$ echo 'vm.max_map_count = 262144' | sudo tee -a /etc/sysctl.conf
$ sudo sysctl -p
$ cd rpot
$ docker-compose pull
$ cp /path/to/pcap/*.pcap ./pcap/
$ docker-compose down -v
$ docker-compose up manager
$ docker-compose up bro
Protocol | Decode Payload | ElasticSearch Output | Kibana Visualization |
---|---|---|---|
ARP | ○ | × | × |
AYIYA | ○ | × | × |
BackDoor | ○ | × | × |
BitTorrent | ○ | × | × |
DCE RPC | ○ | ○ | × |
DHCP | ○ | ○ | ○ |
DNP3 | ○ | ○ | × |
DNS | ○ | ○ | ○ |
File | ○ | ○ | ○ |
Finger | ○ | × | × |
FTP | ○ | ○ | × |
Gnutella | ○ | × | × |
GSSAPI | ○ | × | × |
GTPv1 | ○ | × | × |
HTTP | ○ | ○ | ○ |
ICMP | ○ | ○ | ○ |
Ident | ○ | × | × |
IMAP | ○ | × | × |
IRC | ○ | ○ | ○ |
kerberos | ○ | ○ | × |
Login | ○ | × | × |
MIME | ○ | × | × |
Modbus | ○ | ○ | × |
MySQL | ○ | ○ | × |
NCP | ○ | × | × |
NetBios | ○ | ○ | ○ |
NTLM | ○ | ○ | ○ |
NTP | ○ | × | × |
OpenFlow | ○ | ○ | ○ |
POP3 | ○ | × | × |
RADIUS | ○ | ○ | × |
RDP | ○ | ○ | × |
RFB | ○ | ○ | × |
RPC | ○ | × | × |
SIP | ○ | ○ | ○ |
SMB | ○ | ○ | ○ |
SMTP | ○ | ○ | ○ |
SNMP | ○ | ○ | ○ |
SOCKS | ○ | ○ | ○ |
SSH | ○ | ○ | ○ |
SSL | ○ | ○ | ○ |
Syslog | ○ | ○ | × |
TCP | ○ | ○ | ○ |
Teredo | ○ | ○ | × |
UDP | ○ | ○ | ○ |
XMPP | ○ | × | × |
ZIP | ○ | × | × |
Access Kibana url (http://localhost:5601
)
Click [Dashboard] -> [Open] -> [MAIN]