Snare for Windows 2.6.4
Snare for Windows is a Windows NT, Windows 2, Windows XP, and Windows 2003 compatible service designed to interact with the underlying Windows Eventlog subsystem to facilitate remote, real-time transfer of event log information.
|
Snare for Windows is a Windows NT, Windows 2, Windows XP, and Windows 2003 compatible service designed to interact with the underlying Windows Eventlog subsystem to facilitate remote, real-time transfer of event log information.
Snare is a program that facilitates the central collection and processing of
Windows NT/2/XP/2003 Event Log information. All three primary event logs(Application, System and Security) are monitored, and the secondary logs (DNS, Active Directory, and File Replication) are monitored if available. Event information is converted to tab delimited text format, then delivered over UDP to a remote server.
Snare is currently configured to deliver audit information to a SYSLOG server
running on a remote (or local) machine. A configuration utility allows you to set the appropriate syslog target and priority, as well as the target DNS or IP address of the server that should receive the event information. It should be noted that many syslog servers are not designed to cope with the sorts of volume of data that multiple snare agents can potentially generate.
The Snare service will automatically start after you have completed the initial
configuration process. It is recommended that you configure each of your event logs to 'overwrite as required', as opposed to 'overwrite > 7 days', which is the default on Windows 2 machines.
We also recommend that you configure appropriate access controls on the Snare registry entries using regedt32.exe - perhaps restricting the permission to read or modify the keys and values to Local or Domain Administrators only.
Snare stores it's registry settings in: HKEY_LOCAL_MACHINESOFTWAREInterSect AllianceAuditService
Please remember that event monitoring is a complex area in most modern operating systems, and is not often very granular. Turning on significant event monitoring for a system can often produce unpredictable results, and could seriously detract from the resources available to the rest of your system or network.
We recommend that you have a good understanding of exactly what event information is going to be used for, proir to enabling event monitoring on your servers.
tags
event monitoring that you event information you configure recommend that event log log information you have are monitored with the the snare event logs

Download Snare for Windows 2.6.4
Download Snare for Windows 2.6.4
Authors software
Snare for Windows 2.6.4
InterSect Alliance
Snare for Windows is a Windows NT, Windows 2, Windows XP, and Windows 2003 compatible service designed to interact with the underlying Windows Eventlog subsystem to facilitate remote, real-time transfer of event log information.
Snare BackLogr 1.2
InterSect Alliance
The Snare BackLog application is a program that provides a central collection facility for a variety of log sources, including Snare Agents for Windows, Solaris, AIX, Irix, ISA Server, IIS Server, Lotus Notes (and others), plus any device capable of sending data to a syslog server.
Similar software
Snare for Windows 2.6.4
InterSect Alliance
Snare for Windows is a Windows NT, Windows 2, Windows XP, and Windows 2003 compatible service designed to interact with the underlying Windows Eventlog subsystem to facilitate remote, real-time transfer of event log information.
Key Management Service 1.0
Microsoft
Microsoft Key Management Service for Windows Server 2003 is part of Microsoft Windows Volume Activation 2.
Microsoft Windows Server 003 Service Pack 2
Microsoft Corp
Install Microsoft Windows Server 2003 Service Pack to help secure your server and to better defend against hackers.
Microsoft Windows Software Development Kit Update for Windows Vista 6.0
Microsoft
The Microsoft Windows Software Development Kit (SDK) Update for Windows Vista provides documentation, samples, header files, libraries, and tools you need to develop applications that run on Windows.
Microsoft Windows Theme Nunavut 1.0
Microsoft
If you want to customize your Windows desktop now is more fun than ever with the Microsoft Windows Theme Nunavut.
Microsoft Windows Theme Ontario 1.0
Microsoft
If you want to customize your Windows desktop now is more fun than ever with the Microsoft Windows Theme Ontario.
February 2007 Security and Critical Releases ISO Image
Microsoft Corporation
This ISO-9660 CD image file contains the security updates for Windows released on Windows Update on February 13th, 2007.
Windows Automated Installation Kit (AIK) 1.0
Microsoft
Windows AIK (Windows Automated Installation Kit) will help you customize, install and deploy the Microsoft Windows Vista family of operating systems.
Autostreamer 1.0.33
Neowin
AutoPatcher's little brother, AutoStreamer, has gone final Although still unknown whether it will carry any neowin.
Microsoft ActiveSync 4.5 Build 5096 Final
Microsoft
ActiveSync, the latest sync software release for Windows Mobile-based devices, provides a great synchronization experience with Windows-based computers and Microsoft Outlook right out of the box.
Other software in this category
VisualICE Report Utility 4.7
Visualize Software
VisualICE Report Utility - so what do you do if you would like to know more about what the hacker tried to do, who he is, where he`s from or how to report him to the proper authorities?
That`s where VisualICE Report Utility comes in.
Gopher Smoker .06
PivX Sollutions, LLC
PivX Solutions, LLC released a program appropriately named `Gopher Smoker`.
Bouncer for Windows 1.0 RC6
Chris Mason
Bouncer is a network tool which allows you to bypass proxy restrictions and obtain outside connections from an internal LAN.
Slap 1.2.2.0
Security Software
If your like me you run firewall software that tells you when someone tries to access your system.
VisualZone Report Utility 5.7
Visualize Software
VisualZone Report Utility is a report utility and an intrusion analyser for ZoneAlarm and ZoneAlarm Pro.