|
Click on an image to see it full size
|
KFSensor Administration Console
The Administration Console enables control of the sensors, event notification and investigation.
|

Displays the simulated services on each port. Ports are color coded to indicate recent activity. The events displayed are from a variety of real life attack. |
|

Displays each visitor to the sensor. |

View multiple remote sensors and their events on one console. |
|

When not in use the Administration Console sits in the system tray. It flashes red and optionally plays an alarm sound when an attack is detected. |
Event Investigation
View detailed information on every attack.
|

Each event contains a wealth of detail to enable further analysis of an attack. |
|

View a detailed log of the data transmitted during an attack. This example shows the Opaserv worm attempting spread itself via SMB. |

View the data in different formats. This example shows the Blaster worm's payload in Hex. |
|

Each sensor can be configured for specific tasks or to simulate different systems and services. |
Signatures
KFSensor is contains a fully featured signature based IDS engine.
|

Known attacks patterns are identified by the signature IDS engine and the signature details are available in the events view. |
|

Signature rule administration is totally GUI based. |

Signature rules support port based filters and multiple signatures. Signatures support string, url and decoded data searches as well as regular expressions. |
|

Import Snort format rule sets directly into KFSensor. |
Configurable
KFSensor is highly configurable.
|

Manage multiple sensor installations across the network, from one console. All protected by 3072 bit RSA public/private key authentication and 256 bit AES encryption. |
|

KFSensor can be configured to listen on any port. |

Each sensor can be configured for specific tasks or to simulate different systems and services. |
|

Configure exactly how KFSensor should respond to a NetBIOS scan. |

Each server emulation can be configured. |
|

The interface is fully customizable. Choose exactly how you want the event details to be displayed. |
Custom Enhancements
Add value to KFSensor by writing your own custom reports, or simulated servers.
|

Write your own custom reports in Access, or any other SQL database. |
|

Write your own custom server emulations, using languages like PERL. |

Load the log of spam attacks into Access for further analysis. |
|
|