nfdump is a toolset for collecting and processing netflow/ipfix and sflow data, sent from netflow/sflow compatible devices. It contains several collectors to collect flow data and can process and list flows in many different output formats, creating a wide range of statistics. It also has a powerful flow filter and can aggregate flows according to a user-defined number of elements. nfdump can enrich the listing of flows with geo location information and AS information, and can read and write flow files in various formats. It is compatible with nfdump-1.6.18 and can read files created with earlier versions. nfdump is now a multi-threaded program and uses parallel threads for reading, writing, and processing flows, as well as for sorting. It supports flexible length fields for netflow v9 and IPFIX, and has improved packet processing with nfpcapd. nfdump has new programs such as geolookup, which allows enriching IP addresses with country codes/locations and adding potential missing AS information. It also supports NSEL/ASA and NEL/NAT event logging.
This tool is not verified yet and doesn't have listed features.
Did you submit the verified tool? Sign in to add features.
Are you the author? Claim the tool by clicking the icon above. After claiming, you can add features.
Converts Sigma and Yara rules to CRYPTTECH's SIEM query language.
HonnyPotter is a WordPress plugin that logs all failed login attempts, with a caution to use it at your own risk.
RedELK enhances Red Team operations with SIEM capabilities to monitor and alert on Blue Team activities.
A Security Information and Event Management (SIEM) system with a focus on security and minimalism.
A visualization app for hpfeeds logs.
Elasticsearch is a versatile platform for centralized data storage, fast search, and scalable analytics.