<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://www.woodmann.com/collaborative/tools/skins/common/feed.css?97"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Collaborative RCE Tool Library - Network Monitoring Tools</title>
		<link>http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Network_Monitoring_Tools/feed?feed_type=rss</link>
		<description>Update Notification Feed for Category: Network Monitoring Tools</description>
		<language>en</language>
		<generator>MediaWiki 1.11.2 via dELTA feed generator</generator>
		<lastBuildDate>Fri, 03 Sep 2010 10:46:26 GMT</lastBuildDate>
		<item>
			<title>Tool Updated: Echo Mirage</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Echo_Mirage</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:API_Monitoring_Tools&quot;&gt;API Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.2&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;December 16, 2006&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Echo Mirage is a generic network proxy. It uses DLL injection and function hooking techniques to redirect network related function calls so that data transmitted and received by local applications can be observed and modified.&lt;br /&gt;&lt;br /&gt;Windows encryption and OpenSSL functions are also hooked so that plain text of data being sent and received over an encrypted session is also available.&lt;br /&gt;&lt;br /&gt;Traffic can be intercepted in real-time, or manipulated with regular expressions and action scripts.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Wed, 20 Jan 2010 14:16:26 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: Buster Sandbox Analyzer</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Buster_Sandbox_Analyzer</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_Monitoring_Tools&quot;&gt;File Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_System_Diff_Tools&quot;&gt;File System Diff Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Diff_Tools&quot;&gt;Registry Diff Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Monitoring_Tools&quot;&gt;Registry Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:X86_Sandboxes&quot;&gt;X86 Sandboxes&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.03&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;December 07, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Buster Sandbox Analyzer is a tool that has been designed to analyze the behaviour of sandboxed processes and the changes made to system and then evaluate if they are malware suspicious.&lt;br /&gt; &lt;br /&gt;The changes made to system can be of several types: file system changes, registry changes and port changes.&lt;br /&gt; &lt;br /&gt;A file system change happens when a file is created, deleted or modified. Depending of what type of file has been created (executable, library, javascript, batch, etc) and where was created (what folder) we will be able to get valuable information.&lt;br /&gt; &lt;br /&gt;Registry changes are those changes made to Windows registry. In this case we will be able to get valuable information from the modified value keys and the new created or deleted registry keys.&lt;br /&gt; &lt;br /&gt;Port changes are produced when a connection is done outside, to other computers, or a port is opened locally and this port starts listening for incoming connections.&lt;br /&gt; &lt;br /&gt;From all these changes we will obtain necessary information to evaluate the &amp;quot;risk&amp;quot; of some of the actions taken by sandboxed applications.&lt;br /&gt; &lt;br /&gt;Watching all these operations in an easy and safe manner is possible thanks to Sandboxie (http://sandboxie.com), an excellent tool created by Ronen Tzur.&lt;br /&gt; &lt;br /&gt;Even if Buster Sandbox Analyzer´s main goal is to consider if sandboxed processes have a malware behaviour, the tool can be used also to simply obtain a list of changes made to system, so if you install a software you will know exactly what installs and where.&lt;br /&gt;&lt;br /&gt;Additionally apart of system changes we can consider other actions as malware suspicious: keyboard logging, end the Windows session, load a driver, start a service, connect to Internet, etc.&lt;br /&gt; &lt;br /&gt;All the above operations can be considered as not malicious but if they are performed when it´s not expected, that´s something we must take in consideration. Therefore it´s not only important to consider what actions are performed. It´s also important to consider if it´s reasonable certain actions are performed.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Mon, 07 Dec 2009 01:55:12 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: Sandboxie</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Sandboxie</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_Monitoring_Tools&quot;&gt;File Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_System_Diff_Tools&quot;&gt;File System Diff Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Diff_Tools&quot;&gt;Registry Diff Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Monitoring_Tools&quot;&gt;Registry Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:X86_Sandboxes&quot;&gt;X86 Sandboxes&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;3.42&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;December 1, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer.