BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//Suricata - ECPv6.17.3//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-ORIGINAL-URL:https://suricata.io
X-WR-CALDESC:Events for Suricata
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:America/New_York
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20200308T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20201101T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20210314T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20211107T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20220313T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20221106T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20230312T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20231105T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20240310T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20241103T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20250309T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20251102T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20260308T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20261101T060000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;VALUE=DATE:20251119
DTEND;VALUE=DATE:20251122
DTSTAMP:20250714T135459Z
CREATED:20250714T135459Z
LAST-MODIFIED:20250714T135459Z
UID:8068-1763510400-1763769599@suricata.io
SUMMARY:SuriCon 2025 Montreal
DESCRIPTION:Get ready\, Suricata super fans and open-source security pros—SuriCon2025 is coming to Montreal\, and it’s shaping up to be another unforgettable gathering of the global Suricata community! \nThis year\, we’re also celebrating 15 years of the Open Information Security Foundation (OISF)—the nonprofit steward of Suricata and a driving force behind protecting the true open source of this powerful detection engine. \nWhether you’re a long-time user\, developer\, researcher\, or just starting to explore Suricata\, this is your chance to connect with fellow practitioners\, hear what’s next for the project\, and learn directly from the team building and tuning the engine behind so many critical security systems. \nJoin us in one of Canada’s most vibrant and tech-forward cities for three days of sessions\, conversations\, and community-building—and don’t miss the two days of hands-on pre-conference trainings. \nGet your ticket now: https://www.eventbrite.com/e/suricon2025-montreal-canada-tickets-1299841513959
URL:https://suricata.io/event/suricon-2025-montreal/
LOCATION:Delta Hotels Montreal\, 475 President-Kennedy Avenue\, Montreal\, Québec\, H3A 1J7\, Canada
CATEGORIES:Conference
ORGANIZER;CN="OISF":MAILTO:suricon@oisf.net
END:VEVENT
BEGIN:VEVENT
DTSTART;VALUE=DATE:20251117
DTEND;VALUE=DATE:20251119
DTSTAMP:20250714T134328Z
CREATED:20250714T133824Z
LAST-MODIFIED:20250714T134328Z
UID:8056-1763337600-1763510399@suricata.io
SUMMARY:Threat Hunting with Suricata... Learning the latest in Suricata 8!
DESCRIPTION:Sharpen your threat hunting skills with this immersive\, hands-on training led by Suricata experts Peter Manev and the OISF team. Over two days\, you’ll learn how to detect and investigate real-world attacks using Suricata\, Arkime\, Kibana\, Splunk\, and more. From structured hunts to malware traffic analysis and advanced detection techniques\, this course is designed for defenders ready to go beyond alerts and uncover hidden threats. Bring your laptop\, your curiosity\, and get ready to hunt. \nLed by OISF’s own Peter Manev and members of the OISF development team. \nRegister for this training with a bundled SuriCon 2025 ticket now: https://www.eventbrite.com/e/suricon2025-montreal-canada-tickets-1299841513959 \nMore about the training: https://suricon.net/trainings/
URL:https://suricata.io/event/threat-hunting-with-suricata-learning-the-latest-in-suricata-8/
LOCATION:Delta Hotels Montreal\, 475 President-Kennedy Avenue\, Montreal\, Québec\, H3A 1J7\, Canada
CATEGORIES:Training
ORGANIZER;CN="OISF":MAILTO:suricon@oisf.net
END:VEVENT
BEGIN:VEVENT
DTSTART;VALUE=DATE:20251117
DTEND;VALUE=DATE:20251119
DTSTAMP:20250714T134951Z
CREATED:20250714T133541Z
LAST-MODIFIED:20250714T134951Z
UID:8053-1763337600-1763510399@suricata.io
SUMMARY:Advanced Deployment & Tuning... Dive into the Deep End!
