PSAD

Not Rated
Description
PSAD is a collection of four lightweight system daemons written in Perl and in C that is designed to work with Linux firewalling code (iptables in the 2.4.x kernels, and ipchains in the 2.2.x kernels) to detect port scans. It features a set of highly configurable danger thresholds (with sensible defaults provided), verbose alert messages that include the source, destination, scanned port range, begin and end times, tcp flags and corresponding nmap options (Linux 2.4.x kernels only), reverse DNS info, email alerting, and automatic blocking of offending ip addresses via dynamic configuration of ipchains/iptables firewall rulesets.

In addition, for the 2.4.x kernels psad incorporates many of the tcp signatures included in Snort to detect highly suspect scans for:

* various backdoor programs (e.g. EvilFTP, GirlFriend, SubSeven)
* DDoS tools (mstream, shaft)
* advanced port scans (syn, fin, xmas) such as those made with nmap

Homepage: http://www.cipherdyne.org/
Interface: Command Line
Associated Programs
Bastille Security hardening tool
Perl Larry Wall's Practical Extraction and Report Language
PSmisc Utilities that use the proc filesystem
Available deb Repositories (how-to add a respository)
Debian 32-bit 64-bit
sarge 1.4.1-1 1.4.1-1
etch 1.4.8-1 1.4.8-1
lenny 2.1.1-1.1
sid 2.1.2-1 2.1.2-1

Ubuntu 32-bit 64-bit
dapper 1.4.4-1 1.4.4-1
edgy 1.4.6-1 1.4.6-1
feisty 2.0.4-1 2.0.4-1
gutsy 2.0.7-1 2.0.7-1
hardy 2.1-1 2.1-1

Available rpm Repositories

Rating: Not Rated (0 votes)


Login or Register to rate PSAD, add a Tag, or designate as an alternative to a Windows app



Upload Screenshots
Images must be in GIF, JPG, or PNG formats and can be no larger than 2 MB. Only one file can be uploaded at a time. A description can be included, but it is optional.
Desc:
File:
You must login or register to upload a screenshot.
Submit Web Links
Submit the title and link (including http://) to an article pertaining to PSAD and it will appear in the Web Links section of the right banner. Contact us here if an entry needs to be removed.
Title:
Link:
You must login or register to post links.