Crafting the InfoSec Playbook by Jeff Bollinger Brandon Enright and Matthew Valites

Crafting the InfoSec Playbook by Jeff Bollinger Brandon Enright and Matthew Valites

Author:Jeff Bollinger, Brandon Enright, and Matthew Valites
Language: eng
Format: mobi, epub, pdf
Publisher: O'Reilly Media, Inc.
Published: 2015-05-20T16:00:00+00:00


2014-10-20 07:45:52 -0800|judy32-windows7|172.20.140.227| 2014-10-20 07:52:22.227|

The process 'C:\Program Files\RealVNC\VNC Server\vncserver.exe' (as user NT AUTHORITY\SYSTEM) attempted to accept a connection as a server on TCP port 5900 from 10.1.24.101 using interface Wired\Broadcom NetXtreme Gigabit Ethernet. The operation was allowed.

In this case, we can see the client 10.1.24.101 logged in to user judy32’s Windows 7 system using VNC (a common remote desktop sharing application). The HIPS indicated that the connection was allowed. There’s nothing here that demonstrates anything nefarious, if the VNC session was expected. If it was not expected, then it would reveal unauthorized access to judy32’s PC. If the login was authorized, and then some other malicious event occurred on the PC, we cannot say for certain whether it was judy32 or someone else causing the issue.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.