Section: .. / UNIX / IDS /
| /// File Name: |
radmind-1.7.0.tar.gz |
Description:
|
radmind is a suite of Unix command-line tools and a server designed to remotely administer the file systems of multiple Unix machines. Radmind operates as a tripwire which is able to detect changes to any managed filesystem object, e.g. files, directories, links, etc. However, radmind goes further than just integrity checking: once a change is detected, radmind can optionally reverse the change.
| | Homepage: | http://rsug.itd.umich.edu/software/radmind | | Changes: | Major changes from 1.6.1 include performance improvements to fsdiff and functionality on Linux. | | File Size: | 383633 | | Last Modified: | Aug 17 02:22:25 2006 |
| MD5 Checksum: | b3dd376739d639c381795d25a66019b4 |
|
| /// File Name: |
samhain-2.2.2.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1516317 | | Last Modified: | Jul 20 06:17:27 2006 |
| MD5 Checksum: | d12c12fafe9a920d23d679b62a867c5b |
|
| /// File Name: |
sockstat.tar.gz |
Description:
|
Simple C program written to display open ports on a given host. Useful for when things like netstat and sockstat might be backdoored.
| | Author: | duriel | | File Size: | 1583 | | Last Modified: | Jul 9 07:42:07 2006 |
| MD5 Checksum: | 69e90ab3d31c5acc04a8263c800cee6e |
|
| /// File Name: |
samhain-2.2.1.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1511417 | | Last Modified: | Jun 15 04:34:25 2006 |
| MD5 Checksum: | b54983526aac9191fb195b6aad26e675 |
|
| /// File Name: |
libnids-1.21.tar.gz |
Description:
|
Libnids is a library that provides a functionality of one of NIDS (Network Intrusion Detection System) components, namely E-component. It means that libnids code watches all local network traffic, cooks received datagrams a bit, and provides convenient information on them to analyzing modules of NIDS. So, if you intend to develop a custom NIDS, you do not have to build low-level network code. If you decide to use libnids, and you have got E-component ready - you can focus on implementing other parts of NIDS.
| | Author: | Nergal | | Homepage: | http://libnids.sourceforge.net | | Changes: | Various code updates. | | File Size: | 140138 | | Last Modified: | May 22 00:18:39 2006 |
| MD5 Checksum: | 8c43dd7d66350eed99a29be50bc5615f |
|
| /// File Name: |
beltane-1.0.11.tar.gz |
Description:
|
Beltane is a web-based central management console for the Samhain file integrity / intrusion detection system. It enables the administrator to browse client messages, acknowledge them, and update centrally stored file signature databases. Beltane requires a Samhain (version 1.6.0 or higher) client/server installation, with file signature databases stored on the central server, and logging to a SQL database enabled.
| | Homepage: | http://la-samhna.de/beltane | | Changes: | Multiple improvements have been made. | | File Size: | 177935 | | Last Modified: | May 5 06:42:42 2006 |
| MD5 Checksum: | 262a8576521d4a1a22b2185b39ce287e |
|
| /// File Name: |
samhain-2.2.0.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1525372 | | Last Modified: | May 5 06:41:44 2006 |
| MD5 Checksum: | f2869a6c8a0eef5cb549b93df09d80a1 |
|
| /// File Name: |
darc-0.3.47.tgz |
Description:
|
Darc is a utility for managing large Aide installations in heterogeneous environments. It eliminates the need to maintain read-only media on every system, and provides unified reporting on filesystem changes across all machines.
| | Author: | Jacob Martinson | | Homepage: | http://icculus.org/projects/darc/ | | File Size: | 11683 | | Last Modified: | Apr 29 06:11:10 2006 |
| MD5 Checksum: | 64d89f53bfc800b92b3b8fea9903b4d5 |
|
| /// File Name: |
darc-0.3.42.tgz |
Description:
|
Darc is a utility for managing large Aide installations in heterogeneous environments. It eliminates the need to maintain read-only media on every system, and provides unified reporting on filesystem changes across all machines.
