tag:blogger.com,1999:blog-4088979.post115091590023000294..comments2023-10-16T06:06:25.012-04:00Comments on TaoSecurity Blog: Sguil Makes 2006 Top 100 Security Tools ListRichard Bejtlichhttp://www.blogger.com/profile/13512184196416665417noreply@blogger.comBlogger10125tag:blogger.com,1999:blog-4088979.post-74064055140379238462009-02-10T03:37:00.000-05:002009-02-10T03:37:00.000-05:00This comment has been removed by a blog administrator.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1151069205461661442006-06-23T09:26:00.000-04:002006-06-23T09:26:00.000-04:00That's a good survey. Most of the top ten tools ar...That's a good survey. Most of the top ten tools are already in backtrack. But they should survey well before they post the result.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1151065289136681882006-06-23T08:21:00.000-04:002006-06-23T08:21:00.000-04:00BASE and Sguil do not share the "same functionalit...BASE and Sguil do not share the "same functionality." Sguil is not a log reviewer; Sguil is not a SIM/SEM. I've written about this many times so that's all I'll say here.Richard Bejtlichhttps://www.blogger.com/profile/13512184196416665417noreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1151065038678143632006-06-23T08:17:00.000-04:002006-06-23T08:17:00.000-04:00This comment has been removed by a blog administrator.Joel Eslerhttps://www.blogger.com/profile/05018134738510159518noreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1151045885639678292006-06-23T02:58:00.000-04:002006-06-23T02:58:00.000-04:00Anyway that survey result relies on the popularity...Anyway that survey result relies on the popularity > functionality. So it should be called Most popular Netowkr Security Tools instead of Top * Network Security Tools. <BR/><BR/>By the way, BASE offers web-gui, I wonder what people call if that's not 'gui'.C.S.Leehttps://www.blogger.com/profile/10778262436985693992noreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1150986377879794522006-06-22T10:26:00.000-04:002006-06-22T10:26:00.000-04:00The list is biased towards attack tools. If fragro...The list is biased towards attack tools. If fragroute is listed under Intrusion Detection, to an attacker that category might mean "avoiding intrusion detection".Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1150944202144646562006-06-21T22:43:00.000-04:002006-06-21T22:43:00.000-04:00I love Nagios and have been using it for years (si...I love Nagios and have been using it for years (since the NetSaint days), but it doesn't belong on a security list. Sguil on the other hand, despite it's bugs, makes a lot of the other tools more useful.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1150936927626455782006-06-21T20:42:00.000-04:002006-06-21T20:42:00.000-04:00If you want to sort Snort alerts in a Web browser,...If you want to sort Snort alerts in a Web browser, BASE is great. If you want to use Snort alerts as one possible beginning of a network security investigation, Sguil is essential.<BR/><BR/>I have been involved with Sguil before Sguil existed. :)<BR/><BR/>Nagios does not inspect network traffic the same way Ntop, Ngrep, Argus, etc. do. Network traffic monitoring != service monitoring.Richard Bejtlichhttps://www.blogger.com/profile/13512184196416665417noreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1150934115516933792006-06-21T19:55:00.000-04:002006-06-21T19:55:00.000-04:00Not sure why you regret the positioning of SGUIL v...Not sure why you regret the positioning of SGUIL versus BASE. I find the later totally essential for one reason: <I>no gui!</I>. I want web based administration. I'm actually amazed at how popular sguil is. <BR/><BR/> Ah... heh, I see SGUIL quotes you on their main page. :)<BR/><BR/> On Nagios, it can do network, server, temperature, refrigerator monitoring, so its category is sensible.<BR/><BR/>B. BasgenAnonymousnoreply@blogger.comtag:blogger.com,1999:blog-4088979.post-1150928946314476442006-06-21T18:29:00.000-04:002006-06-21T18:29:00.000-04:00Doh! I never heard about this survey!Doh! I never heard about this survey!Anonymousnoreply@blogger.com