&lt;br /&gt;&lt;br /&gt;You can also access all the changes that were made during the program execution.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Mon, 07 Dec 2009 01:54:02 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: TCPView</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/TCPView</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.54&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 17, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;TCPView is a Windows program that will show you detailed listings of all TCP and UDP endpoints on your system, including the local and remote addresses and state of TCP connections. On Windows Server 2008, Vista, NT, 2000 and XP TCPView also reports the name of the process that owns the endpoint. TCPView provides a more informative and conveniently presented subset of the Netstat program that ships with Windows. The TCPView download includes Tcpvcon, a command-line version with the same functionality.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 31 Mar 2009 23:07:42 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: Fport</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Fport</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2002&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;fport reports all open TCP/IP and UDP ports and maps them to the owning application. This is the same information you would see using the 'netstat -an' command, but it also maps those ports to running processes with the PID, process name and path. Fport can be used to quickly identify unknown open ports and their associated applications.&lt;br /&gt;&lt;br /&gt;Usage:&lt;br /&gt;&lt;br /&gt;C:\&amp;gt;fport&lt;br /&gt;FPort v2.0 - TCP/IP Process to Port Mapper&lt;br /&gt;Copyright 2000 by Foundstone, Inc.&lt;br /&gt;http://www.foundstone.com&lt;br /&gt;&lt;br /&gt;Pid Process Port Proto Path&lt;br /&gt;392 svchost -&amp;gt; 135 TCP C:\WINNT\system32\svchost.exe&lt;br /&gt;8 System -&amp;gt; 139 TCP&lt;br /&gt;8 System -&amp;gt; 445 TCP&lt;br /&gt;508 MSTask -&amp;gt; 1025 TCP C:\WINNT\system32\MSTask.exe&lt;br /&gt;392 svchost -&amp;gt; 135 UDP C:\WINNT\system32\svchost.exe&lt;br /&gt;8 System -&amp;gt; 137 UDP&lt;br /&gt;8 System -&amp;gt; 138 UDP&lt;br /&gt;8 System -&amp;gt; 445 UDP&lt;br /&gt;224 lsass -&amp;gt; 500 UDP C:\WINNT\system32\lsass.exe&lt;br /&gt;212 services -&amp;gt; 1026 UDP C:\WINNT\system32\services.exe&lt;br /&gt;&lt;br /&gt;The program contains five (5) switches. The switches may be utilized using either a '/'&lt;br /&gt;or a '-' preceding the switch. The switches are;&lt;br /&gt;&lt;br /&gt;Usage:&lt;br /&gt;/? usage help&lt;br /&gt;/p sort by port&lt;br /&gt;/a sort by application&lt;br /&gt;/i sort by pid&lt;br /&gt;/ap sort by application path&lt;br /&gt;&lt;br /&gt;fport supports Windows NT4, Windows 2000 and Windows XP&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 17 Jun 2008 12:20:56 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: LSOF</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/LSOF</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_Monitoring_Tools&quot;&gt;File Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;The lsof (LiSt Open Files) diagnostic and forensics tool lists information about any files that are open by processes currently running on the system. It can also list communications sockets open by each process.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 17 Jun 2008 10:39:49 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: SysAnalyzer</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/SysAnalyzer</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:API_Monitoring_Tools&quot;&gt;API Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Disk_Monitoring_Tools&quot;&gt;Disk Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_Monitoring_Tools&quot;&gt;File Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Install_Monitoring_Tools&quot;&gt;Install Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Dumpers&quot;&gt;Memory Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Monitoring_Tools&quot;&gt;Registry Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;January 19, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;SysAnalyzer is an automated malcode run time analysis application that monitors various aspects of system and process states. SysAnalyzer was designed to enable analysts to quickly build a comprehensive report as to the actions a binary takes on a system. SysAnalyzer can automatically monitor and compare:&lt;br /&gt;&lt;br /&gt;    * Running Processes&lt;br /&gt;    * Open Ports&lt;br /&gt;    * Loaded Drivers&lt;br /&gt;    * Injected Libraries&lt;br /&gt;    * Key Registry Changes&lt;br /&gt;    * APIs called by a target process&lt;br /&gt;    * File Modifications&lt;br /&gt;    * HTTP, IRC, and DNS traffic &lt;br /&gt;&lt;br /&gt;SysAnalyzer also comes with a ProcessAnalyzer tool which can perform the following tasks:&lt;br /&gt;&lt;br /&gt;    * Create a memory dump of target process&lt;br /&gt;    * parse memory dump for strings&lt;br /&gt;    * parse strings output for exe, reg, and url references&lt;br /&gt;    * scan memory dump for known exploit signatures&lt;br /&gt;&lt;br /&gt;Full GPL source for SysAnalyzer is included in the installation package.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sat, 05 Jan 2008 13:56:31 GMT</pubDate>								</item>
	</channel>
</rss>