From: TM <ope...@ga...> - 2008-11-29 20:37:02
|
This just appeared on my radar: http://isc.sans.org/diary.html?storyid=5399&rss SidReporter seems aligned with many of the original design goals of opensims. Optionally-anonymized incident reports to a centralized collector. It looks like snort is the only sensor currently supported, but their reporting format accomodates expansion. I'm just starting reading about it, but I figured I should pass this along, since I hadn't heard mention of it from this list. -t. |