#ids — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ids, aggregated by home.social.
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
Как собрать базовый стек для защиты инфраструктуры на open source
Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности
https://habr.com/ru/companies/garda/articles/1067714/
#open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность
-
Как собрать базовый стек для защиты инфраструктуры на open source
Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности
https://habr.com/ru/companies/garda/articles/1067714/
#open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность
-
Как собрать базовый стек для защиты инфраструктуры на open source
Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности
https://habr.com/ru/companies/garda/articles/1067714/
#open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность
-
UUID в Manticore: практическое руководство
В обзорной статье мы разобрали, зачем использовать в поиске тот же UUID, что и в основной базе (если таковая имеется). Здесь сразу перейдём к практике: создадим таблицу, выполним основные операции через SQL и JSON API, а затем загрузим несколько документов через /bulk . Все примеры рассчитаны на Manticore Search 28.5.0 или новее. Значение <generated UUID> в ответах обозначает UUID, который Manticore создаст при обработке запроса. Копировать эту строку в следующий запрос не нужно: подставьте фактический id из своего ответа.
-
UUID в Manticore: практическое руководство
В обзорной статье мы разобрали, зачем использовать в поиске тот же UUID, что и в основной базе (если таковая имеется). Здесь сразу перейдём к практике: создадим таблицу, выполним основные операции через SQL и JSON API, а затем загрузим несколько документов через /bulk . Все примеры рассчитаны на Manticore Search 28.5.0 или новее. Значение <generated UUID> в ответах обозначает UUID, который Manticore создаст при обработке запроса. Копировать эту строку в следующий запрос не нужно: подставьте фактический id из своего ответа.
-
UUID в Manticore: практическое руководство
В обзорной статье мы разобрали, зачем использовать в поиске тот же UUID, что и в основной базе (если таковая имеется). Здесь сразу перейдём к практике: создадим таблицу, выполним основные операции через SQL и JSON API, а затем загрузим несколько документов через /bulk . Все примеры рассчитаны на Manticore Search 28.5.0 или новее. Значение <generated UUID> в ответах обозначает UUID, который Manticore создаст при обработке запроса. Копировать эту строку в следующий запрос не нужно: подставьте фактический id из своего ответа.
-
RE: https://fosstodon.org/@jaandrle/116993316250642409
KALKUVLAČKA: Jak ušetřit na krajských tarifech s Mirko Tomáškem : INTERVIEW - YouTube - https://www.youtube.com/watch?v=P2YlX7nkly8
-
RE: https://fosstodon.org/@jaandrle/116993316250642409
KALKUVLAČKA: Jak ušetřit na krajských tarifech s Mirko Tomáškem : INTERVIEW - YouTube - https://www.youtube.com/watch?v=P2YlX7nkly8
-
RE: https://fosstodon.org/@jaandrle/116993316250642409
KALKUVLAČKA: Jak ušetřit na krajských tarifech s Mirko Tomáškem : INTERVIEW - YouTube - https://www.youtube.com/watch?v=P2YlX7nkly8
-
RE: https://fosstodon.org/@jaandrle/116993316250642409
KALKUVLAČKA: Jak ušetřit na krajských tarifech s Mirko Tomáškem : INTERVIEW - YouTube - https://www.youtube.com/watch?v=P2YlX7nkly8
-
RE: https://fosstodon.org/@jaandrle/116993316250642409
KALKUVLAČKA: Jak ušetřit na krajských tarifech s Mirko Tomáškem : INTERVIEW - YouTube - https://www.youtube.com/watch?v=P2YlX7nkly8
-
Kalkuvlačka - Vyhledávač nejlevnějších vlakových spojení v IDS - https://kalkuvlacka.cz/
-
Kalkuvlačka - Vyhledávač nejlevnějších vlakových spojení v IDS - https://kalkuvlacka.cz/
-
Kalkuvlačka - Vyhledávač nejlevnějších vlakových spojení v IDS - https://kalkuvlacka.cz/
-
Kalkuvlačka - Vyhledávač nejlevnějších vlakových spojení v IDS - https://kalkuvlacka.cz/
-
Kalkuvlačka - Vyhledávač nejlevnějších vlakových spojení v IDS - https://kalkuvlacka.cz/
-
There are many misconceptions about the spread of dis/misinformation. Perhaps the most prevalent is that a particular piece of misinformation is global, when in fact it usually has a local spin. Full article in comments
#techethics #Ireland #IDS #TikTok #Telegram #disinformation #misinformation
-
There are many misconceptions about the spread of dis/misinformation. Perhaps the most prevalent is that a particular piece of misinformation is global, when in fact it usually has a local spin. Full article in comments
#techethics #Ireland #IDS #TikTok #Telegram #disinformation #misinformation
-
There are many misconceptions about the spread of dis/misinformation. Perhaps the most prevalent is that a particular piece of misinformation is global, when in fact it usually has a local spin. Full article in comments
#techethics #Ireland #IDS #TikTok #Telegram #disinformation #misinformation
-
There are many misconceptions about the spread of dis/misinformation. Perhaps the most prevalent is that a particular piece of misinformation is global, when in fact it usually has a local spin. Full article in comments
#techethics #Ireland #IDS #TikTok #Telegram #disinformation #misinformation
-
There are many misconceptions about the spread of dis/misinformation. Perhaps the most prevalent is that a particular piece of misinformation is global, when in fact it usually has a local spin. Full article in comments
#techethics #Ireland #IDS #TikTok #Telegram #disinformation #misinformation
-
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
Как изменилась жизнь интернет-безопасников с приходом QUIC? IDS и threat analysing в реалиях HTTP/3
Обзорный анализ “нового” протокола HTTP/3 и подходов к анализу трафика и защите информационных систем построенных на его основе. Фингерпринтинг выступает одной из больших тем статьи, ему уделено отдельное внимание. Читать
-
Как изменилась жизнь интернет-безопасников с приходом QUIC? IDS и threat analysing в реалиях HTTP/3
Обзорный анализ “нового” протокола HTTP/3 и подходов к анализу трафика и защите информационных систем построенных на его основе. Фингерпринтинг выступает одной из больших тем статьи, ему уделено отдельное внимание. Читать
-
Как изменилась жизнь интернет-безопасников с приходом QUIC? IDS и threat analysing в реалиях HTTP/3
Обзорный анализ “нового” протокола HTTP/3 и подходов к анализу трафика и защите информационных систем построенных на его основе. Фингерпринтинг выступает одной из больших тем статьи, ему уделено отдельное внимание. Читать
-
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
#Suricata powers many of today’s leading network detection and response solutions, including Clear NDR Community, which is widely used by practitioners to explore what is possible with Suricata IDS/IPS/NSM and the network protocol monitoring logs and alerts it produces.
