<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>network Archives - Tech Chronicles</title>
	<atom:link href="http://kostacipo.stream/tag/network/feed/" rel="self" type="application/rss+xml" />
	<link>http://kostacipo.stream/tag/network/</link>
	<description>Ramblings of a Tech Dude</description>
	<lastBuildDate>Sat, 02 Mar 2024 23:16:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>

<image>
	<url>https://kostacipo.stream/wp-content/uploads/2019/12/cropped-profile-32x32.jpg</url>
	<title>network Archives - Tech Chronicles</title>
	<link>http://kostacipo.stream/tag/network/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>NTLM Relay Gat – Automating Exploitation Of NTLM Relay Vulnerabilities</title>
		<link>http://kostacipo.stream/ntlm-relay-gat-automating-exploitation-of-ntlm-relay-vulnerabilities/</link>
					<comments>http://kostacipo.stream/ntlm-relay-gat-automating-exploitation-of-ntlm-relay-vulnerabilities/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Sat, 02 Mar 2024 23:16:38 +0000</pubDate>
				<category><![CDATA[Exploitation Tools]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Networks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[ntlm]]></category>
		<guid isPermaLink="false">https://kostacipo.stream/?p=2196</guid>

					<description><![CDATA[<p>NTLM Relay Gat revolutionizes the approach to exploiting NTLM relay vulnerabilities by automating the use of the Impacket suite’s ntlmrelayx.py tool. Designed for both novices and experienced cybersecurity professionals, this tool streamlines the process of identifying and exploiting weaknesses in network security. With its user-friendly interface and powerful features, NTLM Relay Gat serves as a [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/ntlm-relay-gat-automating-exploitation-of-ntlm-relay-vulnerabilities/">NTLM Relay Gat – Automating Exploitation Of NTLM Relay Vulnerabilities</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>NTLM Relay Gat revolutionizes the approach to exploiting NTLM relay vulnerabilities by automating the use of the Impacket suite’s ntlmrelayx.py tool.</p>
<p>Designed for both novices and experienced cybersecurity professionals, this tool streamlines the process of identifying and exploiting weaknesses in network security.</p>
<p>With its user-friendly interface and powerful features, NTLM Relay Gat serves as a critical asset in the toolkit of ethical hackers and penetration testers aiming to enhance their network defense strategies.</p>
<h2 class="wp-block-heading"><strong>Description</strong></h2>
<p>NTLM Relay Gat is a powerful tool designed to automate the exploitation of NTLM relays using <code>ntlmrelayx.py</code> from the Impacket tool suite. By leveraging the capabilities of <code>ntlmrelayx.py</code>, NTLM Relay Gat streamlines the process of exploiting NTLM relay vulnerabilities, offering a range of functionalities from listing SMB shares to executing commands on MSSQL databases.</p>
<h2 class="wp-block-heading"><strong>Features</strong></h2>
<ul>
<li><strong>Multi-threading Support</strong>: Utilize multiple threads to perform actions concurrently.</li>
<li><strong>SMB Shares Enumeration</strong>: List available SMB shares.</li>
<li><strong>SMB Shell Execution</strong>: Execute a shell via SMB.</li>
<li><strong>Secrets Dumping</strong>: Dump secrets from the target.</li>
<li><strong>MSSQL Database Enumeration</strong>: List available MSSQL databases.</li>
<li><strong>MSSQL Command Execution</strong>: Execute operating system commands via xp_cmdshell or start SQL Server Agent jobs.</li>
</ul>
<h2 class="wp-block-heading"><strong>Prerequisites</strong></h2>
<p>Before you begin, ensure you have met the following requirements:</p>
<ul>
<li><code>proxychains</code> properly configured with ntlmrelayx SOCKS relay port</li>
<li>Python 3.6+</li>
</ul>
<h2 class="wp-block-heading"><strong>Installation</strong></h2>
<p>To install NTLM Relay Gat, follow these steps:</p>
<ol>
<li>Ensure that Python 3.6 or higher is installed on your system.</li>
<li>Clone NTLM Relay Gat repository:</li>
</ol>
<pre class="wp-block-code"><code>git clone https://github.com/ad0nis/ntlm_relay_gat.git
cd ntlm_relay_gat</code></pre>
<p>Install dependencies, if you don’t have them installed already:</p>
<pre class="wp-block-code"><code>pip install -r requirements.txt</code></pre>
<p>NTLM Relay Gat is now installed and ready to use.</p>
<h2 class="wp-block-heading"><strong>Usage</strong></h2>
<p>To use NTLM Relay Gat, make sure you’ve got relayed sessions in <code>ntlmrelayx.py</code>‘s <code>socks</code> command output and that you have proxychains configured to use <code>ntlmrelayx.py</code>‘s proxy, and then execute the script with the desired options. Here are some examples of how to run NTLM Relay Gat:</p>
<pre class="wp-block-code"><code># List available SMB shares using 10 threads
python ntlm_relay_gat.py --smb-shares -t 10

# Execute a shell via SMB
python ntlm_relay_gat.py --smb-shell --shell-path /path/to/shell

# Dump secrets from the target
python ntlm_relay_gat.py --dump-secrets

# List available MSSQL databases
python ntlm_relay_gat.py --mssql-dbs

# Execute an operating system command via xp_cmdshell
python ntlm_relay_gat.py --mssql-exec --mssql-method 1 --mssql-command 'whoami'</code></pre>
<p>The post <a href="http://kostacipo.stream/ntlm-relay-gat-automating-exploitation-of-ntlm-relay-vulnerabilities/">NTLM Relay Gat – Automating Exploitation Of NTLM Relay Vulnerabilities</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/ntlm-relay-gat-automating-exploitation-of-ntlm-relay-vulnerabilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Network Protocols</title>
		<link>http://kostacipo.stream/network-protocols/</link>
					<comments>http://kostacipo.stream/network-protocols/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Mon, 02 Nov 2020 19:46:54 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Networks]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[protocols]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1863</guid>

					<description><![CDATA[<p>It is essential to know the fundamentals of how the networks work. The first step in understanding the composition of a network is to understand how network devices communicate with each other. This knowledge applies to an organization&#8217;s network and to more extensive networks like the web. The same principles apply to all networks. Network [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/network-protocols/">Network Protocols</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It is essential to know the fundamentals of how the networks work. The first step in understanding the composition of a network is to understand how network devices communicate with each other. This knowledge applies to an organization&#8217;s network and to more extensive networks like the web. The same principles apply to all networks.</p>
<h2 id="network-protocols">Network protocols</h2>
<p>A network protocol is a set of conditions and rules that specify how network devices communicate on a given network. It provides a common framework for establishing and maintaining a communications channel, and how to handle errors or faults should they occur. Network protocols allow communication between different network-enabled devices, for example, laptops, tablets, smartphones, desktops, servers, and other network-enabled devices.</p>
<p>The network protocol is an essential building block in the design of an organization&#8217;s network architecture. There are many network protocols available. Each network protocol has many properties that govern its use and implementation.</p>
<p>Let&#8217;s define a few terms before we look at some of the commonly used network protocols.</p>
<h3 id="what-is-a-network-address">What is a network address?</h3>
<p>A network address is a unique identifier that identifies a network-enabled device. A network-enabled device might have more than one address type. Although there are more address types, for this discussion, we&#8217;ll focus on only two of these address types.</p>
<p>The first type is a media access control (MAC) address that identifies the network interface on the hardware level. The second type is an Internet Protocol (IP) address that identifies the network interface on a software level.</p>
<p>We&#8217;ll explore these two address types in more detail later.</p>
<h3 id="what-is-a-data-packet">What is a data packet?</h3>
<p>A data packet is a unit that&#8217;s used to describe the message two devices on a network send each other. A data packet consists of raw data, headers, and potentially also a trailer. The header contains several information items. For example, it includes the sender and destination device addresses, the size of the packet, the protocol used, and the packet number. The trailer in a data packet deals with error checking.</p>
<p>The concept is similar to sending someone a letter in the mail. But instead of sending several pages in one envelope, each page is sent in a separate envelope. Enough information is sent in each envelope to allow the recipient to piece together the complete message after they have all the pages.</p>
<h3 id="what-is-a-datagram">What is a datagram?</h3>
<p>A datagram is considered the same as a data packet. Datagrams commonly refer to data packets of an unreliable service, where delivery can&#8217;t be guaranteed.</p>
<h3 id="what-is-routing">What is routing?</h3>
<p>Routing, in the context of networks, refers to the mechanism used to make sure that data packets follow the correct delivery path between the sending and receiving devices on different networks.</p>
<p>For example, think about the PC you&#8217;re using and the server that&#8217;s serving the page you&#8217;re currently reading. Multiple networks might connect your PC and the server, and various paths might be available between these two devices.</p>
<h2 id="protocol-categories">Protocol categories</h2>
<p>Several types of applications and hardware devices depend on specific network protocols on a typical network. For example, browsing the internet by using a web browser relies on a different protocol than sending or receiving an email. Converting the data that you see in the browser and sending this information over the network requires another protocol.</p>
<p>Protocols fall into three categories:</p>
<ul>
<li>Network communication protocols</li>
<li>Network security protocols</li>
<li>Network management protocols</li>
</ul>
<p>Let&#8217;s have a look at some of the protocols in these categories.</p>
<h2 id="network-communication-protocols">Network communication protocols</h2>
<p>Communication protocols focus on establishing and maintaining a connection between devices. As you work with different devices and network services, you&#8217;ll make use of various network communication protocols.</p>
<p>First, we need to define three foundational protocols of all internet-based networks. These three protocols are Transmission Control Protocol (TCP), Internet Protocol (IP), and User Datagram Protocol (UDP). These protocols are concerned with the logical transmission of data over the network.</p>
<ul>
<li><strong>Transmission Control Protocol</strong>: TCP chunks up data into data packets that can be sent securely and quickly while minimizing the chance of data loss. It provides a stable and reliable mechanism for the delivery of data packets across an IP-based network. Even though TCP is an effective connection-oriented protocol, it has overhead.</li>
<li><strong>Internet Protocol</strong>: IP is responsible for the addressing of a data packet. IP encapsulates the data packet to be delivered and adds an address header. The header contains information on the sender and recipient IP addresses. This protocol isn&#8217;t concerned about the order in which the packets are sent or received. It also doesn&#8217;t guarantee that a packet will be delivered, only the address.</li>
<li><strong>User Datagram Protocol</strong>: UDP is a connectionless protocol that offers a low-latency and loss-tolerant implementation. UDP is used with processes that don&#8217;t need to verify that the recipient device received a datagram.</li>
</ul>
<p>The rest of the protocols that we&#8217;ll discuss here are based on a type of application, for example, an email client or a web browser. Here are the most commonly used network communication protocols:</p>
<ul>
<li><strong>Hypertext Transfer Protocol (HTTP)</strong>: The HTTP protocol uses TCP/IP to deliver web page content from a server to your browser. HTTP can also handle the download and upload of files from remote servers.</li>
<li><strong>File Transfer Protocol (FTP)</strong>: FTP is used to transfer files between different computers on a network. Typically, FTP is used to upload files to a server from a remote location. While you can use FTP to download files, web-based downloads are typically handled through HTTP.</li>
<li><strong>Post Office Protocol 3 (POP3)</strong>: POP3 is one of three email protocols. It&#8217;s most commonly used by an email client to allow you to receive emails. This protocol uses TCP for the management and delivery of an email.</li>
<li><strong>Simple Mail Transfer Protocol (SMTP)</strong>: SMTP is another one of the three email protocols. It&#8217;s most commonly used to send emails from an email client via an email server. This protocol uses the TCP for management and transmission of the email.</li>
<li><strong>Interactive Mail Access Protocol (IMAP)</strong>: IMAP is the more powerful of the three email protocols. With IMAP and an email client, you can manage a single mailbox on an email server in your organization.</li>
</ul>
<h2 id="network-security-protocols">Network security protocols</h2>
<p>Network security protocols are designed to maintain the security and network of data across your network. These protocols encrypt in-transmission messages between users, services, and applications.</p>
<p>Network security protocols use encryption and cryptographic principles to secure messages.</p>
<p>To implement a secure network, you must match the right security protocols for your needs. The following list explores the leading network security protocols:</p>
<ul>
<li><strong>Secure Socket Layer (SSL)</strong>: SSL is a standard encryption and security protocol. It provides a secure and encrypted connection between your computer and the target server or device that you accessed over the internet.</li>
<li><strong>Transport Layer Security (TLS)</strong>: TLS is the successor to SSL and provides a stronger and more robust security encryption protocol. Based on the Internet Engineering Task Force (IETF) standard, it&#8217;s designed to stop message forgery and tampering and eavesdropping. It&#8217;s typically used to protect web browser communications, email, VoIP, and instant messaging. While TLS is now used, the replacement security protocol is often still called SSL.</li>
<li><strong>Hypertext Transfer Protocol Secure (HTTPS)</strong>: HTTPS provides a more secure version of the standard HTTP protocol by using the TLS or SSL encryption standard. This combination of protocols ensures that all data transmitted between the server and the web browser is encrypted and secure from eavesdropping or data packet sniffing. The same principle is applied to the POP, SMTP, and IMAP protocols listed previously to create secure versions known as POPS, SMTPS, and IMAPS.</li>
<li><strong>Secure Shell (SSH)</strong>: SSH is a cryptographic network security protocol that provides a secure data connection across a network. SSH is designed to support command-line execution of instructions, which includes remote authentication to servers. FTP uses many of the SSH functions to provide a secure file transfer mechanism.</li>
<li><strong>Kerberos</strong>: This validation protocol provides a robust authentication for client-server-based applications through secret-key cryptography. Kerberos assumes that all endpoints in the network are insecure. It enforces strong encryption for all communications and data at all times.</li>
</ul>
<h2 id="network-management-protocols">Network management protocols</h2>
<p>In your network, it&#8217;s perfectly acceptable to have multiple different protocols running concurrently. Previously, we discussed communications and security protocols. Equally important to the successful day-to-day running and operating of a network are the management protocols. The focus of this type of protocol is the sustainability of the network by looking at faults and performance.</p>
<p>Network administrators need to monitor their networks and any devices attached to them. Each device in your network exposes some indicators about the state and health of the device. These indicators are requested by the network administrator tool and can be used for monitoring and reporting.</p>
<p>Two network management protocols are available:</p>
<ul>
<li><strong>Simple Network Management Protocol (SNMP)</strong>: SNMP is an internet protocol that allows for the collection of data from devices on your network and the management of those devices. The device has to support SNMP to gather information. Devices that typically support SNMP include switches, routers, servers, laptops, desktops, and printers.</li>
<li><strong>Internet Control Message Protocol (ICMP)</strong>: ICMP is one of the protocols included within the Internet Protocol suite (IPS). It allows network-connected devices to send warning and error messages, along with operation information about the success or failure of a connection request, or if a service is unavailable. Unlike other network transport protocols like UDP and TCP, ICMP isn&#8217;t used to send or receive data from devices on the network.</li>
</ul>
<h3 id="ports">Ports</h3>
<p>A port is a logical construct that allows the routing of incoming messages to specific processes. There&#8217;s a particular port for every type of IPS. A port is an unsigned 16-bit number in the range 0 to 65535 and is also known as a port number. Ports are assigned by the sending TCP or UDP layer based on the communications protocol used.</p>
<p>There are specific port numbers reserved for every service. The first 1,024 ports, called the well-known port numbers, are reserved for the commonly used services. The high-numbered ports, called the ephemeral ports, are unreserved and used by dedicated applications.</p>
<p>Every port links to a specific service or communications protocol. It means that the target network device, say a server, can receive multiple requests on each port and service each of them without conflict.</p>
<h3 id="well-known-port-numbers">Well-known port numbers</h3>
<p>Much in the same way that IP addresses are split into classes, so are ports. There are three ranges of ports: the well-known ports, the registered ports, and the dynamic/private ports.</p>
<p>The Internet Assigned Numbers Authority (IANA) manages the allocation of port numbers, the regional assignment of IP addresses, and Domain Name System (DNS) root zones. IANA also manages a central repository for protocol names and the registry used in internet protocols.</p>
<p>The following table lists some of the more common well-known port numbers.</p>
<div class="table-scroll-wrapper">
<table class="table">
<caption class="visually-hidden">Well-known port numbers</caption>
<thead>
<tr>
<th>Port number</th>
<th>Assignment</th>
</tr>
</thead>
<tbody>
<tr>
<td>20</td>
<td>File Transfer Protocol for data transfer</td>
</tr>
<tr>
<td>21</td>
<td>File Transfer Protocol for command control</td>
</tr>
<tr>
<td>22</td>
<td>Secure Shell for secure authentication</td>
</tr>
<tr>
<td>23</td>
<td>Telnet remote authentication service for unencrypted text messages</td>
</tr>
<tr>
<td>25</td>
<td>Simple Mail Transfer Protocol for email routing</td>
</tr>
<tr>
<td>53</td>
<td>Domain Name System service</td>
</tr>
<tr>
<td>80</td>
<td>Hypertext Transfer Protocol for use in the web</td>
</tr>
<tr>
<td>110</td>
<td>Post Office Protocol</td>
</tr>
<tr>
<td>119</td>
<td>Network News Transfer Protocol (NNTP)</td>
</tr>
<tr>
<td>123</td>
<td>Network Time Protocol (NTP)</td>
</tr>
<tr>
<td>143</td>
<td>Internet Message Access Protocol for management of digital mail</td>
</tr>
<tr>
<td>161</td>
<td>Simple Network Management Protocol</td>
</tr>
<tr>
<td>194</td>
<td>Internet Relay Chat (IRC)</td>
</tr>
<tr>
<td>443</td>
<td>HTTP Secure HTTP over TLS/SSL</td>
</tr>
</tbody>
</table>
</div>
<h2 id="internet-protocol-suite">Internet Protocol suite</h2>
<p>The Internet Protocol suite is a collection of communication protocols, also called a protocol stack. It&#8217;s also sometimes referred to as the TCP/IP protocol suite since both TCP and IP are primary protocols used in the suite.</p>
<p>The IPS is an abstract, layered networking reference model. The IPS describes the different layered protocols used to send and receive data on the internet and similar networks.</p>
<p>The IPS model is one of several similar networking models that varies between three and seven layers. The best-known model is the Open Systems Interconnection (OSI) networking reference model. We&#8217;re not going to cover the OSI model here. A documentation link is available in the &#8220;Learn more&#8221; section at the end of this module.</p>
<p><span class="mx-imgBorder"> <img decoding="async" src="https://docs.microsoft.com/en-us/learn/modules/network-fundamentals/media/4-internet-protocol-suite-layers.svg" alt="Table that shows the four layers of the Internet Protocol suite and the protocols used on each layer." data-linktype="relative-path"> </span></p>
<ul>
<li><strong>Application layer</strong>: The top layer of this stack is concerned with application or process communication. The application layer is responsible for determining which communication protocols to use based on what type of message is transmitted. For example, the layer assigns the correct email protocols such as POP, SMTP, or IMAP if the message is email content.</li>
<li><strong>Transport layer</strong>: This layer is responsible for host-to-host communication on the network. The protocols associated with this layer are TCP and UDP. TCP is responsible for flow control. UDP is responsible for providing a datagram service.</li>
<li><strong>Internet layer</strong>: This layer is responsible for exchanging datagrams. A datagram contains the data from the transport layer and adds in the origin and recipient IP addresses. The protocols associated with this layer are IP, ICMP, and the Internet Protocol Security (IPsec) suite.</li>
<li><strong>Network access layer</strong>: The bottom layer of this stack is responsible for defining how the data is sent across the network. The protocols associated with this layer are ARP, MAC, Ethernet, DSL, and ISDN.</li>
</ul>
<p>The post <a href="http://kostacipo.stream/network-protocols/">Network Protocols</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/network-protocols/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Nfstream &#8211; A Flexible Network Data Analysis Framework</title>
		<link>http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/</link>
					<comments>http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Fri, 07 Feb 2020 10:29:59 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[data analysis]]></category>
		<category><![CDATA[network]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1745</guid>

