home.social

#suricata — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #suricata, aggregated by home.social.

  1. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  2. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  3. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  4. CW: release notes for Malcolm v26.08.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.08.0 adds a NetBox purdue_zone custom field that propagates ICS/OT network zone classifications to devices, prefixes, and virtual machines (and automatically to autopopulated devices from their containing prefix); Raspberry Pi 5 support for Hedgehog Linux; and, configurable Strelka scanner and disabled-Suricata-SID lists. This release also fixes five security vulnerabilities: an nginx RBAC bypass via percent-encoded, case-varied, or slash-doubled request paths; an archive-bomb bypass affecting raw-stream and lzip-compressed uploads; a case-variant path bypass of the nginx auth gate exposing the Arkime backend to forged identity headers; an Arkime authentication gap on sensor nodes that fell back to digest instead of enforcing s2s; and a CSRF vulnerability in the kiosk /script_call endpoint allowing unauthenticated data-destructive operations. Arkime, Zeek, NetBox, OpenSearch, OpenSearch Dashboards, Logstash, Filebeat, Keycloak, and other components have been updated as well. Several other bug fixes and general improvements are also included.

    github.com/idaholab/Malcolm/co

    See the Release Notes for the full set of new features, enhancements, bug fixes, and component version updates.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  5. Big week for #Suricata in Vegas 🎰

    - Peter, Jeff & Lukas ran a hands-on workshop on AI SKILLs for network security monitoring @ #BSidesLV
    - Broke down Suricata 8 @ #BlackHatUSA Arsenal
    - Lukas Sismis won the Telecom Village CTF @ #DEFCON34

    And gave out all the #Suricata swag - Send us pix!

  6. 🚀 SO-CRATES 1.1 is here — now with Light Mode! ☀️

    The tool you loved as OhMyPCAP keeps getting better.

    Your all-in-one Docker/Podman container for rapid analysis of PCAPs, logs, and binaries just leveled up.

    ✅ PCAPs → Suricata alerts, rich metadata, ASCII transcripts, stream carving
    ✅ Logs → Sigma alerts + originals
    ✅ Binaries → YARA matches + metadata

    Perfect for air-gapped environments, malware analysis, IR, threat hunting, forensics & teaching.

    What’s your preference?
    → Dark Mode 🖤
    → Light Mode ☀️
    → Why not both?
    → Needs glorious 4-color CGA option lol
    Comment below!

    #DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma #DarkMode #LightMode

  7. 🚀Introducing SO-CRATES 1.0 — Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

    SO-CRATES is a single container image for analyzing pcap files, log files, and binary files. It was formerly known as OhMyPCAP.

    Here's what you can do with SO-CRATES:
    ✅analyze pcap files and then review Suricata alerts, metadata, and extracted files
    ✅import log files and then review Sigma alerts and the original log entries
    ✅import binary files and then review YARA matches and file metadata

    All of this runs in a single Docker/Podman container — perfect for air-gapped environments, malware analysis, incident response, threat hunting, forensics & teaching.

    Who’s trying it out? Drop a ❤️ and reply with your main use case!

    #DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma

    @securityonion
    @chrissanders88

  8. 🚀 OhMyPCAP 4.0.0 is HERE!

    The ultimate FOSS PCAP analyzer just got a massive upgrade for deeper file intelligence.

    New in v4.0:
    • Upgraded to YARA Forge Full ruleset — more comprehensive malware & threat detection
    • Exiftool + rich file metadata analysis — get more file information even if there are no YARA matches

    All the power you love is still here:
    Suricata alerts, file alerts, Sankey diagrams, full-text search, ASCII transcripts, hexdumps, stream carving + single Docker/Podman container (perfect for air-gapped or quick spins).

    Ideal for malware analysis, incident response, threat hunting, forensics & teaching.

    Who’s pulling this version right now? Drop a ❤️+ reply with your main use case (malware samples? CTFs? real-world incidents? teaching?)

    #PCAP #DFIR #Cybersecurity #Infosec #BlueTeam #ThreatHunting #Suricata #YARA #MalwareAnalysis

    @chrissanders88 @lennyzeltser

  9. Background:
    for my I set up in and have a functioning system with a dashboard (#flake info here codeberg.org/adingbatponder/re ).
    Preliminary plan:
    I now want to go to and system that blocks threats detected. Current plan is with but there is no GUI for that it seems, and it is a bit clunky and black-boxy.
    Question: What are the more user-friendly options for an IPS front-end / GUI ?
    Thanks!

  10. Made a transparent network bridge on which sits between router & switch, monitoring traffic for , and capture and analyze packets → ships with ingest pipeline → setup of dashboard to visualise data is defined in flake itself so using the flake will give the same dashboard. details here codeberg.org/adingbatponder/re
    Hardware: HP EliteDesk 800 G1 SFF 16Gb RAM & jacob.de/produkte/Intel-Ethern

  11. During the #SharkBytes session at #SharkFest conference I had an opportunity to present a lightning talk about my pet project called IDS Lab.
    It is a lab infrastructure deployable as docker containers, which simulates the small company network.

    The IDS Lab consists of web webserver with #Wordpress, #MySQL database, #Linux desktop with RDP, the #WireGuard VPN for "remote" workers and for connecting another virtual or physical machines into the lab network.
    This part of infrastructure can be used for attack simulations.

    There are additional components for playing with logs and detections, too: #Fluentbit, #Suricata and #OpenObserve as lightweight SIEM.

    In the #SIEM we already have preconfgured dashboards for alerts, netflows, web logs and logs from windows machines, if present.

    Using the provided setup script, the whole lab can be up and running in up to 5 minutes. For more info, please check my GitHub repository with the IDS Lab:

    github.com/SecurityDungeon/ids

    #sf24eu #wireshark @wireshark