Does anyone know or use any open source monitoring software like Spectorsoft?
I have played with various Remote Access Tools (Cybergate, etc) and stupid keyloggers, but I am looking for more "forensic" tools. Preyproject.com is close in terms of tracking, but weak on monitoring… Any advice would be great.
Thanks,
B
Curious are you looking for ‘anti-theft type” software, or covert remote monitoring tools specifically?
If referring to the latter then besides the legal ramifications of deploying such tools - A problem you may encounter with some open-source RAT versions is detection of the tools by common AV software. Though less talked about; even a lot of the commercial monitoring tools out there are detectable by AV software, but due to threat of legal action by the monitoring tools company against licensed software – (open source developers don’t have the luxury or an army of attorneys to issue lawsuits against the AV vendors) - many AV companies ‘opt’ not to detect or remove such ‘legitimate, licensed tools’ or give you a very limited an option to “detect commercial key loggers” - which is disabled by default. The issue to contend with when dealing with standard commercial and more advanced covert monitoring tools; is verifying to ensure that when target machine “phones home” with updates – it’s only “your pre-designated home” that they’re sending the updates to, and nowhere else
Open source versions of such tools would help address the 'phone 3rd party risk" but then raise the issue of detection by AV software all over again. It’s a Catch 22 for most when dealing with this subject.
Just a thought
Thanks for the reply. I am looking for an open source monitoring tool. I love Spectorsoft to death and am not worried about legal issues in my jurisdiction, but I am always curious to find open source alternatives to any program.
As for the AV issue, even the pro monitoring companies and government have made no deals with the major AV players. A) You have to disable your AV vendor from flagging your monitoring software or B) Hope it doesn't get fingerprinted by the AV guys… When it does get fingered the pro monitoring guys are usually slow to update. ( So it goes back to plan A to be safe.