					<description><![CDATA[<p>&#160; nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/">Nfstream &#8211; A Flexible Network Data Analysis Framework</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p><strong>nfstream</strong> is a Python package providing fast, flexible, and expressive data structures designed to make working with <strong>online</strong> or <strong>offline</strong> network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, <strong>real world</strong> network data analysis in Python. Additionally, it has the broader goal of becoming <strong>a common network data processing framework for researchers</strong> providing data reproducibility across experiments.<br /><a name="more"></a><br /><b>Main Features</b></p>
<ul>
<li><strong>Performance:</strong> <strong>nfstream</strong> is designed to be fast (x10 faster with pypy3 support) with a small CPU and memory footprint.</li>
<li><strong>Layer-7 visibility:</strong> <strong>nfstream</strong> deep packet inspection engine is based on <a title="a flexible network data analysis framework. (15)" href="https://github.com/ntop/nDPI" target="_blank" rel="nofollow noopener noreferrer"><strong>nDPI</strong></a>. It allows nfstream to perform <a title="a flexible network data analysis framework. (16)" href="http://people.ac.upc.edu/pbarlet/papers/ground-truth.pam2014.pdf" target="_blank" rel="nofollow noopener noreferrer"><strong>reliable</strong></a> encrypted applications identification and metadata extraction (e.g. TLS, QUIC, TOR, HTTP, SSH, DNS).</li>
<li><strong>Flexibility:</strong> add a flow feature in 2 lines as an <a title="a flexible network data analysis framework. (18)" href="https://nfstream.readthedocs.io/en/latest/plugins.html" target="_blank" rel="nofollow noopener noreferrer"><strong>NFPlugin</strong></a>.</li>
<li><strong>Machine Learning oriented:</strong> add your trained model as an <a title="a flexible network data analysis framework. (19)" href="https://nfstream.readthedocs.io/en/latest/plugins.html" target="_blank" rel="nofollow noopener noreferrer"><strong>NFPlugin</strong></a>.</li>
</ul>
<p><b>How to use it?</b></p>
<ul>
<li>Dealing with a big pcap file and just want to aggregate it as network flows? <strong>nfstream</strong> make this path easier in few lines:</li>
</ul>
<div>
<pre><code>   from nfstream import NFStreamer
   my_awesome_streamer = NFStreamer(source="facebook.pcap") # or network interface (source="eth0")
   for flow in my_awesome_streamer:
       print(flow)  # print it, append to pandas Dataframe or whatever you want :)!</code></pre>
</div>
<div>
<pre><code>    NFEntry(
        id=0,
        first_seen=1472393122365,
        last_seen=1472393123665,
        version=4,
        src_port=52066,
        dst_port=443,
        protocol=6,
        vlan_id=0,
        src_ip='192.168.43.18',
        dst_ip='66.220.156.68',
        total_packets=19,
        total_bytes=5745,
        duration=1300,
        src2dst_packets=9,
        src2dst_bytes=1345,
        dst2src_packets=10,
        dst2src_bytes=4400,
        expiration_id=0,
        master_protocol=91,
        app_protocol=119,
        application_name='TLS.Facebook',
        category_name='SocialNetwork',
        client_info='facebook.com',
        server_info='*.facebook.com',
        j3a_client='bfcc1a3891601edb4f137ab7ab25b840',
        j3a_server='2d1eb5817ece335c24904f516ad5da12'
    )</code></pre>
</div>
<ul>
<li>From pcap to Pandas DataFrame?</li>
</ul>
<div>
<pre><code>    import pandas as pd 
    streamer_awesome = NFStreamer(source='devil.pcap')
    data = []
    for flow in streamer_awesome:
       data.append(flow.to_namedtuple())
    my_df = pd.DataFrame(data=data)
    my_df.head(5) # Enjoy!</code></pre>
</div>
<ul>
<li>Didn&#8217;t find a specific flow feature? add a plugin to <strong>nfstream</strong> in few lines:</li>
</ul>
<div>
<pre><code>    from nfstream import NFPlugin

    class my_awesome_plugin(NFPlugin):
        def on_update(self, obs, entry):
            if obs.length &gt;= 666:
                entry.my_awesome_plugin += 1
  
   streamer_awesome = NFStreamer(source='devil.pcap', plugins=[my_awesome_plugin()])
   for flow in streamer_awesome:
      print(flow.my_awesome_plugin) # see your dynamically created metric in generated flows</code></pre>
</div>
<ul>
<li>More example and details are provided on the official <a title="a flexible network data analysis framework. (20)" href="https://readthedocs.org/projects/nfstream/downloads/pdf/latest/" target="_blank" rel="nofollow noopener noreferrer"><strong>documentation</strong></a>.</li>
</ul>
<p><b>Prerequisites</b></p>
<div>
<pre><code>    apt-get install libpcap-dev</code></pre>
</div>
<p><b>Installation</b></p>
<p><b>Using pip</b><br />Binary installers for the latest released version are available:</p>
<div>
<pre><code>    pip3 install nfstream</code></pre>
</div>
<p><b>Build from source</b><br />If you want to build <strong>nfstream</strong> on your local machine:</p>
<div>
<pre><code>    git clone https://github.com/aouinizied/nfstream.git
    cd nfstream
    python3 setup.py install</code></pre>
</div>
<p><b>Contributing</b><br />Please read <a title="a flexible network data analysis framework. (21)" href="https://nfstream.readthedocs.io/en/latest/contributing.html" target="_blank" rel="nofollow noopener noreferrer"><strong>Contributing</strong></a> for details on our code of conduct, and the process for submitting pull requests to us.</p>
<p><b>Authors</b><br /><a title="a flexible network data analysis framework. (22)" href="https://www.linkedin.com/in/dr-zied-aouini" target="_blank" rel="nofollow noopener noreferrer"><strong>Zied Aouini</strong></a> created <strong>nfstream</strong> and <a title="a flexible network data analysis framework. (23)" href="https://github.com/aouinizied/nfstream/graphs/contributors" target="_blank" rel="nofollow noopener noreferrer"><strong>these fine people</strong></a> have contributed.</p>
<p><b>Ethics</b><br /><strong>nfstream</strong> is intended for network data research and forensics. Researchers and network data scientists can use these framework to build reliable datasets, train and evaluate network applied machine learning models. As with any packet monitoring tool, <strong>nfstream</strong> could potentially be misused. <strong>Do not run it on any network of which you are not the owner or the administrator</strong>.</p>
<p><b><a class="kiploit-download" title="Download Nfstream" href="https://github.com/aouinizied/nfstream" target="_blank" rel="nofollow noopener noreferrer">Download Nfstream</a></b></p>
<p>The post <a href="http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/">Nfstream &#8211; A Flexible Network Data Analysis Framework</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Top 32 Nmap Commands For Linux Sys/Network Admins</title>
		<link>http://kostacipo.stream/top-32-nmap-commands-for-linux-sys-network-admins/</link>
					<comments>http://kostacipo.stream/top-32-nmap-commands-for-linux-sys-network-admins/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Thu, 23 Jan 2020 13:30:06 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[pentest]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1693</guid>

