?
Solved

Using HBSS 4.5 as a local monitoring tool

Posted on 2012-03-13
4
Medium Priority
?
1,697 Views
Last Modified: 2013-12-09
I've been asked to configure HIPS to monitor tasks/events on a local machine. This request comes of a possible security violation and we want to monitor everything this user is doing for a while..  I've set HIPS to Log All but it's only giving me info that woulb be considered an intrusion.. I've even set Application Blocking to Learn mode, in hope it would log more..  I need to capture everything this user is doing.. Basically I need HIPS to log the Task manager..  Is there a way to get HIPS or any module in HBSS to log all event/Tasks that are bing executed?

I personally think HBSS may not be the tool they need in accomplishing this issue but I needed to ask around before makeing the argument..
0
Comment
Question by:hotrobb
  • 2
  • 2
4 Comments
 
LVL 16

Accepted Solution

by:
legalsrl earned 2000 total points
ID: 37714855
Hiya,
HIPS won't do it as it's designed to block intrusions, not monitor the user.
Basically what you are doing is trying to spy on the user.Have you connected the machines event viewer remotely ?
Thanks
Simon
0
 

Author Comment

by:hotrobb
ID: 37714914
Yeah I agree, I had to make sure I wasn't missing something..  I have to ask when you say connecting to the machines "Event Viewer Remotely", in what context were you speaking of?  I'm not sure of a way to conect to it remptly with out and RDP session or somthing similar that would alert the user of the monitoring..
0
 
LVL 16

Expert Comment

by:legalsrl
ID: 37714950
Hiya
If you open Event Viewer and choose Action, Connect to another computer, you can then download the event logs
Cheers
Si
0
 

Author Comment

by:hotrobb
ID: 37715072
Right, I remeber now.. Thanks for the info..
0

Featured Post

The new generation of project management tools

With monday.com’s project management tool, you can see what everyone on your team is working in a single glance. Its intuitive dashboards are customizable, so you can create systems that work for you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Spectre and Meltdown, how it affects me and my clients?
This blog will spread awareness about Dropbox. We have given the statements based upon our experience. Along with this, there is a section of some new plans that should be added in Dropbox this year. This will make the storage service enhanced from …
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question