IDS mailing list archives

New Sguil 0.3.0 Install Doc for FreeBSD 4.9 REL


From: Richard Bejtlich <richard_bejtlich () yahoo com>
Date: Wed, 12 Nov 2003 11:52:37 -0800 (PST)

Hello everyone,

I just published a new installation guide for Sguil
0.3.0. Sguil is an interface to Snort which operates
using Network Security Monitoring principles.  This
means it is dedicated to answering the "now what?"
question that faces analysts who receive IDS alerts. 
Sguil provides alert, session, and full content data
with a minimum of mouse clicks, window changes, and
keystrokes.

Users not familiar with FreeBSD should have no
problems following the instructions.  I provide dozens
of screen shots and step-by-step comments to get the
OS and all needed applications installed.  

The document is available in .pdf form here:

http://sguil.sourceforge.net/downloads/sguil_0-3-0_on_freebsd_4-9-REL.pdf

The new guide uses FreeBSD 4.9 RELEASE as the server
platform and Windows 2000 or XP as the analyst
workstation. 

Please send comments on the guide to sguil at
taosecurity dot com.  I plan to incorporate as many
suggestions for improvement as humanly possible.

Thank you,

Richard Bejtlich
http://taosecurity.com

__________________________________
Do you Yahoo!?
Protect your identity with Yahoo! Mail AddressGuard
http://antispam.yahoo.com/whatsnewfree

---------------------------------------------------------------------------
Network with over 10,000 of the brightest minds in information security
at the largest, most highly-anticipated industry event of the year.
Don't miss RSA Conference 2004! Choose from over 200 class sessions and
see demos from more than 250 industry vendors. If your job touches
security, you need to be here. Learn more or register at
http://www.securityfocus.com/sponsor/RSA_focus-ids_031023 
and use priority code SF4.
---------------------------------------------------------------------------


Current thread: