OMCD
- Open
Methodology for Compromise Detection
Project Manager:
Christopher Schooley-
omcd<at>isecom.org
The goal for this document is to present a methodology which
will allow for discovering if the given machine, running
Windows Operating System, is clean or has been
compromised (by an attacker, virus, worm, etc…). The
document gives strong considerations for detecting malware which use
advanced stealth techniques, as seen for example in the latest kernel
mode rootkits, but is not limited to those sophisticated techniques
only, aiming towards defining a more complete reference for malware
detection.
This document will focus on describing “how it works” side more so than
“how to use” aspect. This methodology will serve those who need to
clean Windows systems as well as programmers developing malware
detection tools.
If you are interested in helping with this project please contact us at
omcd<at>isecom.org.