#ids — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ids, aggregated by home.social.
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
Как собрать базовый стек для защиты инфраструктуры на open source
Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности
https://habr.com/ru/companies/garda/articles/1067714/
#open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность
-
UUID в Manticore: практическое руководство
В обзорной статье мы разобрали, зачем использовать в поиске тот же UUID, что и в основной базе (если таковая имеется). Здесь сразу перейдём к практике: создадим таблицу, выполним основные операции через SQL и JSON API, а затем загрузим несколько документов через /bulk . Все примеры рассчитаны на Manticore Search 28.5.0 или новее. Значение <generated UUID> в ответах обозначает UUID, который Manticore создаст при обработке запроса. Копировать эту строку в следующий запрос не нужно: подставьте фактический id из своего ответа.
-
RE: https://fosstodon.org/@jaandrle/116993316250642409
KALKUVLAČKA: Jak ušetřit na krajských tarifech s Mirko Tomáškem : INTERVIEW - YouTube - https://www.youtube.com/watch?v=P2YlX7nkly8
-
RE: https://fosstodon.org/@jaandrle/116993316250642409
KALKUVLAČKA: Jak ušetřit na krajských tarifech s Mirko Tomáškem : INTERVIEW - YouTube - https://www.youtube.com/watch?v=P2YlX7nkly8
-
Kalkuvlačka - Vyhledávač nejlevnějších vlakových spojení v IDS - https://kalkuvlacka.cz/
-
Kalkuvlačka - Vyhledávač nejlevnějších vlakových spojení v IDS - https://kalkuvlacka.cz/
-
There are many misconceptions about the spread of dis/misinformation. Perhaps the most prevalent is that a particular piece of misinformation is global, when in fact it usually has a local spin. Full article in comments
#techethics #Ireland #IDS #TikTok #Telegram #disinformation #misinformation
-
There are many misconceptions about the spread of dis/misinformation. Perhaps the most prevalent is that a particular piece of misinformation is global, when in fact it usually has a local spin. Full article in comments
#techethics #Ireland #IDS #TikTok #Telegram #disinformation #misinformation
-
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
I seem to be seeing that the #ip #ipv4 addresses of some legit #reticulum #nodes are being included in some of the lists used by #suricata #IDS #intrustiondetectionsystem to #blacklist IP addresses, and so they might well end up blocked by your #firewall or #IPS #intrusionprotectionsystem
in particular e.g. database #CINS might be flagging mesh nodes
Please take steps for port 4242
#port4242 normally used by #rns #reticulum to not let bad data spoil the #mesh #nomadnet #meshchat #meshchatx -
Как изменилась жизнь интернет-безопасников с приходом QUIC? IDS и threat analysing в реалиях HTTP/3
Обзорный анализ “нового” протокола HTTP/3 и подходов к анализу трафика и защите информационных систем построенных на его основе. Фингерпринтинг выступает одной из больших тем статьи, ему уделено отдельное внимание. Читать
-
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
#Suricata powers many of today’s leading network detection and response solutions, including Clear NDR Community, which is widely used by practitioners to explore what is possible with Suricata IDS/IPS/NSM and the network protocol monitoring logs and alerts it produces.
-
#Suricata powers many of today’s leading network detection and response solutions, including Clear NDR Community, which is widely used by practitioners to explore what is possible with Suricata IDS/IPS/NSM and the network protocol monitoring logs and alerts it produces.
-
Как работает эта ваша суриката 3 часть
Третья часть цикла статей по разбору устройства работы IDS/IPS решения Suricata. Разберём на практике уязвимость CVE‑2025‑66698 – обход аутентификации в Veda (Semantic Machines) v5.4.8. Запишем трафик с вредоносными запросами и составим suricata-правило, которое детектирует эксплуатацию уязвимости. В статье также приводятся объяснения как работают content, pcre и липкие буферы.
-
Как работает эта ваша суриката 2 часть
Вторая часть цикла статей о практическом применении Suricata IDS/IPS. Рассмотрим базовые модификаторы Suricata на примерах DNS-запросов и на сетевых атаках. Уделим внимание механизму threshold для предотвращения флуда алертов.
-
Yet another way to track US citizens and deny our right to privacy!
FCC Wants to Kill Burner Phones By Forcing Telecoms to Get All Customers’ IDs
#FCC #US #BurnerPhones #Telecoms #IDs #Surveillance #Privacy #Tech
-
Yet another way to track US citizens and deny our right to privacy!
