2.3.190 Hotfix Now Available!

This hotfix improves support for file extraction into :
blog.securityonion.net/2022/12

#securityonion #suricata #Strelka

Last updated 3 years ago

Tip: while a high on a binary isnโ€™t a strong detection signal on its own (indicative of a packer which some legitimate software uses on windows), it IS on Linux.

It is much rarer for Linux binaries, especially for internally developed , to have a high entropy.

Tools such as (built into ) can grab this sort of data for you.

#linux #detection #entropy #windows #apps #Strelka #securityonion #nsm #networksecurity #netsec #DetectionAndResponse #incidentresponse #forensics #dfir #cyber #cybersecurity

Last updated 3 years ago