DESCRIPTION:Take your Suricata skills to the next level with this advanced\, hands-on training led by Eric Leblond and the OISF development team. Over two intensive days\, you’ll dive deep into deployment strategies\, performance tuning\, file extraction\, protocol analysis\, and Suricata 8’s newest features. Designed for experienced users\, this course equips you to build high-performance\, high-visibility deployments in on-prem\, virtual\, or cloud environments. Come with questions—leave with solutions and serious tuning skills. \nLed by long-time Suricata community member and OISF board member Eric Leblond\, along with members of the OISF development team. \nRegister for this training with a bundled SuriCon 2025 ticket now: https://www.eventbrite.com/e/suricon2025-montreal-canada-tickets-1299841513959 \nMore about the training: https://suricon.net/trainings/ \n 
URL:https://suricata.io/event/advanced-deployment-tuning-dive-into-the-deep-end/
LOCATION:Delta Hotels Montreal\, 475 President-Kennedy Avenue\, Montreal\, Québec\, H3A 1J7\, Canada
CATEGORIES:Training
ORGANIZER;CN="OISF":MAILTO:suricon@oisf.net
END:VEVENT
BEGIN:VEVENT
DTSTART;VALUE=DATE:20251117
DTEND;VALUE=DATE:20251119
DTSTAMP:20250714T134802Z
CREATED:20250714T130058Z
LAST-MODIFIED:20250714T134802Z
UID:8048-1763337600-1763510399@suricata.io
SUMMARY:Suricata Rule Writing... Back by Popular Demand!
DESCRIPTION:Ready to move from network observer to threat hunter? This hands-on Suricata rule writing course will teach you how to craft powerful detection rules using real-world examples\, practical exercises\, and the latest features in Suricata 8. Led by Suricata community experts David Wharton and Travis Green\, you’ll learn to detect sophisticated threats\, minimize false positives\, and fine-tune performance. No prior rule writing experience required—just a solid grasp of network fundamentals and a desire to level up your detection skills. \nLed by Suricata community members\, David Wharton and Travis Green. \nRegister for this training with a bundled SuriCon 2025 ticket now: https://www.eventbrite.com/e/suricon2025-montreal-canada-tickets-1299841513959 \nMore about the training: https://suricon.net/trainings/
URL:https://suricata.io/event/suricata-rule-writing-back-by-popular-demand/
LOCATION:Delta Hotels Montreal\, 475 President-Kennedy Avenue\, Montreal\, Québec\, H3A 1J7\, Canada
CATEGORIES:Training
ORGANIZER;CN="OISF":MAILTO:suricon@oisf.net
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20250429T103000
DTEND;TZID=America/New_York:20250429T113000
DTSTAMP:20250422T155637Z
CREATED:20250422T155553Z
LAST-MODIFIED:20250422T155637Z
UID:7937-1745922600-1745926200@suricata.io
SUMMARY:Webinar -  Where to find free and public malware pcaps for Suricata
DESCRIPTION:In this session\, Suricata long-time contributor and Stamus Networks’ co-founder Peter Manev will show the ropes for finding resources of free and publicly available malware pcaps that one can use for many different purposes. \nFor practical exercises\, testing\, tuning\, showcasing\, and more\, having good pcaps is always important. \nRegister via Zoom: https://us02web.zoom.us/webinar/register/WN_pxm1a0e2TcepAyGc8JZcyQ
URL:https://suricata.io/event/webinar-where-to-find-free-and-public-malware-pcaps-for-suricata/
LOCATION:Virtual
ORGANIZER;CN="OISF":MAILTO:suricon@oisf.net
END:VEVENT
BEGIN:VEVENT
DTSTART;VALUE=DATE:20241112
DTEND;VALUE=DATE:20241116
DTSTAMP:20240206T182046Z
CREATED:20240206T181734Z
LAST-MODIFIED:20240206T182046Z
UID:7573-1731434400-1731693599@suricata.io
SUMMARY:SuriCon2024 - Madrid\, Spain
DESCRIPTION:Don’t miss out SuriCon2024!\nSuriCon2024 will be Suricata’s 10th annual conference\, this is your opportunity to meet the team in person\, discuss and share all things Suricata!\nRegister now and get a 20% discount in one of our pre-conference training sessions.
