About This File
The EveBox Standalone Console Edition adds a complete local web-based security console to an existing WinSuricata / Suricata sensor without requiring OpenSearch, a centralized Host, or Remote Node infrastructure. The installer automatically deploys and configures EveBox, establishes the live Suricata `eve.json` ingestion pipeline, provides local SQLite-backed event storage, registers EveBox as a Windows Service, and makes the console available through a web browser on TCP port 5636. Once installed, the sensor provides local alert management, event search, visualization, and persistent historical event storage while continuing to operate entirely within the local WinSuricata environment.
This package is designed as an add-on to the WinSuricata Headless Sensor Edition and builds directly on the existing Suricata event stream. It does not replace the core sensor and does not require OpenSearch, OpenSearch PKI configuration, a centralized WinSuricata Host, or Remote Node registration. Installation, service registration, SQLite storage, EVE JSON ingestion, and local web access are automated to minimize manual configuration.
Complete installation instructions, deployment requirements, verification procedures, troubleshooting information, architecture details, and the final deployment checklist are included in the `README-INSTALL.txt` file contained within this package. Please review the included documentation before beginning the installation and retain it for future administration and troubleshooting.
PACKAGE SECURITY & INTEGRITY
Before extracting or installing the package, verify the downloaded ZIP file against the published SHA-1 hash to confirm that the archive has not been corrupted or altered.
Archive Password : w1nsn03t.c0m SHA-1 Hash : 0F1120D8F9AB8AC2E48D1ABBE4B4AAB40BCBD5FE
To verify the package in Windows, run the following command from Command Prompt or PowerShell, replacing the filename if necessary:
certutil -hashfile "EveBox-SQLite-Installer.zip" SHA1
The calculated SHA-1 value must match the published value exactly. If the hash does not match, do not extract or install the package. Obtain a new copy from the authorized distribution source and perform the verification again.
