lottip icon indicating copy to clipboard operation
lottip copied to clipboard

Initial work on adding audit capabilities to lottip

Open rkoshy opened this issue 3 years ago • 1 comments

This is not meant to be clean code -- it's structurally sound, but was more interested in getting something working for our needs. It may be worth cleaning up.

  1. Added packetization and processing code so that individual packets could be analyzed, rather than entire TCP buffers. This also accounts for partial packets in the stream.
  2. Beginnings of "Stateful Packet" inspection and logging of connection + user
  3. Blocks certain commands - should really be configurable.

rkoshy avatar Jun 24 '22 01:06 rkoshy

Thanks for your PR! I'll examine it carefully, clean it up if necessary, test and merge it. I'll keep you updated.

orderbynull avatar Jun 24 '22 11:06 orderbynull