URL:https://suricata.io/event/suricon2024-madrid-spain/
LOCATION:RIU Plaza de Espana\, C. Gran Via\, 84\, Centro\, Madrid\, 28013\, Spain
CATEGORIES:Conference
ORGANIZER;CN="OISF":MAILTO:suricon@oisf.net
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20241111T020000
DTEND;TZID=America/New_York:20241112T110000
DTSTAMP:20240207T154547Z
CREATED:20240207T154547Z
LAST-MODIFIED:20240207T154547Z
UID:7594-1731290400-1731409200@suricata.io
SUMMARY:Advanced Deployment & Configuration [SuriCon2024 PRE-CONFERENCE TRAINING]
DESCRIPTION:Start your SuriCon week early! \nJoin our trainers in person for this Advanced Deployment & Configuration training course focused on Suricata 7\, and learn how to maximize the visibility that Suricata can provide into your network\, in a variety of deployment\, usage\, and integration scenarios. \nDelivered by Suricata developers\, this 2-day user training is held the same week as SuriCon2024 – join us for both and receive a 20% discount on this training! \nTickets and more information: https://www.eventbrite.com/e/suricon2024-advanced-deployment-configuration-pre-conference-training-tickets-816787010937
URL:https://suricata.io/event/advanced-deployment-configuration-suricon2024-pre-conference-training/
LOCATION:RIU Plaza de Espana\, C. Gran Via\, 84\, Centro\, Madrid\, 28013\, Spain
CATEGORIES:Training
ORGANIZER;CN="OISF":MAILTO:suricon@oisf.net
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20241111T020000
DTEND;TZID=America/New_York:20241112T110000
DTSTAMP:20240207T152431Z
CREATED:20240207T152431Z
LAST-MODIFIED:20240207T152431Z
UID:7586-1731290400-1731409200@suricata.io
SUMMARY:Intrusion Analysis & Threat Hunting [SuriCon2024 PRE-CONFERENCE TRAINING]
DESCRIPTION:Start your SuriCon week early! \nJoin our trainers in person for this intrusion analysis & threat-hunting training course focused on Suricata 7 to improve your infosec and cybersec toolkit. \nDelivered by Suricata developers\, this 2-day user training is held the same week as SuriCon2024 – join us for both and receive a 20% discount on this training! \nMore information and tickets: https://www.eventbrite.com/e/suricon2024-intrusion-analysis-threat-hunting-pre-conference-training-tickets-816838434747
URL:https://suricata.io/event/intrusion-analysis-threat-hunting-suricon2024-pre-conference-training/
LOCATION:RIU Plaza de Espana\, C. Gran Via\, 84\, Centro\, Madrid\, 28013\, Spain
CATEGORIES:Training
ORGANIZER;CN="OISF":MAILTO:suricon@oisf.net
END:VEVENT
BEGIN:VEVENT
DTSTART;VALUE=DATE:20231107
DTEND;VALUE=DATE:20231110
DTSTAMP:20230914T174431Z
CREATED:20230914T171541Z
LAST-MODIFIED:20230914T174431Z
UID:7420-1699315200-1699574399@suricata.io
SUMMARY:SuriCon2023 – Virtual
DESCRIPTION:SuriCon2023 will be from 16:30 – 18:30 CET each day.
URL:https://suricata.io/event/suricon2023-virtual/
LOCATION:Virtual
CATEGORIES:Conference
ATTACH;FMTTYPE=image/jpeg:https://suricata.io/wp-content/uploads/2023/09/23-SuriCon-virtual.final-justheadphones.jpg
END:VEVENT
BEGIN:VEVENT
DTSTART;VALUE=DATE:20221109
DTEND;VALUE=DATE:20221112
DTSTAMP:20220729T173043Z
CREATED:20220729T170857Z
LAST-MODIFIED:20220729T173043Z
UID:6963-1667952000-1668211199@suricata.io
SUMMARY:SuriCon2022 - ATHENS\, GREECE
DESCRIPTION:
URL:https://suricata.io/event/suricon2022-athens-greece/
LOCATION:Grand Hyatt Athens\, 115 Syngrou Avenue\, Athens\, 11745\, Greece
CATEGORIES:Conference
ATTACH;FMTTYPE=image/jpeg:https://suricata.io/wp-content/uploads/2021/05/SuriCon-gray-web.jpg
END:VEVENT
BEGIN:VEVENT
DTSTART;VALUE=DATE:20221107
DTEND;VALUE=DATE:20221109
DTSTAMP:20220729T173543Z
CREATED:20220729T170855Z
LAST-MODIFIED:20220729T173543Z
UID:6962-1667779200-1667951999@suricata.io
SUMMARY:Intrusion Analysis & Threat Hunting [PRE-CONFERENCE TRAINING - SuriCon2022]
DESCRIPTION:
URL:https://suricata.io/event/intrusion-analysis-threat-hunting-pre-conference-training-suricon2022/
LOCATION:Grand Hyatt Athens\, 115 Syngrou Avenue\, Athens\, 11745\, Greece
CATEGORIES:Training
END:VEVENT
BEGIN:VEVENT
DTSTART;VALUE=DATE:20221107
DTEND;VALUE=DATE:20221109
DTSTAMP:20220729T173743Z
CREATED:20220729T170853Z
LAST-MODIFIED:20220729T173743Z
UID:6961-1667779200-1667951999@suricata.io
SUMMARY:Advanced Deployment & Configuration [PRE-CONFERENCE TRAINING - SuriCon2022]
DESCRIPTION:
URL:https://suricata.io/event/advanced-deployment-configuration-pre-conference-training-suricon2022/
LOCATION:Grand Hyatt Athens\, 115 Syngrou Avenue\, Athens\, 11745\, Greece
CATEGORIES:Training
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20221012T110000
DTEND;TZID=America/New_York:20221012T120000
DTSTAMP:20221004T212128Z
CREATED:20221003T163650Z
LAST-MODIFIED:20221004T212128Z
UID:7100-1665572400-1665576000@suricata.io
SUMMARY:Hands On Session: Detect Lateral Movement in Microsoft Environment with Suricata (Part 2)
DESCRIPTION:Suricata is the world-renowned IDS / IPS and NSM engine. It is capable of generating a combined log stream from separate information elements\, including network protocol events\, alerts\, PCAP files (full packet capture)\, and extracted files as it sniffs live network traffic or sits inline. \nSuricata produces over 25 different types of log data\, including protocol and decoding anomalies\, alerts\, and many other network transaction protocol events. Each of the events produced by Suricata has its own type. Two of those log types are SMB and DCERPC. These are produced by Suricata based on its native auto protocol parsing and logging capability.  \nAs fundamental elements of the Microsoft Windows and Active Directory infrastructure\, various versions of the SMB/DCERPC protocols are natively used by enterprises of all sizes.  \nUnfortunately these are often used by threat actors for lateral movement once a breach beachhead has been established in the organization.This is where the Suricata event type SMB and DCERPC logs become very helpful in hunting scenarios. \nIn this 3-part webinar series\, we aim to take a thorough hands-on approach to show you how to use Suricata’s SMB and DCERPC logs for lateral detection.  \nThe series covers hunting approaches with pure network transaction data and explains where\, how\, and when it makes sense to write a signature for a specific use case. \nPart 2 will concentrate on creating and reviewing some useful visualizations for lateral detection hunting based on the SMB and DCERPC protocol data that Suricata produces. This will be a hands-on review of specific cases. \nRegister Here! \nMissed Part 1? No problem – view it here!
URL:https://suricata.io/event/hands-on-detect-lateral-movement-in-microsoft-environment-with-suricata-part-2/
LOCATION:Québec
CATEGORIES:Webinar
ATTACH;FMTTYPE=image/jpeg:https://suricata.io/wp-content/uploads/2022/10/Lateral-Movement-Part-2.jpg
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220525T100000
DTEND;TZID=America/New_York:20220525T110000
DTSTAMP:20220502T175004Z
CREATED:20220426T230946Z
LAST-MODIFIED:20220502T175004Z
UID:6781-1653472800-1653476400@suricata.io
SUMMARY:Webinar - Suricata Metadata Analysis and Threat Hunting with CrystalEye XDR
DESCRIPTION:Suricata has the ability to output alerts\, anomalies\, metadata\, file info and protocol-specific records through JSON EVE output. In this webinar\, we’ll explore how we can use Suricata event data for threat detection and prevention by enriching\, processing and logging EVE JSON output to MongoDB in real-time. We will also analyze threat hunting reports with correlation of Suricata metadata and hunt through traffic with CrystalEye XDR. \nOur Speaker \nVagisha is a security software engineer working with Red Piranha developing advanced security products like IDPS rule management system\, network mapping tools and threat hunt reports. In the past\, she has been an Outreachy intern with OISF where she worked on suricata-update. A postgraduate in data analytics\, she also published a couple of research papers including one in IEEE journal. Vagisha has a growing interest in InfoSec\, data driven programming and malware traffic analysis.
