90 likes | 315 Views
Covering Tracks. Once intruders have successfully gained access and admin or system rights, (in order to maintain access) they will attempt to avoid further detection. Disabling Auditing. Resource kit auditpol Auditpol /disable. Clearing The Event Log. Elsave utility
E N D
Covering Tracks Once intruders have successfully gained access and admin or system rights, (in order to maintain access) they will attempt to avoid further detection.
Disabling Auditing • Resource kit auditpol Auditpol /disable
Clearing The Event Log • Elsave utility • www.ibt.ku.dk/jesper/window-stools
Hiding Files • Attrib +h • Alternate data streams POSIX utility from resource kit Example: cp filename oso001.009 filename cp oso001.009.filename filename
Countermeasures • Rootkits sfind from www.foundstone.com • Security updates (SUS services) • MBSA • Group Policies • Security Wizard • IPSEC • RUNAS • EFS & Windows Firewall • Memory Protection DEP