[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <152533.1342446044@turing-police.cc.vt.edu>
Date: Mon, 16 Jul 2012 09:40:44 -0400
From: valdis.kletnieks@...edu
To: "Ali Varshovi " <ali.varshovi@...mail.com>
Cc: "full-disclosure@...ts.grok.org.uk " <full-disclosure@...ts.grok.org.uk>
Subject: Re: Linux - Indicators of compromise
On Sat, 14 Jul 2012 12:46:50 -0000, "Ali Varshovi " said:
> Most of the materials I've seen are more aligned to malware and rootkit
> detection which is not the only concern apparently.
It's hard to say what else to check without knowing what other concerns
you're checking for, and what data sources are available (I'm thinking about
auditd and friends, but there's other data sources as well).
Content of type "application/pgp-signature" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists