Sguil

Network management software From Wikipedia, the free encyclopedia

Sguil (pronounced sgweel or squeal) is a collection of free software components for Network Security Monitoring (NSM) and event driven analysis of IDS alerts.[2] The sguil client is written in Tcl/Tk[3][2] and can be run on any operating system that supports these. Sguil integrates alert data from Snort, session data from SANCP, and full content data from a second instance of Snort running in packet logger mode.

Original authorBamm Visscher, Steve Halligan
Stable release
0.9.0[1] / April 4, 2014; 11 years ago (2014-04-04)
Written inTcl/Tk
Quick facts Original author, Stable release ...
Sguil
Original authorBamm Visscher, Steve Halligan
Stable release
0.9.0[1] / April 4, 2014; 11 years ago (2014-04-04)
Written inTcl/Tk
Operating systemCross-platform
TypeNetwork Security Monitoring
LicenseGPLv3
Websitesguil.sourceforge.net
Close

Sguil is an implementation of a Network Security Monitoring system. NSM is defined as "collection, analysis, and escalation of indications and warnings to detect and respond to intrusions."

Sguil is released under the GPL 3.0.[4]

Tools that make up Sguil

More information Tool, Purpose ...
ToolPurpose
MySQL 4.x or 5.xData storage and retrieval
Snort 2.x / SuricataIntrusion detection alerts, scan detection, packet logging
Barnyard / Barnyard2Decodes IDS alerts and sends them to sguil
SANCPTCP/IP session records
TcpflowExtract an ASCII dump of a given TCP session
p0fOperating system fingerprinting
tcpdumpExtracts individual sessions from packet logs
WiresharkPacket analysis tool (used to be called Ethereal)
Close

[5]

See also

References

Related Articles

Wikiwand AI