bamm
June 29th, 2004, 12:18
I know there was discussions on sguil a while back so I thought I'd submit a post about our new release (http://sguil.sf.net). If you guys would prefer I don't use this board for that purpose then please let me know.
Also, Richard Bejtlich (http://taosecurity.blogspot.com) received permission to post a chapter (http://sguil.sourceforge.net/downloads/tao_of_nsm_ch10_isbn_0321246772_copyright_2004_pea +rson.pdf) of his book (http://www.taosecurity.com/books.html) (The Tao of Network Security Monitoring: Beyond Intrusion Detection) online. The chapter is titled "Alert Data: NSM Using Sguil" and it provides detailed examples of using sguil and how all the pieces interrelate.
Bammkkkk
Also, Richard Bejtlich (http://taosecurity.blogspot.com) received permission to post a chapter (http://sguil.sourceforge.net/downloads/tao_of_nsm_ch10_isbn_0321246772_copyright_2004_pea +rson.pdf) of his book (http://www.taosecurity.com/books.html) (The Tao of Network Security Monitoring: Beyond Intrusion Detection) online. The chapter is titled "Alert Data: NSM Using Sguil" and it provides detailed examples of using sguil and how all the pieces interrelate.
Bammkkkk