Enhanced Mitigation Experience Toolkit (EMET)
Feature to prevent the execution of malware loaded into data space in memory
Data execution prevention (DEP)
Helps prevent buffer overflows attacks and others that rely on specific acknowledge of memory locations
Address Space Layout Randomization (ASLR)
Name the tools in the Windows Sysinternals Suite
AccessEnum
AutoRuns
Process Explorer
PsTools
- Part of Windows Sysinternals Suite
SDelete
- Part of Windows Sysinternals Suite
ShareEnum
Sysmon
- Part of Windows Sysinternals Suite
ProcDump
TCPView
Standard for logging and is designed to allow logs to be created for an endpoint server, system, or device, and then be stored locally or sent to essential server or storage system
Syslog
SIEM tool designed to provide large-scale data collection and analysis capabilities for broad range of data types
Splunk
Provides SIEM functionality as well as asset discovery, vulnerability scanning and assessment, behavior (heuristic) analysis capabilities, and IDS capabilities
AlienVault’s Universal Security Manager (USM)
An open source SIEM that integrates a number of Open Source tools to provide security information and event capabilities
AlienVault offers OSSIM
A network graphing tool that runs on top of RRDtool (a data logging and graphing system) to allow recurring, time-based data collection and analysis
Cacti
A network monitoring tool that leverages SNMP to monitor traffic on network connections
Multi Router Traffic Grapher (MRTG)
Well-known and widely respected network vulnerability scanning product
Tenable Nessus
A vulnerability scanner that uses Software-as-a-Service (SaaS) management console to run scans using appliances located both in on premise datacenters and in the cloud
Qualys’s QualysGuard
Another commercial vulnerability scanner that offers similar capabilities to Nessus and QualysGuard
Rapid7’s Nexpose
An open source vulnerability scanner
open source OpenVAS
Web application scanners