Программы для анализа

  1. Encrypt
  1. Monitor processes
  1. Monitor processes
  2. dstat –tcp
  1. Monitor memory
  2. free -m
  1. Monitor processes
  1. Monitor network
  2. sudo ifconfig -a
  1. Monitor network:
  2. Part of moreutils
  1. Monitor network
  1. Monitor I/O
  1. Monitor network
  1. Filewall
  1. List open files, including sockets
  2. Output FD is File Descriptor
  3. 4 is IPv4
  4. lsof -i 4 -a
  5. lsof -i 4:80
  1. Monitor memory
  2. memstat -w -p $pid
  1. Monitor network
  1. Monitor network
  1. Monitor processes
  2. netstat -tupln is best
  3. htop
  4. netstat –tcp –udp –listening –program -nat
  5. netstat -a –tcp
  1. Monitor processes
  2. nmap 127.0.0.1
  1. Monitor network
  2. nBox
  3. nProbe
  4. ntop
  5. n2n
  6. PF_RING
  7. vPF_RING
  1. Monitor processes
  2. ps -ef | grep $a_name
  3. ps auwx

I.e. don't use - to prefix auwx if piping into grep, since it produces a warning msg.

  1. Monitor processes
  2. pstree $pid
  1. Monitor network
  1. Monitor system calls
  2. strace -e trace=clone,execve -ff perldoc strict
  1. Monitor network
  1. Monitor memory
  2. vmstat 1 20
  1. Monitor network
  2. vnstat