SAM Jr is a real-time analysis tool for Snort data. It can easily be extended using plugins.
| Tags | Security |
|---|---|
| Licenses | BSD Original |
| Operating Systems | OS Independent |
| Implementation | Java |
Recent releases


Changes: Initial Jabber support was added. The ability to switch databases without restarting was added. The ability to run from the command line (without a GUI) was added. The preferences panel was cleaned up. A preference for sending mail was added. The main window location is now saved, so SAM Jr will remember where the window was last time.


Changes: An issue where the configuration file wasn't being read at startup was fixed.


Changes: A problem in which the configuration file was not read on startup was fixed. A "mail from" field was added to the preferences panel. The Threat Index Monitor example script was changed so that it doesn't send an email about the same intruders every time it updates. The example script was changed so that if intruders fall off the high alert list and then get back on then an email will be sent again. The Threat Index Monitor example script was changed so that it uses the high alert level from the preferences panel to trigger emails. The icons folder was added back so that the window icons will display.


Changes: This release adds a script to email the whois and other info of any IP address with a very high threat index, serving as a complex script example, JavaMail jar files and a SimpleMailSender class, database port number configurability, a whois lookup facility, and keyboard shortcuts for menus.


Changes: This release adds support for multiple script files, adds all current applicable listeners to the scripts files, and fixes a bug which caused the Threat Index Monitor to not read the correct settings from the configuration file.