Impost is a network security auditing tool designed to analyze the forensics behind compromised and/or vulnerable daemons. There are two different kinds of operating modes; it can either act as a honey pot and take orders from a Perl script controlling how it responds and communicates with connecting clients, or it can operate as a packet sniffer and monitor incoming data to specified destination port supplied by the command-line arguments.
Isoqlog is an MTA log analysis program written in C. It is designed to scan qmail, Postfix, Sendmail, and Exim logfiles and produce usage statistics in HTML for viewing through a browser. It produces a "top domains" statistic according to sender, receiver, total mails, and bytes, and keeps the main domain mail statistics with regard to day's top domain, and top users values for per day, per month, and per year.
Lire is a pluggable log analyzer. It has analyzers for over 25 log file formats, ranging from Apache WWW log files to iptables firewall logs and CUPS printing logs. Reports are generated in 9 different output formats, ranging from Excel 95 to PDF to HTML, optionally with included graphs.
Pathalizer is a tool for visualizing the paths most users take when browsing a Web site. This information can be used to decide how to improve the navigation of the site, and for determining which parts are most worth improving and keeping up to date. It generates a directed, weighed graph from an Apache log, but could easily be modified to analyze any list of events.
Webalizer Xtended is a fork of Webalizer and contains a great number of feature improvements, such as monthly statistics for all "HTTP 404 Not Found" errors (including the number of these errors and the corresponding URLs) and additional configuration file keywords. Furthermore, all colors of the statistics can be defined by the user. Webalizer Xtended also fixes several (security-related) bugs in the original Webalizer code and contains the "Apache mod_logio" patch to generate more reliable traffic statistics.
grepcidr can be used to filter a list of IP addresses against one or more Classless Inter-Domain Routing (CIDR) specifications, or arbitrary networks specified by an address range. As with grep, there are options to invert matching and load patterns from a file. grepcidr is capable of comparing thousands or even millions of IPs to networks with little memory usage and in reasonable computation time. It has endless uses in network software, including mail filtering and processing, network security, log analysis, and many custom applications.