Intrusion Detection Software
Snort for Linux
Snort is an open source network intrusion detection system, capable of
performing real-time traffic analysis and packet logging on IP networks. It can
perform protocol analysis, content searching/matching and can be used to detect
a variety of attacks and probes, such as buffer overflows, stealth port scans,
CGI attacks, SMB probes, OS fingerprinting attempts, and much more.
- Snort for Windows
Snort is an open source network intrusion detection system, capable of
performing real-time traffic analysis and packet logging on IP networks. It can
perform protocol analysis, content searching/matching and can be used to detect
a variety of attacks and probes, such as buffer overflows, stealth port scans,
CGI attacks, SMB probes, OS fingerprinting attempts, and much more.
- SnoopNetCop Standard
SnoopNetCop Standard is a program that can detect possible packet sniffing
attack on your network. LAN cards has two oprating modes, 'normal mode' and
'promiscuous mode'.
- AIDE (Advanced Intrusion Detection Environment)
AIDE (Advanced Intrusion Detection Environment) is a free replacement for
Tripwire. It does the same things as the semi-free Tripwire and more.
Prelude is a new innovative Hybrid Intrusion Detection system designed to be
very modular, distributed, rock solid and fast.
- Foundstone Attacker
A TCP/UDP port listener.
Foundstone Carbonite
A Linux Kernel Module to aid in RootKit detection.
Foundstone Filewatch
A file change monitor. Used with BlackICE Defender.