jgh0721 / Windows-Sensor

Perform packet-process correlation on Windows using the Windows equivalent of the Linux sensor.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Host-Network (Hone) Packet-Process Correlator for Windows

Copyright (c) 2014-2015 Battelle Memorial Institute
Licensed under a modification of the 3-clause BSD license
See License.txt for the full text of the license and additional disclaimers

Author: Richard L. Griswold
Contributors: Peter L. Nordquist, Ruslan A. Doroshchuk, Alexis J. Malozemoff,
Brandon J. Carpenter, and Glenn A. Fink


H   H  OOO  N   N EEEEE
H   H O   O NN  N E
HHHHH O   O N N N EEEE
H   H O   O N  NN E
H   H  OOO  N   N EEEEE


Hone is a tool for correlating packets to processes to bridge the HOst-NEtwork
divide. The Hone Packet-Process Correlator for Windows consists of a
kernel-mode driver that performs packet-process correlation and user-mode
utilities for reading data collected by the driver and managing the driver.
For information on building, installing, and using Hone, as well as technical
information about the inner workings of Hone, see the Readme.html file.

About

Perform packet-process correlation on Windows using the Windows equivalent of the Linux sensor.

License:Other


Languages

Language:C++ 76.9%Language:C 16.3%Language:Python 4.2%Language:Inno Setup 1.8%Language:QMake 0.5%Language:JavaScript 0.3%Language:Batchfile 0.2%