					<description><![CDATA[<p>&#160; Nmap is short for Network Mapper. It is an open source security tool for network exploration, security scanning and auditing. However, nmap command comes with lots of options that can make the utility more robust and difficult to follow for new users. The purpose of this post is to introduce a user to the [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/top-32-nmap-commands-for-linux-sys-network-admins/">Top 32 Nmap Commands For Linux Sys/Network Admins</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p><span class="drop_cap">N</span>map is short for Network Mapper. It is an open source security tool for network exploration, security scanning and auditing. However, nmap command comes with lots of options that can make the utility more robust and difficult to follow for new users. The purpose of this post is to introduce a user to the nmap command line tool to scan a host and/or network, so to find out the possible vulnerable points in the hosts. You will also learn how to use Nmap for offensive and defensive purposes.</p>
<p>Let us see some common nmap command examples.</p>
<p><center></center></p>
<figure id="attachment_276" class="wp-caption aligncenter" aria-describedby="caption-attachment-276"><a href="https://www.cyberciti.biz/networking/nmap-command-examples-tutorials/attachment/welcome-nmap/" rel="attachment wp-att-276"><img fetchpriority="high" decoding="async" class="size-full wp-image-276" title="Nmap Tutorial / Examples PDF Download" src="https://www.cyberciti.biz/media/new/cms/2012/11/welcome-nmap.png" sizes="(max-width: 593px) 85vw, 593px" srcset="https://www.cyberciti.biz/media/new/cms/2012/11/welcome-nmap.png 593w, https://www.cyberciti.biz/media/new/cms/2012/11/welcome-nmap-300x223.png 300w" alt="nmap in action" width="593" height="441"></a><figcaption id="caption-attachment-276" class="wp-caption-text"><em>nmap in action</em></figcaption></figure>
<h2>What is Nmap and what is it used for?</h2>
<p>From the man page:</p>
<blockquote>
<p>Nmap (“Network Mapper”) is an open source tool for network exploration and security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. While Nmap is commonly used for security audits, many systems and network administrators find it useful for routine tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime.</p>
</blockquote>
<p>It was originally written by Gordon Lyon and it can answer the following questions easily:</p>
<ol>
<li>What computers did you find running on the local network?</li>
<li>What IP addresses did you find running on the local network?</li>
<li>What is the operating system of your target machine?</li>
<li>Find out what ports are open on the machine that you just scanned?</li>
<li>Find out if the system is infected with malware or virus.</li>
<li>Search for unauthorized servers or network service on your network.</li>
<li>Find and remove computers which don’t meet the organization’s minimum level of security.</li>
</ol>
<h2>Sample setup (LAB)</h2>
<p>Port scanning may be illegal in some jurisdictions. So setup a lab as follows:</p>
<pre>                              +---------+
        +---------+           | Network |         +--------+
        | server1 |-----------+ swtich  +---------|server2 |
        +---------+           | (sw0)   |         +--------+
                              +----+----+
                                   | 
                                   |
                         +---------+----------+
                         | wks01 Linux/OSX    |
                         +--------------------+
</pre>
<p>Where,</p>
<ul>
<li>wks01 is your computer either running Linux/OS X or Unix like operating system. It is used for scanning your local network. The nmap command must be installed on this computer.</li>
<li>server1 can be powered by Linux / Unix / MS-Windows operating systems. This is an unpatched server. Feel free to install a few services such as a web-server, file server and so on.</li>
<li>server2 can be powered by Linux / Unix / MS-Windows operating systems. This is a&nbsp;<a title="See how to setup Linux firewall" href="https://www.cyberciti.biz/tips/linux-iptables-examples.html">fully patched server with firewall</a>. Again, feel free to install few services such as a web-server, file server and so on.</li>
<li>All three systems are connected via switch.</li>
</ul>
<h2>#1: Scan a single host or an IP address (IPv4)</h2>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="bash">### Scan a single ip address ###
nmap 192.168.1.1
&nbsp;
## Scan a host name ###
nmap server1.cyberciti.biz
&nbsp;
## Scan a host name with more info###
nmap -v server1.cyberciti.biz</pre>
</td>
</tr>
</tbody>
</table>
</div>
<p>&nbsp;</p>
<p><em>Sample outputs:</em></p>
<figure class="wp-caption alignnone"><a href="https://www.cyberciti.biz/faq/howto-install-nmap-on-centos-rhel-redhat-enterprise-linux/"><img decoding="async" title="Fig.01: nmap output" src="https://s0.cyberciti.org/uploads/faq/2012/11/redhat-nmap-command-output.png" alt="Fig.01: nmap output" width="592" height="176"></a><figcaption class="wp-caption-text"><em>Fig.01: nmap output</em></figcaption></figure>
<h2>#2: Scan multiple IP address or subnet (IPv4)</h2>
<pre>nmap 192.168.1.1 192.168.1.2 192.168.1.3
## works with same subnet i.e. 192.168.1.0/24 
nmap 192.168.1.1,2,3
</pre>
<p>You can scan a range of IP address too:</p>
<pre>nmap 192.168.1.1-20</pre>
<p>You can scan a range of IP address using a wildcard:</p>
<pre>nmap 192.168.1.*</pre>
<p>Finally, you scan an entire subnet:</p>
<pre>nmap 192.168.1.0/24</pre>
<h2>#3: Read list of hosts/networks from a file (IPv4)</h2>
<p>The -iL option allows you to read the list of target systems using a text file. This is useful to scan a large number of hosts/networks. Create a text file as follows:<br /><code>cat &gt; /tmp/test.txt</code></p>
<p><em>Sample outputs:</em></p>
<pre>server1.cyberciti.biz
192.168.1.0/24
192.168.1.1/24
10.1.2.3
localhost
</pre>
<p>The syntax is:</p>
<pre>nmap -iL /tmp/test.txt</pre>
<h2>#4: Excluding hosts/networks (IPv4)</h2>
<p>When scanning a large number of hosts/networks you can exclude hosts from a scan:</p>
<pre>nmap 192.168.1.0/24 --exclude 192.168.1.5
nmap 192.168.1.0/24 --exclude 192.168.1.5,192.168.1.254</pre>
<p>OR exclude list from a file called /tmp/exclude.txt</p>
<pre>nmap -iL /tmp/scanlist.txt --excludefile /tmp/exclude.txt</pre>
<h2>#5: Turn on OS and version detection scanning script (IPv4)</h2>
<pre>nmap -A 192.168.1.254
nmap -v -A 192.168.1.1
nmap -A -iL /tmp/scanlist.txt </pre>
<h2>#6: Find out if a host/network is protected by a firewall</h2>
<pre>nmap -sA 192.168.1.254
nmap -sA server1.cyberciti.biz</pre>
<h2>#7: Scan a host when protected by the firewall</h2>
<pre>nmap -PN 192.168.1.1
nmap -PN server1.cyberciti.biz</pre>
<h2>#8: Scan an IPv6 host/address</h2>
<p>The&nbsp;<kbd>-6</kbd>&nbsp;option enable IPv6 scanning. The syntax is:</p>
<pre>nmap -6 IPv6-Address-Here
nmap -6 server1.cyberciti.biz
nmap -6 2607:f0d0:1002:51::4
nmap -v A -6 2607:f0d0:1002:51::4</pre>
<h2>#9: Scan a network and find out which servers and devices are up and running</h2>
<p>This is known as host discovery or ping scan:</p>
<pre>nmap -sP 192.168.1.0/24</pre>
<p><em>Sample outputs:</em></p>
<pre>Host 192.168.1.1 is up (0.00035s latency).
MAC Address: BC:AE:C5:C3:16:93 (Unknown)
Host 192.168.1.2 is up (0.0038s latency).
MAC Address: 74:44:01:40:57:FB (Unknown)
Host 192.168.1.5 is up.
Host nas03 (192.168.1.12) is up (0.0091s latency).
MAC Address: 00:11:32:11:15:FC (Synology Incorporated)
Nmap done: 256 IP addresses (4 hosts up) scanned in 2.80 second</pre>
<h2>#10: How do I perform a fast scan?</h2>
<pre>nmap -F 192.168.1.1</pre>
<h2>#11: Display the reason a port is in a particular state</h2>
<pre>nmap --reason 192.168.1.1
nmap --reason server1.cyberciti.biz</pre>
<h2>#12: Only show open (or possibly open) ports</h2>
<pre>nmap --open 192.168.1.1
nmap --open server1.cyberciti.biz</pre>
<h2>#13: Show all packets sent and received</h2>
<pre>nmap --packet-trace 192.168.1.1
nmap --packet-trace server1.cyberciti.biz</pre>
<h2>14#: Show host interfaces and routes</h2>
<p>This is useful for debugging (<a href="https://www.cyberciti.biz/faq/howto-linux-configuring-default-route-with-ipcommand/">ip command</a>&nbsp;or&nbsp;<a href="https://www.cyberciti.biz/faq/what-is-a-routing-table/">route command</a>&nbsp;or&nbsp;<a href="https://www.cyberciti.biz/faq/linux-unix-open-ports/">netstat command</a>&nbsp;like output using nmap)</p>
<pre>nmap --iflist</pre>
<p><em>Sample outputs:</em></p>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="ini">Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 02:01 IST
************************INTERFACES************************
DEV    (SHORT)  IP/MASK          TYPE        UP MAC
lo     (lo)     127.0.0.1/8      loopback    up
eth0   (eth0)   192.168.1.5/24   ethernet    up B8:AC:6F:65:31:E5
vmnet1 (vmnet1) 192.168.121.1/24 ethernet    up 00:50:56:C0:00:01
vmnet8 (vmnet8) 192.168.179.1/24 ethernet    up 00:50:56:C0:00:08
ppp0   (ppp0)   10.1.19.69/32    point2point up
&nbsp;
**************************ROUTES**************************
DST/MASK         DEV    GATEWAY
10.0.31.178/32   ppp0
209.133.67.35/32 eth0   192.168.1.2
192.168.1.0/0    eth0
192.168.121.0/0  vmnet1
192.168.179.0/0  vmnet8
169.254.0.0/0    eth0
10.0.0.0/0       ppp0
0.0.0.0/0        eth0   192.168.1.2</pre>
</td>
</tr>
</tbody>
</table>
</div>
<h2>#15: How do I scan specific ports?</h2>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="bash">nmap -p [port] hostName
## Scan port 80
nmap -p 80 192.168.1.1
&nbsp;
## Scan TCP port 80
nmap -p T:80 192.168.1.1
&nbsp;
## Scan UDP port 53
nmap -p U:53 192.168.1.1
&nbsp;
## Scan two ports ##
nmap -p 80,443 192.168.1.1
&nbsp;
## Scan port ranges ##
nmap -p 80-200 192.168.1.1
&nbsp;
## Combine all options ##
nmap -p U:53,111,137,T:21-25,80,139,8080 192.168.1.1
nmap -p U:53,111,137,T:21-25,80,139,8080 server1.cyberciti.biz
nmap -v -sU -sT -p U:53,111,137,T:21-25,80,139,8080 192.168.1.254
&nbsp;
## Scan all ports with * wildcard ##
nmap -p "*" 192.168.1.1
&nbsp;
## Scan top ports i.e. scan $number most common ports ##
nmap --top-ports 5 192.168.1.1
nmap --top-ports 10 192.168.1.1</pre>
</td>
</tr>
</tbody>
</table>
</div>
<p>&nbsp;</p>
<p><em>Sample outputs:</em></p>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="ini">Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 01:23 IST
Interesting ports on 192.168.1.1:
PORT     STATE  SERVICE
21/tcp   closed ftp
22/tcp   open   ssh
23/tcp   closed telnet
25/tcp   closed smtp
80/tcp   open   http
110/tcp  closed pop3
139/tcp  closed netbios-ssn
443/tcp  closed https
445/tcp  closed microsoft-ds
3389/tcp closed ms-term-serv
MAC Address: BC:AE:C5:C3:16:93 (Unknown)
&nbsp;
Nmap done: 1 IP address (1 host up) scanned in 0.51 seconds</pre>
</td>
</tr>
</tbody>
</table>
</div>
<h2>#16: The fastest way to scan all your devices/computers for open ports ever</h2>
<pre>nmap -T5 192.168.1.0/24</pre>
<h2>#17: How do I detect remote operating system?</h2>
<p>You can&nbsp;identify a remote host apps and OS using the -O option:</p>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="bash">nmap -O 192.168.1.1
nmap -O  --osscan-guess 192.168.1.1
nmap -v -O --osscan-guess 192.168.1.1</pre>
</td>
</tr>
</tbody>
</table>
</div>
<p>&nbsp;</p>
<p><em>Sample outputs:</em></p>
