Key | Value |
---|---|
FileName | ./etc/prelude-lml/ruleset/checkpoint.rules |
FileSize | 19783 |
MD5 | 3758C168285EFC9DC53FB6680FA3E133 |
SHA-1 | 0EC89F425217265014FEE07AEA96EA802D5A0564 |
SHA-256 | A7FC3286863CA138AABE310AA256BF0575587258B7DBC99E62449388600C3E4C |
SSDEEP | 192:YwfaX0haX0gMaX0HaX02OXzbGDOXzbnOXzbR5OXzbSaX0slbOXzs00YmIeBX0A0+:YwOm5AMqTZoS+6XDLK |
TLSH | T13592314E676490D149471014285113B07E7CD5D8DBEF24C8E3B09622E666FECBF9EFA1 |
tar:gname | bin |
tar:uname | root |
hashlookup:parent-total | 81 |
hashlookup:trust | 100 |
The searched file hash is included in 81 parent files which include package known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
MD5 | 83370381B9A6418A65D634F6FE277CEA |
PackageArch | s390 |
PackageDescription | Prelude-LML is a log analyser that allows Prelude to collect and analyze information from all kind of applications emitting logs or syslog messages in order to detect suspicious activities and transform them into Prelude-IDMEF alerts. Prelude-LML handles events generated by a large set of applications, |
PackageMaintainer | Fedora Project |
PackageName | prelude-lml |
PackageRelease | 10.fc19 |
PackageVersion | 1.0.0 |
SHA-1 | 00C52685FDB1A48951430E5E814E65D85E2AA0C0 |
SHA-256 | 2AE1B0472F1FEEBF11F1DFBF6B592FCA5166701D8F5198E086C517271BB17501 |
Key | Value |
---|---|
FileSize | 233536 |
MD5 | BD1AE5FE3C88D5286A9777AE0DD4FE76 |
PackageDescription | Security Information Management System [ Log Agent ] Prelude is a Universal "Security Information Management" (SIM) system. Its goals are performance and modularity. It is divided in two main parts : - the Prelude sensors, responsible for generating alerts, such as snort sensor, featuring a signature engine, plugins for protocol analysis, and intrusion detection plugins, and the Prelude log monitoring lackey. - the Prelude report server, collecting data from Prelude sensors, and generating user-readable reports. . Prelude-LML is a signature based log analyzer monitoring logfile and received syslog messages for suspicious activity. It handle events generated by a large set of components, including but not limited to: Apache, BigIP, Grsecurity, Honeyd, ipchains, Netfilter, ipfw, Nagios, NTsyslog, NuFW, PAM, Portsentry, Postfix, Proftpd, ssh, etc. |
PackageMaintainer | Pierre Chifflier <pollux@debian.org> |
PackageName | prelude-lml |
PackageSection | admin |
PackageVersion | 1.0.0-5.3 |
SHA-1 | 02980F19C2A3168079E78080E03E840B5AE512C5 |
SHA-256 | C3EAAEFCA44BE88E9FB41A04414E71423F6FFAE2F07C18D781D16CFA354DF589 |
Key | Value |
---|---|
FileSize | 235652 |
MD5 | 1897290586C1B3F7E1F64DCB71FB4C5F |
PackageDescription | Security Information Management System [ Log Agent ] Prelude is a Universal "Security Information Management" (SIM) system. Its goals are performance and modularity. It is divided in two main parts : - the Prelude sensors, responsible for generating alerts, such as snort sensor, featuring a signature engine, plugins for protocol analysis, and intrusion detection plugins, and the Prelude log monitoring lackey. - the Prelude report server, collecting data from Prelude sensors, and generating user-readable reports. . Prelude-LML is a signature based log analyzer monitoring logfile and received syslog messages for suspicious activity. It handle events generated by a large set of components, including but not limited to: Apache, BigIP, Grsecurity, Honeyd, ipchains, Netfilter, ipfw, Nagios, NTsyslog, NuFW, PAM, Portsentry, Postfix, Proftpd, ssh, etc. |
PackageMaintainer | Pierre Chifflier <pollux@debian.org> |
PackageName | prelude-lml |
PackageSection | admin |
PackageVersion | 1.0.0-5.3+b4 |
SHA-1 | 070A91F4BD8F6568BC23752A1A651FC917E060A7 |
SHA-256 | DE5FCE204B978D8CB2E57FD2B05E162C1F6AF9481C48BBF291CC2E324D5918BE |
Key | Value |
---|---|
MD5 | 723166817B0F37FF937009D3CFBC4994 |
PackageArch | ppc |
PackageDescription | Prelude-LML is a log analyser that allows Prelude to collect and analyze information from all kind of applications emitting logs or syslog messages in order to detect suspicious activities and transform them into Prelude-IDMEF alerts. Prelude-LML handles events generated by a large set of applications, |
PackageMaintainer | Koji |
PackageName | prelude-lml |
