took some doing, but here is proof of concept for Suricata. I wrote two rules - one looking for example.com in TLS SNI data, and another looking for it in http.host field of the HTTP header. This confirms that suricata is getting both encrypted and unencrypted traffic. #suricata #nsm #TLSDecrypt
#nsm
1 posts · Last used 14d
You've seen all posts