Sign inSign up

madurosecurity/vft-agent

By madurosecurity

•Updated almost 9 years ago

The client/agent for VFT

Image
1

894

madurosecurity/vft-agent repository overview

⁠Venus Fly Trap

GoDoc Reference Build Status Go Report Card

A network anomaly detection engine

⁠Summary

VFT straddles the line between a network intrusion detection system (NIDS), host-based intrustion detection system (HIDS), and a honeypot. It is simultaneously all and none of these. Designed to work best across a fleet of clients, VFT detects connections and potential scanning activity that may evade your NIDS or HIDS, but without requiring setup of heavier systems such ELK or relying on event correlation from Datadog (although that is totally an option).

⁠Quick start

docker run --rm -it --net=host madurosecurity/vft-agent --server vft.yourcompany.net:9999

⁠How it works

This package is the client/agent for the VFT server⁠. The agent starts a TCP listener on 5 random "common" ports and listens for connections. Upon receiving a connection, vft-agent closes it and sends a report of the connection to the server which will then attempt to correlate the activity. The agent requires a VFT server to operate.

⁠Example of starting the client:

$ vft-agent --tls --cert ./cert.pem --server vft.yourcompany.net:9999 --secret sharedsecret

⁠Downloads

Tag summary

Content type

Image

Digest

Size

4.4 MB

Last updated

almost 9 years ago

docker pull madurosecurity/vft-agent