[Question] File monitor?

Problems? Post here...
Post Reply
User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

[Question] File monitor?

Post by ayu »

Ok so i know there are programs to make a list of all the files in your computer and then compare it to another list to see what stuff that has been added to the next time. There are also other programs to monitor the activities in the computer, i believe Mab made something like that not so long ago.


No i am wondering, is there a program like this where i can specify ONE special file? For example a file that i think is malicious, but no AV detects it.....i want to see what that file adds to the system.

Does anyone know of such a program?

User avatar
maboroshi
Dr. Mab
Dr. Mab
Posts: 1624
Joined: 28 Aug 2005, 16:00
18

hmm

Post by maboroshi »

I have not seen such a program but my app uses the win api to read a folder probably something in the api to monitor one file

Else you could build it ;)

Do your homework Im sure you will find something :D

User avatar
Swan
Knight of the Sword
Knight of the Sword
Posts: 827
Joined: 18 Oct 2006, 16:00
17
Contact:

Post by Swan »

sent via MSN *removed.
Last edited by Swan on 24 Jan 2008, 17:39, edited 1 time in total.

User avatar
Big-E
Administrator
Administrator
Posts: 1332
Joined: 16 May 2007, 16:00
16
Location: IN UR ____ , ____ING UR _____ .
Contact:

Post by Big-E »

Yuck, I hope that the tag messed up your formatting or me and you need to sit down and have a talk on creating neat code. ;)

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

hm, on Linux systems you can use Tripwire, it's used on servers to detect file changes helping to notice if a system was compromised. the usage is pretty easy, but the initial setup is a little pain in the rear because you have to edit/add the paths in the config files.
http://www.tripwire.com/products/enterprise/ost/


:wink:

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

sounds nice =o

Doesn't sound doable here though, seeing that it would be an exe file that i want to monitor...i mean...a virus in Linux? THAT'S UNHEARD OF! ^^

User avatar
computathug
Administrator
Administrator
Posts: 2693
Joined: 29 Mar 2007, 16:00
17
Location: UK
Contact:

Post by computathug »

You could try this, it enables you to select the folders you want to monitor.
Hope this what you looking for :wink:

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

hmm well it's a very good program....but the thing is that i would have to specify a range of folders to check there....so if the file adds something that is NOT in that folder...then i will not know of it =/
"The best place to hide a tree, is in a forest"

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

hm, you could still use Tripwire to hash the files and compare the hashes then....of course you would need a dual OS system, but I have to admit I am not 100% sure if it works for NTFS file systems... :-k

Post Reply