#suricata β Public Fediverse posts
Live and recent posts from across the Fediverse tagged #suricata, aggregated by home.social.
-
5 SEATS LEFT! Join us for live training at #SuriCon2026 this November 16-17.
Training is bundled with SuriCon 2026 conference registration, so you can get two days of training followed by three days of conference sessions and community networking.
Choose your training: suricon.net/trainings/
-
CW: release notes for Malcolm v26.08.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.08.0 adds a NetBox
purdue_zonecustom field that propagates ICS/OT network zone classifications to devices, prefixes, and virtual machines (and automatically to autopopulated devices from their containing prefix); Raspberry Pi 5 support for Hedgehog Linux; and, configurable Strelka scanner and disabled-Suricata-SID lists. This release also fixes five security vulnerabilities: an nginx RBAC bypass via percent-encoded, case-varied, or slash-doubled request paths; an archive-bomb bypass affecting raw-stream and lzip-compressed uploads; a case-variant path bypass of the nginx auth gate exposing the Arkime backend to forged identity headers; an Arkime authentication gap on sensor nodes that fell back todigestinstead of enforcings2s; and a CSRF vulnerability in the kiosk/script_callendpoint allowing unauthenticated data-destructive operations. Arkime, Zeek, NetBox, OpenSearch, OpenSearch Dashboards, Logstash, Filebeat, Keycloak, and other components have been updated as well. Several other bug fixes and general improvements are also included.https://github.com/idaholab/Malcolm/compare/v26.07.1...v26.08.0
See the Release Notes for the full set of new features, enhancements, bug fixes, and component version updates.
Malcolm is a powerful, easily deployable network π§ traffic analysis tool suite for network security monitoring π΅π»ββοΈ.
Malcolm operates as a cluster of containers π¦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker π, Podman π¦, and Kubernetes β. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images πΏ for Malcolm and Hedgehog Linux π¦ can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split πͺ into 2GB chunks and can be reassembled with scripts provided for both Bash π§ (
release_cleaver.sh) and PowerShell πͺ (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board π¬ to engage with the community, or pop some corn πΏ and watch a video πΌ.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring
Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the
strelka-backendcontainer on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
β¨ Features and enhancements
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
spicy-iec104Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939 - Make
LOGSTASH_NETBOX_ENRICHMENT_DATASETSmore flexible: it now acceptsdefault,ics/ot,all, explicitprovider.datasetvalues, and combinations such asdefault,ics#1037 - Allow
LOGSTASH_NETBOX_ENRICHMENT_DATASETSto be configured through checkboxes in the configuration TUI #1033 - Improve
./scripts/starterror messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865 - Have
system-quickstartdetect and prepopulate existing time synchronization settings when rerun #992
- Add IEC 60870-5-104 (IEC 104) support using the CERT.LV
π‘οΈ Security Remediation & Hardening
- Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
- Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
- Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
- Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
π Bug fixes
- Co-installation of
opencv-pythonandopencv-contrib-pythoncorruptscv2.abi3.so, segfaultingstrelka-backendat import on arm64 #1046 (fix) - Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
- Fix the broken signal chain in
docker-uid-gid-setup.shso signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers - Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
- Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when
KEYCLOAK_SSL_VERIFY=true#1035 - Restore
curlto the thehtadmincontainer for use by the health check script #1029 - Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
- Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
- Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
- Co-installation of
β Component version updates
- Arkime to v6.6.0
- This update contains a major speed-up when loading the SPIView and Connections pages
- Zeek to v8.2.1 #970
- Fluent Bit Windows installer helper to v5.0.9
- Filebeat OSS to v9.4.3
- Logstash to v9.4.4
- Pillow (Python library used in the
netboxcontainer) to v12.3.0 to address several security findings - Supercronic to v0.2.47
- Alpine Linux base images to v3.24
- KeyCloak to 26.6.4
- cryptography (Python library) to v48.0.1 to address security advisory GHSA-537c-gmf6-5ccf
- Arkime to v6.6.0
π§Ή Code and project maintenance
- Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
- Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
- Improve installer validation, environment-variable mapping tests, and configuration item metadata
- Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
- Minor improvements to the Hedgehog Raspberry Pi image build process.
π Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.LOGSTASH_NETBOX_ENRICHMENT_DATASETSinlogstash.envnow defaults todefaultand may containdefault,ics/ot,all, explicitprovider.datasetvalues, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104inzeek.envcontrols whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES,SAFE_EXTRACT_MAX_DEPTH, andSAFE_EXTRACT_MAX_BYTESinupload-common.envset archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data
Malcolm is a powerful, easily deployable network π§ traffic analysis tool suite for network security monitoring π΅π»ββοΈ.
