IDS: cicflowmeter.py

From OnnoWiki
Revision as of 10:34, 21 April 2022 by Onnowpurbo (talk | contribs) (Created page with "Installation git clone https://gitlab.com/hieulw/cicflowmeter cd cicflowmeter python setup.py install or pip install cicflowmeter Usage usage: cicflowmeter [-h] (-i...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Installation

git clone https://gitlab.com/hieulw/cicflowmeter
cd cicflowmeter
python setup.py install

or

pip install cicflowmeter

Usage

usage: cicflowmeter [-h] (-i INPUT_INTERFACE | -f INPUT_FILE) [-c] [-u URL_MODEL] output

positional arguments:

 output                output file name (in flow mode) or directory (in sequence mode)

optional arguments:

 -h, --help            show this help message and exit
 -i INPUT_INTERFACE    capture online data from INPUT_INTERFACE
 -f INPUT_FILE         capture offline data from INPUT_FILE
 -c, --csv, --flow     output flows as csv

Convert pcap file to flow csv:

cicflowmeter -f example.pcap -c flows.csv

Sniff packets real-time from interface to flow csv: (need root permission)

cicflowmeter -i eth0 -c flows.csv


Referensi