|
|
|
|
|
by com2kid
1215 days ago
|
|
> What you really need here is a strongly isolated VM, Simplify, don't use a VM. Create an isolated network, hook your sacrificial machine up to it, have it install the package. Remotely kill it (network controlled power switch if needed). The machine's hard drive should be hooked up through a network controlled switch of some type. After the sacrificial machine is powered down, reroute the HD so it is connected to a machine that does forensics. Now you have a clear "before" and "after" situation setup for analysis. The sacrificial machine's network activity can be monitored by way of whatever switch/router it uses to connect to the Internet. |
|