The client/agent for VFT
894
A network anomaly detection engine
VFT straddles the line between a network intrusion detection system (NIDS), host-based intrustion detection system (HIDS), and a honeypot. It is simultaneously all and none of these. Designed to work best across a fleet of clients, VFT detects connections and potential scanning activity that may evade your NIDS or HIDS, but without requiring setup of heavier systems such ELK or relying on event correlation from Datadog (although that is totally an option).
docker run --rm -it --net=host madurosecurity/vft-agent --server vft.yourcompany.net:9999
This package is the client/agent for the VFT server. The agent starts a TCP listener on 5 random "common" ports and listens for connections. Upon receiving a connection, vft-agent closes it and sends a report of the connection to the server which will then attempt to correlate the activity. The agent requires a VFT server to operate.
$ vft-agent --tls --cert ./cert.pem --server vft.yourcompany.net:9999 --secret sharedsecret
Content type
Image
Digest
Size
4.4 MB
Last updated
almost 9 years ago
docker pull madurosecurity/vft-agent