Prewikka is a graphical front-end analysis console for the Prelude hybrid IDS framework. Prelude is a hybrid intrusion detection framework implementing an open communication layer for use by any security application. It offers the ability to unify currently available security tools into one, powerful, and distributed application. Providing numerous features, Prewikka facilitate the work of users and analysts. It provides alert aggregation, sensors and hearbeat views, and has user management and configurable filters. It has access to external tools such as whois and traceroute.

2008-03-27 10:38

User can now choose the way alerts are sorted. Asynchronous DNS resolution is now supported in the alert view as well as the message summary. The alert summary view now handles portlist and ip_version service fields, and shows the alert's messageid. An exception when rendering ToolAlert was fixed along with double classification escaping. The Heartbeat view was sped up. A Polish translation was included. There were also various bugfixes and cleanups.

2007-10-18 18:40

A performance improvement of ~36% on aggregated queries when using frontend localtime (the default) or UTC time. Most of the Javascript code has been ported to use JQuery. A show/hide effect has been added to the CSS popup. More filtering functionality in the Agents view. Better integration of CGI authentication allowing user listing and deletion. Template exceptions are reported directly to the user. An exception when an alert analyzer name is empty has been fixed. A problem when adding new Prewikka users has been fixed. An exception when a user had no permission set has been fixed. There are various bugfixes.

2007-08-01 16:05

An auto-refresh system was implemented. The
ability to filter on missing, offline, online, or
unknown agents was added. It is now easier to read
each agent status in collapsed mode. A filter
load/save/delete problem with translation was
fixed. New "My account" tabs were added under the
Settings section. messageid and analyzerid
parameters were added, allowing a link to a
Prewikka alert from an external tool. The timeline
control table layout was improved. Translation of
strings possibly using plural forms was fixed.
Various bugs were fixed.

2007-05-21 20:21

A new powerful and scalable agent view, grouping agent together by Location and Node. This release has been internationalized: a user can choose the language used in their settings tab, or specify a default locale using the "default_locale" configuration keyword. Current translations: Brazilian Portuguese, French, German, Russian, and Spanish. In the Alert/Heartbeat summary view, analyzers are numbered backward to reflect the ordering in the analyzer list. Support has been added for resizing the menu. A Konqueror rendering bug with the inline filter has been fixed. There are various bugfixes.

2007-04-06 15:42

All sources and targets are not shown if they
reach a predefined limit; an expansion link is
provided instead. Two new views were added in the
Events section: CorrelationAlert and ToolAlert.
The ability to filter/aggregate on all IDMEF paths
was added. The user may choose which criteria
filter operator to use. Analyzer aggregation was
added. When a session expires and the user logs
in, she is directed to the last page she attempted
to access. When an error occur, the default layout
is preserved. Non-aggregated views are faster by
around 50%. IDMEF Action, SNMPService, and
WebService class are supported. Support for small
screen resolution was improved.

