home.social

#suricata — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #suricata, aggregated by home.social.

  1. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  2. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  3. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  4. CW: release notes for Malcolm v26.08.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.08.0 adds a NetBox purdue_zone custom field that propagates ICS/OT network zone classifications to devices, prefixes, and virtual machines (and automatically to autopopulated devices from their containing prefix); Raspberry Pi 5 support for Hedgehog Linux; and, configurable Strelka scanner and disabled-Suricata-SID lists. This release also fixes five security vulnerabilities: an nginx RBAC bypass via percent-encoded, case-varied, or slash-doubled request paths; an archive-bomb bypass affecting raw-stream and lzip-compressed uploads; a case-variant path bypass of the nginx auth gate exposing the Arkime backend to forged identity headers; an Arkime authentication gap on sensor nodes that fell back to digest instead of enforcing s2s; and a CSRF vulnerability in the kiosk /script_call endpoint allowing unauthenticated data-destructive operations. Arkime, Zeek, NetBox, OpenSearch, OpenSearch Dashboards, Logstash, Filebeat, Keycloak, and other components have been updated as well. Several other bug fixes and general improvements are also included.

    github.com/idaholab/Malcolm/co

    See the Release Notes for the full set of new features, enhancements, bug fixes, and component version updates.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL