PSD & Associates
Details of the Information Security Audit Tools
Freeware Tools
- Nessus : It is a remote security scanner for Linux,
BSD, Solaris, and other Unices. It is plug-in-based, has a GTK interface, and
performs over 1200 remote security checks.
- Snort : Snort is a network intrusion detection
system, capable of performing real-time traffic analysis and packet logging on
IP networks. It can perform protocol analysis, content searching/matching and
can be used to detect a variety of attacks and probes, such as buffer
overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting
attempts, and much more.
- MBSA (Microsoft Baseline Security Analyser) : to detect common
security misconfigurations and mission security updates on computer systems.
- NMAP (Network Mapper) : A Port Scanner which lists what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use etc..
- WIKTO: Web server/application vulnerability scanner
- IIS exploit: Buffer Overflow
- IIS Hack/IIS: Buffer Overflow
- IIS Crack: Buffer Overflow
- Web Cracker: Web based password cracking
- Brutus: Web based password cracking
- Trojan maker: For creating viruses, worms and trojans
- CrypTool: A cryptanalysis utility
Commercial Tools
- Symantec Net Recon: Network Scanner
- Watchfire Appscan: Web server/application vulnerability scanner
- Acunetix: Web server/application vulnerability scanner
Proprietary Tools
None