[Snort-users] Fwd: Re: Virtual Machines and Hypervisors

Mikael Keri info at ...16060...
Tue Jan 29 09:26:37 EST 2013

Forgotten to cc the list. See below.
But to follow up if you can't go the SF way with RNA there is always p0f.
But I still think that my original  answer would be a way forward for you.

---------- Vidarebefordrat meddelande ----------
Från: "Mikael Keri" <info at ...16060...>
Datum: 29 jan 2013 15:05
Ämne: Re: [Snort-users] Virtual Machines and Hypervisors
Till: "Juan Camilo Valencia" <juan.valencia at ...16028...>

Nmap? Also look in switch logs / dhcp logs for mac address that does not
belong to your standard hardware platform.

This might be a better option then use Snort for the detection. That said
there are rules to detects Vmware software update requests

Den 29 jan 2013 14:33 skrev "Juan Camilo Valencia" <
juan.valencia at ...16028...>:

> Hi Guys,
> I am trying to find a way to ban virtual machines and hypervisors in our
> network, I made a quicly research and I didn't found anything.
> Can somebody tell me if exist a way or a method to detect that, one of my
> ideas is when the VM is configured in NAT mode detect that kind of traffic,
> but the problem is when the VM is configured in bridge mode.
> Thanks for your advance,
> Regards
> --
> Ingeniero de Operaciones
> SeguraTec S.A.S
> Calle 11 # 43B-50 of 307
> Medelllín Colombia
> *“Choose a job you love, and you will never have to work a day in your
> life”*
> ------------------------------------------------------------------------------
> Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS,
> MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current
> with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft
> MVPs and experts. ON SALE this month only -- learn more at:
> http://p.sf.net/sfu/learnnow-d2d
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20130129/6305c163/attachment.html>

More information about the Snort-users mailing list