Start the intrusion detection process by comparing running processes and services. There are times when a compromise...
is fairly simple and can be found by just such a comparison check. The Microsoft Windows Sysinternals tool can be used for listing out processes, services, handles and other types of volatile data useful for incident response. I am going to assume what you're talking about is a server and therefore you cannot do a forensic investigation on the hard drive or storage device. You can, though, dump the contents of memory for use in a forensics investigation using tools such as WinDD or Mdd, but you might want to first start with standard incident response tools. There are commercial forensic tools that will dump volatile data and allow you to take an image of the system remotely.
There are also some system management tools like Ecora Auditor or Microsoft System Center Configuration Manager used for configuration management or patching that can do many of these things and compare a potentially compromised server to a known good system to let you know the differences.
Dig Deeper on Windows Security: Alerts, Updates and Best Practices
Related Q&A from Nick Lewis
The remote administration Ammyy Admin software was repeatedly found to be spreading different types of malware. Expert Nick Lewis explains how ...continue reading
The Keydnap malware has the ability to steal passwords stored in the Keychain Access app on Mac systems. Expert Nick Lewis explains how to mitigate ...continue reading
The CryptXXX ransomware has been spreading through compromised legitimate websites that redirect to malicious sites. Expert Nick Lewis explains how ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.