[] PortscanGeoinfo (Prelude Correlator Plugin) by David Rupprechter
Download ::: md5 checksum
:: release date: 2010-11-06 :: license: GPLv2
PortscanGeoinfo is a plugin for Prelude Correlator which is a sensor of the impressing Prelude security information event management system ( http://www.prelude-technologies.com/en/solutions/universal-sim/index.html)
PortscanGeoinfo creates correlation alarms with geographical information for portscans detected by the NIDS Snort and the HIDS OSSECPlease note that Snort and/or OSSEC must be registered as a Prelude sensor
Please install GeoIP for python. For detailled geographical information please download MaxMind´s GeoLiteCity-Database
Please have a look at the README-file in the archive for installation notes!
|