Patriot NG: Host Based Intrusion Detection System

Intrusion detection system (IDS) is very popular in the field of network security, for a complete disclosure of IDS read our previous article about it click here to understand IDS from basic, and click here learn about different types of IDS.

Patriot NG is host based IDS, and it is design to work on Microsoft plate form, Patriot NG allows real time monitoring of operating system and the network.

As by using the previous articles you have an idea what actually a host based IDS is? What it does? 
Patriot NG is available on windows XP,VISTA and 7 plate form and it applicable on both 32-bit and 64-bit system.

Key Feature 
  • Changes in Registry keys: Indicating whether any sensitive key (autorun, internet explorer settings…) is altered.
  • New files in ‘Startup’ directories
  • New Users in the System
  • New Services installed
  • Changes in the hosts file
  • New scheduled jobs
  • Alteration of the integrity of Internet Explorer: (New BHOs, configuration changes, new toolbars)
  • Changes in ARP table (Prevention of MITM attacks)
  • TCP/IP Defense (New open ports, new connections made by processes, PortScan detection…)
  • Files in critical directories (New executables, new DLLs…)
  • NIDS (Detect anomalous network traffic based on editable rules)

  • Windows contain a host file that stores the information about the host that is IP addresses of a system, some malware affect this host file and change the data.Patriot NG alert the administrator if this will happen.
  • New window may be occur on a background of this current windows this might be happen via malware. Whenever this thing happen Patriot NG warn you.
  • Patriot NG provide us a facility of securing the critical system files, when ever new changes has been made on a critical file system it warn you.
  • Patriot NG has a built-in function to secure the TCP/IP, when ever new port open it warn us, the port may be open via back door like netcat.  
  • When the new services will install on a system, patriot NG inform the administrator about it.
  • It is highly recommended to use patriot NG along Winpcap.
  • Patriot NG warn the administrator if a new driver will install on a system, some malware behave like a driver and they may install on a critical system file. 

Windows XP, Windows Vista, Windows 7 (32Bits)
Patriot NG 2.0

Windows XP, Windows Vista, Windows 7 (64Bits)
PatriotNG 2.0

Video Demonstration 

Note: If you enjoyed this post, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.
Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

How to Exploit Heartbleed using Metasploit in Kali Linux

Heartbleed vulnerability (registered as CVE-2014-0160) is a security bug present in the older version of OpenSSL cryptographic library. OpenSSL is a cryptographic toolkit used...

How to Install Parrot Security OS on VirtualBox in 2020

Parrot Security OS is a free GNU/LINUX distribution, released on 10th April 2013. It is a mixture of Kali Linux and Frozenbox OS, aims to...

How to Install Kali Linux on VirtualBox [Windows Host] in 2020

Kali Linux is a Debian based Linux distribution, released on the 13th March 2013 as a complete rebuild of BackTrack Linux. It is one of...

Acunetix v13 Release Introduces Groundbreaking Innovations

The newest release of the Acunetix Web Vulnerability Scanner further improves performance and premieres best-of-breed technologies London, United Kingdom – February 5, 2019 – Acunetix,...