URL:https://suricata.io/event/webinar-suricata-metadata-logging-to-mongodb-analyzing-reports-w-crystaleye-xdr/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220525T090000
DTEND;TZID=America/New_York:20220525T090000
DTSTAMP:20220729T173215Z
CREATED:20220729T173215Z
LAST-MODIFIED:20220729T173215Z
UID:7025-1653469200-1653469200@suricata.io
SUMMARY:Suricata Metadata Analysis and Threat Hunting with CrystalEye XDR
DESCRIPTION:
URL:https://suricata.io/event/suricata-metadata-analysis-and-threat-hunting-with-crystaleye-xdr/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220512T160000
DTEND;TZID=America/New_York:20220512T170000
DTSTAMP:20220502T191051Z
CREATED:20220502T191051Z
LAST-MODIFIED:20220502T191051Z
UID:6790-1652371200-1652374800@suricata.io
SUMMARY:Live Event with Pluralsight: Open-Source Security - Analyzing Network Traffic with Suricata
DESCRIPTION:In today’s environment of reduced budgets\, loss of talent\, and more breaches than ever before\, how do you stop the adversary before they are able to compromise your environment? In this livestream we’ll be talking with OISF’s own Josh Stroschein\, and discussing the capabilities of Suricata\, an open-source threat detection engine.  \nJoin us to hear about our awesome new partnership\, learn about how to effectively employ Suricata within your organization\, and get a walkthrough on a new lab where you can get some hands-on practice! Check out our lab! https://app.pluralsight.com/labs/detail/5cb37490-9731-4c67-bb8f-6f0b7b5b9f8a/toc  \nMeet our hosts!\nJosh Stroschein\nDr. Josh Stroschein is an Associate Professor at Dakota State University where he teaches malware analysis\, software exploitation\, reverse engineering\, and penetration testing. Josh also works as a Threat Researcher for HP Wolf Security and is the Director of Training for the Open Information Security Foundation (OISF). Josh has spent years developing security-related courses and is passionate about sharing that knowledge with others all over the world.  \nBrandon DeVault\nBrandon DeVault is an Sr. Security Author focusing on general blue team operations\, incident response\, and threat hunting at Pluralsight. He is also a member of the Florida Air National Guard and works as a threat hunter on a Mission Defense Team (MDT) defending North America’s air tracks. Prior to joining Pluralsight\, Brandon worked with Elastic as an Education Architect creating and delivering security content. He also worked with Special Operations Command where he had two deployments to Afghanistan on deployable communications teams. His experience spans satellite communications\, radio technologies\, system and network administration. Brandon is also passionate about hardware hacking\, soldering\, hiking\, and currently holds the GCIA\, GCED\, and Security+ certifications.
URL:https://suricata.io/event/live-event-with-pluralsight-open-source-security-analyzing-network-traffic-with-suricata/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220512T100000
DTEND;TZID=America/New_York:20220512T110000
DTSTAMP:20220426T230757Z
CREATED:20220426T230757Z
LAST-MODIFIED:20220426T230757Z
UID:6779-1652349600-1652353200@suricata.io
SUMMARY:Hands-On Session: Detect Lateral Movement in Microsoft Environment with Suricata (Part 1)
DESCRIPTION:Suricata is the world-renowned IDS / IPS and NSM engine. It is capable of generating a combined log stream from separate information elements\, including network protocol events\, alerts\, PCAP files (full packet capture)\, and extracted files as it sniffs live network traffic or sits inline. \nSuricata produces over 25 different types of log data\, including protocol and decoding anomalies\, alerts\, and many other network transaction protocol events. Each of the events produced by Suricata has its own type. Two of those log types are SMB and DCERPC. These are produced by Suricata based on its native auto protocol parsing and logging capability.  \nAs fundamental elements of the Microsoft Windows and Active Directory infrastructure\, various versions of the SMB/DCERPC protocols are natively used by enterprises of all sizes.  \nUnfortunately these are often used by threat actors for lateral movement once a breach beachhead has been established in the organization.This is where the Suricata event type SMB and DCERPC logs become very helpful in hunting scenarios. \nIn this 3-part webinar series\, we aim to take a thorough hands-on approach to show you how to use Suricata’s SMB and DCERPC logs for lateral detection.  \nThe series covers hunting approaches with pure network transaction data and explains where\, how\, and when it makes sense to write a signature for a specific use case. \nPart 1 will explain the basics of lateral detection and the data Suricata provides in terms of SMB and DCERPC protocol logging. \nParts 1 and 2 will concentrate exclusively on giving you a baseline understanding and introducing you to hunting with the SMB/DCERPC log data. This includes using different aspects of the MS protocols like UUIDs/DCERPC opnum/versions and similar.  \nIn Part 3\, we will explore different techniques for writing signatures using the latest Suricata features for lateral detection.
