Ethical Hacking Training at InfoSec Institute Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Nigilant32 - Free Windows Incident Response Tool based on Sleuthkit - Final Article Released |
|---|---|
| Date: | Wed, 12 Jul 2006 16:46:19 -0400 |
Hello list,
Are there any other products out on the market with similar functionality, specifically "capture as much information as possible from a running system with the smallest potential impact"? Anything else open-source with available code?
Thanks!
To all-
Agile Risk Management is committed to advancing information security concepts, technology, and techniques. As such, we have recently released Nigilant32, a freeware Windows GUI Incident Response tool based on the source code provided by Sleuthkit.
Nigilant32 is an incident response tool designed to capture as much information as possible from a running system with the smallest potential impact. Nigilant32 has been developed with Windows 2000, XP, and 2003 in mind, and should work fine with computers running one of those operating systems. Nigilant32 is beta software and may not work in all instances.
The third article in our series of "Nigilant32 For First Responders" articles is "Active Memory Imaging". This article covers using Nigilant32 to image the active physical memory (RAM) of the suspect workstation or server to secure portable media. Make sure you download the article, as the last pages contain a sneak preview of the current project being developed in the Agile Research Lab.
We sincerely hope you find Nigilant32 useful, however please remember, it is beta software therefore you should exercise good judgment when using it in your IT environment.
Nigilant32, articles (as they are released), and modified Sleuthkit source code (libsleuthkit) is available at http://www.agilerm.net/publications_4.html
Warmest Regards,
Matthew M Shannon, CIFI, CISSP
Principal - Computer Forensics and Litigation Support
Agile Risk Management LLC
2202 N Westshore Blvd, Suite 200
Tampa, FL 33607
(M) 813.732.5076
(O) 1.877.AGILE13 (877.244.5313)
www.agileriskmanagement.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Hardware needed for a complete drive acquisition tool kit and techniques for RAID acquisition, Robertson, Seth (JSC-IM) |
|---|---|
| Next by Date: | Tradeoff's in usage, shyaam |
| Previous by Thread: | Nigilant32 - Free Windows Incident Response Tool based on Sleuthkit - Final Article Released, mshannon |
| Next by Thread: | Re: RE: IE temporary files of wbk###.tmp, kernow2001 |
| Indexes: | [Date] [Thread] [Top] [All Lists] |