FCC Wants to Kill Burner Phones By Forcing Telecoms to Get All Customers’ IDs
#FCC #US #BurnerPhones #Telecoms #IDs #Surveillance #Privacy #Tech
-
Мониторинг, IDS и системный анализ. YARA
YARA — инструмент для идентификации и классификации вредоносного программного обеспечения по правилам. Правила YARA описывают паттерны (строки, бинарные последовательности, регулярные выражения) в файлах. Широко используется в антивирусах, IDS, threat hunting для поиска малвари.
https://habr.com/ru/articles/1044952/
#безопастность #защита #системный_администратор #yara #ids #системный_анализ
-
-
das Reel – das Stigma
Beginnen müssen wir mit dem Stigma.
Als Stigma versteht man im Allgemeinen Merkmale, die negativ bewertet werden. In den Sozialwissenschaften nennt man es Stigmatisierung, wenn Individuen oder Gruppen eine negativ bewertete soziale Identität aufgrund real existierender oder unterstellter Merkmale zugeschrieben wird. Stigmatisierung ist also eine aktiv vorgenommene Handlung ...https://einblogvonvielen.org/das-reel-das-stigma/
#Autismus #IDS #Stigmatisierung #Blog -
«Слепой прогон»: почему ваш IPS начинает стрелять по своим в первый же день
Когда IPS включают «в бой» сразу после установки, он часто начинает защищать инфраструктуру от неё самой: блокирует легитимные скрипты, бэкапы, нестандартные запросы и рабочие процессы. В статье разбираем, почему отсутствие baseline превращает IDS/IPS из средства защиты в источник инцидентов, как возникают ложные срабатывания и почему перед режимом блокировки системе нужно дать время изучить нормальный трафик вашей сети.
https://habr.com/ru/companies/otus/articles/1037456/
#IDS #IPS #baseline #ложные_срабатывания #информационная_безопасность #сетевая_безопасность #защита_инфраструктуры #сигнатуры #мониторинг_трафика #эшелонированная_защита
-
1964 setzte das Institut für deutsche Sprache einen klaren Schnitt: Fokus auf Gegenwartssprache statt historische Germanistik. Warum die Vergangenheit zunächst ausgeblendet wurde und wie Nachkriegsdebatten über Sprache diese Entscheidung prägten, zeigt Stefan Scholl 👇
-
1964 setzte das Institut für deutsche Sprache einen klaren Schnitt: Fokus auf Gegenwartssprache statt historische Germanistik. Warum die Vergangenheit zunächst ausgeblendet wurde und wie Nachkriegsdebatten über Sprache diese Entscheidung prägten, zeigt Stefan Scholl 👇
-
EU Age Control: The trojan horse for digital IDs
https://juraj.bednar.io/en/blog-en/2026/04/17/eu-age-control-the-trojan-horse-for-digital-ids/
#HackerNews #EU #Age #Control #digital #IDs #privacy #security #technology
-
EU Age Control: The trojan horse for digital IDs
https://juraj.bednar.io/en/blog-en/2026/04/17/eu-age-control-the-trojan-horse-for-digital-ids/
#HackerNews #EU #Age #Control #digital #IDs #privacy #security #technology
-
France confirms data breach at government agency that manages citizens' IDs
#HackerNews #France #data #breach #government #agency #citizens #IDs #cybersecurity #privacy
-
France confirms data breach at government agency that manages citizens' IDs
#HackerNews #France #data #breach #government #agency #citizens #IDs #cybersecurity #privacy
-
СЗИ — средства защиты информации, своими словами
Когда я только начинал в ИБ, я часами лазил по сайтам в попытках понять: а что вообще нужно знать новичку? Какими базовыми вещами должен владеть специалист по защите информации — будь то внутри контура организации или за его пределами. Так я наткнулся на статьи про СЗИ — средства защиты информации. По сути, это тот самый инструментарий, с помощью которого специалист и строит защиту. Думаю, выпущу несколько материалов, где своими словами разберу разные виды СЗИ. Для тех, кто только вникает в профессию, — чтобы было проще ориентироваться в этих штуках. СПИСОК СЗИ ПРО КОТОРЫЕ Я РАССКАЗЫВАЮ В ЭТОЙ СТАТЬЕ: 1. Межсетевой экран (МЭ) — он же Firewall (англ.) или Brandmauer (нем.). 2. IDS/IPS — Intrusion Detection System / Intrusion Prevention System 3. DLP — Data Leak Prevention 4. SIEM — Security Information and Event Management 5. Sandbox — «песочница» Межсетевой экран Думаю, многие уже слышали о межсетевых экранах. Их называют по-разному: Firewall — с английского «огненная стена», или Brandmauer — с немецкого тоже «огненная стена». В общем как ни назови, он делает одно и то же — не дает нежелательному трафику проникнуть в сеть.