URL:https://suricata.io/event/hands-on-session-detect-lateral-movement-in-microsoft-environment-with-suricata-part-1/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220512T090000
DTEND;TZID=America/New_York:20220512T090000
DTSTAMP:20220729T173201Z
CREATED:20220729T173201Z
LAST-MODIFIED:20220729T173201Z
UID:7024-1652346000-1652346000@suricata.io
SUMMARY:Detect Lateral Movement in Microsoft Environment with Suricata (Part 1)
DESCRIPTION:
URL:https://suricata.io/event/detect-lateral-movement-in-microsoft-environment-with-suricata-part-1/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220414T090000
DTEND;TZID=America/New_York:20220414T090000
DTSTAMP:20220729T173201Z
CREATED:20220729T173201Z
LAST-MODIFIED:20220729T173201Z
UID:7023-1649926800-1649926800@suricata.io
SUMMARY:Hands-On: Match on millions of IoCs in Suricata (Thanks to Datasets)!
DESCRIPTION:
URL:https://suricata.io/event/hands-on-match-on-millions-of-iocs-in-suricata-thanks-to-datasets/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220317T100000
DTEND;TZID=America/New_York:20220317T110000
DTSTAMP:20220228T192314Z
CREATED:20220228T182322Z
LAST-MODIFIED:20220228T192314Z
UID:6723-1647511200-1647514800@suricata.io
SUMMARY:Hands-On Session - Get to Know Suricata Language Server with Eric Leblond
DESCRIPTION:Writing signatures for Suricata and other intrusion detection systems (IDS) is considered by many to be a form of art. One of the main reasons is that the rule writer needs to start by examining a network trace to identify patterns that are representative to a threat/behavior without being too broad (to avoid false positives) or too narrow (to avoid being escaped at the first change of a bit in the attack). But the language used to write signatures is the second reason. It is not really expressive and doesn’t have advanced constructs. As a result signatures require complex writing to do things that could appear simple. And there are implicit conventions and structures that must be followed to guarantee correct integration in the detection engine. \nFree registration -> https://www.eventbrite.com/e/hands-on-session-get-to-know-suricata-server-language-with-eric-leblond-tickets-276748481157?ref=estw \nThe open-source Suricata Language Server (SLS) has been developed to solve these problems. SLS is a Language Server Protocol implementation that allows the user to benefit from built-in Suricata diagnostic capabilities when editing rules. SLS provides advanced diagnostics as well as auto-completion. \nIn this webinar\, you will see how SLS can be used and how to make sense of the error messages. You will also discover what Suricata features are used behind the scene to make this possible.
URL:https://suricata.io/event/hands-on-session-get-to-know-suricata-server-language-with-eric-leblond/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220317T090000
DTEND;TZID=America/New_York:20220317T090000
DTSTAMP:20220729T173201Z
CREATED:20220729T173201Z
LAST-MODIFIED:20220729T173201Z
UID:7022-1647507600-1647507600@suricata.io
SUMMARY:Hands-On Session: Get to Know Suricata Language Server with Eric Leblond
DESCRIPTION:
URL:https://suricata.io/event/hands-on-session-get-to-know-suricata-language-server-with-eric-leblond/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220224T090000
DTEND;TZID=America/New_York:20220224T100000
DTSTAMP:20220209T193734Z
CREATED:20220209T193356Z
LAST-MODIFIED:20220209T193734Z
UID:6710-1645693200-1645696800@suricata.io
SUMMARY:WEBINAR - Contributing to Suricata: from test clean-ups to adding new features
DESCRIPTION:Free registration & detailed event description here: https://suri-outreachy-2022.eventbrite.com \nPresented by the Women of Suricata & hosted by our 2021/2022 Outreachy interns Sam & Modupe. This course is a sequel to our 2020/2021 Outreachy intern-led webinar:  A Beginner’s Guide to Adding New Features to Suricata
URL:https://suricata.io/event/webinar-contributing-to-suricata-from-test-clean-ups-to-adding-new-features/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220224T080000
DTEND;TZID=America/New_York:20220224T080000
DTSTAMP:20220729T173201Z
CREATED:20220729T173201Z
LAST-MODIFIED:20220729T173201Z
UID:7021-1645689600-1645689600@suricata.io
SUMMARY:Contributing to Suricata: from test clean-ups to adding new features
DESCRIPTION:
URL:https://suricata.io/event/contributing-to-suricata-from-test-clean-ups-to-adding-new-features/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220113T090000
DTEND;TZID=America/New_York:20220113T100000
DTSTAMP:20220111T183856Z
CREATED:20211229T151828Z
LAST-MODIFIED:20220111T183856Z