| | Author: | Jacob Martinson | | Homepage: | http://icculus.org/projects/darc/ | | File Size: | 11273 | | Last Modified: | Apr 25 18:30:27 2006 |
| MD5 Checksum: | 6f2b6fe69bb39970a14925a415612724 |
|
| /// File Name: |
beltane-1.0.10.tar.gz |
Description:
|
Beltane is a web-based central management console for the Samhain file integrity / intrusion detection system. It enables the administrator to browse client messages, acknowledge them, and update centrally stored file signature databases. Beltane requires a Samhain (version 1.6.0 or higher) client/server installation, with file signature databases stored on the central server, and logging to a SQL database enabled.
| | Homepage: | http://la-samhna.de/beltane | | Changes: | Fixed an arcane bug in configure.ac. | | File Size: | 177881 | | Last Modified: | Mar 28 01:42:20 2006 |
| MD5 Checksum: | 646445fa2f85414214a2c22c26591fab |
|
| /// File Name: |
radmind-1.6.0.tar.gz |
Description:
|
radmind is a suite of Unix command-line tools and a server designed to remotely administer the file systems of multiple Unix machines. Radmind operates as a tripwire which is able to detect changes to any managed filesystem object, e.g. files, directories, links, etc. However, radmind goes further than just integrity checking: once a change is detected, radmind can optionally reverse the change.
| | Homepage: | http://rsug.itd.umich.edu/software/radmind | | Changes: | Added support for network communication compression. OS X Package contains universal binaries. | | File Size: | 360040 | | Last Modified: | Mar 28 01:40:40 2006 |
| MD5 Checksum: | 19ca1d4b40e6dbdf7fc15611236c9093 |
|
| /// File Name: |
prelude-manager-0.9.4.tar.gz |
Description:
|
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
| | Homepage: | http://prelude.sourceforge.net | | Changes: | Various bug fixes and improvements. | | File Size: | 573436 | | Last Modified: | Mar 28 01:24:02 2006 |
| MD5 Checksum: | ccde00b47f0bc8586aed23286162d0d0 |
|
| /// File Name: |
samhain-2.1.3.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1330406 | | Last Modified: | Mar 28 01:18:09 2006 |
| MD5 Checksum: | b6082cbec978d483fabe638f991acdb4 |
|
| /// File Name: |
hlbr-1.0.tar.gz |
Description:
|
HLBR is an IPS (Intrusion Prevention System) that works directly at the layer 2 of the OSI model staying invisible from layer 3.
| | Author: | Joao Eriberto Mota Filho,Andre Bertelli Araujo | | Homepage: | http://hlbr.sourceforge.net | | Changes: | Version 1.0 now can detect malicious traffic using regular expressions. | | File Size: | 193460 | | Last Modified: | Mar 8 00:33:49 2006 |
| MD5 Checksum: | b0739e53c26fa5bb40e34764bd102b46 |
|
| /// File Name: |
aide-0.11.tar.gz |
Description:
|
AIDE (Advanced Intrusion Detection Environment) is a free replacement for Tripwire(tm). It generates a database that can be used to check the integrity of files on server. It uses regular expressions for determining which files get added to the database. You can use several message digest algorithms to ensure that the files have not been tampered with.
| | Author: | Rami Lehti | | Homepage: | http://www.cs.tut.fi/~rammer/aide.html | | Changes: | Various bug fixes. | | File Size: | 266978 | | Last Modified: | Feb 25 21:08:59 2006 |
| MD5 Checksum: | 9a44e5386b0355ef57c60f627ff4d085 |
|
| /// File Name: |
logcheck_1.2.43a.tar.gz |
Description:
|
Logcheck parses system logs and generates email reports based on anomalies. Anomalies can be defined by users with 'violations' files. It differentiates between 'Active System Attacks', 'Security Violations', and 'Unusual Activity', and is smart enough to remember where in the log it stopped processing to improve efficiency. It can also warn when log files shrink, and does not report errors when they are rotated.
| | Author: | Todd Troxell | | Homepage: | http://logcheck.org/ | | Changes: | Various updates. See changelog. | | File Size: | 108932 | | Last Modified: | Feb 25 21:06:53 2006 |
| MD5 Checksum: | 43d89ab60356afc2294949e5ab8cf659 |
|
| /// File Name: |
honeyd-1.5.tar.gz |
Description:
|
Honeyd is a small daemon that creates virtual honey pot hosts on a network. The hosts can be configured to run arbitrary services, and their TCP personality can be adapted so that they appear to be running certain versions of operating systems. Any type of service on the virtual machine can be simulated according to a simple configuration file. Instead of simulating a service, it is also possible to proxy it to another machine.