https://habr.com/ru/articles/1020192/
#сзи #безопасность #информационная_безопасность #ids #ips #dlpсистемы #firewall #sandbox #межсетевой_экран
-
Крекс-пекс-фекс, вжух и ты бедняк: исследуем под «микроскопом» потрошителя банковских счетов CrахsRAT
Половина краж с банковских карт в России за последние полгода — дело рук одного семейства троянов . SpyNote и его наследник CraxsRAT заражают Android-устройства, открывают банковские приложения и выводят деньги. Большинство разборов этих вредоносов заканчиваются списком IOC и общими рекомендациями. Эта статья устроена иначе. Меня зовут Евгения Устинова, я старший аналитик сетевой безопасности в компании «Гарда». Я провела статический разбор нескольких версий трояна (v3.7.1–v7.6, включая форки EagleSpy, VIPRat, RedBat, MedusaRat, DesertRat и утечку исходного кода v6/v7), восстановила полную хронологию атаки по реальному трафику и разобрала протокол до байтов. Оказалось, что у CraxsRAT есть сетевая активность, которую невозможно отключить, не сломав клиент. Я использовала эти базовые свойства протокола, чтобы построить правила Suricata, которые не устареют завтра, как обычные IOC. Читайте подробное исследование под катом. Заглянуть внутрь CraxsRAT
https://habr.com/ru/companies/garda/articles/1018424/
#сетевая_безопасность #craxsrat #SpyNot #банковский_троян #ids #защита_сети
-
Advvvvertorial: Read about how SCHNELLE BUNTE BILDER are using industrial cameras by IDS-Imaging to create their magic:
https://de.ids-imaging.com/casestudies-detail/items/interactive-installations.html
-
Advvvvertorial: Read about how SCHNELLE BUNTE BILDER are using industrial cameras by IDS-Imaging to create their magic:
https://de.ids-imaging.com/casestudies-detail/items/interactive-installations.html
-
От сигнатур к ML IDS: чему IDS Suricata может научить модель?
[Текст не для публикации: не нашел как Редакции прикрепить сообщение, эта статья написана в рамках Блога "Институт системного программирования им. В.П. Иванникова РАН"]
-
29ct Premium-Laden, #VW- #IDs mit #Steckdose, Aufladen in 5min, #Mazda- #Gate, Abzocke im #D_Netz
Stabile #EAuto- #Zulassungen im Februar, neue Zahlen zum Fahrzeugbestand und ein möglicher Technologiesprung bei Batterien: In den aktuellen nextnews geht es außerdem um die neue elektrische Mercedes V-Klasse, zahlreiche neue Funktionen für VWs ID-Modelle und Probleme mit der LFP-Batterie im Mazda 6e...
#nextmove
@nextmovevideos -
29ct Premium-Laden, #VW- #IDs mit #Steckdose, Aufladen in 5min, #Mazda- #Gate, Abzocke im #D_Netz
Stabile #EAuto- #Zulassungen im Februar, neue Zahlen zum Fahrzeugbestand und ein möglicher Technologiesprung bei Batterien: In den aktuellen nextnews geht es außerdem um die neue elektrische Mercedes V-Klasse, zahlreiche neue Funktionen für VWs ID-Modelle und Probleme mit der LFP-Batterie im Mazda 6e...
#nextmove
@nextmovevideos -
Investigation scenario:
We just received three notifications with alerts from #Suricata #IDS1) GPL SMTP vrfy root, from unknown IP to our mailserver
Shortly after that, two more alerts appeared:
2) ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response; from the same unknown IP to Windows computer in our network
3) ET MALWARE Possible Metasploit Payload Common Construct Bind_API, again from the same unknown IP to the same Windows computerWhat happened?
What to do? How to analyze network traffic and investigate those alerts?We do not have any EDR or XDR installed on that Windows computer. Right now,we have only Suricata eve.json logs ingested to the #OpenObserve #SIEM
If you would like to see more, you are welcome to attend my @suricata webinar on March 11.
Register here: https://us02web.zoom.us/webinar/register/WN_I6BNbCU2SNG2fAOEiotPiQ -
Investigation scenario:
We just received three notifications with alerts from #Suricata #IDS1) GPL SMTP vrfy root, from unknown IP to our mailserver
Shortly after that, two more alerts appeared:
2) ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response; from the same unknown IP to Windows computer in our network
3) ET MALWARE Possible Metasploit Payload Common Construct Bind_API, again from the same unknown IP to the same Windows computerWhat happened?
