Thread: How To Analyse Suspicious Internet Activity
.....in real time
hypothetical situation..
user has full ip logging , has log viewer opened , using firefox ( or browser ) on computer. spots couple of ip addresses going out aren't there web site visits. has sort of disk monitor program running , shows quite unusual activity of reading disk. rather disconnecting decides wants monitor activity , has small window of opportunity( few seconds ) capture has can.
1....what commands run on terminal capture as can may in deciding if activity abnormal?
2....could put commands in script , have sort of 'hot switch' run commands @ click of mouse
3...are there programs out there run spot unusual activity.
i'm thinking along lines of looking @ open files, processes running, memory dumps, packet capture on port 80, etc. there may more hence question..
Forum The Ubuntu Forum Community Ubuntu Specialised Support Security [ubuntu] How To Analyse Suspicious Internet Activity
Ubuntu
Comments
Post a Comment