Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
aiengine — AIEngine é um NIDS (sistema de detecção de intrusão em rede) de próxima geração, interativo/programável, para Python/Ruby/Java/Lua e Go. | Kitploit
Ferramentas/BitbucketBitbucket/camp0/aiengine
Ferramentas DefensivasForensia de RedeSegurança de RedeInteligência de AmeaçasAprendizado de MáquinaDetecção de IntrusãoAnálise de DNSDetecção de Anomalias
Bitbucketcamp0/aiengine

aiengine

AIEngine é um NIDS (sistema de detecção de intrusão em rede) de próxima geração, interativo/programável, para Python/Ruby/Java/Lua e Go.

Ver Repositório
26há 3 anosAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

Documentation Status codecov coverity CII Best Practices Python 2.7|3.5|3.6|3.7|3.8|3.9 Lua 5.1|5.2|5.4 Go 1.15 License LGTM Grade LGTM Grade

AIEngine (Motor de Inteligência Artificial)

O AIEngine é um mecanismo de sistema de detecção de intrusão em rede de próxima geração, interativo/programável em Python/Ruby/Java/Lua e Go, com capacidades de aprendizado sem qualquer intervenção humana, classificação de domínios DNS, detecção de spam, coletor de rede, perícia forense de rede e muitas outras.

O AIEngine também ajuda profissionais de rede/segurança a identificar tráfego e desenvolver assinaturas para usá-las em NIDS, Firewalls, classificadores de tráfego e assim por diante.

As principais funcionalidades do AIEngine são:

  • Suporte para interação/programação com o usuário enquanto o mecanismo está em execução.
  • Suporte para PCRE JIT para correspondência de regex.
  • Suporte para grafos de regex (padrões de detecção complexos).
  • Suporte a seis tipos de NetworkStacks (lan, mobile, lan6, virtual, oflow e mobile6).
  • Suporte a Sets e filtros de Bloom para buscas de IP.
  • Suporta arquiteturas x86_64, ARM e MIPS em sistemas operacionais como Linux, FreeBSD e MacOS.
  • Suporte para correspondência de domínios HTTP, DNS e SSL.
  • Suporte para domínios e hosts bloqueados para HTTP, DNS, SMTP e SSL.
  • Análise de frequência para tráfego desconhecido e geração automática de regex.
  • Geração de assinaturas Yara.
  • Integração fácil com bancos de dados (MySQL, Redis, Cassandra, Hadoop, etc...) para correlação de dados.
  • Integração fácil com outros mecanismos de pacotes (Netfilter).
  • Suporte a caches de limpeza de memória para atualizar informações armazenadas em memória.
  • Suporte para detecção de DDoS na camada de rede/aplicação.
  • Suporte para rejeição de conexões TCP/UDP.
  • Suporte para perícia forense de rede em tempo real.
  • Suporte para assinaturas TLS JA3 em SSL.
  • Suporta protocolos como Bitcoin, CoAP, DHCPv4/DHCPv6, DNS, DTLS, GPRS, GRE, HTTP, ICMPv4/ICMPv6, IMAP, IPv4/v6, Modbus, MPLS, MQTT, Netbios, NTP, OpenFlow, PPPoE, POP, Quic, RTP, SIP, SMB, SMTP, SSDP, SSH, SSL, TCP, UDP, VLAN, VXLAN.
  • Integração de servidor HTTP para recuperar e configurar o sistema em tempo real.

Consulte a pasta docs para mais informações

Usando o AIEngine

Para usar o AIEngine(versão reduzida) basta executar o binário aiengine ou usar o binding python/ruby/java/lua.

luis@luis-xps:~/c++/aiengine/src$ ./aiengine -h
aiengine 2.1.0
Mandatory arguments:
  -I [ --input ] arg                Sets the network interface ,pcap file or 
                                    directory with pcap files.

Link Layer optional arguments:
  -q [ --tag ] arg      Selects the tag type of the ethernet layer (vlan,mpls).

