port80 isn't a software house, and we don't produce software products for sale. However
we have occasionally seen the need for a tool to fulfill a client's specific requirements
but have found that software does not yet exist. In these circumstances we
have produced the software ourselves and released
it free of charge for any person or company who wishes to use it under the Gnu Public License
(see here for details of the license).
|| serverM
serverM is port80's host-based intrusion detection system
written for the *nix platform, including Linux, BSD, Solaris, HP-UX and other flavors. It is
an extremely flexible platform with a comprehensive detection rule programming language, and the
ability to alert on intrusion symptoms via email, SMS, or arbitrary command execution. serverM is
already in use in a number of companies ranging from large corporations, government departments,
and smaller companies.
You can download the software and associated documentation and examples
here.
|| scour
scour is a powerful log file analysis tool that can
be used to find patterns in a wide variety of *nix log files produced by
systems such as syslog, Apache, and
snort. Scour is different from most log analysis programs in that it understands
the time-stamps within the log files, and can tune its searches accordingly: for example, it
is able to look for recurring patterns within given time frames.
You can download the software and associated documentation and examples
here.