Saltar al contenido principal

Quick start

You want to start straight away? Pick a tool, copy the commands, paste them in a terminal, and it runs.

ToolWhat it doesYou needTime
PiRogueCaptures and analyzes the network traffic of a deviceA Debian 12 machine10 min
ColanderCase and digital investigation platformDocker, Node.js10 min
ThreatrThreat intelligence aggregationDocker2 min

You need: a machine with a fresh Debian 12 installation, on amd64 or arm64, with at least 4 GB of RAM and 40 GB of disk, and Internet access. It can be a physical machine, a virtual machine, or a Raspberry Pi. The PiRogue changes the network configuration of the machine, so use a dedicated one.

Connect to it with SSH and run the following block:

Install PiRogue on Debian 12
sudo apt-get update
sudo apt-get dist-upgrade
sudo apt-get install wget
sudo wget -O /etc/apt/sources.list.d/pirogue.list https://pts-project.org/debian-12/pirogue.list
sudo wget -O /etc/apt/trusted.gpg.d/pirogue.gpg https://pts-project.org/debian-12/pirogue.gpg
sudo apt-get update
sudo apt-get install pirogue-base

If the installer asks whether non-superusers may capture network traffic, answer Yes.

información

The operating mode is selected automatically from the network interfaces of the machine:

  • a second Wi-Fi interface: Access point, the devices to analyze connect to the Wi-Fi network of the PiRogue
  • a second Ethernet interface: Appliance
  • a single interface: VPN, the devices connect with WireGuard. This is the simplest way to try a PiRogue in a virtual machine.

See Installation for the details of each mode.

Check that it works​

Display the configuration of your PiRogue, including the generated passwords:

pirogue-admin-client system get-configuration

Check that SYSTEM_OPERATING_MODE is the mode you expect, and note DASHBOARD_PASSWORD (also displayed with pirogue-admin-client dashboard get-configuration) and, in access point mode, WIFI_PASSPHRASE.

Then open the dashboard in your browser, with the user admin and the password above:

https://<EXTERNAL_ADDRESS>/dashboard

Your browser warns about the certificate because it is self-signed. For a first try, accept the warning and continue.

What's next​

Prerequisites

This documentation is designed to be readable and provide clear instructions for users with some network and Linux experience. However, experienced security professionals, network administrators, and system administrators will also find valuable information here.

Minimum Requirements​

We recommend that you have experience interacting with the command line interface (CLI) for your operating system.

Additional Helpful Skills​

This documentation assumes you have:

  • Some understanding of security concepts
  • Basic familiarity with internet and networking protocols
  • Some experience interpreting network traffic anomalies and responding to incidents