What to do? How to analyze network traffic and investigate those alerts?We do not have any EDR or XDR installed on that Windows computer. Right now,we have only Suricata eve.json logs ingested to the #OpenObserve #SIEM
If you would like to see more, you are welcome to attend my @suricata webinar on March 11.
Register here: https://us02web.zoom.us/webinar/register/WN_I6BNbCU2SNG2fAOEiotPiQ -
Hey Security folks - tell me about your rules and detections for OpenClaw - IDS, SIEM, other!
-
Hey Security folks - tell me about your rules and detections for OpenClaw - IDS, SIEM, other!
-
@da_667 i may have to break into the mountains and drink a cold one
make a paid version of suri with ndpi for opnsense - plus upsells - their licensing is good , somebody may already do this? either way good idea#hashcat #ntop products #ids #opnsense
#you can't run away from your problems #you can run away from your problems
-
@da_667 i may have to break into the mountains and drink a cold one
make a paid version of suri with ndpi for opnsense - plus upsells - their licensing is good , somebody may already do this? either way good idea#hashcat #ntop products #ids #opnsense
#you can't run away from your problems #you can run away from your problems
-
Rulezet (The detection rule management) v1.4.0 released — Taxonomy, Precision, and Advanced Discovery
Version 1.4.0 is a milestone update that transforms how intelligence is categorized and retrieved within Rulezet. By placing Tags and Taxonomies at the heart of the ecosystem, this release empowers users with granular control over their data. From private custom tagging to a revolutionary filtering engine, v1.4.0 ensures that finding the right rule is no longer a search—it’s a precision operation.
On the administrative side, we’ve introduced robust tools for visibility control and system resilience, including a new backup architecture and CVE sanitization to maintain data integrity across the platform.
🔗 Online version https://rulezet.org/
:github: Release notes https://github.com/ngsoti/rulezet-core/releases/tag/v1.4.0
🔗 Source code https://github.com/ngsoti/rulezet-core#nids #ids #opensource #opendata #cybersecurity #detection #soc
-
Indiana quietly bans trans residents from changing gender markers on IDs
https://web.brid.gy/r/https://www.advocate.com/politics/indiana-gender-marker-change-ban
-
I am told #proxmox is fab & it is ... but does it make sense to run #nixos #virtualmachines on proxmox: one for each task e.g. #ids #Jellyfin #peertube ? Or is it best to put all one's eggs into 1 single #cpu #ram #storage basket in one bare metal server that does it all? Or what of a #minipc #nixos farm instead? Does that spread risk of downtime due to machine breakdown issues or is maintenance too hard? Any experiments or experiences to report ? Thanks. #homelab #PVE #lxe @homelab
-
palestine.pixel
「彼がイスラエル人だから、この件は表に出なかったんだ」
ラスベガスに秘密のバイオ研究所を所有するイスラエル人、オリ・ソロモンは、当局が#HIV、結核、マラリアを含む1,000点以上の致死性#ウイルスサンプルを発見した後、釈放された。彼は移動を容易にするため、#フランスパスポートと複数の偽造#身分証明書も所持していた。
“You didn’t hear about it because he’s Israeli.”
Ori Solomon, the #Israeli owner of a secret bio lab in Las Vegas, was released after authorities discovered over 1,000 samples of deadly #viruses , including #HIV, tuberculosis, and malaria. He also held a #French passport and multiple fake #IDs to facilitate his movements. -
How to Stop AUTO_INCREMENT Gaps From Breaking IDs
Rollbacks still consume auto increment values.
-
Very interesting firewall settings. Thanks for sharing them. Question into the void: is there a “menu-style” FOSS #firewall setup for #NixOS —prebuilt profiles with different strictness levels one can apply and test? I’m running #Suricata #IDS, but I don’t have a systematic way to validate #firewallpolicy beyond “tweak until it works.” I’d love a repeatable approach to reach a good protection baseline with minimal site access #breakage .
-
@joschi @homelab @homelab_de I chickened out and made and #suricata #ids - see my repo flake under features/network-appliance https://repoducible.org
Wanted first to see what was going on on my network.... -
🚀 Breaking news: #GitHub objects have two IDs! 🎉 Because one just wasn't confusing enough. 🙄 Dive into the mind-numbing intricacies of node and database ID archaeology, because who doesn't love deciphering cryptic hieroglyphs in their spare time? 😅
https://www.greptile.com/blog/github-ids #IDs #NodeID #DatabaseID #Confusion #TechNews #HackerNews #ngated