In case you are following at home you will need to go download the following;
- WireShark http://www.wireshark.org/download.html.
I am just at the point where I am ready to take our bot we built and see if we can get it to run on the target machine. But I want to make sure we are going to collect every little thing we can. What we are going to setup to do is the following.
After the fact of building my bot, it's worth looking at what the basic config file looks like.
entry "StaticConfig" ;botnet "btn1" timer_config 60 1 timer_logs 1 1 timer_stats 20 1 url_config "http://localhost/config.bin" remove_certs 1 disable_tcpserver 0 ...