Register here About this event Also known as Bokbot, IcedID is one of many families of malware distributed through malicious spam. In this webinar, Brad reviews two email-based distribution campaigns regularly distributing IcedID since November 2021. He reviews recent examples of IcedID infection traffic and reveals indicators that can be identified through Suricata-based signatures. Many […]
Free registration & detailed event description here: https://suri-outreachy-2022.eventbrite.com Presented by the Women of Suricata & hosted by our 2021/2022 Outreachy interns Sam & Modupe. This course is a sequel to our 2020/2021 Outreachy intern-led webinar: A Beginner's Guide to Adding New Features to Suricata
Writing signatures for Suricata and other intrusion detection systems (IDS) is considered by many to be a form of art. One of the main reasons is that the rule writer needs to start by examining a network trace to identify patterns that are representative to a threat/behavior without being too broad (to avoid false positives) […]
Suricata is the world-renowned IDS / IPS and NSM engine. It is capable of generating a combined log stream from separate information elements, including network protocol events, alerts, PCAP files (full packet capture), and extracted files as it sniffs live network traffic or sits inline. Suricata produces over 25 different types of log data, including […]
In today’s environment of reduced budgets, loss of talent, and more breaches than ever before, how do you stop the adversary before they are able to compromise your environment? In this livestream we’ll be talking with OISF’s own Josh Stroschein, and discussing the capabilities of Suricata, an open-source threat detection engine. Join us to hear […]
Suricata has the ability to output alerts, anomalies, metadata, file info and protocol-specific records through JSON EVE output. In this webinar, we’ll explore how we can use Suricata event data for threat detection and prevention by enriching, processing and logging EVE JSON output to MongoDB in real-time. We will also analyze threat hunting reports with […]
Suricata is the world-renowned IDS / IPS and NSM engine. It is capable of generating a combined log stream from separate information elements, including network protocol events, alerts, PCAP files (full packet capture), and extracted files as it sniffs live network traffic or sits inline. Suricata produces over 25 different types of log data, including […]
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.