#suricata — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #suricata, aggregated by home.social.
-
i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: https://github.com/cmhobbs/suricata2ilf
it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.
a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.
-
i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: https://github.com/cmhobbs/suricata2ilf
it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.
a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.
-
i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: https://github.com/cmhobbs/suricata2ilf
it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.
a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.
-
CW: release notes for Malcolm v26.08.0, a network traffic analysis tool suite for network security monitoring
Malcolm v26.08.0 adds a NetBox
purdue_zonecustom field that propagates ICS/OT network zone classifications to devices, prefixes, and virtual machines (and automatically to autopopulated devices from their containing prefix); Raspberry Pi 5 support for Hedgehog Linux; and, configurable Strelka scanner and disabled-Suricata-SID lists. This release also fixes five security vulnerabilities: an nginx RBAC bypass via percent-encoded, case-varied, or slash-doubled request paths; an archive-bomb bypass affecting raw-stream and lzip-compressed uploads; a case-variant path bypass of the nginx auth gate exposing the Arkime backend to forged identity headers; an Arkime authentication gap on sensor nodes that fell back todigestinstead of enforcings2s; and a CSRF vulnerability in the kiosk/script_callendpoint allowing unauthenticated data-destructive operations. Arkime, Zeek, NetBox, OpenSearch, OpenSearch Dashboards, Logstash, Filebeat, Keycloak, and other components have been updated as well. Several other bug fixes and general improvements are also included.https://github.com/idaholab/Malcolm/compare/v26.07.1...v26.08.0
See the Release Notes for the full set of new features, enhancements, bug fixes, and component version updates.
Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (
release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
Antiphishing Detection Update
A new threat intelligence cycle has been processed by the Antiphishing pipeline.
Current detection coverage:
• 6,007,331 HTTP signatures
• 243,098 TLS signatures
• 243,098 DNS signatures
• 6,493,527 total generated signaturesThe pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.
The ruleset is available through the suricata-update ecosystem.
Detection is only useful when intelligence can reach the enforcement layer.
Feeds → IOC processing → Rule generation → Suricata → Detection
Run julioliraup/Antiphishing on @suricata
https://github.com/julioliraup/Antiphishing
#Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity -
Antiphishing Detection Update
A new threat intelligence cycle has been processed by the Antiphishing pipeline.
Current detection coverage:
• 6,007,331 HTTP signatures
• 243,098 TLS signatures
• 243,098 DNS signatures
• 6,493,527 total generated signaturesThe pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.
The ruleset is available through the suricata-update ecosystem.
Detection is only useful when intelligence can reach the enforcement layer.
Feeds → IOC processing → Rule generation → Suricata → Detection
Run julioliraup/Antiphishing on @suricata
https://github.com/julioliraup/Antiphishing
#Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity -
Antiphishing Detection Update
A new threat intelligence cycle has been processed by the Antiphishing pipeline.
Current detection coverage:
• 6,007,331 HTTP signatures
• 243,098 TLS signatures
• 243,098 DNS signatures
• 6,493,527 total generated signaturesThe pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.
The ruleset is available through the suricata-update ecosystem.
Detection is only useful when intelligence can reach the enforcement layer.
Feeds → IOC processing → Rule generation → Suricata → Detection
Run julioliraup/Antiphishing on @suricata
https://github.com/julioliraup/Antiphishing
#Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity -
Antiphishing Detection Update
A new threat intelligence cycle has been processed by the Antiphishing pipeline.
Current detection coverage:
• 6,007,331 HTTP signatures
• 243,098 TLS signatures
• 243,098 DNS signatures
• 6,493,527 total generated signaturesThe pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.
The ruleset is available through the suricata-update ecosystem.
Detection is only useful when intelligence can reach the enforcement layer.
Feeds → IOC processing → Rule generation → Suricata → Detection
Run julioliraup/Antiphishing on @suricata
https://github.com/julioliraup/Antiphishing
#Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity -
Antiphishing Detection Update
A new threat intelligence cycle has been processed by the Antiphishing pipeline.
Current detection coverage:
• 6,007,331 HTTP signatures
• 243,098 TLS signatures
• 243,098 DNS signatures
• 6,493,527 total generated signaturesThe pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.
The ruleset is available through the suricata-update ecosystem.
Detection is only useful when intelligence can reach the enforcement layer.
Feeds → IOC processing → Rule generation → Suricata → Detection
Run julioliraup/Antiphishing on @suricata
https://github.com/julioliraup/Antiphishing
#Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity -
Background:
for my #homelab I set up #suricata in #nixos and have a functioning #ids #intrusiondetection system with a #grafana dashboard (#flake info here https://codeberg.org/adingbatponder/reticulum_nixos_flake/src/commit/9ebc4cd68ba461b0baad990cbdd4a4ef50b57045/features/network-appliance/README.md ).
Preliminary plan:
I now want to go to and #ips #intrusionprevention system that blocks threats detected. Current plan is #nftables with #nfqueue but there is no GUI for that it seems, and it is a bit clunky and black-boxy.
Question: What are the more user-friendly options for an IPS front-end / GUI ?
Thanks! -
Meerkat @ Home
#Oil on #canvas, 60 x 50 cm
www.jurakuba.com
#meerkats #suricata #art #meercat #animal #painting #paintings #humor #humour #humorous #funny #animals #painting #artwork #artworks #cute #sofa #couch #creative #resting #home #cozy #blue #creative #Kunst #Malerei #gemälde #artist #jokes #artists #joke -
Made a transparent network bridge on #NixOS which sits between router & #LAN switch, monitoring traffic for #IDS #intrusiondetection , #Suricata and #Zeek capture and analyze packets → #Filebeat ships #logs → #Elasticsearch with #GeoIP ingest pipeline → #Grafana setup of dashboard to visualise data is defined in flake itself so using the flake will give the same dashboard. #flake details here https://codeberg.org/adingbatponder/reticulum_nixos_flake/src/branch/main/features/network-appliance
Hardware: HP EliteDesk 800 G1 SFF 16Gb RAM & https://www.jacob.de/produkte/Intel-Ethernet-Server-Adapter-I350-T4-I350T4V2-artnr-2094756.html #i350t4 -
Cyber threats are becoming more advanced every day, making it crucial to stay informed and prepared. Social engineering and deepfake attacks are two significant concerns that require robust security measures.
https://linuxexpert.org/cybersecurity-rising-threats-and-how-to-protect-against-them/
#Cybersecurity #SocialEngineering #DeepfakeAttacks #ZeroTrust #ContinuousMonitoring #LinuxSecurity #NetworkSecurity #OpenSourceSecurity #MFA #SecurityTraining #IntrusionDetection #OSSEC #Suricata #OpenLDAP #LeastPrivilege #GnuPG #ITSecurity #linux