TCP optional arguments:
  -t [ --tcp-flows ] arg (=32768) Sets the number of TCP flows on the pool.

UDP optional arguments:
  -u [ --udp-flows ] arg (=16384) Sets the number of UDP flows on the pool.

    Domain optional arguments:
      -D [ --domain-file ] arg             Reads domain names from file.
      -B [ --domain-protocol ] arg (=dns)  Protocol to plug the domain-file (dns, 
                                           ssl, http).
      -S [ --matched-domain ]              Shows only the domains that matches.

Regex optional arguments:
  -R [ --enable-signatures ]     Enables the Signature engine.
  -r [ --regex ] arg (=.*)       Sets the regex for evaluate agains the flows.
  -c [ --flow-class ] arg (=all) Uses tcp, udp or all for matches the signature
				 on the flows.
  -m [ --matched-flows ]         Shows the flows that matchs with the regex.
  -M [ --matched-packet ]        Shows the packet payload that matchs with 
    	                         the regex.
  -C [ --continue ]              Continue evaluating the regex with the 
                                 next packets of the Flow.
  -j [ --reject-flows ]          Rejects the flows that matchs with the 
                                     regex.
  -w [ --evidence ]              Generates a pcap file with the matching 
                                     regex for forensic analysis.

Frequencies optional arguments:
  -F [ --enable-frequencies ]       Enables the Frequency engine.
  -g [ --group-by ] arg (=dst-port) Groups frequencies by src-ip,dst-ip,src-por
				    t and dst-port.
  -f [ --flow-type ] arg (=tcp)     Uses tcp or udp flows.
  -L [ --enable-learner ]           Enables the Learner engine.
  -k [ --key-learner ] arg (=80)    Sets the key for the Learner engine.
  -b [ --buffer-size ] arg (=64)    Sets the size of the internal buffer for 
    	                            generate the regex.
      -Q [ --byte-quality ] arg (=80)   Sets the minimum quality for the bytes of 
                                        the generated regex.
  -y [ --enable-yara ]              Generates a yara signature.

Optional arguments:
  -n [ --stack ] arg (=lan)    Sets the network stack (lan,mobile,lan6,virtual,
			       oflow).
  -d [ --dumpflows ]           Dump the flows to stdout.
  -s [ --statistics ] arg (=0) Show statistics of the network stack (5 levels).
  -T [ --timeout ] arg (=180)  Sets the flows timeout.
  -P [ --protocol ] arg        Show statistics of a specific protocol of the 
                                   network stack.
  -a [ --port ] arg (=0)       Sets the HTTP listenting port.
  -e [ --release ]             Release the caches.
  -l [ --release-cache ] arg   Release a specific cache.
  -p [ --pstatistics ]         Show statistics of the process.
      -o [ --summary ]             Show protocol summmary statistics 
                                   (bytes,packets,% bytes,cache miss,memory).
  -h [ --help ]                Show help.
  -v [ --version ]             Show version string.

Tipos de NetworkStack

O AIEngine suporta seis tipos de stacks de rede, dependendo da topologia de rede.

  • StackLan (lan) Rede Local baseada em IPv4.

  • StackLanIPv6 (lan6) Rede Local com suporte a IPv6.

  • StackMobile (mobile) Rede Móvel (interface Gn) para IPv4.

  • StackVirtual (virtual) Stack para ambientes virtuais/nuvem com VxLan e GRE Transparente.

  • StackOpenFlow (oflow) Stack para ambientes openflow.

  • StackMobileIPv6 (mobile6) Rede Móvel (interface Gn) para IPv6.

Integração/Programação do AIEngine com outros sistemas

O AIEngine é também um módulo python/ruby/java/lua que permite ser mais flexível em termos de integração com outros sistemas e funcionalidades. Os principais objetos exportados pelo módulo python são os seguintes.

Baixar ferramenta