Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.
weslambert edited this page Jan 26, 2016 · 33 revisions
  • Developed by Bamm Visscher:
    http://sguil.net

  • tcl/tk (not web-based)

  • Single central MySQL database

  • For login information, please see:
    https://github.com/Security-Onion-Solutions/security-onion/wiki/Passwords#sguil

  • Data types:

    • NIDS alerts from Snort/Suricata (if snort_agent is enabled)
    • HIDS alerts from OSSEC (if ossec_agent is enabled)
    • session data from PRADS (if PRADS and sancp_agent are enabled)
    • asset data from PRADS (if PRADS and pads_agent are enabled)
    • HTTP logs from Bro (if http_agent is enabled)
  • Can pivot to transcript/Wireshark/NetworkMiner by right-clicking the Alert ID field.

  • Pivot to ELSA by right-clicking an IP address and choosing "ELSA IP Lookup".
Clone this wiki locally