How to construct a Baseline? Hi,
I am wondering how what you folks use to construct a baseline so as to detect if you've been hacked. I am currently using HijackThis to save a hijack log and a startup list. And am also using MsInfo to export a pc configuration txt file. I am thinking of using SysInternal's RootkitRevealer to save a log too. Is this any good?
I'm assuming that any keylogger and hacker's monitoring tools needs to start up when I login somehow and that is covered by HijackThis's monitoring of startup points in the system. If the hacking tool is a driver, then a diff with MsInfo logs will catch those. And Rootkits will show up on RootKitRevealer.
Does this combination capture enough info to form a baseline ? What do you guys use?
Last edited by lunarlander : 22-Jun-2008 12:11 PM.
|