UID:6580-1642064400-1642068000@suricata.io
SUMMARY:IcedID Infection Activity: Traffic & Other Indicators with Brad Duncan
DESCRIPTION:Register here\nAbout this event\n\n\nAlso known as Bokbot\, IcedID is one of many families of malware distributed through malicious spam. In this webinar\, Brad reviews two email-based distribution campaigns regularly distributing IcedID since November 2021. He reviews recent examples of IcedID infection traffic and reveals indicators that can be identified through Suricata-based signatures. Many prominent malware families use encrypted HTTPS for post-infection command and control (C2) traffic. This HTTPS traffic often uses self-signed certificates that have unusual or unique certificate issuer data. Understanding this and other traffic characteristics can help security professionals quickly identify IcedID. Our goal is to stop these infections before they lead to more dangerous activity like ransomware. \n\n\n\n\nJoin Brad as he reviews recent examples of IcedID traffic and reveals indicators that can be identified through Suricata-based signatures.\n\n\n\n\nOur Speaker – Brad Duncan \nAfter 21 years in the US Air Force\, Brad transitioned to cyber security in 2010\, and he is a currently a Threat Intelligence Analyst for Palo Alto Networks Unit 42. Brad specializes in analysis of malware infection traffic. He is also a handler for the Internet Storm Center (ISC) and has posted more than 140 diaries athttp://isc.sans.edu/. Brad routinely blogs technical details and analysis of infection traffic at http://www.malware-traffic-analysis.net/\, where he provides traffic analysis exercises and over 1\,600 malware and traffic samples to a growing community of information security professionals.
URL:https://suricata.io/event/icedid-infection-activity-traffic-other-indicators-with-brad-duncan/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220113T080000
DTEND;TZID=America/New_York:20220113T080000
DTSTAMP:20220729T173201Z
CREATED:20220729T173201Z
LAST-MODIFIED:20220729T173201Z
UID:7020-1642060800-1642060800@suricata.io
SUMMARY:IcedID Infection Activity: Traffic & Other Indicators with Brad Duncan
DESCRIPTION:
URL:https://suricata.io/event/icedid-infection-activity-traffic-other-indicators-with-brad-duncan-2/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20220111T130000
DTEND;TZID=America/New_York:20220111T160000
DTSTAMP:20211221T181342Z
CREATED:20211118T204653Z
LAST-MODIFIED:20211221T181342Z
UID:6467-1641906000-1641916800@suricata.io
SUMMARY:FloCon 2022: Intrusion Analysis & Threat Hunting with Open Source Tools
DESCRIPTION:FloCon 2022 – Instructed by Dr. Josh Stroschein & Peter Manev! \n  \nLimited spots available on Day 1 & Day 2: \nTrack III: Intrusion Analysis & Threat Hunting with Open Source Tools (Day 1) \nTrack III: Intrusion Analysis & Threat Hunting with Open Source Tools (Day 2) \n  \nClick here to register for FloCon 2022 on Eventbrite \nClick here to view the FloCon landing page \nFind instructor information & course info here \n  \nCourse description: \nIn today’s threat landscape\, sophisticated adversaries have routinely demonstrated the ability to compromise enterprise networks and remain hidden for extended periods of time. In Intrusion Analysis and Threat Hunting with Open Source Tools\, you will learn how to dig deep into network traffic to identify key evidence that a compromise has occurred\, learn how to deal with new forms of attack\, and develop the skills necessary to proactively search for evidence of new breaches. We will explore key phases of adversary tactics and techniques – from delivery mechanisms to post-infection traffic – to get hands-on analysis experience. Open-source tools such as Suricata and Moloch will be utilized to generate data\, perform exhaustive traffic analysis\, and develop comprehensive threat hunting strategies. By the end of this workshop\, you will have the knowledge and skills necessary to discover new threats in your network. \nTo help you prepare for this workshop\, we recommend that you are familiar with the basics of network security monitoring\, IDS/IPS systems and Linux environments. Familiarization with IDS rules is recommended\, but not required. We also recommend the following readings: \n\nMITRE Attack Design and Philosophy by Blake Strom\, et al\n\nhttps://www.mitre.org/sites/default/files/publications/pr-18-0944-11-mitre-attack-design-and-philosophy.pdf\n\n\nThe Diamond Model of Intrusion Analysis by Sergio Caltagirone\, et al\n\nhttp://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf\n\n\nIntelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains by Eric Hutchins\, et al\n\nhttps://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Intel-Driven-Defense.pdf\n\n\n\n  \n 
