Re: Sflow/netflow/ipfix open source security projects

2022-08-10 Thread Dave
Argus and the Argus Clients have quite a bit to offer in this line and they are open source. Check qosient.com for the GitHub information. Dave > On Aug 10, 2022, at 7:37 AM, Peter Phaal wrote: > > Sounds like an interesting project. You might want to take a look at > sflowtool to get starte

Re: Sflow/netflow/ipfix open source security projects

2022-08-10 Thread Peter Phaal
Sounds like an interesting project. You might want to take a look at sflowtool to get started. The following article shows how to use sflowtool to decode sFlow datagrams and includes a simple Python script matching IP addresses against a known threat database. https://blog.sflow.com/2018/12/sflow-

Sflow/netflow/ipfix open source security projects

2022-08-10 Thread Drew Weaver
Hello, I am interested in getting involved with an open source project in my spare time. I thought that it may be useful to contribute to an open source project that uses flow data to check for lateral movement inside of networks and also to check for known bads in remote connections. This se