argus – Auditing Network Activity – Performance & Status Monitoring


Another tool for the security side, good for forensics, monitoring and auditing.

Argus is a fixed-model Real Time Flow Monitor designed to track and report on the status and performance of all network transactions seen in a data network traffic stream. Argus provides a common data format for reporting flow metrics such as connectivity, capacity, demand, loss, delay, and jitter on a per transaction basis. The record format that Argus uses is flexible and extensible, supporting generic flow identifiers and metrics, as well as application/protocol specific information.

Argus can be used to analyze and report on the contents of packet capture files or it can run as a continuous monitor, examining data from a live interface; generating an audit log of all the network activity seen in the packet stream. Argus can be deployed to monitor individual end-systems, or an entire enterprises network activity. As a continuous monitor, Argus provides both push and pull data handling models, to allow flexible strategies for collecting network audit data. Argus data clients support a range of operations, such as sorting, aggregation, archival and reporting. There is XML support for Argus data, which makes handling Argus data a bit easier.

Argus currently runs on Linux, Solaris, FreeBSD, OpenBSD, NetBSD, and MAC OS X and its client programs have also been ported to Cygwin. The software should be portable to many versions of Unix with little or no modification. Performance is such that auditing an entire enterprises Internet activity can be accomplished using modest computing resources.

You can download argus here:

argus-2.0.6 (various options available)

Or read more here.

Posted in: Countermeasures, Forensics, Networking Hacking Tools, Security Software

, , , , ,


Latest Posts:


tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.
Arcane - Tool To Backdoor iOS Packages (iPhone ARM) Arcane – Tool To Backdoor iOS Packages (iPhone ARM)
Arcane is a simple script tool to backdoor iOS packages (iPhone ARM) and create the necessary resources for APT repositories.
SharpHose - Asynchronous Password Spraying Tool SharpHose – Asynchronous Password Spraying Tool
SharpHose is an asynchronous password spraying tool in C# for Windows environments that takes into consideration fine-grained password policies and can be run over Cobalt Strike's execute-assembly.
Axiom - Pen-Testing Server For Collecting Bug Bounties Axiom – Pen-Testing Server For Collecting Bug Bounties
Project Axiom is a set of utilities for managing a small dynamic infrastructure setup for bug bounty, basically a pen-testing server out of the box with 1-line.
Quasar RAT - Windows Remote Administration Tool Quasar RAT – Windows Remote Administration Tool
Quasar is a fast and light-weight Windows remote administration tool coded in C#. Used for user support through day-to-day administrative work to monitoring.
Pingcastle - Active Directory Security Assessment Tool Pingcastle – Active Directory Security Assessment Tool
PingCastle is a Active Directory Security Assessment Tool designed to quickly assess the Active Directory security level based on a risk and maturity framework.


7 Responses to argus – Auditing Network Activity – Performance & Status Monitoring

  1. mumble January 26, 2008 at 11:33 pm #

    Someone tell me what I’m missing here. As a systems administrator, I can see a lot of value in tracking the performance of Internet transactions. What I don’t see are the security uses for this tool. Am I brain-damaged today?

  2. rumble January 27, 2008 at 1:14 am #

    argus records are cheap to store, and they can be used for a lot of security-related things: building flow records between servers, mining flows for unusual communication patterns, mining historical traffic patterns, etc. We can cram about a year’s worth of all activity on our 20Mbps internet perimeter into about 20 gig or so worth of uncompressed argus logs. makes for some interesting hunting. Argus records are good for answering rate/direction/historical context questions. Ie.g. have you ever seen this host initiate a tcp connection to that host (or any host in that network), and has there ever been more data transferred out than in?

  3. Pantagruel January 27, 2008 at 5:21 pm #

    @mumble, indeed the security edge seems to be missing but rumble gives ample reply to the use of Argus. We use it to map network flow and use the logs to analyze why and when network congestion occurs. The fact that it is modest regarding record size while generating extensive data is definitely a plus.

  4. Darknet January 27, 2008 at 6:48 pm #

    Well as a sys admin you should know if someone untoward goes down it’s you they are gonna ask to prove/disprove it from a technical standpoint.

    If you don’t have records you are screwed :) That’s why this is in forensics category.

    And networking is a fundamental part of security anyway especially from an understand point of view, on top of that from a monitoring point – you can find anomalies which can point to deeper problems, and from a intrusion response angle – records are golden. Thats why we advocate the use of syslog-ng on a separate server :)

  5. Bogwitch January 29, 2008 at 1:59 pm #

    From a security POV, there are three main aspects for security, Confidentiality, Integrity and Availability. This tool can help with all but particularly the latter two.
    Security is not all about penetration testing!

  6. mumble January 29, 2008 at 2:53 pm #

    In general, as a systems admin, I’m used to being in charge of the availability part. In the real world (of not penetration testing) the causes of downtime are normally things like dead PSUs, bad switches, dead NICs, bad software updates, database corruption, bad juju, phase of the moon, upstream routing BS…..

    This is a very useful tool for looking at bandwidth, flows, traffic/responsiveness, etc. I usually see that work as being mora a sysad’s job that a SA’s job. Given where I’m coming from, that’s reasonably sane…..

  7. eM3rC February 7, 2008 at 7:56 am #

    Really helpful stuff for an admin.

    Could this be somehow remotely installed into a server so you can monitor everything going over a network?