Files
securityonion/salt/common/files/analyst
2020-10-02 12:12:28 -04:00
..
2020-10-01 16:21:51 -04:00
2020-10-02 12:12:28 -04:00
2020-10-02 11:28:53 -04:00

The following GUI tools are available on the analyst workstation:

chromium
  url: https://www.chromium.org/Home
  To run chromium, click Applications > Internet > Chromium Web Browser
  
Wireshark
  url: https://www.wireshark.org/
  To run Wireshark, click Applications > Internet > Wireshark Network Analyzer

NetworkMiner
  url: https://www.netresec.com
  To run NetworkMiner, click Applications > Internet > NetworkMiner

The following CLI tools are available on the analyst workstation:

bit-twist
  url: http://bittwist.sourceforge.net
  To run bit-twist, open a terminal and type: bittwist -h

chaosreader
  url: http://chaosreader.sourceforge.net
  To run chaosreader, open a terminal and type: chaosreader -h

dnsiff
  url: https://www.monkey.org/~dugsong/dsniff/
  To run dsniff, open a terminal and type: dsniff -h

foremost
  url: http://foremost.sourceforge.net
  To run foremost, open a terminal and type: foremost -h
  
hping3
  url: http://www.hping.org/hping3.html
  To run hping3, open a terminal and type: hping3 -h

netsed
  url: http://silicone.homelinux.org/projects/netsed/
  To run netsed, open a terminal and type: netsed -h

ngrep
  url: https://github.com/jpr5/ngrep
  To run ngrep, open a terminal and type: ngrep -h

scapy
  url: http://www.secdev.org/projects/scapy/
  To run scapy, open a terminal and type: scapy

ssldump
  url: http://www.rtfm.com/ssldump/
  To run ssldump, open a terminal and type: ssldump -h

sslsplit
  url: https://github.com/droe/sslsplit
  To run sslsplit, open a terminal and type: sslsplit -h

tcpdump
  url: http://www.tcpdump.org
  To run tcpdump, open a terminal and type: tcpdump -h

tcpflow
  url: https://github.com/simsong/tcpflow
  To run tcpflow, open a terminal and type: tcpflow -h

tcpstat
  url: https://frenchfries.net/paul/tcpstat/
  To run tcpstat, open a terminal and type: tcpstat -h

tcptrace
  url: http://www.tcptrace.org
  To run tcptrace, open a terminal and type: tcptrace -h

tcpxtract
  url: http://tcpxtract.sourceforge.net/
  To run tcpxtract, open a terminal and type: tcpxtract -h

whois
  url: http://www.linux.it/~md/software/
  To run whois, open a terminal and type: whois -h