I don’t know if there’s already an implementation of this, but has anybody tried, putting together an IDS agent which in some way utilises functions of UNIX security tools? Snort is already a standalone IDS tool, but I’m talking about integrating like nmap, swatch, and all and produce an IDS agent or agents from this. Anyone taking this up?