Jump to content
io.kent

Patriot NG (HIDS)

Recommended Posts

Posted

Patriot NG

panel.JPG

Patriot is a 'Host IDS' tool which allows real time monitoring of changes in Windows systems or Network attacks.

Patriot monitors:

•Changes in Registry keys: Indicating whether any sensitive key (autorun, internet explorer settings...) is altered.

•New files in 'Startup' directories

•New Users in the System

•New Services installed

•Changes in the hosts file

•New scheduled jobs

•Alteration of the integrity of Internet Explorer: (New BHOs, configuration changes, new toolbars)

•Changes in ARP table (Prevention of MITM attacks)

•Installation of new Drivers

•New Netbios shares

•TCP/IP Defense (New open ports, new connections made by processes, PortScan detection...)

•Files in critical directories (New executables, new DLLs...)

•New hidden windows (cmd.exe / Internet Explorer using OLE objects)

•Netbios connections to the System

•ARP Watch (New hosts in your network)

•NIDS (Detect anomalous network traffic based on editable rules)

alerta.jpg

Important: You need WinPcap · Download to run Patriot NG[*] Install it first

Windows XP, Windows Vista, Windows 7 (32Bits) ---> http://sbdtools.googlecode.com/files/PatriotNG2.01.zip

Windows XP, Windows Vista, Windows 7 (64Bits) ---> http://sbdtools.googlecode.com/files/PatriotNG2.0164.zip

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...