極楽せきゅあブログ

ときどきセキュリティ

Honeysnap

Honeysnap | The Honeynet Project
ほほー、なになに。

Honeysnap is a command line tool for parsing single or multiple  
packet capture data files and producing a first-cut analysis report  
that identifies significant events within the data captured in the  
network attack.  Honeysnap provides security analysts with a prepared  
menu of high value network activity, enabling manual forensic  
analysis and saving significant incident investigation time.   
Honeysnap is highly suitable for batch mode operation and automation.

なるほど、おもしろそーだ。今度コレ入れてみるかなー。解析の部分どんなことやっとるのか見てみたいところだなー。