[c-nsp] OT: Following Up on Netflow Information

Andrew Miehs andrew at 2sheds.de
Fri Jul 8 12:55:43 EDT 2011


On 08.07.2011, at 18:11, Jeff Cartier <Jeff.Cartier at pernod-ricard.com> wrote:

> The question, more or less, is do I have any options to keep moving forward in finding out what this user was actually doing?

You may want to look at snort or in this case force users over a proxy.

If this an enterprise environment I am sure that there is some spyware
that you can install on your clients.

Just make sure you dont break any local laws.

Andrew


More information about the cisco-nsp mailing list