WinIDS Development is proud to announce the release of WinIDS v4.0. This major milestone represents a complete ground-up rewrite of the framework, moving from version 2.5 to 4.0 to reflect extensive architectural improvements and new utility integrations.
WinIDS 4.0 provides a near-zero configuration deployment of a full Intrusion Detection System, utilizing the latest in open-source security software.
Enterprise Compatibility & Flexible Deployment
-
Operating Systems: Full support for Windows 10/11 and Windows Server 2019 through 2025.
-
Sensor Architecture: Automated installers are now available for Standalone sensors, Host sensors, and Remote nodes.
-
Modular Infrastructure Stack: Users can mix and match web servers (IIS or Apache) with database engines (PostgreSQL or MySQL) based on specific environmental requirements or personal preference.
-
Intelligent Remote Nodes: Remote node installers now feature Auto-Detection logic that identifies the Host’s active database engine and automatically establishes the appropriate connection parameters.
-
Scalability: A new utility allows for the seamless conversion of a Standalone sensor to a Host sensor, with the ability to manage and add multiple remote nodes.
System Resilience & Recovery
Admin safety is prioritized through integrated recovery tools, accessible via new system menu shortcuts:
-
Pre-Install Restore Points: Workstation installers can automatically create a System Restore point during the installation process.
-
RestorePoint Utility: A dedicated utility is included to completely remove the Windows Intrusion Detection system and revert the OS to its exact pre-installation state.
Advanced Management Tools
-
Database Manager: A centralized tool for connectivity testing, user credential refreshing, and database maintenance.
-
Security Console: Features a specialized Windows-optimized version of BASE (Basic Analysis and Security Engine) for event viewing and management.
-
Rules Updater (PulledPork Wrapper): A completely rewritten utility featuring:
-
Integrated Scheduler: Automate your rule updates.
-
Rollback Protection: Automatically reverts to previous rule sets on update failure.
-
Version Retention: Retains a configurable number of successful rule sets.
-
Alerting: Built-in SMTP mail support for status notifications.
-
Silent Mode: Facilitates background execution with extensive logging for audit trails.
-
Documentation
Each deployment package includes a comprehensive README file detailing the specific configurations and advanced features of these utilities.