<pre>Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 01:29 IST
NSE: Loaded 0 scripts for scanning.
Initiating ARP Ping Scan at 01:29
Scanning 192.168.1.1 [1 port]
Completed ARP Ping Scan at 01:29, 0.01s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 01:29
Completed Parallel DNS resolution of 1 host. at 01:29, 0.22s elapsed
Initiating SYN Stealth Scan at 01:29
Scanning 192.168.1.1 [1000 ports]
Discovered open port 80/tcp on 192.168.1.1
Discovered open port 22/tcp on 192.168.1.1
Completed SYN Stealth Scan at 01:29, 0.16s elapsed (1000 total ports)
Initiating OS detection (try #1) against 192.168.1.1
Retrying OS detection (try #2) against 192.168.1.1
Retrying OS detection (try #3) against 192.168.1.1
Retrying OS detection (try #4) against 192.168.1.1
Retrying OS detection (try #5) against 192.168.1.1
Host 192.168.1.1 is up (0.00049s latency).
Interesting ports on 192.168.1.1:
Not shown: 998 closed ports
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: BC:AE:C5:C3:16:93 (Unknown)
Device type: WAP|general purpose|router|printer|broadband router
Running (JUST GUESSING) : Linksys Linux 2.4.X (95%), Linux 2.4.X|2.6.X (94%), MikroTik RouterOS 3.X (92%), Lexmark embedded (90%), Enterasys embedded (89%), D-Link Linux 2.4.X (89%), Netgear Linux 2.4.X (89%)
Aggressive OS guesses: OpenWrt White Russian 0.9 (Linux 2.4.30) (95%), OpenWrt 0.9 - 7.09 (Linux 2.4.30 - 2.4.34) (94%), OpenWrt Kamikaze 7.09 (Linux 2.6.22) (94%), Linux 2.4.21 - 2.4.31 (likely embedded) (92%), Linux 2.6.15 - 2.6.23 (embedded) (92%), Linux 2.6.15 - 2.6.24 (92%), MikroTik RouterOS 3.0beta5 (92%), MikroTik RouterOS 3.17 (92%), Linux 2.6.24 (91%), Linux 2.6.22 (90%)
No exact OS matches for host (If you know what OS is running on it, see http://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=5.00%D=11/27%OT=22%CT=1%CU=30609%PV=Y%DS=1%G=Y%M=BCAEC5%TM=50B3CA
OS:4B%P=x86_64-unknown-linux-gnu)SEQ(SP=C8%GCD=1%ISR=CB%TI=Z%CI=Z%II=I%TS=7
OS:)OPS(O1=M2300ST11NW2%O2=M2300ST11NW2%O3=M2300NNT11NW2%O4=M2300ST11NW2%O5
OS:=M2300ST11NW2%O6=M2300ST11)WIN(W1=45E8%W2=45E8%W3=45E8%W4=45E8%W5=45E8%W
OS:6=45E8)ECN(R=Y%DF=Y%T=40%W=4600%O=M2300NNSNW2%CC=N%Q=)T1(R=Y%DF=Y%T=40%S
OS:=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%R
OS:D=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=
OS:0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID
OS:=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)
Uptime guess: 12.990 days (since Wed Nov 14 01:44:40 2012)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=200 (Good luck!)
IP ID Sequence Generation: All zeros
Read data files from: /usr/share/nmap
OS detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 12.38 seconds
           Raw packets sent: 1126 (53.832KB) | Rcvd: 1066 (46.100KB)
</pre>
<p>See also:&nbsp;<a href="https://www.cyberciti.biz/faq/find-out-remote-webserver-name/">Fingerprinting a web-server</a>&nbsp;and a&nbsp;<a href="https://www.cyberciti.biz/tips/howto-remotely-determine-dns-server-version.html">dns server</a>&nbsp;command line tools for more information.</p>
<h2>#18: How do I detect remote services (server / daemon) version numbers?</h2>
<pre>nmap -sV 192.168.1.1</pre>
<p><em>Sample outputs:</em></p>
<pre>Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 01:34 IST
Interesting ports on 192.168.1.1:
Not shown: 998 closed ports
PORT   STATE SERVICE VERSION
22/tcp open  ssh     <strong>Dropbear sshd 0.52 (protocol 2.0)</strong>
80/tcp open  http?
1 service unrecognized despite returning data.
</pre>
<h2>#19: Scan a host using TCP ACK (PA) and TCP Syn (PS) ping</h2>
<p>If firewall is blocking standard ICMP pings, try the following host discovery methods:</p>
<pre>nmap -PS 192.168.1.1
nmap -PS 80,21,443 192.168.1.1
nmap -PA 192.168.1.1
nmap -PA 80,21,200-512 192.168.1.1</pre>
<h2>#20: Scan a host using IP protocol ping</h2>
<pre>nmap -PO 192.168.1.1</pre>
<h2>#21: Scan a host using UDP ping</h2>
<p>This scan bypasses firewalls and filters that only screen TCP:</p>
<pre>nmap -PU 192.168.1.1
nmap -PU 2000.2001 192.168.1.1</pre>
<h2>#22: Find out the most commonly used TCP ports using TCP SYN Scan</h2>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="bash">### Stealthy scan ###
nmap -sS 192.168.1.1
&nbsp;
### Find out the most commonly used TCP ports using  TCP connect scan (warning: no stealth scan)
###  OS Fingerprinting ###
nmap -sT 192.168.1.1
&nbsp;
### Find out the most commonly used TCP ports using TCP ACK scan
nmap -sA 192.168.1.1
&nbsp;
### Find out the most commonly used TCP ports using TCP Window scan
nmap -sW 192.168.1.1
&nbsp;
### Find out the most commonly used TCP ports using TCP Maimon scan
nmap -sM 192.168.1.1</pre>
</td>
</tr>
</tbody>
</table>
</div>
<h2>#23: Scan a host for UDP services (UDP scan)</h2>
<p>Most popular services on the Internet run over the TCP protocol. DNS, SNMP, and DHCP are three of the most common UDP services. Use the following syntax to find out UDP services:</p>
<pre>nmap -sU nas03
nmap -sU 192.168.1.1</pre>
<p><em>Sample outputs:</em></p>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="ini">Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 00:52 IST
Stats: 0:05:29 elapsed; 0 hosts completed (1 up), 1 undergoing UDP Scan
UDP Scan Timing: About 32.49% done; ETC: 01:09 (0:11:26 remaining)
Interesting ports on nas03 (192.168.1.12):
Not shown: 995 closed ports
PORT     STATE         SERVICE
111/udp  open|filtered rpcbind
123/udp  open|filtered ntp
161/udp  open|filtered snmp
2049/udp open|filtered nfs
5353/udp open|filtered zeroconf
MAC Address: 00:11:32:11:15:FC (Synology Incorporated)
&nbsp;
Nmap done: 1 IP address (1 host up) scanned in 1099.55 seconds</pre>
</td>
</tr>
</tbody>
</table>
</div>
<h2>#24: Scan for IP protocol</h2>
<p>This type of scan allows you to determine which IP protocols (TCP, ICMP, IGMP, etc.) are supported by target machines:</p>
<pre>nmap -sO 192.168.1.1</pre>
<h2>#25: Scan a firewall for security weakness</h2>
<p>The following scan types exploit a subtle loophole in the TCP and good for testing security of common attacks:</p>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="bash">## TCP Null Scan to fool a firewall to generate a response ##
## Does not set any bits (TCP flag header is 0) ##
nmap -sN 192.168.1.254
&nbsp;
## TCP Fin scan to check firewall ##
## Sets just the TCP FIN bit ##
nmap -sF 192.168.1.254
&nbsp;
## TCP Xmas scan to check firewall ##
## Sets the FIN, PSH, and URG flags, lighting the packet up like a Christmas tree ##
nmap -sX 192.168.1.254</pre>
</td>
</tr>
</tbody>
</table>
</div>
<p>&nbsp;</p>
<p>See&nbsp;how to block Xmas packkets, syn-floods and other conman attacks&nbsp;with iptables.</p>
<h2>#26: Scan a firewall for packets fragments</h2>
<p>The -f option causes the requested scan (including ping scans) to use tiny fragmented IP packets. The idea is to split up the TCP header over<br />several packets to make it harder for packet filters, intrusion detection systems, and other annoyances to detect what you are doing.</p>
<p>&lt;pre &#8220;=&#8221;&#8221; lang=&#8221;bash&#8221;&gt;nmap -f 192.168.1.1 nmap -f fw2.nixcraft.net.in nmap -f 15 fw2.nixcraft.net.in ## Set your own offset size with the &#8211;mtu option ## nmap &#8211;mtu 32 192.168.1.1</p>
<h2>#27: Cloak a scan with decoys</h2>
<p>The&nbsp;<kbd>-D</kbd>&nbsp;option it appear to the remote host that the host(s) you specify as&nbsp;decoys are scanning the target network too. Thus their IDS might report 5-10 port scans from unique IP addresses, but they won’t know which IP was scanning them and which were innocent decoys:</p>
<pre>nmap -n -Ddecoy-ip1,decoy-ip2,your-own-ip,decoy-ip3,decoy-ip4 remote-host-ip
nmap -n -D192.168.1.5,10.5.1.2,172.1.2.4,3.4.2.1 192.168.1.5</pre>
<h2>#28: Scan a firewall for MAC address spoofing</h2>
<div class="wp_syntax">
<table>
<tbody>
<tr>
<td class="code">
<pre class="bash">### Spoof your MAC address ##
nmap --spoof-mac MAC-ADDRESS-HERE 192.168.1.1
&nbsp;
### Add other options ###
nmap -v -sT -PN --spoof-mac MAC-ADDRESS-HERE 192.168.1.1
&nbsp;
&nbsp;
### Use a random MAC address ###
### The number 0, means nmap chooses a completely random MAC address ###
nmap -v -sT -PN --spoof-mac 0 192.168.1.1</pre>
</td>
</tr>
</tbody>
</table>
</div>
<h2>#29: How do I save output to a text file?</h2>
<p>The syntax is:</p>
<pre>nmap 192.168.1.1 &gt; output.txt
nmap -oN /path/to/filename 192.168.1.1
nmap -oN output.txt 192.168.1.1
</pre>
<h2>#30 Scans for web servers and pipes into Nikto for scanning</h2>
<p><code>nmap -p80 192.168.1.2/24 -oG - | /path/to/nikto.pl -h -<br />nmap -p80,443 192.168.1.2/24 -oG - | /path/to/nikto.pl -h -</code></p>
<h2>#31 Speed up nmap</h2>
<p>Pass the -T option:<br /><code>nmap -v -sS -A -T4 192.168.2.5</code></p>
<p><em>Sample outputs:</em></p>
<pre>Starting Nmap 7.40 ( https://nmap.org ) at 2017-05-15 01:52 IST
NSE: Loaded 143 scripts for scanning.
NSE: Script Pre-scanning.
Initiating NSE at 01:52
Completed NSE at 01:52, 0.00s elapsed
Initiating NSE at 01:52
Completed NSE at 01:52, 0.00s elapsed
Initiating ARP Ping Scan at 01:52
Scanning 192.168.2.15 [1 port]
Completed ARP Ping Scan at 01:52, 0.01s elapsed (1 total hosts)
Initiating SYN Stealth Scan at 01:52
Scanning dellm6700 (192.168.2.15) [1000 ports]
Discovered open port 5900/tcp on 192.168.2.15
Discovered open port 80/tcp on 192.168.2.15
Discovered open port 22/tcp on 192.168.2.15
Completed SYN Stealth Scan at 01:53, 4.62s elapsed (1000 total ports)
Initiating Service scan at 01:53
Scanning 3 services on dellm6700 (192.168.2.15)
Completed Service scan at 01:53, 6.01s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against dellm6700 (192.168.2.15)
Retrying OS detection (try #2) against dellm6700 (192.168.2.15)
NSE: Script scanning 192.168.2.15.
Initiating NSE at 01:53
Completed NSE at 01:53, 30.02s elapsed
Initiating NSE at 01:53
Completed NSE at 01:53, 0.00s elapsed
Nmap scan report for dellm6700 (192.168.2.15)
Host is up (0.00044s latency).
Not shown: 996 filtered ports
PORT     STATE  SERVICE VERSION
22/tcp   open   ssh     (protocol 2.0)
| fingerprint-strings: 
|   NULL: 
|_    SSH-2.0-OpenSSH_7.4p1 Ubuntu-10
| ssh-hostkey: 
|   2048 1d:14:84:f0:c7:21:10:0e:30:d9:f9:59:6b:c3:95:97 (RSA)
|_  256 dc:59:c6:6e:33:33:f2:d2:5d:9b:fd:b4:9c:52:c1:0a (ECDSA)
80/tcp   open   http    nginx 1.10.0 (Ubuntu)
| http-methods: 
|_  Supported Methods: GET HEAD
|_http-server-header: nginx/1.10.0 (Ubuntu)
|_http-title: Apache2 Ubuntu Default Page: It works
443/tcp  closed https
5900/tcp open   vnc     VNC (protocol 3.7)
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port22-TCP:V=7.40%I=7%D=5/15%Time=5918BCAA%P=x86_64-apple-darwin16.3.0%
SF:r(NULL,20,"SSH-2\.0-OpenSSH_7\.4p1\x20Ubuntu-10\n");
MAC Address: F0:1F:AF:1F:2C:60 (Dell)
Device type: general purpose
Running (JUST GUESSING): Linux 3.X|4.X|2.6.X (95%), OpenBSD 4.X (85%)
OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:openbsd:openbsd:4.0
Aggressive OS guesses: Linux 3.11 - 4.1 (95%), Linux 4.4 (95%), Linux 3.13 (92%), Linux 4.0 (90%), Linux 2.6.32 (89%), Linux 2.6.32 or 3.10 (89%), Linux 3.2 - 3.8 (89%), Linux 3.10 - 3.12 (88%), Linux 2.6.32 - 2.6.33 (87%), Linux 2.6.32 - 2.6.35 (87%)
No exact OS matches for host (test conditions non-ideal).
Uptime guess: 0.000 days (since Mon May 15 01:53:08 2017)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=252 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT     ADDRESS
1   0.44 ms dellm6700 (192.168.2.15)

