Ethical Hacking Training at InfoSec Institute

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Computer Forensics Computer-Forensics
[Top] [All Lists]

Re: Nigilant32 - Free Windows Incident Response Tool based on Sleuthkit

Subject: Re: Nigilant32 - Free Windows Incident Response Tool based on Sleuthkit - Final Article Released
Date: Wed, 12 Jul 2006 16:46:19 -0400
Hello list,

Are there any other products out on the market with similar
functionality, specifically "capture as much information as possible
from a running system with the smallest potential impact"? Anything
else open-source with available code?

Thanks!

On 7 Jul 2006 14:59:03 -0000, mshannon@agilerm.net <mshannon@agilerm.net> wrote:
To all-


Agile Risk Management is committed to advancing information security concepts, technology, and techniques. As such, we have recently released Nigilant32, a freeware Windows GUI Incident Response tool based on the source code provided by Sleuthkit.


Nigilant32 is an incident response tool designed to capture as much information as possible from a running system with the smallest potential impact. Nigilant32 has been developed with Windows 2000, XP, and 2003 in mind, and should work fine with computers running one of those operating systems. Nigilant32 is beta software and may not work in all instances.


The third article in our series of "Nigilant32 For First Responders" articles is "Active Memory Imaging". This article covers using Nigilant32 to image the active physical memory (RAM) of the suspect workstation or server to secure portable media. Make sure you download the article, as the last pages contain a sneak preview of the current project being developed in the Agile Research Lab.


We sincerely hope you find Nigilant32 useful, however please remember, it is beta software therefore you should exercise good judgment when using it in your IT environment.


Nigilant32, articles (as they are released), and modified Sleuthkit source code (libsleuthkit) is available at http://www.agilerm.net/publications_4.html


Warmest Regards,


Matthew M Shannon, CIFI, CISSP

Principal - Computer Forensics and Litigation Support

Agile Risk Management LLC

2202 N Westshore Blvd, Suite 200

Tampa, FL 33607

(M) 813.732.5076

(O) 1.877.AGILE13 (877.244.5313)

www.agileriskmanagement.com



<Prev in Thread] Current Thread [Next in Thread>