Network Monitoring

From: Ken (SHIELDSIT)27 Nov 2013 09:30
To: ALL1 of 9
Does anyone have a recommendation for a decent (free) network monitoring program?  Preferably a linux distro.  I have tried a couple that I can't remember the names of right now but I'm just curious to see if there might be something better than what I've tried.

I am looking mostly for something that will detect issues, like botnet activity, etc.  Not interested in being a spy on the workers.

Ta!  
From: graphitone27 Nov 2013 11:18
To: Wattsy (SLAYERPUNX) Ken (SHIELDSIT) 2 of 9
Didn't Wattsy recommend something a while back? Can't remember the name of it myself now... :C

It was a linux distro and I remember trying it out, but had to use the machine it was on for something else so didn't really get a chance to play.
From: Ken (SHIELDSIT)27 Nov 2013 11:26
To: graphitone 3 of 9
He very well could have.  I can't remember anything anymore!  I downloaded nagios a bit ago.  As soon as I get these final updates installed I'm going to give it a try.

Sorry if I've already asked this!
From: ANT_THOMAS27 Nov 2013 11:49
To: graphitone 4 of 9
Was it Backtrack?
From: Ken (SHIELDSIT)27 Nov 2013 12:29
To: ANT_THOMAS 5 of 9
I use that for exploit type stuff.  I want something that has monitoring agents n shit.
From: graphitone27 Nov 2013 12:51
To: ANT_THOMAS 6 of 9
Doesn't ring a bell.

<searches frantically through the disks on my desk>

Backbox.

That's the one.
From: Mizzy27 Nov 2013 16:59
To: Ken (SHIELDSIT) 7 of 9
Have a look at this, it might be overkill but it is free.

http://www.alienvault.com/open-threat-exchange/projects#ossim-tab

i use the commercial version (Alienvault USM)



From: patch27 Nov 2013 17:58
To: Ken (SHIELDSIT) 8 of 9
Most people seem to pay for their IPS. This list might have something.
From: Ken (SHIELDSIT)27 Nov 2013 19:08
To: patch 9 of 9
Yeah, I'm just tired of fighting for every cent at this point.