NSE: Script Post-scanning.
Initiating NSE at 01:53
Completed NSE at 01:53, 0.00s elapsed
Initiating NSE at 01:53
Completed NSE at 01:53, 0.00s elapsed
Read data files from: /usr/local/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 46.02 seconds
           Raw packets sent: 2075 (95.016KB) | Rcvd: 50 (3.084KB)
</pre>
<h2>#32: Not a fan of command line tools?</h2>
<p>Try&nbsp;<a href="https://nmap.org/zenmap/" target="_blank" rel="noopener noreferrer">zenmap the official network mapper</a>&nbsp;front end:</p>
<blockquote>
<p>Zenmap is the official Nmap Security Scanner GUI. It is a multi-platform (Linux, Windows, Mac OS X, BSD, etc.) free and open source application which aims to make Nmap easy for beginners to use while providing advanced features for experienced Nmap users. Frequently used scans can be saved as profiles to make them easy to run repeatedly. A command creator allows interactive creation of Nmap command lines. Scan results can be saved and viewed later. Saved scan results can be compared with one another to see how they differ. The results of recent scans are stored in a searchable database.</p>
</blockquote>
<p>You can install zenmap using the following&nbsp;<a href="https://www.cyberciti.biz/tips/linux-debian-package-management-cheat-sheet.html">apt-get command</a>:<br /><code>$ sudo apt-get install zenmap</code></p>
<p><em>Sample outputs:</em></p>
<pre>[sudo] password for vivek: 
Reading package lists... Done
Building dependency tree       
Reading state information... Done
The following NEW packages will be installed:
  zenmap
0 upgraded, 1 newly installed, 0 to remove and 11 not upgraded.
Need to get 616 kB of archives.
After this operation, 1,827 kB of additional disk space will be used.
Get:1 http://debian.osuosl.org/debian/ squeeze/main zenmap amd64 5.00-3 [616 kB]
Fetched 616 kB in 3s (199 kB/s)                       
Selecting previously deselected package zenmap.
(Reading database ... 281105 files and directories currently installed.)
Unpacking zenmap (from .../zenmap_5.00-3_amd64.deb) ...
Processing triggers for desktop-file-utils ...
Processing triggers for gnome-menus ...
Processing triggers for man-db ...
Setting up zenmap (5.00-3) ...
Processing triggers for python-central ...</pre>
<p>Type the following command to start zenmap:<br /><code>$ sudo zenmap</code></p>
<p><em>Sample outputs</em></p>
<figure id="attachment_275" class="wp-caption aligncenter" aria-describedby="caption-attachment-275"><a href="https://www.cyberciti.biz/networking/nmap-command-examples-tutorials/attachment/nmap-usage-examples-output/" rel="attachment wp-att-275"><img decoding="async" class="size-full wp-image-275" title="Nmap Command GUI Usage Examples Output From zenmap" src="https://www.cyberciti.biz/media/new/cms/2012/11/nmap-usage-examples-output.png" sizes="(max-width: 592px) 85vw, 592px" srcset="https://www.cyberciti.biz/media/new/cms/2012/11/nmap-usage-examples-output.png 592w, https://www.cyberciti.biz/media/new/cms/2012/11/nmap-usage-examples-output-278x300.png 278w" alt="Fig.02: zenmap in action" width="592" height="640"></a><figcaption id="caption-attachment-275" class="wp-caption-text"><em>Fig.02: zenmap in action</em></figcaption></figure>
<h5>References:</h5>
<ul>
<li><a href="https://nmap.org/book/toc.html" target="_blank" rel="noopener noreferrer">The official Nmap project guide to network discovery and security Scanning</a>.</li>
<li><a href="https://nmap.org/" target="_blank" rel="noopener noreferrer">The official Nmap project</a>&nbsp;home page.</li>
</ul>
<p><em>The nmap command has many more options, please go through man page or the documentation for more information.&nbsp;</em></p>
<p>The post <a href="http://kostacipo.stream/top-32-nmap-commands-for-linux-sys-network-admins/">Top 32 Nmap Commands For Linux Sys/Network Admins</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/top-32-nmap-commands-for-linux-sys-network-admins/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Nemesis &#8211; A Command-Line Network Packet Crafting And Injection Utility</title>
		<link>http://kostacipo.stream/nemesis-a-command-line-network-packet-crafting-and-injection-utility/</link>
					<comments>http://kostacipo.stream/nemesis-a-command-line-network-packet-crafting-and-injection-utility/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Wed, 22 Jan 2020 10:11:07 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[network]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1689</guid>