| | Author: | Niels Provos | | Homepage: | http://www.honeyd.org | | Changes: | The new release contains a bunch of new features: - Honeyd stats collector - Improved Subsystem support - Examples of real subsystems - fixed security issue allowing remote identification. | | File Size: | 893208 | | Last Modified: | Feb 16 17:59:03 2006 |
| MD5 Checksum: | cf328a2443f1f4233c6117fbf0a72de3 |
|
| /// File Name: |
hlbr-0.2.tar.gz |
Description:
|
HLBR is an IPS (Intrusion Prevention System) that works directly at the layer 2 of the OSI model staying invisible from layer 3.
| | Author: | Joao Eriberto Mota Filho,Andre Bertelli Araujo | | Homepage: | http://hlbr.sourceforge.net | | File Size: | 194744 | | Last Modified: | Feb 14 00:05:18 2006 |
| MD5 Checksum: | 5f48b9d7ef29b33c5ee95e843dfc15b0 |
|
| /// File Name: |
prelude-manager-0.9.3.tar.gz |
Description:
|
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
| | Homepage: | http://prelude.sourceforge.net | | Changes: | Fixed a crash, improved error handling, various bug fixes, and more. | | File Size: | 567751 | | Last Modified: | Feb 9 21:29:50 2006 |
| MD5 Checksum: | ca714e2b3e581f18954fa6b7285622ee |
|
| /// File Name: |
samhain-2.1.2.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 196096 | | Last Modified: | Feb 8 00:38:39 2006 |
| MD5 Checksum: | 25bbf93bca768e66e553b24c92ab11b0 |
|
| /// File Name: |
mwcollect-3.0.3.tar.bz2 |
Description:
|
mwcollect is an easy solution to collect worms and other autonomous spreading malware in a non-native environment like Linux. The mwcollect daemon mwcollectd opens ports that are known to be commonly exploited by Malware and simulates certain known vulnerabilities on them.
| | Author: | Honeynet Project | | Homepage: | http://www.mwcollect.org/ | | Changes: | The Threestone mwcollect version fixes some timeout bugs and should increase overall performance. The submit-gotek module for Alliance support has been added and this version now finally builds and runs very good on FreeBSD. | | File Size: | 72623 | | Last Modified: | Feb 5 22:13:14 2006 |
| MD5 Checksum: | d9ecc6cd8838d6ade4b486e9e27e4cfb |
|
| /// File Name: |
prelude-manager-0.9.2.tar.gz |
Description:
|
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
| | Homepage: | http://prelude.sourceforge.net | | Changes: | Better error reporting. Various bug fixes. | | File Size: | 567365 | | Last Modified: | Feb 2 06:22:01 2006 |
| MD5 Checksum: | cf3aedb580d9912f9ae677c0393e1c9b |
|
| /// File Name: |
radmind-1.5.1.tgz |
Description:
|
radmind is a suite of Unix command-line tools and a server designed to remotely administer the file systems of multiple Unix machines. Radmind operates as a tripwire which is able to detect changes to any managed filesystem object, e.g. files, directories, links, etc. However, radmind goes further than just integrity checking: once a change is detected, radmind can optionally reverse the change.
| | Homepage: | http://rsug.itd.umich.edu/software/radmind | | Changes: | Added support for case insensitive file systems. Added lsort to sort transcripts. Various bug fixes. | | File Size: | 353879 | | Last Modified: | Dec 28 19:14:27 2005 |
| MD5 Checksum: | 6c8d0e9a9e954e89cffcc64421b783f5 |
|
| /// File Name: |
samhain-2.1.1a.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1329395 | | Last Modified: | Dec 28 19:07:53 2005 |
| MD5 Checksum: | 8ace68c504e7c149a4647b33a5ea3078 |
|
| /// File Name: |
prelude-manager-0.9.1.tar.gz |
Description:
|
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
| | Homepage: | http://prelude.sourceforge.net | | Changes: | Added ability to listen on multiple IP addresses. Some bug fixes and code cleanup. | | File Size: | 550672 | | Last Modified: | Nov 20 13:29:30 2005 |
| MD5 Checksum: | 059f4df26f1656941df553347a7fcd7d |
|
|
|
|
|