Skip to content

v0.2.0 — Network Traffic Map

Latest

Choose a tag to compare

@nizartuanku nizartuanku released this 24 Aug 04:06
· 13 commits to main since this release
26f4484

Loglight now sees the network, not just the logs.

New in this release:

• NetFlow v5 / v9 / IPFIX ingest — add a netflow source, point your router or firewall's flow export at it (MikroTik, pfSense, FortiGate, Cisco, Ubiquiti). No agent, no packet capture; flow metadata only.
• 3D Network Map — a live, rotatable WebGL map of who talks to whom: node size = traffic, links = conversations, hosts with active detections glow by severity. Fully offline (vendored renderer, no CDN).
• Two new detections: Beaconing (regular-interval calls to one external endpoint — the C2 heartbeat) and New service (a host starts accepting connections on a never-seen port).
• The existing scan and exfiltration detectors now also fire from flow telemetry, and flow events feed the kill-chain correlator.

Upgrading: stop the binary, swap it, start again — the database migrates automatically, licenses unchanged.

Download: loglight-free-0.2.0-linux-amd64.tar.gz. Verify with SHA256SUMS (sha256sum -c SHA256SUMS). Apache-2.0.

Free edition: 1 source, 3-day retention. Pro/Team at whop.com/nizar-tuanku/loglight — 14-day trial.