Securix-NSM 1.0 Released
Yesterday I read A successor is born... Securix-NSM 1.0. Securix-NSM is a Debian-based live CD that is the fastest way I've ever seen for a new user to try Sguil. All you have to do is download the 280 MB .iso, boot it, and follow the quick start documentation.
Those steps are basically:
To test Sguil, I executed 'apt-get install lynx' then visited www.testmyids.com. In the screenshot you'll see the default Sguil installation generated two alerts. I was able to generate a transcript and launch Wireshark. However, SANCP session records did not appear to be inserted into the database although SANCP was running.
I suggest trying Securix-NSM if you'd like to try using Sguil but have no experience setting it up.
Those steps are basically:
- Open a terminal.
- Execute 'sudo nsm start'.
- Double-click on the Sguil client icon.
- Log into Sguil.
To test Sguil, I executed 'apt-get install lynx' then visited www.testmyids.com. In the screenshot you'll see the default Sguil installation generated two alerts. I was able to generate a transcript and launch Wireshark. However, SANCP session records did not appear to be inserted into the database although SANCP was running.
I suggest trying Securix-NSM if you'd like to try using Sguil but have no experience setting it up.
Comments
1. Check if the sancp_agent has updated its status in the sguil "Agent Status" window.
2. If the "Last" column shows N/A then performing a "sudo /etc/init.d/sancpd restart" should update the time in about 15 seconds and from then on its all good again.
That's the temporary work around at this stage and we'll have a more permanent fix in the next release 1.1.
see www.securixlive.com for more details.
Thanks Richard for the feedback.
Regards,
Coops
The requested URL /securix-nsm/download.php was not found on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.securixlive.com Port 80