SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis paper describes how one can use open source tools to create an incident response toolkit. A significant piece of your toolkit is a Security Information and Event Manager (SIEM), or the ability to store and process event logs. Two reasons you may want to create your own toolkit and SIEM are: financial and the ability to customize. In addition to outlining what software tools you should have in your kit and how to create them, I will explain how to prioritize your efforts in creating the toolkit. This paper could easily be used to guide in the selection of a commercial SIEM.