subject: (Fwd) Re: Win32 HIDS
posted: Mon, 30 Sep 2002 13:57:35 +0100


on collecting and crunching Windows logs with a central unix box..

------- Forwarded message follows -------
Date sent: Thu, 26 Sep 2002 00:21:21 +0200
From: oudot laurent <[email protected]>
To: David Ellis <[email protected]>
Copies to: "'Chris Peden'" <[email protected]>,
[email protected],
"[email protected]" <[email protected]>
Subject: Re: Win32 HIDS

[ Double-click this line for list subscription options ]


Snort for Win32 is not an HIDS
This is an NIDS launched on a win32 platform.

If you really need HIDS under Win32, you can use Prelude-IDS (http://www.prelude-ids.org) [GNU]

What to do ?

Take your Windows boxes, install a forwarder of their logs (i mean coming from their eventlog) in the
Unix syslog format (like nt-syslog) to a Unix accepting syslog alerts in remote (look at "syslogd -r"
in the man)
Then on the Unix box, install the composant called prelude-lml (Log Monitor Lakey) and tell him to
parse the collected logs
Some guys use it to parse logs coming from their windows (ex: on ... host, administrator
authentication error...)
You can specify what to create as an alert..
It's all free and opensource...
Take a look if you need something very powerfull.

my 2 cents,

laurent

David Ellis wrote:

> Snort for win32
> -----Original Message-----
> From: Chris Peden [mailto:[email protected]]
> Sent: Tuesday, September 17, 2002 4:45 PM
> To: Windows Security Issues
> Cc: [email protected]
> Subject: Win32 HIDS
>
> Does anyone know of any free or low cost HIDS for win32 platform?
>
> Thanks,
> Chris Peden, MCP
> Information Technology Director
> Sundowner Interiors
> 1110 CR6 West
> Elkhart, IN 46514
> P: 574-262-1523x117
> F: 574-264-0022
> [email protected]
> www.sundownertrailer.com
> **************************************************************************************************
> The contents of this email and any attachments are confidential.
> It is intended for the named recipient(s) only.
> If you have received this email in error please notify the system manager or the
> sender immediately and do not disclose the contents to anyone or make copies.
>
> ** eSafe-portsmouth scanned this email for viruses, vandals and malicious content **
> **************************************************************************************************
------- End of forwarded message -------

---
* Origin: [adminz] tech, security, support (192.168.0.2)

generated by msg2page 0.06 on Jul 21, 2006 at 19:04:36

 search: