Stefan Dembowski · @I_am_stefan
122 followers · 2195 posts · Server dembowski.social

Fun fact: Micro SD cards go bad occasionally.😳🤦‍♂️

Now rebuilding Zeek. At least I can remote in (best to be rebuilt from console).

#zeek #infosec

Last updated 1 year ago

Tom · @tom
36 followers · 563 posts · Server bonequest.net

I'm looking for guidance, I remember when was suggested for detecting , but there's so many options, with and .

I thought OSSEC with the GUI looked nice, especially if there was a central monitoring server that agents could report to. Zeek looks more like that but looks like it may have to sit at the router, which is annoying, and doesn't detect rootkits at all. My end goal is preventing SIP phone fraud.

linuxsecurity.expert/tools/sam

#ossec #tripwire #rootkits #zeek #maltrail #hids #intrusiondetection

Last updated 1 year ago

keithjjones · @keithjjones
38 followers · 46 posts · Server infosec.exchange

ICYMI check out my BACNet basics with @zeek How-To video:

youtube.com/watch?v=C1y6UY_ith

#bacnet #zeek #ics

Last updated 2 years ago

keithjjones · @keithjjones
38 followers · 45 posts · Server infosec.exchange
ottO · @ottobackwards
98 followers · 921 posts · Server fosstodon.org

@keithjjones @zeek don’t forget the !

#zeek

Last updated 2 years ago

GeneBean · @genebean
171 followers · 736 posts · Server fosstodon.org

@ckreibich pretty cool to hear that is incorporating into Defender and open sourcing the work.

#microsoft #zeek

Last updated 2 years ago

Malcolm v23.03.0 is a release with enhancements, component version updates and bug fixes.

Malcolm is a powerful, easily deployable (via Docker) network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

  • Enhancements

    • Replace Zeek's misc/scan.zeek with ncsa/bro-simple-scan
    • terminate start and restart scripts once Malcolm has started properly (cisagov/Malcolm#240 and cisagov/Malcolm#241, thanks @Njinx)
    • minor usability improvements for ISO-installed Malcolm and Hedgehog (idaholab/Malcolm#155)
      • Added a "Configure Malcolm" menu item (under the "Internet" GTK menu with the other Malcolm stuff) and launcher on the top panel of icons in Malcolm. This runs ./scripts/install.py --configure in full screen. May look at starting this automatically on first boot in the future. (Malcolm)
      • Added Malcolm shortcut to gtk-3.0/bookmarks so it shows up in Thunar sidebar (Malcolm)
      • Added /opt/sensor/sensor_ctl shortcut to gtk-3.0/bookmarks so it shows up in Thunar sidebar (Hedgehog)
      • Have tilix from launcher panel start in /opt/sensor/sensor_ctl (Hedgehog)
    • minor tweaks to defaults for install.py --configure (enable offline-capable file scanners by default)
    • interrupt startup import script when netbox-restore is run
    • added NetBox restore logic to reset_and_auto_populate.sh script (used mostly for demos and presentations)
  • Component version updates

  • Fixes

    • last few seconds' Zeek logs prior to log rotation may be lost (idaholab/Malcolm#151)
    • in ISO-packaged Malcolm installation scripts directory, symlink netbox-backup and netbox-restore to control.py
    • improve opensearchpy connect/health check logig in pcap_watcher.py in pcap-monitor container

#netbox #arkime #malcolm #opensearch #zeek #suricata #pcap #networktrafficanalysis #cybersecurity #cyber #infosec #github #inl #dhs #cisa #CISAgov

Last updated 2 years ago

Check out the latest and Spicy video from Keith Jones -- here's his playlist: youtube.com/playlist?list=PLNE

#zeek

Last updated 2 years ago

Christian wrote a detailed post explaining what's new with 5.2.0. Check it out here: community.zeek.org/t/introduci

#zeek

Last updated 2 years ago

Håkon O. · @eselet
247 followers · 508 posts · Server snabelen.no

Drodlet litt med for å analysere nettverkstrafikk på en kompromittert VM: blogg.optkontek.com/post/skyne

#zeek #infosec #Norsktut

Last updated 2 years ago

ottO · @ottobackwards
93 followers · 862 posts · Server fosstodon.org

Zeek Newsletter - Issue 26 - February 2023 - Announcements - Zeek community.zeek.org/t/zeek-news

#zeek

Last updated 2 years ago

The February issue of the newsletter is available. Catch up with the project and community in this fast read. community.zeek.org/t/zeek-news

#zeek

Last updated 2 years ago

The recording of the monthly community call for March, hosted by Fatema Bannat Wala, is now live:

youtu.be/yrw0lZFrWNU

#zeek

Last updated 2 years ago

The recording of the monthly community call for February, hosted by Fatema Bannat Wala, is now live:

youtu.be/yrw0lZFrWNU

#zeek

Last updated 2 years ago

Security Onion 🧅​ · @securityonion
1186 followers · 92 posts · Server infosec.exchange

2.3.220 now available including:

8.6.2
9.2.10
4.27.1
5.0.7

and more!

blog.securityonion.net/2023/02

Looking for a fun project? 😀

Want to practice your 🔍 and skills?

Install 🧅2.3.220 in a VM:
docs.securityonion.net/en/2.3/

Then follow along with our recent quick analysis blog posts:
blog.securityonion.net/search/

You can then stand up a production deployment and sniff live traffic from a tap or span port. You'll get NIDS alerts, protocol metadata, and full packet capture!
docs.securityonion.net/en/2.3/

Then augment that network visibility with host visibility by deploying endpoint agents:
docs.securityonion.net/en/2.3/

Once you find something of interest in your network or endpoint logs, you can escalate to a case:
docs.securityonion.net/en/2.3/

Inside the case, you can identify indicators and analyze them using Analyzers:
docs.securityonion.net/en/2.3/

Looking for more documentation?

It's built into our web interface for 2.3.220 but you can also find it online at:
securityonion.net/docs

You can also purchase a printed copy of the documentation at securityonion.net/book with proceeds going to Rural Technology Fund!

The printed book also includes an inspiring foreword by @taosecurity and a 20% discount code for our certification and on-demand training!

#securityonion #elastic #grafana #fleetdm #zeek #cybersecurity #threathunting #incidentresponse #malware

Last updated 2 years ago

Martin S 🌻🇺🇦 · @krampus
39 followers · 181 posts · Server infosec.exchange

@misp Did this update by any chance fix export? It broke in an earlier update.

#bro #zeek

Last updated 2 years ago

If your Security Onion install is still on Ubuntu 18.04 you should upgrade soon as support ends in April. Here's a guide from on how to do so:
blog.securityonion.net/2023/02

#securityonion #ubuntu1804 #update #eol #endoflife #april #ubuntu #zeek #blueteam

Last updated 2 years ago