Dashboard of network top-talkers using netflow sources
FlowDoh is an NFSEN (nfsen.sourceforge.net) plugin that can...
* Provide a real-time dashboard of the top-talkers on your network
* Send email alerts based on networkactivity thresholds
* Allow quick drill-down into detailed flow information
* Record historical values so you can know if the network traffic is normal (Planned feature)
FlowDoh can be used for multiple purposes:
* Find hacked servers on your network
* Identify users who are hogging bandwidth (such as peer-to-peer file-sharing)
* Create a baseline of network statistics about your servers (planned feature)
FAQ:
Q: Why is it called FlowDoh?
...
The Logging of User Actions in Relational Mode (LUARM) is a logging/audit engine designed to record in detail user actions in a Relational Database Management System (RDBMS). You can then have an organized 'who is doing what' view in your system, being able to easily correlate program execution, file access and network endpoint activity to user entities.
Pace-IDS is an Intrusion Detection system designed to replace Tripwire, in that it is faster, and more effective of detecting trojan activity, and is easier to configure. All you have to do usually is simply change one variable to your email address.