Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer.
http://www.sandboxie.com/
Showing posts with label Security Tools. Show all posts
Showing posts with label Security Tools. Show all posts
Monday, May 24, 2010
Sunday, May 9, 2010
OSSIM
OSSIM stands for Open Source Security Information Management. Its goal is to provide a comprehensive compilation of tools which, when working together, grant network/security administrators with a detailed view over each and every aspect of his or her networks, hosts, physical access devices, server, etc.
Besides getting the most out of well known open source tools, some of which are briefly described below, OSSIM provides a strong correlation engine, detailed low, medium and high level visualization interfaces, and reporting and incident management tools, based on a set of defined assets such as hosts, networks, groups and services.
All of this information can be restricted by network or sensor in order to provide only the required information to specific users; allowing for a fine grained multi–user security environment. Finally, the ability to perform as an IPS (Intrusion Prevention System), using correlated information from virtually any source, will be a useful addition to any security professional’s arsenal.
Components
OSSIM features the following software components:
* Arpwatch – used for MAC anomaly detection.
* P0f – used for passive OS detection and OS change analysis.
* Pads – used for service anomaly detection.
* Nessus – used for vulnerability assessment and for cross correlation (IDS vs Security Scanner).
* Snort – the IDS, also used for cross correlation with nessus.
* Tcptrack – used for session data information which can prove useful for attack correlation.
* Ntop – which builds an impressive network information database from which we can identify aberrant behavior/anomaly detection.
* Nagios – fed from the host asset database, it monitors host and service availability information.
* Osiris – a great HIDS.
* OCS-NG – cross-platform inventory solution.
* OSSEC – integrity, rootkit, registry detection, and more.
http://www.alienvault.com/community.php?section=Home
Besides getting the most out of well known open source tools, some of which are briefly described below, OSSIM provides a strong correlation engine, detailed low, medium and high level visualization interfaces, and reporting and incident management tools, based on a set of defined assets such as hosts, networks, groups and services.
All of this information can be restricted by network or sensor in order to provide only the required information to specific users; allowing for a fine grained multi–user security environment. Finally, the ability to perform as an IPS (Intrusion Prevention System), using correlated information from virtually any source, will be a useful addition to any security professional’s arsenal.
Components
OSSIM features the following software components:
* Arpwatch – used for MAC anomaly detection.
* P0f – used for passive OS detection and OS change analysis.
* Pads – used for service anomaly detection.
* Nessus – used for vulnerability assessment and for cross correlation (IDS vs Security Scanner).
* Snort – the IDS, also used for cross correlation with nessus.
* Tcptrack – used for session data information which can prove useful for attack correlation.
* Ntop – which builds an impressive network information database from which we can identify aberrant behavior/anomaly detection.
* Nagios – fed from the host asset database, it monitors host and service availability information.
* Osiris – a great HIDS.
* OCS-NG – cross-platform inventory solution.
* OSSEC – integrity, rootkit, registry detection, and more.
http://www.alienvault.com/community.php?section=Home
Thursday, July 16, 2009
Nmap 5.00 is Out
New features:
Ncat tool aims to be your Swiss Army Knife for data transfer, redirection, and debugging. We released a whole users' guide detailing security testing and network administration tasks made easy with Ncat.
The addition of the Ndiff scan comparison tool completes Nmap's growth into a whole suite of applications which work together to serve network administrators and security practitioners.
Nmap Network Scanning, the official Nmap guide to network discovery and security scanning. From explaining port scanning basics for novices to detailing low-level packet crafting methods used by advanced hackers, this book suits all levels of security and networking professionals. A 42-page reference guide documents every Nmap feature and option, while the rest of the book demonstrates how to apply those features to quickly solve real-world tasks. More than half the book is available in the free online edition.
The Nmap Scripting Engine (NSE) is one of Nmap's most powerful and flexible features.
Visit and download the new version @ http://nmap.org/5/#changes-nse
Ncat tool aims to be your Swiss Army Knife for data transfer, redirection, and debugging. We released a whole users' guide detailing security testing and network administration tasks made easy with Ncat.
The addition of the Ndiff scan comparison tool completes Nmap's growth into a whole suite of applications which work together to serve network administrators and security practitioners.
Nmap Network Scanning, the official Nmap guide to network discovery and security scanning. From explaining port scanning basics for novices to detailing low-level packet crafting methods used by advanced hackers, this book suits all levels of security and networking professionals. A 42-page reference guide documents every Nmap feature and option, while the rest of the book demonstrates how to apply those features to quickly solve real-world tasks. More than half the book is available in the free online edition.
The Nmap Scripting Engine (NSE) is one of Nmap's most powerful and flexible features.
Visit and download the new version @ http://nmap.org/5/#changes-nse
Friday, March 27, 2009
Nmap 4.85BETA 4
From Fyodor
4.85BETA4 (compared to 4.76) includes our new Ncat and Ndiff tools, a ton of new NSE scripts for superior network discovery, more than 5,000 version detection signatures and nearly 2,000 OS fingerprints, improved scan performance, and much more! You can read about all the changes at http://nmap.org/changelog.html. Be sure to read all the way down to 4.85BETA1, as that includes some of the most dramatic changes.
4.85BETA4 (compared to 4.76) includes our new Ncat and Ndiff tools, a ton of new NSE scripts for superior network discovery, more than 5,000 version detection signatures and nearly 2,000 OS fingerprints, improved scan performance, and much more! You can read about all the changes at http://nmap.org/changelog.html. Be sure to read all the way down to 4.85BETA1, as that includes some of the most dramatic changes.
Friday, November 28, 2008
Web Site Advisors
I've been using McAfee's site advisor and recently ran to Norton's Safe Web services. Both tools are pretty good. Both services can analyze Web sites and be able to give you information on how they will affect your computer.
Friday, November 21, 2008
Tools: PsExec
PsExec is a light-weight telnet-replacement that lets you execute processes on other systems, complete with full interactivity for console applications, without having to manually install client software. Download now...
Tools: Process Explorer
Ever wondered which program has a particular file or directory open? Now you can find out. Process Explorer shows you information about which handles and DLLs processes have opened or loaded. Download now...
Subscribe to:
Posts (Atom)
-
In 2013 Android grew to a very large number: 87%. This was its share of the global smartphone market. It also grew to an even larger one: 97...
-
OpenSSH is a freely available version of the Secure Shell (SSH) protocol family of tools for remotely controlling a computer or transferring...
-
By Bill Sizemore The Virginian-Pilot © June 4, 2009 State officials are notifying more than a half-million Virginians that their Social Secu...