Snort mailing list archives
Tcl/tk Analysis Interface for Snort
From: Bamm Visscher <bamm () satx rr com>
Date: 13 Jan 2003 15:43:23 -0600
I posted this to snort-devel about a month ago. A good four people have now successfully installed the sguil client on different platforms (Linux, OpenBSD, and Win2k), so it must be ready for prime time </sarcasm>. Beware, sguil is still considered "beta" and the installation requires the addition/modification of plugins/code not included with the standard snort and barnyard releases. If you have comments, suggestions, or need help with the installation, I can be contacted via email or in #snort-gui on irc.freenode.net. Quick description: Sguil consist of three main components, a plugin to barnyard (op_sguil), a GUI server (sguild), and a GUI client (sguil.tk).Once installed, these components allow the analyst to view snort events in near real time. Events can be validated by placing them into one of seven incident categories or marking the event as having no further action required (NA). These actions remove the events from the RealTime tab of all the connected clients but are not deleted from the database. Archived events can easily be retrieved from the database through preformatted queries, or the analyst can create a custom query using SQL. Also included in the sguil package, is a modified portscan preprocessor (spp_portscan) and a tcl script (portscan_loader.tcl) for loading the modified spp_portscan output into the database. These two components give the analyst immediate access to portscan data. The final components are for analyzing the raw data associated with a given session. Xscriptd is a daemon that listens for request from sguil.tk and once queried, it parses raw tcpdump files for packets matching the requested session and either feeds the stream through tcpflow creating a transcript or sends the binary data back to the client to be loaded into ethereal. Currently, sguil does not have any sensor or rule management capabilities. I hope to work on those features once the event management interface is a little more mature. More info and downloads are available at the link below. Be gentle. http://www.satexas.com/~bamf/sguil/ Bammkkkk ------------------------------------------------------- This SF.NET email is sponsored by: FREE SSL Guide from Thawte are you planning your Web Server Security? Click here to get a FREE Thawte SSL guide and find the answers to all your SSL security issues. http://ads.sourceforge.net/cgi-bin/redirect.pl?thaw0026en _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Tcl/tk Analysis Interface for Snort Bamm Visscher (Jan 13)
