Slashdot stories can be listened to in audio form via an RSS feed, as read by our own robotic overlord.

 



Forgot your password?
typodupeerror
Security

+ - How can you safely confirm breach without details?

Submitted by crawdaddy
crawdaddy (344241) writes "A friend suspects some of his employees (that access the network using remote desktop connections over a VPN) may be up to no good, due to certain suspicious activities. The business has an Active Directory domain setup on a Windows Server box, as well as several desktops. What are some things I can look for that might indicate whether or not further investigation (ie. professional forensic analysis) is warranted? What tools are recommended for accomplishing those tasks without compromising the courtroom validity of the data? Would it be better/safer, in terms of preserving the data, to install stealth monitoring software to track the users' movements and simply analyze that, instead?"
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

How can you safely confirm breach without details?

Comments Filter:

Give a man a fish, and you feed him for a day. Teach a man to fish, and he'll invite himself over for dinner. - Calvin Keegan

Working...