nmap (Network Address Translation)
- 功能: nmap 是最常用的网络检测工具之一,用于扫描网络流量以检测是否被恶意攻击。
- 使用场景: 测试网络稳定性、检测网络攻击、检测网络设备故障等。
- 命令示例:
nmap -s -t -k 1
- 参数说明:
-s: 打开网络扫描模式-t: 设置扫描时间(1秒)-k: 设置扫描数量(1条)
sedan (Security Evaluation and Analysis Network)
- 功能: sedan 是针对网络攻击的工具,用于检测和分析网络攻击行为。
- 使用场景: 确认网络设备是否被攻击,检测网络攻击流量。
- 命令示例:
sedan -i -f test.log
- 参数说明:
-i: 读取攻击日志文件test.log-f: 输出攻击日志
eject (Network Eject)
- 功能: eject 用于检测网络攻击,特别是在网络攻击者试图攻击设备时,用来检测并清除攻击者。
- 使用场景: 验证网络设备是否被攻击,检测网络攻击流量。
- 命令示例:
eject -i -f test.log
- 参数说明:
-i: 读取攻击日志文件test.log-f: 输出攻击日志
NSX (Network Security eXport)
- 功能: NSX 是用于检测网络攻击的高级工具,可以检测网络攻击者试图攻击的设备。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nsx -i -f test.log
- 参数说明:
-i: 读取攻击日志文件test.log-f: 输出攻击日志
ZAP (Zombie Ant Protocol)
- 功能: ZAP 用于检测网络攻击,特别是在网络攻击者试图攻击设备时,用来清除攻击者。
- 使用场景: 验证网络设备是否被攻击,检测网络攻击流量。
- 命令示例:
zap -i -f test.log
- 参数说明:
-i: 读取攻击日志文件test.log-f: 输出攻击日志
ZAP-64 (Zombie Ant Protocol 64-bit)
- 功能: ZAP-64 与 ZAP 类似,用于检测网络攻击,但针对 64-bit 系统。
- 使用场景: 在 64-bit 系统上检测网络攻击。
- 命令示例:
zap-64 -i -f test.log
- 参数说明:
-i: 读取攻击日志文件test.log-f: 输出攻击日志
nslookup (Network Scan Lookup)
- 功能: nslookup 用于检测网络设备是否被攻击,验证网络设备是否被攻击。
- 使用场景: 测试网络设备是否被攻击,验证设备安全。
- 命令示例:
nslookup -i -f test.log
- 参数说明:
-i: 读取攻击日志文件test.log-f: 输出攻击日志
nslookupd (Network Scan Lookup Daemon)
- 功能: nslookupd 是 nslookup 的 daemon,用于同时处理多个攻击日志文件。
- 使用场景: 测试网络设备是否被攻击,同时处理多个攻击日志。
- 命令示例:
nslookupd -i -f test.log
nslookupd -c (Network Scan Lookup daemon with cross-correlation)
- 功能: nslookupd -c 用于检测网络攻击者试图攻击的设备,同时记录攻击者与攻击目标之间的关系。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nslookupd -c -i -f test.log
nslookupd -x (Network Scan Lookup daemon with cross-correlation and exclusion)
- 功能: nslookupd -x 用于检测网络设备是否被攻击,同时记录攻击者与攻击目标之间的关系,并排除攻击者。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nslookupd -x -i -f test.log
nslookupd -x -x (Network Scan Lookup daemon with cross-correlation and exclusion)
- 功能: nslookupd -x -x 用于检测网络设备是否被攻击,同时记录攻击者与攻击目标之间的关系,并排除攻击者。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nslookupd -x -x -i -f test.log
nslookupd -x -x -c (Network Scan Lookup daemon with cross-correlation and exclusion and cross-correlation)
- 功能: nslookupd -x -x -c 用于检测网络设备是否被攻击,同时记录攻击者与攻击目标之间的关系,并排除攻击者。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nslookupd -x -x -c -i -f test.log
nslookupd -x -x -c -x (Network Scan Lookup daemon with cross-correlation and exclusion and cross-correlation and exclusion)
- 功能: nslookupd -x -x -c -x 用于检测网络设备是否被攻击,同时记录攻击者与攻击目标之间的关系,并排除攻击者。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nslookupd -x -x -c -x -i -f test.log
nslookupd -x -x -c -x -x (Network Scan Lookup daemon with cross-correlation and exclusion and cross-correlation and exclusion and cross-correlation and exclusion)
- 功能: nslookupd -x -x -c -x -x 用于检测网络设备是否被攻击,同时记录攻击者与攻击目标之间的关系,并排除攻击者。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nslookupd -x -x -c -x -x -i -f test.log
nslookupd -x -x -c -x -x -x (Network Scan Lookup daemon with cross-correlation and exclusion and cross-correlation and exclusion and cross-correlation and exclusion and cross-correlation and exclusion)
- 功能: nslookupd -x -x -c -x -x -x 用于检测网络设备是否被攻击,同时记录攻击者与攻击目标之间的关系,并排除攻击者。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nslookupd -x -x -c -x -x -x -i -f test.log
nslookupd -x -x -c -x -x -x -x (Network Scan Lookup daemon with cross-correlation and exclusion and cross-correlation and exclusion and cross-correlation and exclusion and cross-correlation and exclusion and cross-correlation and exclusion)
- 功能: nslookupd -x -x -c -x -x -x -x 用于检测网络设备是否被攻击,同时记录攻击者与攻击目标之间的关系,并排除攻击者。
- 使用场景: 测试网络设备是否被攻击,验证网络攻击者的意图。
- 命令示例:
nslookupd -x -x -c -x -x -x -x -i -f test.log









