home.social

#suricata — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #suricata, aggregated by home.social.

  1. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  2. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  3. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  4. Big week for #Suricata in Vegas 🎰

    - Peter, Jeff & Lukas ran a hands-on workshop on AI SKILLs for network security monitoring @ #BSidesLV
    - Broke down Suricata 8 @ #BlackHatUSA Arsenal
    - Lukas Sismis won the Telecom Village CTF @ #DEFCON34

    And gave out all the #Suricata swag - Send us pix!

  5. During the #SharkBytes session at #SharkFest conference I had an opportunity to present a lightning talk about my pet project called IDS Lab.
    It is a lab infrastructure deployable as docker containers, which simulates the small company network.

    The IDS Lab consists of web webserver with #Wordpress, #MySQL database, #Linux desktop with RDP, the #WireGuard VPN for "remote" workers and for connecting another virtual or physical machines into the lab network.
    This part of infrastructure can be used for attack simulations.

    There are additional components for playing with logs and detections, too: #Fluentbit, #Suricata and #OpenObserve as lightweight SIEM.

    In the #SIEM we already have preconfgured dashboards for alerts, netflows, web logs and logs from windows machines, if present.

    Using the provided setup script, the whole lab can be up and running in up to 5 minutes. For more info, please check my GitHub repository with the IDS Lab:

    github.com/SecurityDungeon/ids

    #sf24eu #wireshark @wireshark

  6. During the #SharkBytes session at #SharkFest conference I had an opportunity to present a lightning talk about my pet project called IDS Lab.
    It is a lab infrastructure deployable as docker containers, which simulates the small company network.

    The IDS Lab consists of web webserver with #Wordpress, #MySQL database, #Linux desktop with RDP, the #WireGuard VPN for "remote" workers and for connecting another virtual or physical machines into the lab network.
    This part of infrastructure can be used for attack simulations.

    There are additional components for playing with logs and detections, too: #Fluentbit, #Suricata and #OpenObserve as lightweight SIEM.

    In the #SIEM we already have preconfgured dashboards for alerts, netflows, web logs and logs from windows machines, if present.

    Using the provided setup script, the whole lab can be up and running in up to 5 minutes. For more info, please check my GitHub repository with the IDS Lab:

    github.com/SecurityDungeon/ids

    #sf24eu #wireshark @wireshark

  7. During the #SharkBytes session at #SharkFest conference I had an opportunity to present a lightning talk about my pet project called IDS Lab.
    It is a lab infrastructure deployable as docker containers, which simulates the small company network.

    The IDS Lab consists of web webserver with #Wordpress, #MySQL database, #Linux desktop with RDP, the #WireGuard VPN for "remote" workers and for connecting another virtual or physical machines into the lab network.
    This part of infrastructure can be used for attack simulations.

    There are additional components for playing with logs and detections, too: #Fluentbit, #Suricata and #OpenObserve as lightweight SIEM.

    In the #SIEM we already have preconfgured dashboards for alerts, netflows, web logs and logs from windows machines, if present.

    Using the provided setup script, the whole lab can be up and running in up to 5 minutes. For more info, please check my GitHub repository with the IDS Lab:

    github.com/SecurityDungeon/ids

    #sf24eu #wireshark @wireshark

  8. During the #SharkBytes session at #SharkFest conference I had an opportunity to present a lightning talk about my pet project called IDS Lab.
    It is a lab infrastructure deployable as docker containers, which simulates the small company network.

    The IDS Lab consists of web webserver with #Wordpress, #MySQL database, #Linux desktop with RDP, the #WireGuard VPN for "remote" workers and for connecting another virtual or physical machines into the lab network.
    This part of infrastructure can be used for attack simulations.

    There are additional components for playing with logs and detections, too: #Fluentbit, #Suricata and #OpenObserve as lightweight SIEM.

    In the #SIEM we already have preconfgured dashboards for alerts, netflows, web logs and logs from windows machines, if present.

    Using the provided setup script, the whole lab can be up and running in up to 5 minutes. For more info, please check my GitHub repository with the IDS Lab:

    github.com/SecurityDungeon/ids

    #sf24eu #wireshark @wireshark

  9. During the #SharkBytes session at #SharkFest conference I had an opportunity to present a lightning talk about my pet project called IDS Lab.
    It is a lab infrastructure deployable as docker containers, which simulates the small company network.

    The IDS Lab consists of web webserver with #Wordpress, #MySQL database, #Linux desktop with RDP, the #WireGuard VPN for "remote" workers and for connecting another virtual or physical machines into the lab network.
    This part of infrastructure can be used for attack simulations.

    There are additional components for playing with logs and detections, too: #Fluentbit, #Suricata and #OpenObserve as lightweight SIEM.

    In the #SIEM we already have preconfgured dashboards for alerts, netflows, web logs and logs from windows machines, if present.

    Using the provided setup script, the whole lab can be up and running in up to 5 minutes. For more info, please check my GitHub repository with the IDS Lab:

    github.com/SecurityDungeon/ids

    #sf24eu #wireshark @wireshark