YAIDS Logo

YAIDS

0
Free
Visit Website

YAIDS is a Multi-Threaded Intrusion Detection System using Yara. It's a performant, written in C, and supports any PCAP compatible data stream (Network, USB, Bluetooth, etc.). It supports BPF (traffic filtering), all valid Yara rules (including modules), and includes External Variables to build traffic/packet attribute conditions. It also includes multiple logging modes (alerts, PCAP data, console, file, etc.).

FEATURES

ALTERNATIVES

PFQ v6.2 is a functional framework for Linux optimized for efficient packet capture/transmission and in-kernel processing.

Django based web application for network traffic analysis with protocol handling capabilities.

Zeek Remote desktop fingerprinting script for fingerprinting Remote Desktop clients.

An IP address intelligence API that provides geolocation data and threat detection capabilities for IPv4 and IPv6 addresses.

Ensnare is a gem plugin for Ruby on Rails that enables quick deployment of a malicious behavior detection and response scheme using Honey Traps and Trap Responses.

A tool for classifying packets into flows based on 4-tuple without additional processing.

A private network system utilizing WireGuard for enhanced networking capabilities.

A tool for discovering and enumerating external attack surfaces