Skip to main content

Thread: How To Analyse Suspicious Internet Activity


.....in real time

hypothetical situation..

user has full ip logging , has log viewer opened , using firefox ( or browser ) on computer. spots couple of ip addresses going out aren't there web site visits. has sort of disk monitor program running , shows quite unusual activity of reading disk. rather disconnecting decides wants monitor activity , has small window of opportunity( few seconds ) capture has can.

1....what commands run on terminal capture as can may in deciding if activity abnormal?

2....could put commands in script , have sort of 'hot switch' run commands @ click of mouse

3...are there programs out there run spot unusual activity.

i'm thinking along lines of looking @ open files, processes running, memory dumps, packet capture on port 80, etc. there may more hence question..


Forum The Ubuntu Forum Community Ubuntu Specialised Support Security [ubuntu] How To Analyse Suspicious Internet Activity


Ubuntu

Comments

Popular posts from this blog

Joomal 3.6.3 update error - PHP temporary folder is not set - Joomla! Forum - community, help and support

Upgrade 3.4.8 to 3.5.1 failed "download package failed" - Joomla! Forum - community, help and support

Fatal error during instalation - Joomla! Forum - community, help and support