Loglight v0.2 — it now sees your network, not just your logs
Loglight just shipped its biggest update yet: Network Traffic Map.
What's new
NetFlow / IPFIX ingest — add a
netflowsource and point your router or firewall's flow export at it (MikroTik, pfSense, FortiGate, Cisco, Ubiquiti all support it natively). No agent, no packet capture — flow metadata only, never packet contents.3D Network Map — a live, rotatable map of who talks to whom. Node size = traffic, links = conversations, and any host with an active detection glows by severity. Rendered fully offline with a vendored WebGL engine — no CDN, nothing leaves your network.
Two new detections: Beaconing — an internal host calling one external endpoint at a metronome-regular interval, the classic C2 heartbeat — and New service — a host starts accepting connections on a port never seen before.
The existing scan and exfiltration detectors now fire from flow telemetry too, and flows feed the kill-chain correlator — so a beacon plus a decoy trip plus an exfil spike becomes one incident, not three alerts.
Upgrading takes a minute: stop the binary, swap it, start again. The database migrates automatically and your existing license already covers everything — no new key, no extra charge.
Get Loglight (14-day trial): https://whop.com/nizar-tuanku/loglight
Free edition (1 source, Apache-2.0): github.com/nizartuanku/loglight
Full six-tool platform: https://whop.com/nizar-tuanku/hexward-suite
