| question | réponse | 
        
        | commencer à apprendre |  |  |  |  | 
| commencer à apprendre |  |  |  |  | 
| commencer à apprendre |  |  |  |  | 
|  commencer à apprendre Netstat all executable files running running processes  |  |  |  |  | 
|  commencer à apprendre basic info about processes  |  |  |  |  | 
| commencer à apprendre |  |  |  |  | 
|  commencer à apprendre chcek service for any malicious programm installed  |  |  |  |  | 
| commencer à apprendre |  |   net sessions; logonsessions  |  |  | 
| commencer à apprendre |  |  |  |  | 
| commencer à apprendre |  |  |  |  | 
|  commencer à apprendre netstat TCP and UDP including ports  |  |  |  |  | 
| commencer à apprendre |  |  |  |  | 
| commencer à apprendre |  |   icmp. type==8; icmp. type==0; tcp. dstport==7; udp. dstport==7  |  |  | 
| commencer à apprendre |  |  |  |  | 
| commencer à apprendre |  |  |  |  | 
| commencer à apprendre |  |  |  |  | 
| commencer à apprendre |  |   C\users\user_name\AppData\local\Mozilla\Firefox\Profiles\XXXdefault\cache: cookies. sqllite, fomhistory. sqllite  |  |  | 
| commencer à apprendre |  |   C\users\user_name\AppData\local\google\chrome\user data\default\cache: Profile 1(cookies): Default(history)  |  |  | 
| commencer à apprendre |  |   C\users\Admin\AppData\local\microsoft\windows\INetCache:\AC\MsEdge(cookies): History  |  |  | 
| commencer à apprendre |  |   c: programfiles\MSsqlServer\MSsql12...\MSSQL\LOG\EROR LOG: log_n. trc (open with notepad)  |  |  | 
|  commencer à apprendre function that allows retrival of the active portion of the transaction log file  |  |  |  |  | 
| commencer à apprendre |  |   SENDMAIL - log - /var/log/maillog - most linux. /var/adm/maillog Solaris. /var/log/mail. log Debian/Ubuntu  |  |  | 
|  commencer à apprendre Microsoft Exchange Email Server Log  |  |   Microsoft Exchange Email Server Log -. edb database files,. stm, checkpoint files, temp files  |  |  | 
| commencer à apprendre |  |   access locate times - dir command, ls command  |  |  | 
|  commencer à apprendre Collecting volatile info: open files  |  |   Collecting volatile info: open files - "net file", psFile utility, OpenFiles command  |  |  | 
|  commencer à apprendre Collecting volatile info: clopboard  |  |   Collecting volatile info: clopboard - Free Clopboard Viewer  |  |  | 
|  commencer à apprendre Collecting volatile info: Service/Driver info  |  |   Collecting volatile info: Service/Driver info - tasklist, wmic  |  |  | 
|  commencer à apprendre Collecting volatile info: logged on users  |  |   Collecting volatile info: logged on users - PsLoggedOn, netsessions, LogonSessions  |  |  | 
|  commencer à apprendre Logged on users PsLoggedOn  |  |   Logged on users PsLoggedOn - "-l"-only local logons, "-x"-doesnt display times  |  |  | 
|  commencer à apprendre Logged on users LogonSessions  |  |   Logged on users LogonSessions: "-c"-CSV, "-ct"-prints as tab, "-p"-processes list  |  |  | 
|  commencer à apprendre Collecting volatile info: DLL and shared libraries  |  |   Collecting volatile info: DLL and shared libraries: ListDLL(win) "-r"-relocated "-u"-unsigned DLL, "-r"-DLL version. Ldd/ls(linux)  |  |  | 
| commencer à apprendre |  |   Nbstat: "-c"-NetBIOS name-to-IP mapping, "-n"-names registered locally, "-r"-names resolved by broadcast and querying, "-s"-current NetBIOS sessions and statuses  |  |  | 
|  commencer à apprendre netstat listening connections  |  |  |  |  | 
|  commencer à apprendre netstat ethernet statistics - number of bytes, packets  |  |  |  |  | 
|  commencer à apprendre |  |   Malware is the most common threat  |  |  | 
|  commencer à apprendre port monitoring command and tool  |  |   port monitoring command and tool - netstat, TCPView  |  |  | 
| commencer à apprendre |  |   registry monitoring tool - jv16 Power tools 2017  |  |  | 
|  commencer à apprendre windows service monitoring  |  |   windows service monitoring - windows server manager (SrvMan)  |  |  | 
|  commencer à apprendre startup programs monitoring  |  |   startup programs monitoring - Autoruns for Windows  |  |  | 
|  commencer à apprendre Perform string search tool  |  |   Perform string search tool - BinText  |  |  | 
|  commencer à apprendre identyfing packing/obfuscation methotds tool  |  |   identifying packing/obfuscation methotds tool - PEiD  |  |  | 
|  commencer à apprendre intrusion analysis: covert communication tools:  |  |   intrusion analysis: covert communication tools: SSDT View, ReKall, RougeKiller  |  |  | 
|  commencer à apprendre Detect packet sniffing: MAC flooding  |  |   Detect packet sniffing: MAC flooding - from various IP to single with same TTL (malformed packets)  |  |  | 
|  commencer à apprendre Detect packet sniffing: ARP poisoning  |  |   Detect packet sniffing: ARP poisoning - filter: arp. duplicate-address-detected, Xarp tool  |  |  | 
|  commencer à apprendre Machine generating ... will be most likely running a sniffer  |  |   Machine generating REVERSE DNS LOOKUP TRAFFIC will be most likely running a sniffer  |  |  | 
|  commencer à apprendre check if host has its network card in promiscuos mode  |  |   check if host has its network card in promiscuous mode - nmap -script = sniffer-detect [IP]  |  |  | 
|  commencer à apprendre Detects potentially malicious elements within HTML:  |  |   Detects potentially malicious elements within HTML: tags like <FK>, , <BR>, <DIV> and background-image, <script>, <object>, <applet>, <enabled> |  |  | 
| commencer à apprendre |  |   Apache web server logs: /var/log/'apache2/access. log - useful with Local File Injection LFI detection  |  |  | 
|  commencer à apprendre command line tool to locate connected devices  |  |   command line tool to locate connected devices: DevCon(windows)  |  |  | 
| commencer à apprendre |  |   Behavioral analysis: 1) extract behavioral patterns 2) compare to other users 3) generated clusters based on behav simmilarity 4) build profiles of each group 5) discover outliners of each group  |  |  |