					<description><![CDATA[<p>&#160; The Nemesis Project is designed to be a command line based, portable human IP stack for UNIX-like and Windows systems. The suite is broken down by protocol, and should allow for useful scripting of injected packets from simple shell scripts. Key Features ARP/RARP, DNS, ETHERNET, ICMP, IGMP, IP, OSPF, RIP, TCP and UDP protocol [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/nemesis-a-command-line-network-packet-crafting-and-injection-utility/">Nemesis &#8211; A Command-Line Network Packet Crafting And Injection Utility</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>The Nemesis Project is designed to be a command line based, portable human IP stack for UNIX-like and Windows systems. The suite is broken down by protocol, and should allow for useful scripting of injected packets from simple shell scripts.</p>
<div id="main-wrapper">
<div id="main" class="main section">
<div id="Blog1" class="widget Blog" data-version="1">
<div class="blog-posts hfeed">
<div class="post-outer">
<div class="post">
<div class="post-header">
<div id="post-body-8064117169396713018" class="post-body entry-content"><a name="more"></a><br /><b>Key Features</b></p>
<ul>
<li>ARP/RARP, DNS, ETHERNET, ICMP, IGMP, IP, OSPF, RIP, TCP and UDP protocol support</li>
<li>Layer 2 or Layer 3 injection on UNIX-like systems</li>
<li>Layer 2 injection (only) on Windows systems</li>
<li>Packet payload from file</li>
<li>IP and TCP options from file</li>
<li>Tested on OpenBSD, Linux, Solaris, Mac OS X and Windows 2000</li>
</ul>
<p>Each supported protocol uses its own protocol &#8220;injector&#8221; which is accompanied by a man page explaining its functionality.<br />Consult the ChangeLog for release details, and the documentation for each protocol injector for in-depth descriptions of the available functionality.</p>
<p><b>Examples</b></p>
<ul>
<li>Inject malformed ICMP redirect
<pre><code>  sudo nemesis icmp -S 10.10.10.3 -D 10.10.10.1 -G 10.10.10.3 -i 5</code></pre>
</li>
<li>IGMP v2 join for group 239.186.39.5
<pre><code>  sudo nemesis igmp -v -p 22 -S 192.168.1.20 -i 239.186.39.5 -D 239.186.39.5</code></pre>
</li>
<li>IGMP v2 query, max resp. time 10 sec, with Router Alert IP option
<pre><code>  echo -ne '\x94\x04\x00\x00' &gt;RA
  sudo nemesis igmp -v -p 0x11 -c 100 -D 224.0.0.1 -O RA</code></pre>
<p>or</p>
<pre><code>  echo -ne '\x94\x04\x00\x00' | sudo nemesis igmp -v -p 0x11 -c 100 -D 224.0.0.1 -O -</code></pre>
</li>
<li>IGMP v3 query, with Router Alert IP option
<pre><code>  echo -ne '\x03\x64\x00\x00' &gt; v3
  sudo ./src/nemesis igmp -p 0x11 -c 100 -i 0.0.0.0 -P v3 -D 224.0.0.1 -O RA</code></pre>
</li>
<li>Random TCP packet
<pre><code>  sudo nemesis tcp</code></pre>
</li>
<li>DoS and DDoS testing
<pre><code>  sudo nemesis tcp -v -S 192.168.1.1 -D 192.168.2.2 -fSA -y 22 -P foo
  sudo nemesis udp -v -S 10.11.12.13 -D 10.1.1.2 -x 11111 -y 53 -P bindpkt
  sudo nemesis icmp redirect -S 10.10.10.3 -D 10.10.10.1 -G 10.10.10.3 -qR
  sudo nemesis arp -v -d ne0 -H 0:1:2:3:4:5 -S 10.11.30.5 -D 10.10.15.1</code></pre>
</li>
</ul>
<p><b>Build &amp; Install</b></div>
<div>&nbsp;</div>
<div class="post-body entry-content">Nemesis is built around <a href="https://sourceforge.net/projects/libnet-dev/" target="_blank" rel="nofollow noopener noreferrer">libnet</a>. Windows platform builds require <a href="http://www.tcpdump.org/" target="_blank" rel="nofollow noopener noreferrer">libpcap</a> as well. On Debian and Ubuntu derived GNU/Linux systems:</p>
<pre><code>sudo apt install libnet1-dev</code></pre>
<p>The <a href="https://airs.com/ian/configure/" target="_blank" rel="nofollow noopener noreferrer">GNU Configure &amp; Build</a> system use <code>/usr/local</code> as the default install prefix. Usually this is sufficient, the below example installs to <code>/usr</code> instead:</p>
<pre><code>tar xf nemesis-1.5.tar.xz
cd nemesis-1.5/
./configure --prefix=/usr
make -j5
sudo make install-strip</code></pre>
<p><b>Building from GIT</b></div>
<div>&nbsp;</div>
<div class="post-body entry-content">If you want to contribute, or simply want to try out the latest but still unreleased features, then you need to know a few things about the <a href="https://airs.com/ian/configure/" target="_blank" rel="nofollow noopener noreferrer">GNU Configure &amp; Build</a> system:</p>
<ul>
<li><code>configure.ac</code> and a per-directory <code>Makefile.am</code> are key files</li>
<li><code>configure</code> and <code>Makefile.in</code> are generated from <code>autogen.sh</code>, they are not stored in GIT but automatically generated for the release tarballs</li>
<li><code>Makefile</code> is generated by <code>configure</code> script</li>
</ul>
<p>To build from GIT you first need to clone the repository and run the <code>autogen.sh</code> script. This requires <code>automake</code> and <code>autoconf</code> to be installed on your system.</p>
<pre><code>git clone https://github.com/troglobit/inadyn.git
cd inadyn/
./autogen.sh
./configure &amp;&amp; make</code></pre>
<p>GIT sources are a moving target and are not recommended for production systems, unless you know what you are doing!</p>
<p><b>Origin &amp; References</b></p>
<ul>
<li><strong>1999</strong>: Nemesis was created by Mark Grimes</li>
<li><strong>2001</strong>: Jeff Nathan took over maintainership</li>
<li><strong>2018</strong>: Project resurrected by Joachim Nilsson</li>
</ul>
<p>The project is currently maintained at <a href="https://github.com/troglobit/mini-snmpd" target="_blank" rel="nofollow noopener noreferrer">GitHub</a> with the intention to serve as a focal point for new development. If you have patches and/or ideas, please submit them using the issue tracker or as pull requests.</p>
<p></p>
<div><b><a href="https://github.com/troglobit/nemesis" target="_blank" rel="nofollow noopener noreferrer">Download Nemesis</a></b></div>
</div>
</div>
<p><a name="ad-title"></a></p>
<article></article>
</div>
</div>
</div>
</div>
</div>
</div>
<p>The post <a href="http://kostacipo.stream/nemesis-a-command-line-network-packet-crafting-and-injection-utility/">Nemesis &#8211; A Command-Line Network Packet Crafting And Injection Utility</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/nemesis-a-command-line-network-packet-crafting-and-injection-utility/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AIEngine – AI-driven Network Intrusion Detection System</title>
		<link>http://kostacipo.stream/aiengine-ai-driven-network-intrusion-detection-system-2/</link>
					<comments>http://kostacipo.stream/aiengine-ai-driven-network-intrusion-detection-system-2/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Fri, 13 Dec 2019 13:14:52 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[intrusion detection]]></category>
		<category><![CDATA[network]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1461</guid>

