Sguil

From Wikipedia, the free encyclopedia

Sguil (pronounced sgweel or squeal) is a collection of free software components for Network Security Monitoring (NSM) and event driven analysis of IDS alerts.[2] The sguil client is written in Tcl/Tk[3][2] and can be run on any operating system that supports these. Sguil integrates alert data from Snort, session data from SANCP, and full content data from a second instance of Snort running in packet logger mode.

Sguil is an implementation of a Network Security Monitoring system. NSM is defined as "collection, analysis, and escalation of indications and warnings to detect and respond to intrusions."

Sguil is released under the GPL 3.0.[4]

ToolPurpose
MySQL 4.x or 5.xData storage and retrieval
Snort 2.x / SuricataIntrusion detection alerts, scan detection, packet logging
Barnyard / Barnyard2Decodes IDS alerts and sends them to sguil
SANCPTCP/IP session records
TcpflowExtract an ASCII dump of a given TCP session
p0fOperating system fingerprinting
tcpdumpExtracts individual sessions from packet logs
WiresharkPacket analysis tool (used to be called Ethereal)

[5]

See also

References

Related Articles

Wikiwand AI