Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures. The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro
Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity. The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous app
SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)
Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations. The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metad
Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com
Principalele funcționalități ale google/stenographer sunt: Network Forensics, Network Monitoring Tools, Command Line Tools, Incident Response Frameworks, Network Security, Network Security Monitoring.
Alternativele open-source pentru google/stenographer includ: arkime/arkime — Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network… zeek/zeek — Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level… cisco/mercury. aol/moloch — Moloch is a full packet capture system and network forensics platform designed for large scale network traffic… blechschmidt/massdns — A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration). arthepsy/ssh-audit — SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc).