Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

March 31, 2004 12:00 AM

New Forensics Tool: Port Reporter

Windows IT Pro
InstantDoc ID #42212
Rating: (0)
Can you ever have enough tools to assist with troubleshooting and forensic analysis? Probably not, and that's a good reason to add the new tool, Port Reporter, into your toolkit. Port Reporter is a free tool offering from Microsoft that logs TCP and UDP port activity to a text file.

Port Reporter can track activity in a fair amount of detail, cross referencing port activity to the actual application using the port along with its process ID (PID).

Port Reporter creates three log files: an initialization log, a ports log, and a PID log. The initialization log provides a list of ports, processes, and loaded service modules that are active at the time Port Reporter starts.

The ports log is updated as port activity occurs on a system. The log typically includes a date stamp, protocol type (TCP or UDP), a source port and source IP address, a destination port and address, the application that initiated the port activity, and user account (security context) the application is operating under.

The PID log shows more detail about a given application conducting network activity. Records include the process ID number, application file name, security context, a summary of ports used along with their state, and a list of all DLLs loaded by the application.

Port Reporter runs as a service on Windows Server 2003, Windows XP, and Windows 2000 systems. You can learn more about the tool and view sample log files in Microsoft's article, 837243, on the company's support Web site where you'll also find a link to download the new tool.

Related Content:

ARTICLE TOOLS

Comments
  • ning
    8 years ago
    Apr 13, 2004

    Thanks Microsoft!!!

  • Pete Pinkston
    8 years ago
    Apr 07, 2004

    Great tool! It really provides useful information to manage and secure your network.
    Thanks

  • Frank Concha
    8 years ago
    Apr 02, 2004

    What a gift!

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.