USB Monitoring Tools Linux or Win (Freeware)
-
@dashrender Thanks Dashrender but checking everytime in event log viewer is very painful. like if any one tried to connect a pen drive we shud get a email alert or some kind of msg triggering system would be very helpful.
example : GFI Endpoint security
-
@nagendra if I have understood it correctly try Comodo One Monitoring tools, ( https://one.comodo.com/rmm.php ) and its Free. if you haven't found any solutions, Hope it helps.
-
@malli085 said in USB Monitoring Tools Linux or Win (Freeware):
Comodo One Monitoring tools
Thanks @Malli085 but this is cloud based i need offline sorry i didn't mentioned previously.
-
@nagendra thats okay, anyways!
-
@nagendra said in USB Monitoring Tools Linux or Win (Freeware):
@dashrender Thanks Dashrender but checking everytime in event log viewer is very painful. like if any one tried to connect a pen drive we shud get a email alert or some kind of msg triggering system would be very helpful.
example : GFI Endpoint security
I specifically told you how to get an email, by monitoring the logs with something like ELK. It has rules that will do things based on events in the collected logs.
-
@Dashrender sure i will check ELK ..
-
@nagendra said in USB Monitoring Tools Linux or Win (Freeware):
@Dashrender sure i will check ELK ..
Or Graylog, similar but a little easier than ELK.
-
@scottalanmiller said in USB Monitoring Tools Linux or Win (Freeware):
@nagendra said in USB Monitoring Tools Linux or Win (Freeware):
@Dashrender sure i will check ELK ..
Or Graylog, similar but a little easier than ELK.
Especially for alerting. The alert streams are super easy to set up and get running. Plus the dashboards are a lot easier.
-
Also since everyone was confused at the beginning about whether this was Linux or Windows, there is a utility for Linux called USBGuard. It will only allow trusted USB devices based on a white list and log all attempts. It's easy to automate also.
-
@scottalanmiller Thanks Scot... thanks everyone will find these solutions