home.social

#suricata — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #suricata, aggregated by home.social.

  1. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  2. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  3. i wanted to try out the new #astra model from #openai so i worked back and forth with it on a janky little script to convert eve.json from #suricata to #mitre ILF, then i had it generate a pile of tests: github.com/cmhobbs/suricata2ilf

    it's... fine? i guess? doesn't seem like a wild improvement over sol to me. much how #fable and #opus 5 didn't feel like terribly useful leaps to me.

    a lot of this #ai stuff feels like mega-hype and i feel crazy when it doesn't work for me.

  4. CW: release notes for Malcolm v26.08.0, a network traffic analysis tool suite for network security monitoring

    Malcolm v26.08.0 adds a NetBox purdue_zone custom field that propagates ICS/OT network zone classifications to devices, prefixes, and virtual machines (and automatically to autopopulated devices from their containing prefix); Raspberry Pi 5 support for Hedgehog Linux; and, configurable Strelka scanner and disabled-Suricata-SID lists. This release also fixes five security vulnerabilities: an nginx RBAC bypass via percent-encoded, case-varied, or slash-doubled request paths; an archive-bomb bypass affecting raw-stream and lzip-compressed uploads; a case-variant path bypass of the nginx auth gate exposing the Arkime backend to forged identity headers; an Arkime authentication gap on sensor nodes that fell back to digest instead of enforcing s2s; and a CSRF vulnerability in the kiosk /script_call endpoint allowing unauthenticated data-destructive operations. Arkime, Zeek, NetBox, OpenSearch, OpenSearch Dashboards, Logstash, Filebeat, Keycloak, and other components have been updated as well. Several other bug fixes and general improvements are also included.

    github.com/idaholab/Malcolm/co

    See the Release Notes for the full set of new features, enhancements, bug fixes, and component version updates.

    Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

    Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

    Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

    As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

    #Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

  5. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  6. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  7. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  8. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  9. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  10. Antiphishing Detection Update

    A new threat intelligence cycle has been processed by the Antiphishing pipeline.

    Current detection coverage:

    • 6,007,331 HTTP signatures
    • 243,098 TLS signatures
    • 243,098 DNS signatures
    • 6,493,527 total generated signatures

    The pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.

    The ruleset is available through the suricata-update ecosystem.

    Detection is only useful when intelligence can reach the enforcement layer.

    Feeds → IOC processing → Rule generation → Suricata → Detection

    Run julioliraup/Antiphishing on @suricata
    github.com/julioliraup/Antiphi
    #Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity

  11. Antiphishing Detection Update

    A new threat intelligence cycle has been processed by the Antiphishing pipeline.

    Current detection coverage:

    • 6,007,331 HTTP signatures
    • 243,098 TLS signatures
    • 243,098 DNS signatures
    • 6,493,527 total generated signatures

    The pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.

    The ruleset is available through the suricata-update ecosystem.

    Detection is only useful when intelligence can reach the enforcement layer.

    Feeds → IOC processing → Rule generation → Suricata → Detection

    Run julioliraup/Antiphishing on @suricata
    github.com/julioliraup/Antiphi
    #Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity

  12. Antiphishing Detection Update

    A new threat intelligence cycle has been processed by the Antiphishing pipeline.

    Current detection coverage:

    • 6,007,331 HTTP signatures
    • 243,098 TLS signatures
    • 243,098 DNS signatures
    • 6,493,527 total generated signatures

    The pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.

    The ruleset is available through the suricata-update ecosystem.

    Detection is only useful when intelligence can reach the enforcement layer.

    Feeds → IOC processing → Rule generation → Suricata → Detection

    Run julioliraup/Antiphishing on @suricata
    github.com/julioliraup/Antiphi
    #Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity

  13. Antiphishing Detection Update

    A new threat intelligence cycle has been processed by the Antiphishing pipeline.

    Current detection coverage:

    • 6,007,331 HTTP signatures
    • 243,098 TLS signatures
    • 243,098 DNS signatures
    • 6,493,527 total generated signatures

    The pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.

    The ruleset is available through the suricata-update ecosystem.

    Detection is only useful when intelligence can reach the enforcement layer.

    Feeds → IOC processing → Rule generation → Suricata → Detection

    Run julioliraup/Antiphishing on @suricata
    github.com/julioliraup/Antiphi
    #Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity

  14. Antiphishing Detection Update

    A new threat intelligence cycle has been processed by the Antiphishing pipeline.

    Current detection coverage:

    • 6,007,331 HTTP signatures
    • 243,098 TLS signatures
    • 243,098 DNS signatures
    • 6,493,527 total generated signatures

    The pipeline transforms phishing indicators from community intelligence sources into Suricata detection signatures across DNS, TLS and HTTP.

    The ruleset is available through the suricata-update ecosystem.

    Detection is only useful when intelligence can reach the enforcement layer.

    Feeds → IOC processing → Rule generation → Suricata → Detection

    Run julioliraup/Antiphishing on @suricata
    github.com/julioliraup/Antiphi
    #Suricata #ThreatIntelligence #DetectionEngineering #Phishing #OpenSource #CyberSecurity

  15. Background:
    for my I set up in and have a functioning system with a dashboard (#flake info here codeberg.org/adingbatponder/re ).
    Preliminary plan:
    I now want to go to and system that blocks threats detected. Current plan is with but there is no GUI for that it seems, and it is a bit clunky and black-boxy.
    Question: What are the more user-friendly options for an IPS front-end / GUI ?
    Thanks!

  16. Made a transparent network bridge on which sits between router & switch, monitoring traffic for , and capture and analyze packets → ships with ingest pipeline → setup of dashboard to visualise data is defined in flake itself so using the flake will give the same dashboard. details here codeberg.org/adingbatponder/re
    Hardware: HP EliteDesk 800 G1 SFF 16Gb RAM & jacob.de/produkte/Intel-Ethern