PaulDotCom mailing list archives

Re: Unix/Linux Incident Response resources


From: Christopher Croad <ccroad () syr edu>
Date: Wed, 16 Nov 2011 14:14:26 +0000

A good cheat sheet is at the link below.  Covers more than unix, but is very handy.


http://zeltser.com/network-os-security/security-incident-survey-cheat-sheet.pdf

Chris
--------------------------------------------------------------------------------
Christopher D. Croad, Director of Information Security
Information Technology and Services, Syracuse University

On Nov 15, 2011, at 8:25 PM, "Kevin Shaw" <kevin.lee.shaw () gmail com<mailto:kevin.lee.shaw () gmail com>> wrote:


In all seriousness SANS has a lot of things for this.

On Nov 15, 2011 8:09 PM, "Jon Schipp" <jonschipp () gmail com<mailto:jonschipp () gmail com>> wrote:
Hey guys,

Do you know of any good resources e.g. books, articles, cheat sheets on incident response for *nix machines.

Things I'm looking for e.g. uses of "find", "grep", "strings", and tools covering time stamp information etc.

Basically, going through your typical unix tools except with a IR perspective/focus. I figured something like this 
would help me pay more attention to things on my systems.

Thanks
Jon

_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com<mailto:Pauldotcom () mail pauldotcom com>
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com
_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com<mailto:Pauldotcom () mail pauldotcom com>
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com
_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

Current thread: