#suricata

19 posts · Last used 13d

CrowdSec + Suricata: do you actually need both for Linux servers? 🤔 They both detect threats, but they solve different problems. We break down where each fits, when to use them together, and why enforcement matters more than simply collecting alerts. 👉 Read the full article: https://www.crowdsec.net/blog/crowdsec-vs-suricata-do-you-need-both-for-linux-servers #Linux #IDS #IPS #cybersecurity #suricata
0
0
1
0
took some doing, but here is proof of concept for Suricata. I wrote two rules - one looking for example.com in TLS SNI data, and another looking for it in http.host field of the HTTP header. This confirms that suricata is getting both encrypted and unencrypted traffic. #suricata #nsm #TLSDecrypt
4
2
2
0
Great news! We’ve been invited to do a 4 hour workshop training for Security BSides Las Vegas 2026! Join us for “Engineering the Hunt: Developing AI SKILLs for Network Security Monitoring” with Peter Manev, Jeff Lucovsky & Lukas Sismis on August 3rd at 3pm PST. Learn more: bsideslv.org #Suricata #BSidesLasVegas
1
0
1
0
release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring
1
0
3
0
SuriCon is community-funded - sponsorships keep it self-sustaining. Spots remain from the $800 Mob tier (for individual super fans) up to Community Partner ($10K). And our last exclusive slot: Welcome Reception Sponsor ($6K). Secure your spot: suricon.net/sponsorships/ #Suricata #SuriCon #SuriCon2026
0
0
1
0
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own. The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding. Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/ #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity
1
0
0
0
Hey there, I'm on vacation until the 13th, and probably won't be answering social media much until then. If you have any questions for me, feel free to DM me and I'll give it best effort to answer the following Monday. If you have #malware , #sandbox runs, proof of concept #Exploits , and/or want to see #Snort and/or #Suricata rules for said bad things, leave me a DM, @ me, or if you want things looked at more quickly, contact my co-workers through community.emergingthreats.net . I promise the forums get checked very frequently, and we respond to inquiries quite fast. Until then, cheers! and feel free to leave some birthday wishes or shitposts for me to come back to.
2
4
0
0
Major releases take time. They evolve through development, testing, review, feedback, and real deployment needs. If you use #Suricata today, what should be improved or carried forward toward Suricata 9? Share your thoughts now, or bring them to #SuriCon .
6
4
4
0
Bueno, parece que los ataques de scraping estan cesando o por lo menos el bloqueo del firewall está siendo exitoso y permite más o menos respirar al servidor. Como últimas novedades, ayer terminé de migrar las listas de bloque de Alias y reglas manuales, a listas dinámicas automáticas, aparte de que agregué algunas más que estaban faltando. Las listas dinámicas corren en bajo nivel en el firewall y aprovechan el motor pf packet filter que hace famoso a pf-Sense. Eso quedó lujo y los tests que corrí muestran que el firewall ni se despeina filtrando unas 50k IPs. También en el proxy Nginx dejé corriendo CrowdSec junto con Fail2ban y ahora ambos alimentan de IPs maliciosas que detectan, al pf-Sense que las bloquea para toda la red. CrowdSec fue sugerencia de @j3j5@mastodon.uy y luego de @ElenaMusk@tuiter.rocks y valió la pena porque solo lo conocía de nombre, nunca lo había probado, muchas gracias por el apoyo y la ayuda. Pensé que era similar a Fail2ban pero se nota que es mucho más moderno y agarra IPs que Fail2ban no agarra, justamente por el análisis decomportamiento. Yo creo que estamos bastante bien ahora, con pfBlocker-NG, Suricata y DNSBL corriendo en pf-Sense y Fail2ban y CrowdSec corriendo en el proxy que a su vez retroalimenta a pf-Sense. #pfsense #crowdsec #dnsbl #suricata #seguridad #undernet #mastodon
11
5
5
0
You've seen all posts