I published the following diary on isc.sans.org: “Detecting Undisclosed Vulnerabilities with Security Tools & Features“. I’m a big fan of OSSEC. This tools is an open source HIDS and log management tool. Although often considered as the “SIEM of the poor”, it integrates a lot of interesting features and is fully configurable
FIM or “File Integrity Monitoring” can be defined as the process of validating the integrity of operating system and applications files with a verification method using a hashing algorythm like MD5 or SHA1 and then comparing the current file state with a baseline. A hash will allow the detection of files content modification but
For the family usage, we have a laptop running Vista. Yesterday, the system suddenly requested to restart the OS without alternative. After the first reboot, I got the following screen: The laptop started an infinite loop of patch install, reboot, patch install, reboot, … I googled the message and found
623MB of patches? WTF!