PackageRelease | 4.fc15 |
PackageVersion | 1.0.0 |
SHA-1 | 0A128C32A6610B73E4A0D55681EC4BA7B97DC12E |
SHA-256 | A105610776B95454BC395D3965B5E5A48DD5BD706CA0CEF9D357796F831DE4C9 |
Key | Value |
---|---|
FileName | https://ftp.lysator.liu.se/pub/OpenBSD//4.4//packages//powerpc//prelude-lml-0.9.10.tgz |
MD5 | 74F84CA3BAB1453955AE0320D7CF54CD |
SHA-1 | 0B7E36C6420A9A6BC4FF9A6C06774849FD0383D0 |
SHA-256 | 4404815092FFF7557330B8FF715D9EEC8F05AEE7F07B146DB1D00E88B20E79F6 |
SSDEEP | 3072:zLGZivuE5XnxLt2LP/shlkp1uILWqiDMEf53lONy7NnfYQG:nkimO9tocA+zDrR3IGNnfXG |
TLSH | T19FD3126A3499E1905DCAC38EEC93DC281DC04FFB17095FA996432E969F133E6449235B |
Key | Value |
---|---|
FileSize | 131990 |
MD5 | 091ABBD2B4FDF7331F96EFF207CEA445 |
PackageDescription | Security Information Management System [ Log Agent ] Prelude is a Universal "Security Information Management" (SIM) system. Its goals are performance and modularity. It is divided in two main parts : - the Prelude sensors, responsible for generating alerts, such as snort sensor, featuring a signature engine, plugins for protocol analysis, and intrusion detection plugins, and the Prelude log monitoring lackey. - the Prelude report server, collecting data from Prelude sensors, and generating user-readable reports. . Prelude-LML is a signature based log analyzer monitoring logfile and received syslog messages for suspicious activity. It handle events generated by a large set of components, including but not limited to: Apache, BigIP, Grsecurity, Honeyd, ipchains, Netfilter, ipfw, Nagios, NTsyslog, NuFW, PAM, Portsentry, Postfix, Proftpd, ssh, etc. |
PackageMaintainer | Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com> |
PackageName | prelude-lml |
PackageSection | admin |
PackageVersion | 1.0.0-5build1 |
SHA-1 | 0C95E178EAF9F850E778DBC2722EDDD5231062CF |
SHA-256 | CF96A52610A17997A46E87F851C34429A64395F994ACAA402B94DE51DC425F30 |
Key | Value |
---|---|
MD5 | ADB7EC94887D2F21F1E4B9BB04FA59EA |
PackageArch | s390x |
PackageDescription | Prelude-LML is a log analyser that allows Prelude to collect and analyze information from all kind of applications emitting logs or syslog messages in order to detect suspicious activities and transform them into Prelude-IDMEF alerts. Prelude-LML handles events generated by a large set of applications, |
PackageMaintainer | Fedora Project |
PackageName | prelude-lml |
PackageRelease | 4.fc15 |
PackageVersion | 1.0.0 |
SHA-1 | 0CD1D632D8C9FF937C9863CF50C0F5EF10FBC887 |
SHA-256 | 606B8D80FFC40277D5C0CCCCB80C98F9615032487713DD2506855CEF3A75B8FA |
Key | Value |
---|---|
MD5 | 6E4BA087E5259C946588DBE0E49E38DF |
PackageArch | armv5tel |
PackageDescription | Prelude-LML is a log analyser that allows Prelude to collect and analyze information from all kind of applications emitting logs or syslog messages in order to detect suspicious activities and transform them into Prelude-IDMEF alerts. Prelude-LML handles events generated by a large set of applications, |
PackageMaintainer | Fedora Project |
PackageName | prelude-lml |
PackageRelease | 1.fc14 |
PackageVersion | 1.0.0 |
SHA-1 | 11B2B40188022101BBDEB396077A4997AEF2EB82 |
SHA-256 | 25025D638FC21BB24D779BA4A546AD158576273970830AE7831A48B0CFC9BDA6 |
Key | Value |
---|---|
MD5 | FDD9FBE9B945C7D2ED6727917AB76511 |
PackageArch | ia64 |
PackageDescription | Prelude-LML’s primary function is log analysis. Logs on a local system or logs monitored over the network (if configured to accept syslog messages from other hosts) can be processed and analyzed in order to discover security anomalies. |
PackageMaintainer | Fedora Project |
PackageName | prelude-lml |
PackageRelease | 2.fc9 |
PackageVersion | 0.9.11 |
SHA-1 | 11B5BC2BADA97B588F6B280253B79F54C439626B |
SHA-256 | D5A1A9450BD996C6460CC5E69CFF4D9AE3A0B2B52EE86617FB20249C924635EA |
Key | Value |
---|---|
FileName | https://ftp.lysator.liu.se/pub/OpenBSD//4.3//packages//sparc64//prelude-lml-0.9.10.tgz |
MD5 | 77137E65FD150BEDAB7F13FC8088652E |
SHA-1 | 12620F846B3B196FDEF51FD84B6091BC73739B0D |
SHA-256 | 44333FE9EC3F1F75E557E5983631248ECCAC95C886BD981D8914F3471278F9CF |
SSDEEP | 3072:cn4WYUCp7TEWD0kmLFlRzDwR8A7ksM3NSaRDFoAHzO:c4bU+Ik2RzDwR5sNSaRDdHy |
TLSH | T1B5D3121E1178CE6D8F4D4B47DF208469BB1DA347AF2B0309DA47D46AB25AAB041CCF8D |