Skip to content
Scripts to inject demo data and network traffic into an existing Alienvault/OSSIM installation
Perl PHP Makefile Shell Other
Branch: master
Clone or download

Latest commit

santiago-bassett Merge pull request #2 from packetinspector/master
Better? Randomization of pcap injections
Latest commit bc8c137 Feb 3, 2016

Files

Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
Daemon-Control-0.001006 New Proc Control Jul 21, 2014
assets Refined Pcaps Jul 22, 2014
misc Create user_form.php Sep 2, 2015
ossecwin Added files Jul 14, 2014
pcaps cosmetic changes Nov 17, 2015
plugins Updated for 5.1 Jul 21, 2015
screenshots Added Screenshots Jul 22, 2014
sonicwall Added files Jul 14, 2014
ssh Added files Jul 14, 2014
README.md Update README.md Jul 22, 2015
install.pl cosmetic changes Nov 17, 2015
runlogs.pl Refined Pcaps Jul 22, 2014
runpcaps.pl Real Close Jul 22, 2014

README.md

##Makes an AV install a demo box for fun and potential profit

This will add named assets with properties, logged in users, netflow, vulnerability scan, and more....

demo. demo. Dance!

####To install:

git clone https://github.com/packetinspector/Alienvault-Demo
cd Alienvault-Demo
perl install.pl

####Fast Install:

apt-get -y install git;git clone https://github.com/packetinspector/Alienvault-Demo;cd Alienvault-Demo/;perl install.pl

The script will do all the work. Nothing to do beforehand. Nothing to do afterhand. You can re-run it with no consequences

Need to start over?

alienvault-reconfig -c -d -v --rebuild_db;sleep 15;perl install.pl

The installer will install the generators, add them to startup, and run them. In case you want to start/stop them yourself..

/etc/init.d/runpcaps [start|stop|restart]
/etc/init.d/runlogs [start|stop|restart]

####Want to add your own pcaps?

  • Add them to the ./pcaps directory
  • Done
  • The IPs will be rewritten on playback to match the assets

####Want to add your own plugins/logs?

  • Add them to the plugins directory. Everything must have the same basename.
  • You can add .sql/.log/.cfg files.
  • Re-run the installer

####Log Samples Your .log files can just be copies of logs right off a system. No need to do anything.

You can have IPs substituted for you automatically by adding a variable into your logs

Key Replaced With
<RNDIP> Random IP, Totally made up. No bounds.
<OTXIP> IP From OTX. Uses DB from install

Where are all the logfiles going?

All the generated log files are put in /var/log/demologs They will be separated by plugin. A logrotate script for them is installed automatically.

####Screenshot ScreenShot

ScreenShot

ScreenShot

Forked from Santiago Bassett (@santiagobassett)

You can’t perform that action at this time.