Malcolm operates as a cluster of containers π¦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker π, Podman π¦, and Kubernetes β. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images πΏ for Malcolm and Hedgehog Linux π¦ can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split πͺ into 2GB chunks and can be reassembled with scripts provided for both Bash π§ (
release_cleaver.sh) and PowerShell πͺ (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board π¬ to engage with the community, or pop some corn πΏ and watch a video πΌ.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
CW: release notes for Malcolm v26.06.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.06.0 is primarily a security hardening release, addressing fifteen vulnerabilities (2 high severity, 6 medium, and 7 low) identified in a security assessment. Bug fixes address an issue with the
zeekcontainer causing performance degredation over time and a fix for duplicate virtual machine entries in NetBox autopopulation. A few component versions have also been updated.If you are upgrading from an existing Malcolm installation, run
./scripts/statusfor Malcolm to migrate some settings prior to running./scripts/configure,./scripts/start, or other Malcolm control scripts.https://github.com/idaholab/Malcolm/compare/v26.05.2...v26.06.0
- π‘οΈ Security Remediation & Hardening (#996)
- Unauthenticated reflected XSS / open redirect in
/dashboards/app/refred; also addedContent-Security-Policyframing headers (frame-ancestors,base-uri,form-action) andX-Frame-Options: SAMEORIGINglobally to mitigate clickjacking (#997) - Authenticated command injection in filebeat container via SFTP-uploaded filename (#998)
- Password stored as MD5-crypt for SFTP (#1009)
- Authenticated archive zip-slip file write in filebeat container (#999)
- OpenSearch path injection via
/mapi/fields?template(#1000) submit.phpLocation:open redirect viaReferer(#1007)- htadmin proxied with no nginx auth gate (#1003)
- Keycloak OIDC
ssl_verifyalways set to false (#1006) - NetBox
SUPERUSER_PASSWORD=adminshipped default (#1011) - RBAC
defaultdict(lambda: True)fail-open for unlisted handlers in Malcolm API (#1004) - Read-only Arkime deny-regex omits
addtags/removetags(#1008) - Read-only deployment allows
POST /mapi/event(#1002) - WISE auth path selectable by client
User-Agent(#1001) ARKIME_PASSWORD_SECRET=Malcolmshipped default (#1005)requestsCVE bump reverted in logstash image (#1010)- Fix API auth errors and hide NGINX version disclosure (#989)
- Unauthenticated reflected XSS / open redirect in
- π Bug fixes
- auto-discovered Virtual Machines in NetBox seem to allow for duplicates (#978)
- Ensure list of archive file types supported by Malcolm for uploading Zeek logs (
application/gzip,application/vnd.rar,application/x-7z-compressed,application/x-bzip2,application/x-cpio,application/x-gzip,application/x-lzip,application/x-lzma,application/x-rar-compressed,application/x-tar,application/x-xz,application/zip) are consistently used across the platform. zeekcontainer continually grows/usr/local/zeek/crontab, causing Malcolm performance to gradually worsen (#1015)
- β Component version updates
- π§Ή Code and project maintenance
- Fixed some incorrect links in documentation (#988, thanks @jsoref)
- Refactored NGINX error pages configuration into its own
includefile and added a401.htmlpage
- π Configuration changes for Malcolm (in environment variables in
./config/). The Malcolm control script (e.g.,./scripts/status,./scripts/start) automatically handles creation and migration of variables according to./config/env-var-actions.yml.- Added
KEYCLOAK_SSL_VERIFY(defaultfalse) tokeycloak.envfor #1006 - The Arkime password hash secret
ARKIME_PASSWORD_SECRETinarkime-secret.envno longer has a default value: it must be set duringauth_setup(for #1005) - The Netbox superuser password
SUPERUSER_PASSWORDinnetbox-secret.envno longer has a default value: it must be set duringauth_setup(for #1011)
- Added
Malcolm is a powerful, easily deployable network π§ traffic analysis tool suite for network security monitoring π΅π»ββοΈ.
Malcolm operates as a cluster of containers π¦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker π, Podman π¦, and Kubernetes β. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images πΏ for Malcolm and Hedgehog Linux π¦ can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split πͺ into 2GB chunks and can be reassembled with scripts provided for both Bash π§ (
release_cleaver.sh) and PowerShell πͺ (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board π¬ to engage with the community, or pop some corn πΏ and watch a video πΌ.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
- π‘οΈ Security Remediation & Hardening (#996)
-
Background:
for my #homelab I set up #suricata in #nixos and have a functioning #ids #intrusiondetection system with a #grafana dashboard (#flake info here https://codeberg.org/adingbatponder/reticulum_nixos_flake/src/commit/9ebc4cd68ba461b0baad990cbdd4a4ef50b57045/features/network-appliance/README.md ).
Preliminary plan:
I now want to go to and #ips #intrusionprevention system that blocks threats detected. Current plan is #nftables with #nfqueue but there is no GUI for that it seems, and it is a bit clunky and black-boxy.
Question: What are the more user-friendly options for an IPS front-end / GUI ?
Thanks! -
Made a transparent network bridge on #NixOS which sits between router & #LAN switch, monitoring traffic for #IDS #intrusiondetection , #Suricata and #Zeek capture and analyze packets β #Filebeat ships #logs β #Elasticsearch with #GeoIP ingest pipeline β #Grafana setup of dashboard to visualise data is defined in flake itself so using the flake will give the same dashboard. #flake details here https://codeberg.org/adingbatponder/reticulum_nixos_flake/src/branch/main/features/network-appliance
Hardware: HP EliteDesk 800 G1 SFF 16Gb RAM & https://www.jacob.de/produkte/Intel-Ethernet-Server-Adapter-I350-T4-I350T4V2-artnr-2094756.html #i350t4 -
Cyber threats are becoming more advanced every day, making it crucial to stay informed and prepared. Social engineering and deepfake attacks are two significant concerns that require robust security measures.
https://linuxexpert.org/cybersecurity-rising-threats-and-how-to-protect-against-them/
#Cybersecurity #SocialEngineering #DeepfakeAttacks #ZeroTrust #ContinuousMonitoring #LinuxSecurity #NetworkSecurity #OpenSourceSecurity #MFA #SecurityTraining #IntrusionDetection #OSSEC #Suricata #OpenLDAP #LeastPrivilege #GnuPG #ITSecurity #linux