Some Tools For Computer Security Incident Response Team (Csirt)
Some Tools For Computer Security Incident Response Team (Csirt)
AfNOG 12
30th May 2011 – 10th June 2011
Tanzania
By
Marcus K. G. Adomey
Overview
Some Unix Commands
Some Selected Tools
Snort
AirSnort
hping
Nmap
Kismet
Tcpreplay
Aircrak
Tripwire
Argus
Tor
Nepenthes
Nessus
Wireshark
LanSpy
Rational for using tools in CSIRT Management
Network analysis
Log analysis
Incident, Vulnerability or Malware Handling
Investigation or research
While useful for detecting intrusions after the event, it can also
serve many other purposes, such as integrity assurance, change
management, and policy compliance.
Argus
Argus – (Audit Record Generation and Utilization System) is a fixed-
model real-time flow monitor designed to track and report on the
status and performance of all network transactions seen in a data
network traffic stream, doing that by that categorizing IP packets
which match the Boolean expression into a protocol-specific
network transaction model.