How to Analyse IDS/ IPS alert in properway

24 views
Skip to first unread message

SRIHARI RAJ

unread,
Jun 29, 2016, 10:56:21 AM6/29/16
to securit...@googlegroups.com
Hello all,

    I need your guidance/ procedure  to investigate Source fire IDS/IPS critical alerts in proper and structured way. Can any one please help on this. Also please provide me the IDS/IPS learning source and sample investigation documents / templates.


Thanks in advance

Hari.

Nishant Gupta

unread,
Jul 15, 2016, 1:07:04 PM7/15/16
to securit...@googlegroups.com
Hi Hari,

I think I can help you on this.
for viewing my WAF I use jwall audit viewer
You can get it from here.
https://www.jwall.org/web/audit/viewer.jsp
And I can give you some sample file to view too. Stay tuned.
for any query you can communicate me here.

-Nishant


--
Our Infosec Network
------------------------------
SecurityXploded - http://securityxploded.com/
SecurityTrainings - http://securitytrainings.net/
MalwareNet - http://malwarenet.com
SecurityPhresh - http://securityphresh.com
 
 
...
---
You received this message because you are subscribed to the Google Groups "SecurityXploded" group.
To unsubscribe from this group and stop receiving emails from it, send an email to securityxplod...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

gaurav damri

unread,
Jul 16, 2016, 6:53:00 AM7/16/16
to securit...@googlegroups.com
Can anyone guide me to name famous/useful VAPT tools...Even commercial ones!!
--
Regards
Gaurav Damri

SRIHARI RAJ

unread,
Jul 16, 2016, 6:53:00 AM7/16/16
to securit...@googlegroups.com

Thank you Nitin,

I can go through suggested link.

I will come back here.

Thanks
Hari.

SRIHARI RAJ

unread,
Jul 16, 2016, 6:53:00 AM7/16/16
to securit...@googlegroups.com
Hello Nishant,

     I have browsed https://www.jwall.org/security/ . But im not understanding exactly, may be i don't have more java skills. Can you please help me on IDS/IPS.



Thanks

Hari.

NaxoneZ .

unread,
Jul 16, 2016, 6:53:00 AM7/16/16
to securit...@googlegroups.com

Hi,

You can try with this tool:

http://pytbull.sourceforge.net/

Regards


--

Nishant Gupta

unread,
Jul 20, 2016, 9:43:28 AM7/20/16
to securit...@googlegroups.com
Hi Hari,

First try to get knowledge and do install/hands on for any IDS/IPS like Snort (For Network Level), Mod Security (For Application level), read source online and if you need books then contact me.

-Nishant
Reply all
Reply to author
Forward
0 new messages