Chat now with support
Chat with Support

InTrust 11.3.2 - InTrust Reports

Logons

AIX 5L failed login attempts

This InTrust report shows details of failed AIX 5L login attempts.

AIX 5L login statistics

This InTrust report shows how many successful and failed AIX 5L logins occurred within the specified period of time. It also displays the number of cases when there were multiple consecutive failed logins, which indicates possible password-picking activity.

AIX 5L multiple failed login attempts

This InTrust report shows details of situations when multiple failed AIX 5L login attempts occurred in a row. Click a number in the Count column for a particular attempt to view the original Syslog messages about each attempt.

AIX 5L password changes

This InTrust report shows password change events.

AIX 5L su activity

This InTrust report shows details of AIX 5L su activity.

AIX 5L successful logins

This InTrust report shows details of successful AIX 5L login attempts.

All AIX 5L syslog events

This InTrust report is designed for manual analysis of AIX 5L Syslog messages. Use filtering by date and time, host, message source and message content to find out the information you need.

Report Pack for IIS

Report Pack for Microsoft IIS

This section contains a list of reports included in the InTrust11.3.2 Report Pack for Microsoft IIS.

FTP Site Usage

Clients

FTP site top 100 most active clients

This InTrust report lists the 100 most active Microsoft IIS FTP site visitors.

Files Access

FTP site access to files

This InTrust report provides comprehensive information on files access events for your FTP site.

Traffic

FTP site daily traffic [chart]

This InTrust chart provides statistics on FTP site daily traffic for the specified date.

FTP site total statistics

This InTrust report provides aggregate statistics for Microsoft Internet Information Server FTP site.

Security

Advanced Forensic Analysis

Security Subsystem Faults

Audit subsystem faults

This InTrust report displays information on problems with Microsoft IIS logging. This data helps examine audit subsystem health of specified servers.

Suspicious Activity

Published Resources Access

FTP site detailed access analysis

  • This InTrust report helps perform detailed analysis of FTP events.

Web site detailed access analysis

  • This InTrust report helps perform detailed analysis of HTTP events.

Suspicious Requests

FTP site failed logons

  • This InTrust report shows all failed FTP logons. Numerous FTP logon failures may indicate intrusion attempts.

Web site all requests

  • This Intrust report displays general information related to the Web requests.

Common Security Incidents

Gaining Privileged Access

Administration web sites access attempts

This InTrust report shows attempts to gain access to administration sites from the Web. An administration Web site can usually be accessed on port 5466. Normally, access is allowed only from the local host, so access attempts from the Web can indicate unauthorized access.

Administrative folders access attempts

Administrative folders are critical resources, because they allow gaining access to server management. This InTrust report enables you to monitor administrative folder access attempts performed from the Web.

Gaining User Access

FTP site daily failed logons [chart]

This InTrust chart presents statistics on failed attempts to log on to an FTP server. Multiple FTP server logon attempts displayed as graph spikes may indicate a brute force attack.

Multiple Failed FTP Server Logon Attempts detailed

Multiple failed FTP server logon attempts may indicate a brute force attack. This InTrust report shows detailed information on each session all requests, date and time, client IP and server where the user tried to log on.

Web site daily failed logons [chart]

This InTrust chart displays failed Web server access events. Spikes in the graph indicate abnormal numbers of errors. Peaks might indicate Denial of Service attacks against the server. The X-axis represents time, and the Y-axis represents the number of events.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating