Hi all,
I'm currently in the design stage of a honeynet with a Windows
honeypot inside. I want to add a Terminal Server service to the
honeypot or at least have the technology to "see" whats happening via
Terminal Server if any intruder activates it ¿?
I have been searching for tools that can "look" into a TS session (I
know I can't just look at the traffic, I'm looking for a host-level
tool). I found this post:
http://seclists.org/lists/honeypots/2004/Jan-Mar/0105.html
but I didn't find any implementation of this concept.
Any thoughts, workarounds or alternatives?
Thanks
Received on Jul 04 2006