INDIAN

http://groups.google.com/group/nforceit/about

Saturday, 2 April 2011

How to Identify Your System Is Infected (or) any Intruder Entering into Your System

How do i know that my system is infected or How do i know that an attacker is entered into my system,this is the thing that always baffle us..Here, I will give u some tips where u can find an intruder if he is entering into u r system ,these are the basic details you need to perform, even there are more steps in security forensics but for your information i will give some tips which u might know or may not.

1)Go for the Taskmanager check the process ,services & applications that are running in your system

2)Go for wmic process in cmd type "wmic" and then type process ,Here you will find all the details of the services that are running in you system

3)Go FOr Logs type in run box eventvwr ,Here You find all logs what ever u have done in your system & if any intruder attemted to entered in your system his log also created here but u need to do some studies on this

4)For Malicious Software to identify in u r system go for process explorer tool

5) netstat command just type in cmd,it will give statistics of your Network 

0 comments:

Post a Comment