					<description><![CDATA[<p>&#160; AIEngine is a next-generation interactive/programmable Python/Ruby/Java/Lua and Go AI-driven Network Intrusion Detection System engine with capabilities of learning without any human intervention, DNS domain classification, Spam detection, network collector, network forensics and many others. AIEngine also helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/aiengine-ai-driven-network-intrusion-detection-system-2/">AIEngine – AI-driven Network Intrusion Detection System</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>AIEngine is a next-generation interactive/programmable Python/Ruby/Java/Lua and Go AI-driven Network Intrusion Detection System engine with capabilities of learning without any human intervention, DNS domain classification, Spam detection, network collector, network forensics and many others.</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-medium wp-image-5346" src="https://cdn.darknet.org.uk/wp-content/uploads/2019/11/AIEngine-AI-driven-Network-Intrusion-Detection-System-640x404.jpg" sizes="auto, (max-width: 640px) 100vw, 640px" srcset="https://cdn.darknet.org.uk/wp-content/uploads/2019/11/AIEngine-AI-driven-Network-Intrusion-Detection-System-640x404.jpg 640w, https://cdn.darknet.org.uk/wp-content/uploads/2019/11/AIEngine-AI-driven-Network-Intrusion-Detection-System.jpg 994w" alt="AIEngine - AI-driven Network Intrusion Detection System" width="640" height="404"></p>
<p>AIEngine also helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and so on.</p>
<h2>Functionality of AIEngine AI-driven Network Intrusion Detection System</h2>
<p>The main functionalities of AIEngine are:</p>
<ul>
<li>Support for interacting/programing with the user while the engine is running.</li>
<li>Support for PCRE JIT for regex matching.</li>
<li>Support for regex graphs (complex detection patterns).</li>
<li>Support six types of NetworkStacks (lan, mobile, lan6, virtual, oflow and mobile6).</li>
<li>Support Sets and Bloom filters for IP searches.</li>
<li>Supports x86_64, ARM and MIPS architecture over operating systems such as Linux, FreeBSD and MacOS.</li>
<li>Support for HTTP, DNS and SSL Domains matching.</li>
<li>Support for banned domains and hosts for HTTP, DNS, SMTP and SSL.</li>
<li>Frequency analysis for unknown traffic and auto-regex generation.</li>
<li>Generation of Yara signatures.</li>
<li>Easy integration with databases (MySQL, Redis, Cassandra, Hadoop, etc…) for data correlation.</li>
<li>Easy integration with other packet engines (Netfilter).</li>
<li>Support memory clean caches for refresh stored memory information.</li>
<li>Support for detect DDoS at network/application layer.</li>
<li>Support for rejecting TCP/UDP connections.</li>
<li>Support for network forensics on real time.</li>
<li>Support for JA3 TLS Signatures on SSL.</li>
<li>Supports protocols such as Bitcoin, CoAP, DHCPv4/DHCPv6, DNS, GPRS, GRE, HTTP, ICMPv4/ICMPv6, IMAP, IPv4/v6, Modbus, MPLS, MQTT, Netbios, NTP, OpenFlow, PPPoE, POP, Quic, RTP, SIP, SMB, SMTP, SSDP, SSH, SSL, TCP, UDP, VLAN, VXLAN.</li>
<li>Integration of HTTP Server for retrieve and configure the system.</li>
</ul>
<p>&nbsp;</p>
<h3>Using AIEngine AI-driven Network Intrusion Detection System</h3>
<p>To use AIEngine(reduce version) just execute the binary aiengine or use the python/ruby/java/lua binding.</p>
<div id="crayon-5df375e527260322873315" class="crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"><textarea class="crayon-plain print-no" readonly="readonly" data-settings="dblclick" wrap="soft">luis@luis-xps:~/c++/aiengine/src$ ./aiengine -h<br />
aiengine 1.9.0<br />
Mandatory arguments:<br />
  -I [ &#8211;input ] arg                Sets the network interface ,pcap file or<br />
                                    directory with pcap files.</p>
<p>Link Layer optional arguments:<br />
  -q [ &#8211;tag ] arg      Selects the tag type of the ethernet layer (vlan,mpls).</p>
<p>TCP optional arguments:<br />
  -t [ &#8211;tcp-flows ] arg (=32768) Sets the number of TCP flows on the pool.</p>
<p>UDP optional arguments:<br />
  -u [ &#8211;udp-flows ] arg (=16384) Sets the number of UDP flows on the pool.</p>
<p>Regex optional arguments:<br />
  -R [ &#8211;enable-signatures ]     Enables the Signature engine.<br />
  -r [ &#8211;regex ] arg (=.*)       Sets the regex for evaluate agains the flows.<br />
  -c [ &#8211;flow-class ] arg (=all) Uses tcp, udp or all for matches the signature<br />
                 on the flows.<br />
  -m [ &#8211;matched-flows ]         Shows the flows that matchs with the regex.<br />
  -M [ &#8211;matched-packet ]        Shows the packet payload that matchs with<br />
                                 the regex.<br />
  -C [ &#8211;continue ]              Continue evaluating the regex with the<br />
                                 next packets of the Flow.<br />
  -j [ &#8211;reject-flows ]          Rejects the flows that matchs with the<br />
                                     regex.<br />
  -w [ &#8211;evidence ]              Generates a pcap file with the matching<br />
                                     regex for forensic analysis.</p>
<p>Frequencies optional arguments:<br />
  -F [ &#8211;enable-frequencies ]       Enables the Frequency engine.<br />
  -g [ &#8211;group-by ] arg (=dst-port) Groups frequencies by src-ip,dst-ip,src-por<br />
                    t and dst-port.<br />
  -f [ &#8211;flow-type ] arg (=tcp)     Uses tcp or udp flows.<br />
  -L [ &#8211;enable-learner ]           Enables the Learner engine.<br />
  -k [ &#8211;key-learner ] arg (=80)    Sets the key for the Learner engine.<br />
  -b [ &#8211;buffer-size ] arg (=64)    Sets the size of the internal buffer for<br />
                                    generate the regex.<br />
      -Q [ &#8211;byte-quality ] arg (=80)   Sets the minimum quality for the bytes of<br />
                                        the generated regex.<br />
  -y [ &#8211;enable-yara ]              Generates a yara signature.</p>
<p>Optional arguments:<br />
  -n [ &#8211;stack ] arg (=lan)    Sets the network stack (lan,mobile,lan6,virtual,<br />
                   oflow).<br />
  -d [ &#8211;dumpflows ]           Dump the flows to stdout.<br />
  -s [ &#8211;statistics ] arg (=0) Show statistics of the network stack (5 levels).<br />
  -T [ &#8211;timeout ] arg (=180)  Sets the flows timeout.<br />
  -P [ &#8211;protocol ] arg        Show statistics of a specific protocol of the<br />
                                   network stack.<br />
  -a [ &#8211;port ] arg (=0)       Sets the HTTP listenting port.<br />
  -e [ &#8211;release ]             Release the caches.<br />
  -l [ &#8211;release-cache ] arg   Release a specific cache.<br />
  -p [ &#8211;pstatistics ]         Show statistics of the process.<br />
      -o [ &#8211;summary ]             Show protocol summmary statistics<br />
                                   (bytes,packets,% bytes,cache miss,memory).<br />
  -h [ &#8211;help ]                Show help.<br />
  -v [ &#8211;version ]             Show version string.</textarea></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="show">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5df375e527260322873315-1">1</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-2">2</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-3">3</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-4">4</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-5">5</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-6">6</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-7">7</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-8">8</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-9">9</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-10">10</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-11">11</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-12">12</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-13">13</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-14">14</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-15">15</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-16">16</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-17">17</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-18">18</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-19">19</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-20">20</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-21">21</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-22">22</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-23">23</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-24">24</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-25">25</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-26">26</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-27">27</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-28">28</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-29">29</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-30">30</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-31">31</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-32">32</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-33">33</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-34">34</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-35">35</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-36">36</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-37">37</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-38">38</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-39">39</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-40">40</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-41">41</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-42">42</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-43">43</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-44">44</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-45">45</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-46">46</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-47">47</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-48">48</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-49">49</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-50">50</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-51">51</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-52">52</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-53">53</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-54">54</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-55">55</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-56">56</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-57">57</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5df375e527260322873315-58">58</div>
<div class="crayon-num" data-line="crayon-5df375e527260322873315-59">59</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5df375e527260322873315-1" class="crayon-line"><span class="crayon-v">luis</span><span class="crayon-sy">@</span><span class="crayon-v">luis</span><span class="crayon-o">&#8211;</span><span class="crayon-v">xps</span><span class="crayon-o">:</span><span class="crayon-o">~</span><span class="crayon-o">/</span><span class="crayon-v">c</span><span class="crayon-o">++</span><span class="crayon-o">/</span><span class="crayon-v">aiengine</span><span class="crayon-o">/</span><span class="crayon-v">src</span><span class="crayon-sy">$</span> <span class="crayon-sy">.</span><span class="crayon-o">/</span><span class="crayon-v">aiengine</span> <span class="crayon-o">&#8211;</span><span class="crayon-i">h</span></div>
<div id="crayon-5df375e527260322873315-2" class="crayon-line crayon-striped-line"><span class="crayon-i">aiengine</span> <span class="crayon-cn">1.9.0</span></div>
<div id="crayon-5df375e527260322873315-3" class="crayon-line"><span class="crayon-e">Mandatory </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5df375e527260322873315-4" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">I</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">input</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">network </span><span class="crayon-t">interface</span> <span class="crayon-sy">,</span><span class="crayon-e">pcap </span><span class="crayon-e">file </span><span class="crayon-st">or</span></div>
<div id="crayon-5df375e527260322873315-5" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">directory </span><span class="crayon-e">with </span><span class="crayon-e">pcap </span><span class="crayon-v">files</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-6" class="crayon-line crayon-striped-line">&nbsp;</div>
<div id="crayon-5df375e527260322873315-7" class="crayon-line"><span class="crayon-e">Link </span><span class="crayon-e">Layer </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5df375e527260322873315-8" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">q</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">tag</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Selects </span><span class="crayon-e">the </span><span class="crayon-e">tag </span><span class="crayon-e">type </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-e">ethernet </span><span class="crayon-e">layer</span> <span class="crayon-sy">(</span><span class="crayon-v">vlan</span><span class="crayon-sy">,</span><span class="crayon-v">mpls</span><span class="crayon-sy">)</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-9" class="crayon-line">&nbsp;</div>
<div id="crayon-5df375e527260322873315-10" class="crayon-line crayon-striped-line"><span class="crayon-e">TCP </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5df375e527260322873315-11" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">t</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">tcp</span><span class="crayon-o">&#8211;</span><span class="crayon-i">flows</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">32768</span><span class="crayon-sy">)</span> <span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">number </span><span class="crayon-e">of </span><span class="crayon-e">TCP </span><span class="crayon-e">flows </span><span class="crayon-e">on </span><span class="crayon-e">the </span><span class="crayon-v">pool</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-12" class="crayon-line crayon-striped-line">&nbsp;</div>
<div id="crayon-5df375e527260322873315-13" class="crayon-line"><span class="crayon-e">UDP </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5df375e527260322873315-14" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">u</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">udp</span><span class="crayon-o">&#8211;</span><span class="crayon-i">flows</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">16384</span><span class="crayon-sy">)</span> <span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">number </span><span class="crayon-e">of </span><span class="crayon-e">UDP </span><span class="crayon-e">flows </span><span class="crayon-e">on </span><span class="crayon-e">the </span><span class="crayon-v">pool</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-15" class="crayon-line">&nbsp;</div>
<div id="crayon-5df375e527260322873315-16" class="crayon-line crayon-striped-line"><span class="crayon-e">Regex </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5df375e527260322873315-17" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">R</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">enable</span><span class="crayon-o">&#8211;</span><span class="crayon-i">signatures</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Enables </span><span class="crayon-e">the </span><span class="crayon-e">Signature </span><span class="crayon-v">engine</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-18" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">r</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">regex</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-sy">.</span><span class="crayon-o">*</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">regex </span><span class="crayon-st">for</span> <span class="crayon-e">evaluate </span><span class="crayon-e">agains </span><span class="crayon-e">the </span><span class="crayon-v">flows</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-19" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">c</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">flow</span><span class="crayon-o">&#8211;</span><span class="crayon-t">class</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-v">all</span><span class="crayon-sy">)</span> <span class="crayon-e">Uses </span><span class="crayon-v">tcp</span><span class="crayon-sy">,</span> <span class="crayon-e">udp </span><span class="crayon-st">or</span> <span class="crayon-e">all </span><span class="crayon-st">for</span> <span class="crayon-e">matches </span><span class="crayon-e">the </span><span class="crayon-e">signature</span></div>
<div id="crayon-5df375e527260322873315-20" class="crayon-line crayon-striped-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">on </span><span class="crayon-e">the </span><span class="crayon-v">flows</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-21" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">m</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">matched</span><span class="crayon-o">&#8211;</span><span class="crayon-i">flows</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Shows </span><span class="crayon-e">the </span><span class="crayon-e">flows </span><span class="crayon-e">that </span><span class="crayon-e">matchs </span><span class="crayon-e">with </span><span class="crayon-e">the </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-22" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">M</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">matched</span><span class="crayon-o">&#8211;</span><span class="crayon-i">packet</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Shows </span><span class="crayon-e">the </span><span class="crayon-e">packet </span><span class="crayon-e">payload </span><span class="crayon-e">that </span><span class="crayon-e">matchs </span><span class="crayon-e">with </span></div>
<div id="crayon-5df375e527260322873315-23" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">the </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-24" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">C</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-st">continue</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-st">Continue</span> <span class="crayon-e">evaluating </span><span class="crayon-e">the </span><span class="crayon-e">regex </span><span class="crayon-e">with </span><span class="crayon-e">the </span></div>
<div id="crayon-5df375e527260322873315-25" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">next </span><span class="crayon-e">packets </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-v">Flow</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-26" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">j</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">reject</span><span class="crayon-o">&#8211;</span><span class="crayon-i">flows</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Rejects </span><span class="crayon-e">the </span><span class="crayon-e">flows </span><span class="crayon-e">that </span><span class="crayon-e">matchs </span><span class="crayon-e">with </span><span class="crayon-e">the </span></div>
<div id="crayon-5df375e527260322873315-27" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-28" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">w</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">evidence</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-i">Generates</span> <span class="crayon-i">a</span> <span class="crayon-e">pcap </span><span class="crayon-e">file </span><span class="crayon-e">with </span><span class="crayon-e">the </span><span class="crayon-e">matching </span></div>
<div id="crayon-5df375e527260322873315-29" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">regex </span><span class="crayon-st">for</span> <span class="crayon-e">forensic </span><span class="crayon-v">analysis</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-30" class="crayon-line crayon-striped-line">&nbsp;</div>
<div id="crayon-5df375e527260322873315-31" class="crayon-line"><span class="crayon-e">Frequencies </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5df375e527260322873315-32" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">F</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">enable</span><span class="crayon-o">&#8211;</span><span class="crayon-i">frequencies</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Enables </span><span class="crayon-e">the </span><span class="crayon-e">Frequency </span><span class="crayon-v">engine</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-33" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">g</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">group</span><span class="crayon-o">&#8211;</span><span class="crayon-i">by</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-v">dst</span><span class="crayon-o">&#8211;</span><span class="crayon-v">port</span><span class="crayon-sy">)</span> <span class="crayon-e">Groups </span><span class="crayon-e">frequencies </span><span class="crayon-e">by </span><span class="crayon-v">src</span><span class="crayon-o">&#8211;</span><span class="crayon-v">ip</span><span class="crayon-sy">,</span><span class="crayon-v">dst</span><span class="crayon-o">&#8211;</span><span class="crayon-v">ip</span><span class="crayon-sy">,</span><span class="crayon-v">src</span><span class="crayon-o">&#8211;</span><span class="crayon-i">por</span></div>
<div id="crayon-5df375e527260322873315-34" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-i">t</span> <span class="crayon-st">and</span> <span class="crayon-v">dst</span><span class="crayon-o">&#8211;</span><span class="crayon-v">port</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-35" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">f</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">flow</span><span class="crayon-o">&#8211;</span><span class="crayon-i">type</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-v">tcp</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Uses </span><span class="crayon-e">tcp </span><span class="crayon-st">or</span> <span class="crayon-e">udp </span><span class="crayon-v">flows</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-36" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">L</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">enable</span><span class="crayon-o">&#8211;</span><span class="crayon-i">learner</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Enables </span><span class="crayon-e">the </span><span class="crayon-e">Learner </span><span class="crayon-v">engine</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-37" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">k</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">key</span><span class="crayon-o">&#8211;</span><span class="crayon-i">learner</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">80</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">key </span><span class="crayon-st">for</span> <span class="crayon-e">the </span><span class="crayon-e">Learner </span><span class="crayon-v">engine</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-38" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">b</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">buffer</span><span class="crayon-o">&#8211;</span><span class="crayon-i">size</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">64</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">size </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-e">internal </span><span class="crayon-e">buffer </span><span class="crayon-st">for</span></div>
<div id="crayon-5df375e527260322873315-39" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">generate </span><span class="crayon-e">the </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-40" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">Q</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-t">byte</span><span class="crayon-o">&#8211;</span><span class="crayon-i">quality</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">80</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp; </span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">minimum </span><span class="crayon-e">quality </span><span class="crayon-st">for</span> <span class="crayon-e">the </span><span class="crayon-e">bytes </span><span class="crayon-e">of </span></div>
<div id="crayon-5df375e527260322873315-41" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">the </span><span class="crayon-e">generated </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-42" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">y</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">enable</span><span class="crayon-o">&#8211;</span><span class="crayon-i">yara</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-i">Generates</span> <span class="crayon-i">a</span> <span class="crayon-e">yara </span><span class="crayon-v">signature</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-43" class="crayon-line">&nbsp;</div>
<div id="crayon-5df375e527260322873315-44" class="crayon-line crayon-striped-line"><span class="crayon-e">Optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5df375e527260322873315-45" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">n</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">stack</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-v">lan</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">network </span><span class="crayon-e">stack</span> <span class="crayon-sy">(</span><span class="crayon-v">lan</span><span class="crayon-sy">,</span><span class="crayon-v">mobile</span><span class="crayon-sy">,</span><span class="crayon-v">lan6</span><span class="crayon-sy">,</span><span class="crayon-v">virtual</span><span class="crayon-sy">,</span></div>
<div id="crayon-5df375e527260322873315-46" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-v">oflow</span><span class="crayon-sy">)</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-47" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">d</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">dumpflows</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Dump </span><span class="crayon-e">the </span><span class="crayon-e">flows </span><span class="crayon-st">to</span> <span class="crayon-v">stdout</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-48" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">s</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">statistics</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">0</span><span class="crayon-sy">)</span> <span class="crayon-e">Show </span><span class="crayon-e">statistics </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-e">network </span><span class="crayon-e">stack</span> <span class="crayon-sy">(</span><span class="crayon-cn">5</span> <span class="crayon-v">levels</span><span class="crayon-sy">)</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-49" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">T</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">timeout</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">180</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">flows </span><span class="crayon-v">timeout</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-50" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">P</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">protocol</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Show </span><span class="crayon-e">statistics </span><span class="crayon-i">of</span> <span class="crayon-i">a</span> <span class="crayon-e">specific </span><span class="crayon-e">protocol </span><span class="crayon-e">of </span><span class="crayon-e">the </span></div>
<div id="crayon-5df375e527260322873315-51" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">network </span><span class="crayon-v">stack</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-52" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">a</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">port</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">0</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">HTTP </span><span class="crayon-e">listenting </span><span class="crayon-v">port</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-53" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">e</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">release</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Release </span><span class="crayon-e">the </span><span class="crayon-v">caches</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-54" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">l</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">release</span><span class="crayon-o">&#8211;</span><span class="crayon-i">cache</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg&nbsp;&nbsp; </span><span class="crayon-i">Release</span> <span class="crayon-i">a</span> <span class="crayon-e">specific </span><span class="crayon-v">cache</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-55" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">p</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">pstatistics</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Show </span><span class="crayon-e">statistics </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-v">process</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-56" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">o</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">summary</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Show </span><span class="crayon-e">protocol </span><span class="crayon-e">summmary </span><span class="crayon-e">statistics</span></div>
<div id="crayon-5df375e527260322873315-57" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-sy">(</span><span class="crayon-v">bytes</span><span class="crayon-sy">,</span><span class="crayon-v">packets</span><span class="crayon-sy">,</span><span class="crayon-o">%</span> <span class="crayon-v">bytes</span><span class="crayon-sy">,</span><span class="crayon-e">cache </span><span class="crayon-v">miss</span><span class="crayon-sy">,</span><span class="crayon-v">memory</span><span class="crayon-sy">)</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-58" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">h</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">help</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Show </span><span class="crayon-v">help</span><span class="crayon-sy">.</span></div>
<div id="crayon-5df375e527260322873315-59" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">v</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">version</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Show </span><span class="crayon-e">version </span><span class="crayon-t">string</span><span class="crayon-sy">.</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>You can download AIEngine here:</p>
<p><a href="https://bitbucket.org/camp0/aiengine/downloads/aiengine-1.9.1.tar.gz">aiengine-1.9.1.tar.gz</a></p>
<p>Or read more <a href="https://bitbucket.org/camp0/aiengine/src/master/">here</a>.</p>
<p>The post <a href="http://kostacipo.stream/aiengine-ai-driven-network-intrusion-detection-system-2/">AIEngine – AI-driven Network Intrusion Detection System</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/aiengine-ai-driven-network-intrusion-detection-system-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AIEngine – AI-driven Network Intrusion Detection System</title>
		<link>http://kostacipo.stream/aiengine-ai-driven-network-intrusion-detection-system/</link>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Tue, 26 Nov 2019 12:22:47 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion detection]]></category>
		<category><![CDATA[network]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1382</guid>