URL:https://suricata.io/event/flocon-2022-intrusion-analysis-threat-hunting-with-open-source-tools/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20211221T183000
DTEND;TZID=America/New_York:20211221T203000
DTSTAMP:20211210T182320Z
CREATED:20211210T174526Z
LAST-MODIFIED:20211210T182320Z
UID:6485-1640111400-1640118600@suricata.io
SUMMARY:SWFLSec Suricata 101 Presentation
DESCRIPTION:Here’s your chance to attend a Suricata 101 training led by OISF developers Shivani Bhardwaj & Juliana Fajardini! \nWith the increasing reliance on the internet for all businesses and transactions\, the importance of monitoring the network has never been greater. In order to detect or prevent such attacks\, network monitoring is of the utmost importance. In this talk\, we will introduce you to Suricata\, which is a world-class network monitoring and security tool. Suricata is a robust engine for network detection\, prevention\, and security monitoring. This means that while Suricata can serve the purpose of detection and prevention\, it can also provide you with a lot of network metadata with its engine that you can use to analyze the traffic and determine a course of action. Where does Suricata’s power come from? Suricata is a high-performance network monitoring and security engine with active and passive monitoring\, metadata logging and real-time file identification and extraction – this allows Suricata to quickly identify\, stop\, and assess the most sophisticated attacks. Suricata integrates seamlessly with your network and can be embedded within numerous respected commercial and open source solutions.  \nJoin us for an introduction to Suricata\, where we shall show how to install and use it on your network\, how to build a simple system of detection on your home network; different ways Suricata ingests traffic; different logs of Suricata\, and analyzing them and rule management with Suricata-update. We shall also work on a real-world malware example\, see how to make Suricata detect it\, and analyze logs to get a lot more information.  \nTuesday\, December 21\, 2021\n6:30 PM to 8:30 PM EST \nHosted by @SWFLSec \nReserve your virtual spot here: \nhttps://www.meetup.com/SWFLSec-Southwest-Florida-Infosec-Meetup/events/273288367/
URL:https://suricata.io/event/swflsec-suricata-101-presentation/
LOCATION:Meetup ONLINE
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20211215T090000
DTEND;TZID=America/New_York:20211215T100000
DTSTAMP:20211130T195207Z
CREATED:20211130T195207Z
LAST-MODIFIED:20211130T195207Z
UID:6474-1639558800-1639562400@suricata.io
SUMMARY:Webinar - Finding and Triaging Unknown Threats
DESCRIPTION:In this webinar we’re going to break from our normal “presentation” mode and instead\, provide a back and forth discussion around finding and identifying new threats. Through a live demonstration\, we will cover how to find new threats\, how we identify important information and ways to categorize the malware family it belongs to. This session will be unscripted and take you through our process of analysis\, the tools we use and\, likely\, the road blocks we run into.  \nRegister here -> https://www.eventbrite.com/e/webinar-finding-and-triaging-unknown-threats-tickets-219597811967
URL:https://suricata.io/event/webinar-finding-and-triaging-unknown-threats/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20211215T080000
DTEND;TZID=America/New_York:20211215T080000
DTSTAMP:20220729T173145Z
CREATED:20220729T173145Z
LAST-MODIFIED:20220729T173145Z
UID:7019-1639555200-1639555200@suricata.io
SUMMARY:Webinar - Finding and Triaging Unknown Threats
DESCRIPTION:
URL:https://suricata.io/event/webinar-finding-and-triaging-unknown-threats-2/
LOCATION:Québec
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20211116T080000
DTEND;TZID=America/New_York:20211117T170000
DTSTAMP:20211018T185012Z
CREATED:20211018T183548Z
LAST-MODIFIED:20211018T185012Z
UID:6437-1637049600-1637168400@suricata.io
SUMMARY:DeepSec IDSC 2021: Advanced Deployment and Architecture for Network Traffic Analysis
DESCRIPTION:Instruction by OISF team Peter Manev\, Eric Leblond\, & Josh Stroschein \nClick here for the conference schedule. \nClick here for a course description & instructor information.
URL:https://suricata.io/event/deepsec-idsc-2021-advanced-deployment-and-architecture-for-network-traffic-analysis/
LOCATION:Québec
CATEGORIES:Training
END:VEVENT
END:VCALENDAR