Sebek2 - A Kernel-based Data Capture Tool
LogError writes "Sebek is a piece of code the lives entirely in kernel space and records either some or all data accessed by users on the system. This paper is a detailed discussion of Sebek, how it works and its value."
I'm sure the speed of a kernel-level logger will be amazing. I bet WinXP comes with one already running and recording everything.
Actually, doesn't Windows come with some pretty fancy-schmancy documented (and undocumented) kernel-level logging APIs?
Or is this *nix? I should RTFA.
Wer mit Ungeheuern kämpft, mag zusehn, dass er nicht dabei zum Ungeheuer wird. --Nietzsche
After all, with the Gen2 honeynets out there, this is the tool of choice.
This tool has been out at honeynet.org for months now.I've been using it for at least 2 months.
THIS IS NOT NEWS,