+ Reply to Thread
Results 1 to 1 of 1

Thread: Patriot NG: New HostBased Intrusion Detection System

  1. #1
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581

    Patriot NG: New HostBased Intrusion Detection System

    Patriot is a 'Host IDS' tool which allows real time monitoring of changes in Windows systems or Network attacks.

    Patriot monitors:

    * Changes in Registry keys: Indicating whether any sensitive key (autorun, internet explorer settings...) is altered.
    * New files in 'Startup' directories
    * New Users in the System
    * New Services installed
    * Changes in the hosts file
    * New scheduled jobs
    * Alteration of the integrity of Internet Explorer: (New BHOs, configuration changes, new toolbars)
    * Changes in ARP table (Prevention of MITM attacks)
    * Installation of new Drivers
    * New Netbios shares
    * TCP/IP Defense (New open ports, new connections made by processes, PortScan detection...)
    * Files in critical directories (New executables, new DLLs...)
    * New hidden windows (cmd.exe / Internet Explorer using OLE objects)
    * Netbios connections to the System
    * ARP Watch (New hosts in your network)
    * NIDS (Detect anomalous network traffic based on editable rules)


    It needs winpcap.
    You can view the security logs made by Patriot NG through Windows Event viewer in ‘Application’.
    Changes are not persistent so when you restart, all apps / ports / hosts blocked are unblocked.

    Security Projects - Patriot NG
    Last edited by Renk; 23.02.11 at 00:12.
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    SealLion (23.02.11)

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •