Entries Tagged as ‘argus’

January 24, 2008

Flowtime – Create a timeline for packet flow

You can never have too many tools for pcap visualization
Flowtime is a script written in Ruby that produces a timeline of the network flows in a pcap file. Everything is better with a picture, so here’s a picture: (warning, this picture is 3000×2000 pixels, kind of large)

Each bar on the left is a [...]

January 8, 2008

NSM-Console version 0.3 release

Yep, I’ve just been cranking out code lately, so I am proud to present the 0.3 release of nsm-console!
You can download NSM-Console here:
http://navi.eight7.org/~hinmanm/files/nsm-console-0.3.tar.gz
This release was focused a bit more on usability, features and bugfixes rather than the addition of new modules, however, there were still a couple that were added. Since this release has some [...]

November 28, 2007

NSM Console projected module list

Here’s a list of all the planned modules and completed (struck-out) modules for nsm-console: (if a module is struck out, it’s because I’ve finished making a module for it, it isn’t necessarily in the tarball for download)

aimsnarf
ngrep (gif/jpg/pdf/exe/pe/ne/elf/3pg/torrent)
tcpxtract
tcpflow
chaosreader
bro-IDS
snort
tcpdstat
capinfos
tshark
argus
ragator
racount
rahosts
hash (md5 & sha256)
ra
honeysnap
p0f
pads
fl0p
iploc

foremost – thanks shadowbq!
flowgrep
tcptrace
tcpick
flowtime
flowtag
harimau
clamscan

Think of any other useful modules? Leave me a comment and let [...]