activity graph Good documentation

Page 38: Active Ports 1.4 ZoneLog

Lessons Learned Lots of harmless traffic Big improvement over ZA log viewer