Prewikka is a graphical front-end analysis console for the Prelude hybrid IDS framework. Prelude is a hybrid intrusion detection framework implementing an open communication layer for use by any security application. It offers the ability to unify currently available security tools into one, powerful, and distributed application. Providing numerous features, Prewikka facilitate the work of users and analysts. It provides alert aggregation, sensors and hearbeat views, and has user management and configurable filters. It has access to external tools such as whois and traceroute.
|Tags||Security Logging Monitoring Networking|
|Operating Systems||Unix Mac OS X POSIX|
Release Notes: User can now choose the way alerts are sorted. Asynchronous DNS resolution is now supported in the alert view as well as the message summary. The alert summary view now handles portlist and ip_version service fields, and shows the alert's messageid. An exception when rendering ToolAlert was fixed along with double classification escaping. The Heartbeat view was sped up. A Polish translation was included. There were also various bugfixes and cleanups.
Release Notes: An auto-refresh system was implemented. The ability to filter on missing, offline, online, or unknown agents was added. It is now easier to read each agent status in collapsed mode. A filter load/save/delete problem with translation was fixed. New "My account" tabs were added under the Settings section. messageid and analyzerid parameters were added, allowing a link to a Prewikka alert from an external tool. The timeline control table layout was improved. Translation of strings possibly using plural forms was fixed. Various bugs were fixed.
Release Notes: A new powerful and scalable agent view, grouping agent together by Location and Node. This release has been internationalized: a user can choose the language used in their settings tab, or specify a default locale using the "default_locale" configuration keyword. Current translations: Brazilian Portuguese, French, German, Russian, and Spanish. In the Alert/Heartbeat summary view, analyzers are numbered backward to reflect the ordering in the analyzer list. Support has been added for resizing the menu. A Konqueror rendering bug with the inline filter has been fixed. There are various bugfixes.
Release Notes: All sources and targets are not shown if they reach a predefined limit; an expansion link is provided instead. Two new views were added in the Events section: CorrelationAlert and ToolAlert. The ability to filter/aggregate on all IDMEF paths was added. The user may choose which criteria filter operator to use. Analyzer aggregation was added. When a session expires and the user logs in, she is directed to the last page she attempted to access. When an error occur, the default layout is preserved. Non-aggregated views are faster by around 50%. IDMEF Action, SNMPService, and WebService class are supported. Support for small screen resolution was improved.