Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Incidents
[Top] [All Lists]

Re: CERT Software

Subject: Re: CERT Software
Date: Wed, 17 Nov 2004 07:37:22 +0100
Hello,

In the wise words of Brian Peister, on Tuesday 16 November 2004 21:27:
Does anyone know of or has used CERT (Computer Emergency Response Team)
software? I reviewed Guidance software's Encase Enterprise product,  and
it's mostly focused on the forensics aspect of indecent handling. I'm
looking for a software product that stream-lines the Computer security
incident handling process (Similar to SANS 6 phases of incident handling)
I guess you'll hear a few words about Remedy (http://www.remedy.com/) or RT/IR 
(http://www.bestpractical.com/rtir/). They are not specifically mapped on the 
SANS 6 phases, but they do the job. At BELNET CERT we use RT/IR, which has 
the advantage (for us) of being open-source, and thus allows us to tune it 
where needed.

The handling process is the following:
Incident Report(s) -> Incident -> Investigation(s) -> Firewall-level blocks 
(if needed)
Don't misunderstand the 'firewall-level blocks' part: RT/IR does not interface 
with your firewall, but allows you to keep track of what is blocked at what 
level, and why (thanks to the links to the incidents).

Best regards,

Lionel

-- 
"They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety." -- Benjamin Franklin

Lionel Ferette
BELNET CERT Coordinator

Tel: +32 2 7903385                  http://cert.belnet.be/
Fax: +33 2 7903375                  PGP Key Id: 0x5662FD4B

Attachment: pgpZzO6HOoDqu.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>