Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Management
[Top] [All Lists]

Re: Security Event format standards?

Subject: Re: Security Event format standards?
Date: Fri, 07 Jan 2005 14:51:00 -0700
Many people have tried to build a schema for security event formatting, but each security vendor has usually used syslog format for their security event data or used some format that made sense to the engineers who coded the product and no one else. Depending on the security product, detailed security events may have not been on their customer feature list for that particular release of the product. :(

At 06:01 PM 1/3/2005, Bill Stout wrote:

Are there standard formats for reporting desktop security events?

Is there a standard format, and a standard event number for events (such as; attach to process, alter users run key), similar to CAN or CVE numbers for vulnerabilities?

Thanks,

Bill Stout

This electronic transmission (and any attached documents) is for the sole use of the individual or entity to whom it is addressed. It is confidential and may be privileged. Any further distribution or copying of this message is strictly prohibited. If you received this message in error, please notify GreenBorder immediately by telephone at (650) 625.0601 and destroy the message (and all attached documents), immediately.

<Prev in Thread] Current Thread [Next in Thread>