Security Basics mailing list archives

Re: Importing Security Product Output Into A Database


From: Ken Swain <ken () kenswain com>
Date: Tue, 29 May 2007 18:27:57 -0500

Any SIM tool can do this. You can write queries to find anything you are looking for. Some of the information can leveraged automatically to alert and draw your attention to spacific incidents.

Cheers


On May 29, 2007, at 3:21 PM, Daniel Miessler wrote:

Greetings,

I'm wondering if anyone here knows of a product -- commercial or otherwise -- that is able to parse output from various tools, such as Foundscan, Nessus, Nmap, WebInspect, etc. and pull them into a single database format.

Such a tool seems easy enough in concept -- i.e. outputting into XML from the various tools and then mapping the XML schema from each into the central DB schema. But as easy as it is/sounds -- it's a lot of work doing that mapping.

I'd be interested in hearing about anything along these lines that you guys know of and/or related thoughts on creating a queryable database of security information based on the input from the security tools.

Thanks,

--
Daniel Miessler
E: daniel () dmiessler com
W: http://dmiessler.com
G: 0xDA6D50EAC




Current thread: