Skip to content

Latest commit

 

History

History
22 lines (15 loc) · 977 Bytes

README.md

File metadata and controls

22 lines (15 loc) · 977 Bytes

symantec-parser (ex. sep-seclog-ips-parser)

Symantec Endpoint Protection (SEP) seclog file IP Analyzer

Please note that this version is not suitable for production use, this is a beta version for development purpose only which is used for a personal RDP server with a normal workload.

The script tries to find the attacker's IP addresses in the 'seclog' file and blocks if the number of attacks exceeds a certain number. All settings are in the settings.ini file.

[!] Pre-set maximum log file size for SEP SEP [!] Create a predefined rule for auto update SEP FW

SEP firewall rule blocking:

  1. Export current rules
  2. Add IP addresses to the predefined rule.
  3. Import rules into SEP Simple and works fine.

Check all settings in the config file before use.