#Suricata 4.1 is out with default Rust support, adding SMB, DHCP, TLS 1.3 and many more protocol additions and improvements.
Some other additions: compressed pcap logging, community flow id, new compact DNS EVE format, filestore v2.
Check: https://t.co/gyaO8FODhf #ids#ips
A few words about the Buffered Traffic Capture process that may be useful. Just enjoy it and ask if you want to play with it. @owlhnet#bufferedtrafficcapture#networkids#nhids https://t.co/OK131LZpGT
Better than traffic capture after an incident, start recording traffic before incident happens. @OwlHnet#Buffered#Traffic#Capture (#BTC)
- Select targets to monitor
- Define buffer to store pre-incident traffic
- Specify Incident Indicator Trigger
- Pre and Post capture
@wazuh and @owlhnet - NHIDS implementation
- Network IDS traffic analysis and alert
โ
- Using eBPF at host for
-> #OwlH - Host Traffic Capture and related service details
-> #Wazuh - Host IDS alerts with process detail
โฌ๏ธโฌ๏ธ
- Network IDS Alert enrichment with Process details
Trace TCP traffic in an instance and find what process (PID and name) is using it by using #eBPF, #BCC tools. The tool is modified to export in json format to simplify management. Will be really useful to enrich #Suricata_IDS and #Bro_IDS alerts. To be continued
#Wazuh 3.2.4 has just been released. A comprehensive security monitoring platform based on #OSSEC, #OpenSCAP and #Elasticsearch. Great for intrusion detection, compliance and incident response. Completely free open source. More info at https://t.co/pc4pl6GyZy
Another @owlhnet ๐ฆ step: Integrating #Bro_IDS in @wazuh: ๐ย 1.-#Bro_IDS events output to JSON and event enrichment ๐ 2.- Secure transport by @wazuh ๐ 3.- @owlhnet#Bro_IDS rules for @wazuh ๐ 4.- JSON tuning for @wazuh index on #ELK. Et voilร https://t.co/8YA0Rk3Q1J
job done! Using #suricata_ids to analyze traffic from multiple #AWS based instances and integrate detected alerts in @wazuh. Capture traffic with #tcpdump as software TAP #vTAP and use #ansible helping with process orchestration #NIDS_Management https://t.co/oWQLC4FrwA
#OwlH. Unified #IDS Management.
An open source tool to easily Visualize and Manage #Suricata_IDS and #BroIDS at scale. Big-Data, Incident Response.., Dashboards, Cloud Network IDS support and on-demand capture ...
https://t.co/HWRt3AiVfe
(Promete y mucho. Seguimiento, si o si.)
Great @wazuh 2018 kick-off. Thanks, guys for such amazing time this week. Impressive team building a great product for the big security market. And thanks for letting me introduce you the @owlhnet project. #hids#nids_management
Over 1 TB of #PCAP files from the @wrccdc#CDX have been released online thanks to @spiceywasabi and @disturbedmime. The WRCCDC dataset is now linked from our PCAP repository list.
https://t.co/rAvYVoDQct
@yashar6909@wazuh Thanks for your feedback @yashar6909, We are in PoC mode right now. So, if you want to play just say hellowl!. check our https://t.co/TleKlHUMad site too.