ThreatMon can run on the following OS:
Windows 2000 Professional (any service pack)
Windows 2000 Server and Advanced Server with any service packs.
Windows XP Professional, SP1 and SP2.
Currently ThreatMon is a IDS product. It can detects the intrusion
from Internet and the from the malicious application already running
on your computer.
In the coming release, ThreatMon will detect the rootkit and hidden
process. The rootkit is usually loaded by attacker and open a backdoor
for attacker's exploration. Usually rootkit can hide itself. It
is impossible to find it by using the tool come with Widows 2000
and XP.
First ThreatMon can detect malicious activities coming from Internet.
For example, the spyware, Trojan horse, virus and worm.
Second, ThreatMon's detection engine watches the application behavior
and detects the malicious activities of running bad application.
For example, worm and keylogger. Usually you are never aware of
the existence of those software.
ThreatMon implements a detection engine watching the system and
application behaviors. Based on the characteristic of attack behavior,
it determine the security breach from Internet or from the existing
malicious application.