This major milestone represents a complete ground-up rewrite of the framework, moving from version 2.5to 4.1 to reflect extensive architectural improvements and new utility integrations.
WinIDS 4.1 provides a near-zero configuration deployment of a full Intrusion Detection System, utilizing the latest in open-source security software.
Enterprise Compatibility & Flexible Deployment
- Operating Systems: Full support for Windows 10/11 and Windows Server 2019 through 2025
- Sensor Architecture: Automated installers are now available for Standalone sensors, Host sensors, and Remote nodes
- Modular Infrastructure Stack: Users can mix and match web servers (IIS or Apache) with database engines (PostgreSQL or MySQL) based on specific environmental requirements or personal preference.
- Intelligent Remote Nodes: Remote node installers now feature Auto-Detection logic that identifies the Host’s active database engine and automatically establishes the appropriate connection parameters.
- Scalability: A new utility allows for the seamless conversion of a Standalone sensor to a Host sensor, with the ability to manage and add multiple remote nodes.
System Resilience & Recovery
Admin safety is prioritized through integrated recovery tools, accessible via new system menu shortcuts:- Pre-Install Restore Points: Workstation installers can automatically create a System Restore point during the installation process.
- RestorePoint Utility: A dedicated utility is included to completely remove the Windows Intrusion Detection system and revert the OS to its exact pre-installation state.
Advanced Management Tools
- Database Manager: A centralized tool for connectivity testing, user credential refreshing, and database maintenance.
- Security Console: Features a specialized Windows-optimized version of BASE (Basic Analysis and Security Engine) for event viewing and management.
- Rules Updater (PulledPork Wrapper): A completely rewritten utility featuring:
- Integrated Scheduler: Automate your rule updates.
- Rollback Protection: Automatically reverts to previous rule sets on update failure.
- Version Retention: Retains a configurable number of successful rule sets.
- Alerting: Built-in SMTP mail support for status notifications.
- Silent Mode: Facilitates background execution with extensive logging for audit trails.
