So I installed roo 1.1 version to get around the issue of walleye not reporting after 24 hour of operation. I see through the walleye interface that I have sebek data etc. The question is how can I view the keystrokes captured by sebek. When I click the process tree icon, I do get the process tree etc nicely mapped and I see that there are bunch of ssh sessions but how can I see what the attacker is typing or has typed? Is it getting hopefully logged somewhere. I did choose the ACCEPT and LOG option of sebek.

Any help highly appreciated.

Thanks
Parvinder Bhasin
_______________________________________________
Honeywall mailing list
[email protected]
https://public.honeynet.org/mailman/listinfo/honeywall

Reply via email to