<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://www.woodmann.com/collaborative/tools/skins/common/feed.css?97"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Collaborative RCE Tool Library - Network Monitoring Tools</title>
		<link>http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Network_Monitoring_Tools/feed?feed_type=rss</link>
		<description>Update Notification Feed for Category: Network Monitoring Tools</description>
		<language>en</language>
		<generator>MediaWiki 1.11.2 via dELTA feed generator</generator>
		<lastBuildDate>Sat, 21 Nov 2009 21:28:47 GMT</lastBuildDate>
		<item>
			<title>Tool Updated: TCPView</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/TCPView</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.54&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;March 17, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;TCPView is a Windows program that will show you detailed listings of all TCP and UDP endpoints on your system, including the local and remote addresses and state of TCP connections. On Windows Server 2008, Vista, NT, 2000 and XP TCPView also reports the name of the process that owns the endpoint. TCPView provides a more informative and conveniently presented subset of the Netstat program that ships with Windows. The TCPView download includes Tcpvcon, a command-line version with the same functionality.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 31 Mar 2009 23:07:42 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: Fport</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/Fport</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.0&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2002&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;fport reports all open TCP/IP and UDP ports and maps them to the owning application. This is the same information you would see using the 'netstat -an' command, but it also maps those ports to running processes with the PID, process name and path. Fport can be used to quickly identify unknown open ports and their associated applications.&lt;br /&gt;&lt;br /&gt;Usage:&lt;br /&gt;&lt;br /&gt;C:\&amp;gt;fport&lt;br /&gt;FPort v2.0 - TCP/IP Process to Port Mapper&lt;br /&gt;Copyright 2000 by Foundstone, Inc.&lt;br /&gt;http://www.foundstone.com&lt;br /&gt;&lt;br /&gt;Pid Process Port Proto Path&lt;br /&gt;392 svchost -&amp;gt; 135 TCP C:\WINNT\system32\svchost.exe&lt;br /&gt;8 System -&amp;gt; 139 TCP&lt;br /&gt;8 System -&amp;gt; 445 TCP&lt;br /&gt;508 MSTask -&amp;gt; 1025 TCP C:\WINNT\system32\MSTask.exe&lt;br /&gt;392 svchost -&amp;gt; 135 UDP C:\WINNT\system32\svchost.exe&lt;br /&gt;8 System -&amp;gt; 137 UDP&lt;br /&gt;8 System -&amp;gt; 138 UDP&lt;br /&gt;8 System -&amp;gt; 445 UDP&lt;br /&gt;224 lsass -&amp;gt; 500 UDP C:\WINNT\system32\lsass.exe&lt;br /&gt;212 services -&amp;gt; 1026 UDP C:\WINNT\system32\services.exe&lt;br /&gt;&lt;br /&gt;The program contains five (5) switches. The switches may be utilized using either a '/'&lt;br /&gt;or a '-' preceding the switch. The switches are;&lt;br /&gt;&lt;br /&gt;Usage:&lt;br /&gt;/? usage help&lt;br /&gt;/p sort by port&lt;br /&gt;/a sort by application&lt;br /&gt;/i sort by pid&lt;br /&gt;/ap sort by application path&lt;br /&gt;&lt;br /&gt;fport supports Windows NT4, Windows 2000 and Windows XP&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 17 Jun 2008 12:20:56 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: LSOF</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/LSOF</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_Monitoring_Tools&quot;&gt;File Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;The lsof (LiSt Open Files) diagnostic and forensics tool lists information about any files that are open by processes currently running on the system. It can also list communications sockets open by each process.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 17 Jun 2008 10:39:49 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: SysAnalyzer</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/SysAnalyzer</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:API_Monitoring_Tools&quot;&gt;API Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Disk_Monitoring_Tools&quot;&gt;Disk Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:File_Monitoring_Tools&quot;&gt;File Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Install_Monitoring_Tools&quot;&gt;Install Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Dumpers&quot;&gt;Memory Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Network_Monitoring_Tools&quot;&gt;Network Monitoring Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Registry_Monitoring_Tools&quot;&gt;Registry Monitoring Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;January 19, 2007&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;SysAnalyzer is an automated malcode run time analysis application that monitors various aspects of system and process states. SysAnalyzer was designed to enable analysts to quickly build a comprehensive report as to the actions a binary takes on a system. SysAnalyzer can automatically monitor and compare:&lt;br /&gt;&lt;br /&gt;    * Running Processes&lt;br /&gt;    * Open Ports&lt;br /&gt;    * Loaded Drivers&lt;br /&gt;    * Injected Libraries&lt;br /&gt;    * Key Registry Changes&lt;br /&gt;    * APIs called by a target process&lt;br /&gt;    * File Modifications&lt;br /&gt;    * HTTP, IRC, and DNS traffic &lt;br /&gt;&lt;br /&gt;SysAnalyzer also comes with a ProcessAnalyzer tool which can perform the following tasks:&lt;br /&gt;&lt;br /&gt;    * Create a memory dump of target process&lt;br /&gt;    * parse memory dump for strings&lt;br /&gt;    * parse strings output for exe, reg, and url references&lt;br /&gt;    * scan memory dump for known exploit signatures&lt;br /&gt;&lt;br /&gt;Full GPL source for SysAnalyzer is included in the installation package.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sat, 05 Jan 2008 13:56:31 GMT</pubDate>								</item>
	</channel>
</rss>