home.social

#suricata — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #suricata, aggregated by home.social.

  1. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  2. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  3. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  4. I seem to be seeing that the addresses of some legit are being included in some of the lists used by to IP addresses, and so they might well end up blocked by your or
    in particular e.g. database might be flagging mesh nodes
    Please take steps for port 4242
    normally used by to not let bad data spoil the

  5. Background:
    for my I set up in and have a functioning system with a dashboard (#flake info here codeberg.org/adingbatponder/re ).
    Preliminary plan:
    I now want to go to and system that blocks threats detected. Current plan is with but there is no GUI for that it seems, and it is a bit clunky and black-boxy.
    Question: What are the more user-friendly options for an IPS front-end / GUI ?
    Thanks!

  6. Made a transparent network bridge on which sits between router & switch, monitoring traffic for , and capture and analyze packets → ships with ingest pipeline → setup of dashboard to visualise data is defined in flake itself so using the flake will give the same dashboard. details here codeberg.org/adingbatponder/re
    Hardware: HP EliteDesk 800 G1 SFF 16Gb RAM & jacob.de/produkte/Intel-Ethern

  7. The deadline is fast approaching! Have interesting ideas the #Suricata InfoSec community might want to hear? Share them at #SuriCon2024! Apply today to talk at our upcoming SuriCon. 📣 Submit by June 15th! suricon.net/call-for-talks/

    #Call4Talks #SuriCon

  8. Attention! 📢 We are looking for Suricata users, developers, product managers, integrators, researchers, and more, interested in sharing their innovative work with Suricata’s global open-source community at this upcoming SuriCon. Our call for talks is now open! #SuriCon2024 #Suricata #Call4Talks

    Working on something interesting? Submit today! suricon.net/call-for-talks/