Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: CERT Software |
|---|---|
| Date: | Wed, 17 Nov 2004 07:37:22 +0100 |
Hello, In the wise words of Brian Peister, on Tuesday 16 November 2004 21:27:
Does anyone know of or has used CERT (Computer Emergency Response Team) software? I reviewed Guidance software's Encase Enterprise product, and it's mostly focused on the forensics aspect of indecent handling. I'm looking for a software product that stream-lines the Computer security incident handling process (Similar to SANS 6 phases of incident handling)
I guess you'll hear a few words about Remedy (http://www.remedy.com/) or RT/IR (http://www.bestpractical.com/rtir/). They are not specifically mapped on the SANS 6 phases, but they do the job. At BELNET CERT we use RT/IR, which has the advantage (for us) of being open-source, and thus allows us to tune it where needed. The handling process is the following: Incident Report(s) -> Incident -> Investigation(s) -> Firewall-level blocks (if needed) Don't misunderstand the 'firewall-level blocks' part: RT/IR does not interface with your firewall, but allows you to keep track of what is blocked at what level, and why (thanks to the links to the incidents). Best regards, Lionel -- "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety." -- Benjamin Franklin Lionel Ferette BELNET CERT Coordinator Tel: +32 2 7903385 http://cert.belnet.be/ Fax: +33 2 7903375 PGP Key Id: 0x5662FD4B
pgpZzO6HOoDqu.pgp
Description: PGP signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | CERT Software, Brian Peister |
|---|---|
| Next by Date: | Re: CERT Software, John Kinsella |
| Previous by Thread: | CERT Software, Brian Peister |
| Next by Thread: | Re: CERT Software, John Kinsella |
| Indexes: | [Date] [Thread] [Top] [All Lists] |