#portscanning — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #portscanning, aggregated by home.social.
-
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning -
Using #suricata #IDS and #abuseipdb with manual checks using #claudecode to identify IP addresses that are attacking my reverse proxy device. I block in #nftables the IPs that tick all three boxes:
1. suricata reports attack,
2. claude code investigates and confirms attack (and we log the CVE etc.), and
3. IP is already high confidence bad actor.
A bit slow really due to manual checking. How does one extend to #IPv6 ? What measures should one add? #portscanning