					<description><![CDATA[<p>&#160; AIEngine is a next-generation interactive/programmable Python/Ruby/Java/Lua and Go AI-driven Network Intrusion Detection System engine with capabilities of learning without any human intervention, DNS domain classification, Spam detection, network collector, network forensics and many others. AIEngine also helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/aiengine-ai-driven-network-intrusion-detection-system/">AIEngine – AI-driven Network Intrusion Detection System</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>AIEngine is a next-generation interactive/programmable Python/Ruby/Java/Lua and Go AI-driven Network Intrusion Detection System engine with capabilities of learning without any human intervention, DNS domain classification, Spam detection, network collector, network forensics and many others.</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-medium wp-image-5346" src="https://cdn.darknet.org.uk/wp-content/uploads/2019/11/AIEngine-AI-driven-Network-Intrusion-Detection-System-640x404.jpg" sizes="auto, (max-width: 640px) 100vw, 640px" srcset="https://cdn.darknet.org.uk/wp-content/uploads/2019/11/AIEngine-AI-driven-Network-Intrusion-Detection-System-640x404.jpg 640w, https://cdn.darknet.org.uk/wp-content/uploads/2019/11/AIEngine-AI-driven-Network-Intrusion-Detection-System.jpg 994w" alt="AIEngine - AI-driven Network Intrusion Detection System" width="640" height="404"></p>
<p>AIEngine also helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and so on.</p>
<h2>Functionality of AIEngine AI-driven Network Intrusion Detection System</h2>
<p>The main functionalities of AIEngine are:</p>
<ul>
<li>Support for interacting/programing with the user while the engine is running.</li>
<li>Support for PCRE JIT for regex matching.</li>
<li>Support for regex graphs (complex detection patterns).</li>
<li>Support six types of NetworkStacks (lan, mobile, lan6, virtual, oflow and mobile6).</li>
<li>Support Sets and Bloom filters for IP searches.</li>
<li>Supports x86_64, ARM and MIPS architecture over operating systems such as Linux, FreeBSD and MacOS.</li>
<li>Support for HTTP, DNS and SSL Domains matching.</li>
<li>Support for banned domains and hosts for HTTP, DNS, SMTP and SSL.</li>
<li>Frequency analysis for unknown traffic and auto-regex generation.</li>
<li>Generation of Yara signatures.</li>
<li>Easy integration with databases (MySQL, Redis, Cassandra, Hadoop, etc…) for data correlation.</li>
<li>Easy integration with other packet engines (Netfilter).</li>
<li>Support memory clean caches for refresh stored memory information.</li>
<li>Support for detect DDoS at network/application layer.</li>
<li>Support for rejecting TCP/UDP connections.</li>
<li>Support for network forensics on real time.</li>
<li>Support for JA3 TLS Signatures on SSL.</li>
<li>Supports protocols such as Bitcoin, CoAP, DHCPv4/DHCPv6, DNS, GPRS, GRE, HTTP, ICMPv4/ICMPv6, IMAP, IPv4/v6, Modbus, MPLS, MQTT, Netbios, NTP, OpenFlow, PPPoE, POP, Quic, RTP, SIP, SMB, SMTP, SSDP, SSH, SSL, TCP, UDP, VLAN, VXLAN.</li>
<li>Integration of HTTP Server for retrieve and configure the system.</li>
</ul>
<h3>Using AIEngine AI-driven Network Intrusion Detection System</h3>
<p>To use AIEngine(reduce version) just execute the binary aiengine or use the python/ruby/java/lua binding.</p>
<div id="crayon-5ddd17541bd0b009295843" class="crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-toolbar" data-settings=" mouseover overlay hide delay">
<div class="crayon-tools">
<div class="crayon-button crayon-popup-button" title="Open Code In New Window">
<div class="crayon-button-icon">&nbsp;</div>
</div>
</div>
</div>
<div class="crayon-plain-wrap"><textarea class="crayon-plain print-no" readonly="readonly" data-settings="dblclick" wrap="soft">luis@luis-xps:~/c++/aiengine/src$ ./aiengine -h<br />
aiengine 1.9.0<br />
Mandatory arguments:<br />
  -I [ &#8211;input ] arg                Sets the network interface ,pcap file or<br />
                                    directory with pcap files.</p>
<p>Link Layer optional arguments:<br />
  -q [ &#8211;tag ] arg      Selects the tag type of the ethernet layer (vlan,mpls).</p>
<p>TCP optional arguments:<br />
  -t [ &#8211;tcp-flows ] arg (=32768) Sets the number of TCP flows on the pool.</p>
<p>UDP optional arguments:<br />
  -u [ &#8211;udp-flows ] arg (=16384) Sets the number of UDP flows on the pool.</p>
<p>Regex optional arguments:<br />
  -R [ &#8211;enable-signatures ]     Enables the Signature engine.<br />
  -r [ &#8211;regex ] arg (=.*)       Sets the regex for evaluate agains the flows.<br />
  -c [ &#8211;flow-class ] arg (=all) Uses tcp, udp or all for matches the signature<br />
                 on the flows.<br />
  -m [ &#8211;matched-flows ]         Shows the flows that matchs with the regex.<br />
  -M [ &#8211;matched-packet ]        Shows the packet payload that matchs with<br />
                                 the regex.<br />
  -C [ &#8211;continue ]              Continue evaluating the regex with the<br />
                                 next packets of the Flow.<br />
  -j [ &#8211;reject-flows ]          Rejects the flows that matchs with the<br />
                                     regex.<br />
  -w [ &#8211;evidence ]              Generates a pcap file with the matching<br />
                                     regex for forensic analysis.</p>
<p>Frequencies optional arguments:<br />
  -F [ &#8211;enable-frequencies ]       Enables the Frequency engine.<br />
  -g [ &#8211;group-by ] arg (=dst-port) Groups frequencies by src-ip,dst-ip,src-por<br />
                    t and dst-port.<br />
  -f [ &#8211;flow-type ] arg (=tcp)     Uses tcp or udp flows.<br />
  -L [ &#8211;enable-learner ]           Enables the Learner engine.<br />
  -k [ &#8211;key-learner ] arg (=80)    Sets the key for the Learner engine.<br />
  -b [ &#8211;buffer-size ] arg (=64)    Sets the size of the internal buffer for<br />
                                    generate the regex.<br />
      -Q [ &#8211;byte-quality ] arg (=80)   Sets the minimum quality for the bytes of<br />
                                        the generated regex.<br />
  -y [ &#8211;enable-yara ]              Generates a yara signature.</p>
<p>Optional arguments:<br />
  -n [ &#8211;stack ] arg (=lan)    Sets the network stack (lan,mobile,lan6,virtual,<br />
                   oflow).<br />
  -d [ &#8211;dumpflows ]           Dump the flows to stdout.<br />
  -s [ &#8211;statistics ] arg (=0) Show statistics of the network stack (5 levels).<br />
  -T [ &#8211;timeout ] arg (=180)  Sets the flows timeout.<br />
  -P [ &#8211;protocol ] arg        Show statistics of a specific protocol of the<br />
                                   network stack.<br />
  -a [ &#8211;port ] arg (=0)       Sets the HTTP listenting port.<br />
  -e [ &#8211;release ]             Release the caches.<br />
  -l [ &#8211;release-cache ] arg   Release a specific cache.<br />
  -p [ &#8211;pstatistics ]         Show statistics of the process.<br />
      -o [ &#8211;summary ]             Show protocol summmary statistics<br />
                                   (bytes,packets,% bytes,cache miss,memory).<br />
  -h [ &#8211;help ]                Show help.<br />
  -v [ &#8211;version ]             Show version string.</textarea></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="show">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-1">1</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-2">2</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-3">3</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-4">4</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-5">5</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-6">6</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-7">7</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-8">8</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-9">9</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-10">10</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-11">11</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-12">12</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-13">13</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-14">14</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-15">15</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-16">16</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-17">17</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-18">18</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-19">19</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-20">20</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-21">21</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-22">22</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-23">23</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-24">24</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-25">25</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-26">26</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-27">27</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-28">28</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-29">29</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-30">30</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-31">31</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-32">32</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-33">33</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-34">34</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-35">35</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-36">36</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-37">37</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-38">38</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-39">39</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-40">40</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-41">41</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-42">42</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-43">43</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-44">44</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-45">45</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-46">46</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-47">47</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-48">48</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-49">49</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-50">50</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-51">51</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-52">52</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-53">53</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-54">54</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-55">55</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-56">56</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-57">57</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5ddd17541bd0b009295843-58">58</div>
<div class="crayon-num" data-line="crayon-5ddd17541bd0b009295843-59">59</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5ddd17541bd0b009295843-1" class="crayon-line"><span class="crayon-v">luis</span><span class="crayon-sy">@</span><span class="crayon-v">luis</span><span class="crayon-o">&#8211;</span><span class="crayon-v">xps</span><span class="crayon-o">:</span><span class="crayon-o">~</span><span class="crayon-o">/</span><span class="crayon-v">c</span><span class="crayon-o">++</span><span class="crayon-o">/</span><span class="crayon-v">aiengine</span><span class="crayon-o">/</span><span class="crayon-v">src</span><span class="crayon-sy">$</span> <span class="crayon-sy">.</span><span class="crayon-o">/</span><span class="crayon-v">aiengine</span> <span class="crayon-o">&#8211;</span><span class="crayon-i">h</span></div>
<div id="crayon-5ddd17541bd0b009295843-2" class="crayon-line crayon-striped-line"><span class="crayon-i">aiengine</span> <span class="crayon-cn">1.9.0</span></div>
<div id="crayon-5ddd17541bd0b009295843-3" class="crayon-line"><span class="crayon-e">Mandatory </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5ddd17541bd0b009295843-4" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">I</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">input</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">network </span><span class="crayon-t">interface</span> <span class="crayon-sy">,</span><span class="crayon-e">pcap </span><span class="crayon-e">file </span><span class="crayon-st">or</span></div>
<div id="crayon-5ddd17541bd0b009295843-5" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">directory </span><span class="crayon-e">with </span><span class="crayon-e">pcap </span><span class="crayon-v">files</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-6" class="crayon-line crayon-striped-line">&nbsp;</div>
<div id="crayon-5ddd17541bd0b009295843-7" class="crayon-line"><span class="crayon-e">Link </span><span class="crayon-e">Layer </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5ddd17541bd0b009295843-8" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">q</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">tag</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Selects </span><span class="crayon-e">the </span><span class="crayon-e">tag </span><span class="crayon-e">type </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-e">ethernet </span><span class="crayon-e">layer</span> <span class="crayon-sy">(</span><span class="crayon-v">vlan</span><span class="crayon-sy">,</span><span class="crayon-v">mpls</span><span class="crayon-sy">)</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-9" class="crayon-line">&nbsp;</div>
<div id="crayon-5ddd17541bd0b009295843-10" class="crayon-line crayon-striped-line"><span class="crayon-e">TCP </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5ddd17541bd0b009295843-11" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">t</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">tcp</span><span class="crayon-o">&#8211;</span><span class="crayon-i">flows</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">32768</span><span class="crayon-sy">)</span> <span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">number </span><span class="crayon-e">of </span><span class="crayon-e">TCP </span><span class="crayon-e">flows </span><span class="crayon-e">on </span><span class="crayon-e">the </span><span class="crayon-v">pool</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-12" class="crayon-line crayon-striped-line">&nbsp;</div>
<div id="crayon-5ddd17541bd0b009295843-13" class="crayon-line"><span class="crayon-e">UDP </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5ddd17541bd0b009295843-14" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">u</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">udp</span><span class="crayon-o">&#8211;</span><span class="crayon-i">flows</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">16384</span><span class="crayon-sy">)</span> <span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">number </span><span class="crayon-e">of </span><span class="crayon-e">UDP </span><span class="crayon-e">flows </span><span class="crayon-e">on </span><span class="crayon-e">the </span><span class="crayon-v">pool</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-15" class="crayon-line">&nbsp;</div>
<div id="crayon-5ddd17541bd0b009295843-16" class="crayon-line crayon-striped-line"><span class="crayon-e">Regex </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5ddd17541bd0b009295843-17" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">R</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">enable</span><span class="crayon-o">&#8211;</span><span class="crayon-i">signatures</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Enables </span><span class="crayon-e">the </span><span class="crayon-e">Signature </span><span class="crayon-v">engine</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-18" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">r</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">regex</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-sy">.</span><span class="crayon-o">*</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">regex </span><span class="crayon-st">for</span> <span class="crayon-e">evaluate </span><span class="crayon-e">agains </span><span class="crayon-e">the </span><span class="crayon-v">flows</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-19" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">c</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">flow</span><span class="crayon-o">&#8211;</span><span class="crayon-t">class</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-v">all</span><span class="crayon-sy">)</span> <span class="crayon-e">Uses </span><span class="crayon-v">tcp</span><span class="crayon-sy">,</span> <span class="crayon-e">udp </span><span class="crayon-st">or</span> <span class="crayon-e">all </span><span class="crayon-st">for</span> <span class="crayon-e">matches </span><span class="crayon-e">the </span><span class="crayon-e">signature</span></div>
<div id="crayon-5ddd17541bd0b009295843-20" class="crayon-line crayon-striped-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">on </span><span class="crayon-e">the </span><span class="crayon-v">flows</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-21" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">m</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">matched</span><span class="crayon-o">&#8211;</span><span class="crayon-i">flows</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Shows </span><span class="crayon-e">the </span><span class="crayon-e">flows </span><span class="crayon-e">that </span><span class="crayon-e">matchs </span><span class="crayon-e">with </span><span class="crayon-e">the </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-22" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">M</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">matched</span><span class="crayon-o">&#8211;</span><span class="crayon-i">packet</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Shows </span><span class="crayon-e">the </span><span class="crayon-e">packet </span><span class="crayon-e">payload </span><span class="crayon-e">that </span><span class="crayon-e">matchs </span><span class="crayon-e">with </span></div>
<div id="crayon-5ddd17541bd0b009295843-23" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">the </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-24" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">C</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-st">continue</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-st">Continue</span> <span class="crayon-e">evaluating </span><span class="crayon-e">the </span><span class="crayon-e">regex </span><span class="crayon-e">with </span><span class="crayon-e">the </span></div>
<div id="crayon-5ddd17541bd0b009295843-25" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">next </span><span class="crayon-e">packets </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-v">Flow</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-26" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">j</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">reject</span><span class="crayon-o">&#8211;</span><span class="crayon-i">flows</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Rejects </span><span class="crayon-e">the </span><span class="crayon-e">flows </span><span class="crayon-e">that </span><span class="crayon-e">matchs </span><span class="crayon-e">with </span><span class="crayon-e">the </span></div>
<div id="crayon-5ddd17541bd0b009295843-27" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-28" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">w</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">evidence</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-i">Generates</span> <span class="crayon-i">a</span> <span class="crayon-e">pcap </span><span class="crayon-e">file </span><span class="crayon-e">with </span><span class="crayon-e">the </span><span class="crayon-e">matching </span></div>
<div id="crayon-5ddd17541bd0b009295843-29" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">regex </span><span class="crayon-st">for</span> <span class="crayon-e">forensic </span><span class="crayon-v">analysis</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-30" class="crayon-line crayon-striped-line">&nbsp;</div>
<div id="crayon-5ddd17541bd0b009295843-31" class="crayon-line"><span class="crayon-e">Frequencies </span><span class="crayon-e">optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5ddd17541bd0b009295843-32" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">F</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">enable</span><span class="crayon-o">&#8211;</span><span class="crayon-i">frequencies</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Enables </span><span class="crayon-e">the </span><span class="crayon-e">Frequency </span><span class="crayon-v">engine</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-33" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">g</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">group</span><span class="crayon-o">&#8211;</span><span class="crayon-i">by</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-v">dst</span><span class="crayon-o">&#8211;</span><span class="crayon-v">port</span><span class="crayon-sy">)</span> <span class="crayon-e">Groups </span><span class="crayon-e">frequencies </span><span class="crayon-e">by </span><span class="crayon-v">src</span><span class="crayon-o">&#8211;</span><span class="crayon-v">ip</span><span class="crayon-sy">,</span><span class="crayon-v">dst</span><span class="crayon-o">&#8211;</span><span class="crayon-v">ip</span><span class="crayon-sy">,</span><span class="crayon-v">src</span><span class="crayon-o">&#8211;</span><span class="crayon-i">por</span></div>
<div id="crayon-5ddd17541bd0b009295843-34" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-i">t</span> <span class="crayon-st">and</span> <span class="crayon-v">dst</span><span class="crayon-o">&#8211;</span><span class="crayon-v">port</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-35" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">f</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">flow</span><span class="crayon-o">&#8211;</span><span class="crayon-i">type</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-v">tcp</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Uses </span><span class="crayon-e">tcp </span><span class="crayon-st">or</span> <span class="crayon-e">udp </span><span class="crayon-v">flows</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-36" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">L</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">enable</span><span class="crayon-o">&#8211;</span><span class="crayon-i">learner</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Enables </span><span class="crayon-e">the </span><span class="crayon-e">Learner </span><span class="crayon-v">engine</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-37" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">k</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">key</span><span class="crayon-o">&#8211;</span><span class="crayon-i">learner</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">80</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">key </span><span class="crayon-st">for</span> <span class="crayon-e">the </span><span class="crayon-e">Learner </span><span class="crayon-v">engine</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-38" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">b</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">buffer</span><span class="crayon-o">&#8211;</span><span class="crayon-i">size</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">64</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">size </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-e">internal </span><span class="crayon-e">buffer </span><span class="crayon-st">for</span></div>
<div id="crayon-5ddd17541bd0b009295843-39" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">generate </span><span class="crayon-e">the </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-40" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">Q</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-t">byte</span><span class="crayon-o">&#8211;</span><span class="crayon-i">quality</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">80</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp; </span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">minimum </span><span class="crayon-e">quality </span><span class="crayon-st">for</span> <span class="crayon-e">the </span><span class="crayon-e">bytes </span><span class="crayon-e">of </span></div>
<div id="crayon-5ddd17541bd0b009295843-41" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">the </span><span class="crayon-e">generated </span><span class="crayon-v">regex</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-42" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">y</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">enable</span><span class="crayon-o">&#8211;</span><span class="crayon-i">yara</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-i">Generates</span> <span class="crayon-i">a</span> <span class="crayon-e">yara </span><span class="crayon-v">signature</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-43" class="crayon-line">&nbsp;</div>
<div id="crayon-5ddd17541bd0b009295843-44" class="crayon-line crayon-striped-line"><span class="crayon-e">Optional </span><span class="crayon-v">arguments</span><span class="crayon-o">:</span></div>
<div id="crayon-5ddd17541bd0b009295843-45" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">n</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">stack</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-v">lan</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">network </span><span class="crayon-e">stack</span> <span class="crayon-sy">(</span><span class="crayon-v">lan</span><span class="crayon-sy">,</span><span class="crayon-v">mobile</span><span class="crayon-sy">,</span><span class="crayon-v">lan6</span><span class="crayon-sy">,</span><span class="crayon-v">virtual</span><span class="crayon-sy">,</span></div>
<div id="crayon-5ddd17541bd0b009295843-46" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-v">oflow</span><span class="crayon-sy">)</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-47" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">d</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">dumpflows</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Dump </span><span class="crayon-e">the </span><span class="crayon-e">flows </span><span class="crayon-st">to</span> <span class="crayon-v">stdout</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-48" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">s</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">statistics</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">0</span><span class="crayon-sy">)</span> <span class="crayon-e">Show </span><span class="crayon-e">statistics </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-e">network </span><span class="crayon-e">stack</span> <span class="crayon-sy">(</span><span class="crayon-cn">5</span> <span class="crayon-v">levels</span><span class="crayon-sy">)</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-49" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">T</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">timeout</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">180</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">flows </span><span class="crayon-v">timeout</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-50" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">P</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">protocol</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Show </span><span class="crayon-e">statistics </span><span class="crayon-i">of</span> <span class="crayon-i">a</span> <span class="crayon-e">specific </span><span class="crayon-e">protocol </span><span class="crayon-e">of </span><span class="crayon-e">the </span></div>
<div id="crayon-5ddd17541bd0b009295843-51" class="crayon-line"><span class="crayon-e">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">network </span><span class="crayon-v">stack</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-52" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">a</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">port</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg</span> <span class="crayon-sy">(</span><span class="crayon-o">=</span><span class="crayon-cn">0</span><span class="crayon-sy">)</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Sets </span><span class="crayon-e">the </span><span class="crayon-e">HTTP </span><span class="crayon-e">listenting </span><span class="crayon-v">port</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-53" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">e</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">release</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Release </span><span class="crayon-e">the </span><span class="crayon-v">caches</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-54" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">l</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-v">release</span><span class="crayon-o">&#8211;</span><span class="crayon-i">cache</span> <span class="crayon-sy">]</span> <span class="crayon-e">arg&nbsp;&nbsp; </span><span class="crayon-i">Release</span> <span class="crayon-i">a</span> <span class="crayon-e">specific </span><span class="crayon-v">cache</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-55" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">p</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">pstatistics</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Show </span><span class="crayon-e">statistics </span><span class="crayon-e">of </span><span class="crayon-e">the </span><span class="crayon-v">process</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-56" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">o</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">summary</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Show </span><span class="crayon-e">protocol </span><span class="crayon-e">summmary </span><span class="crayon-e">statistics</span></div>
<div id="crayon-5ddd17541bd0b009295843-57" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-sy">(</span><span class="crayon-v">bytes</span><span class="crayon-sy">,</span><span class="crayon-v">packets</span><span class="crayon-sy">,</span><span class="crayon-o">%</span> <span class="crayon-v">bytes</span><span class="crayon-sy">,</span><span class="crayon-e">cache </span><span class="crayon-v">miss</span><span class="crayon-sy">,</span><span class="crayon-v">memory</span><span class="crayon-sy">)</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-58" class="crayon-line crayon-striped-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">h</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">help</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span class="crayon-e">Show </span><span class="crayon-v">help</span><span class="crayon-sy">.</span></div>
<div id="crayon-5ddd17541bd0b009295843-59" class="crayon-line"><span class="crayon-h">&nbsp;&nbsp;</span><span class="crayon-o">&#8211;</span><span class="crayon-i">v</span> <span class="crayon-sy">[</span> <span class="crayon-o">&#8212;</span><span class="crayon-i">version</span> <span class="crayon-sy">]</span><span class="crayon-h">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span class="crayon-e">Show </span><span class="crayon-e">version </span><span class="crayon-t">string</span><span class="crayon-sy">.</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>You can download AIEngine here:</p>
<p><a href="https://bitbucket.org/camp0/aiengine/downloads/aiengine-1.9.1.tar.gz">aiengine-1.9.1.tar.gz</a></p>
<p>Or read more <a href="https://bitbucket.org/camp0/aiengine/src/master/">here</a>.</p>
<p>The post <a href="http://kostacipo.stream/aiengine-ai-driven-network-intrusion-detection-system/">AIEngine – AI-driven Network Intrusion Detection System</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
