home.social

#threathunting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threathunting, aggregated by home.social.

  1. Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.

    The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
    Full breakdown here: graylog.org/post/suricata-ids-
    #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity

  2. CISA Deploys Cyber Decoys to Disrupt Attackers

    CISA is shaking things up in the cybersecurity world with a clever tactic: deploying cyber decoys to lure in and expose attackers, making it easier to detect and respond to threats. By using these low-cost, high-impact decoys, critical infrastructure owners and operators can stay one step ahead of intruders.

    osintsights.com/cisa-deploys-c

    #CyberDecoys #Cisa #EmergingThreats #DetectionAndResponse #ThreatHunting