-
#Suricata powers many of today’s leading network detection and response solutions, including Clear NDR Community, which is widely used by practitioners to explore what is possible with Suricata IDS/IPS/NSM and the network protocol monitoring logs and alerts it produces.
-
#Suricata powers many of today’s leading network detection and response solutions, including Clear NDR Community, which is widely used by practitioners to explore what is possible with Suricata IDS/IPS/NSM and the network protocol monitoring logs and alerts it produces.
-
#Suricata powers many of today’s leading network detection and response solutions, including Clear NDR Community, which is widely used by practitioners to explore what is possible with Suricata IDS/IPS/NSM and the network protocol monitoring logs and alerts it produces.
-
#Suricata powers many of today’s leading network detection and response solutions, including Clear NDR Community, which is widely used by practitioners to explore what is possible with Suricata IDS/IPS/NSM and the network protocol monitoring logs and alerts it produces.
-
https://www.europesays.com/sk/112054/ Počas leta ide na linke 280 do Plaveckého Podhradia cyklobus ##sMHDpozelenej #BID #BK #Bratislava #cyklobusy #IDS #SK #Slovak #Slovakia #Slovenčina #Slovensko
-
Как работает эта ваша суриката 3 часть
Третья часть цикла статей по разбору устройства работы IDS/IPS решения Suricata. Разберём на практике уязвимость CVE‑2025‑66698 – обход аутентификации в Veda (Semantic Machines) v5.4.8. Запишем трафик с вредоносными запросами и составим suricata-правило, которое детектирует эксплуатацию уязвимости. В статье также приводятся объяснения как работают content, pcre и липкие буферы.
-
Как работает эта ваша суриката 3 часть
Третья часть цикла статей по разбору устройства работы IDS/IPS решения Suricata. Разберём на практике уязвимость CVE‑2025‑66698 – обход аутентификации в Veda (Semantic Machines) v5.4.8. Запишем трафик с вредоносными запросами и составим suricata-правило, которое детектирует эксплуатацию уязвимости. В статье также приводятся объяснения как работают content, pcre и липкие буферы.
-
Как работает эта ваша суриката 3 часть
Третья часть цикла статей по разбору устройства работы IDS/IPS решения Suricata. Разберём на практике уязвимость CVE‑2025‑66698 – обход аутентификации в Veda (Semantic Machines) v5.4.8. Запишем трафик с вредоносными запросами и составим suricata-правило, которое детектирует эксплуатацию уязвимости. В статье также приводятся объяснения как работают content, pcre и липкие буферы.
-
Как работает эта ваша суриката 2 часть
Вторая часть цикла статей о практическом применении Suricata IDS/IPS. Рассмотрим базовые модификаторы Suricata на примерах DNS-запросов и на сетевых атаках. Уделим внимание механизму threshold для предотвращения флуда алертов.
-
Как работает эта ваша суриката 2 часть
Вторая часть цикла статей о практическом применении Suricata IDS/IPS. Рассмотрим базовые модификаторы Suricata на примерах DNS-запросов и на сетевых атаках. Уделим внимание механизму threshold для предотвращения флуда алертов.
-
Как работает эта ваша суриката 2 часть
Вторая часть цикла статей о практическом применении Suricata IDS/IPS. Рассмотрим базовые модификаторы Suricata на примерах DNS-запросов и на сетевых атаках. Уделим внимание механизму threshold для предотвращения флуда алертов.
-
https://www.europesays.com/cz/116521/ O miliardu levněji. ŘSD vybralo firmy, které přestaví jihomoravskou silnici na třípruh #ČeskáRepublika #Česko #CzechRepublic #Czechia #I/53 #I/53LechovicePohořelice #IDS–InženýrskéADopravníStavbyOlomouc #MSilnice #ŘeditelstvíSilnicADálnic #ŘSD #seznam
-
https://www.europesays.com/africa/277223/ The overlooked South Africans still struggling to get Smart IDs #Banks #DepartmentOfHomeAffairs #HomeAffairs #IDs #iol #NationalPopulationRegister #nationals #residents #smart #SmartID #SouthAfrica #SouthAfricans
-
Yet another way to track US citizens and deny our right to privacy!
FCC Wants to Kill Burner Phones By Forcing Telecoms to Get All Customers’ IDs
#FCC #US #BurnerPhones #Telecoms #IDs #Surveillance #Privacy #Tech