This article can also be found in the Premium Editorial Download "Information Security magazine: Comparing seven top integrated endpoint security suites."
Download it now to read this article plus other related content.
Paraben's P2 Enterprise Shuttle is a remote digital forensic suite, allowing you to remotely conduct undetected forensic tests on Windows machines in your network without taking the machines offline.
This can be useful to acquire the data without raising suspicion of the target. It may also be used to monitor infected systems in real time.
The installation automatically filled in the IP address to be used by the proxy and server with the hostname, which did not seem to work. The proxy would not start and did not really give a reason. We corrected the issue by editing the config files and changing the hostname to be the actual IP address.
The client agents can be installed directly or through the Captain, which controls agents and acquires and analyzes data from systems.
The latter allows you to place the agent without alerting the user or install agents on multiple machines.
This was first published in November 2007