Start the intrusion detection process by comparing running processes and services. There are times when a compromise
is fairly simple and can be found by just such a comparison check. The Microsoft Windows Sysinternals tool can be used for listing out processes, services, handles and other types of volatile data useful for incident response. I am going to assume what you're talking about is a server and therefore you cannot do a forensic investigation on the hard drive or storage device. You can, though, dump the contents of memory for use in a forensics investigation using tools such as WinDD or Mdd, but you might want to first start with standard incident response tools. There are commercial forensic tools that will dump volatile data and allow you to take an image of the system remotely.
There are also some system management tools like Ecora Auditor or Microsoft System Center Configuration Manager used for configuration management or patching that can do many of these things and compare a potentially compromised server to a known good system to let you know the differences.
Dig deeper on Windows Security: Alerts, Updates and Best Practices
Related Q&A from Nick Lewis, Enterprise Threats
Expert Nick Lewis explains how to keep call center employees from getting duped by social engineering scams and pretexting.continue reading
Researchers reportedly succeeded in extracting decryption keys using sound-based attacks. Is this a threat enterprises should worry about?continue reading
The amount of malware using peer-to-peer communications has increased dramatically. Enterprise threats expert Nick Lewis explains how to detect P2P ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.