Chapter 13 Cybersecurity Toolkit Flashcards
- Set of security mitigation capabilities bundled together to help prevent malware from exploiting vulnerabilities and other attacks
- Includes: Data execution prevention (DEP) and Address space layout randomization (ASLR)
Enhanced Mitigation Experience Toolkit (EMET)
Feature to prevent the execution of malware loaded into data space in memory
Data execution prevention (DEP)
Helps prevent buffer overflows attacks and others that rely on specific acknowledge of memory locations
Address Space Layout Randomization (ASLR)
Name the tools in the Windows Sysinternals Suite
- AccessEnum
- AutoRuns
- Process Explorer
- PsTools
- SDelete
- ShareEnum
- Sysmon
- ProcDump
- TCPView
- Enumerates the access on a system
- Provides a good view of who has permissions to files, directories, and other objects
- Part of Windows Sysinternals Suite
AccessEnum
- A utility that shows what programs start at login or system boot
- Part of Windows Sysinternals Suite
AutoRuns
- Tool that shows the files, DLLs, registry keys and other objects in use by each process
- Part of Windows Sysinternals Suite
Process Explorer
- Set of command line utilities with a broad range of functions, including process information and start/stop capabilities, event log dumping, password changes, and many others
- Part of Windows Sysinternals Suite
PsTools
- Secure file deletion utility
- Part of Windows Sysinternals Suite
SDelete
- Tool that analyzes shares and their permissions
- Part of Windows Sysinternals Suite
ShareEnum
- Often used for intrusion detection and forensic analysis for its ability to monitor processes and their activity in a searchable and easily viewable manner
- Part of Windows Sysinternals Suite
Sysmon
- Provides process dumping for memory and error analysis
- Part of Windows Sysinternals Suite
ProcDump
- Tool for stock at level visibility for analyzing network connected services
- Part of Windows Sysinternals Suite
TCPView
Standard for logging and is designed to allow logs to be created for an endpoint server, system, or device, and then be stored locally or sent to essential server or storage system
Syslog
SIEM tool designed to provide large-scale data collection and analysis capabilities for broad range of data types
Splunk
Provides SIEM functionality as well as asset discovery, vulnerability scanning and assessment, behavior (heuristic) analysis capabilities, and IDS capabilities
AlienVault’s Universal Security Manager (USM)
An open source SIEM that integrates a number of Open Source tools to provide security information and event capabilities
AlienVault offers OSSIM
A network graphing tool that runs on top of RRDtool (a data logging and graphing system) to allow recurring, time-based data collection and analysis
Cacti
A network monitoring tool that leverages SNMP to monitor traffic on network connections
Multi Router Traffic Grapher (MRTG)