Directory
Shoki is a NIDS intended to be simple, modular, and flexible. Currently supported functionality includes: * Signature matching using libpcap-style filter expressions * Signatures based on POSIX extended regular expressions * Multi-filter rulesets that match individual packets or ordered series of packets * Threshold based logging * Fragment reassembly * Remote OS identification via passive fingerprinting * Logging to a Postgres database