verovaleros, to grafana

I am proud of the infrastructure we created for our Introduction to Security class at CTU in Prague.

It is a challenge to keep services and student containers up in a quite adversarial network where everyone is attacking but we managed to secure a 99% uptime.

In 15-16 weeks of class, our network sees hundreds of millions of network flows. We use #zeek for log collection, a dockerised suite with #grafana for monitoring, and #splunk for threat hunting.

Students are in full control of their containers. Our classes are a well-balanced mix of attack and defence, where students are in charge of protecting their own containers for the duration of the class. The attacking includes a wide variety of attacks and tools, including active exploiting of web applications and services.

Very proud of each of our students who do not stop surprising us each year!

misp, to opensource

Using Zeek’s new JavaScript support for MISP integration.

With Zeek 6.0, experimental JavaScript support was added to Zeek, making Node.js and its vast ecosystem available to Zeek script developers to more easily integrate with external systems.

https://www.misp-project.org/2024/01/03/Zeek_JavaScript_MISP_Integration.html/

@zeek

itisiboller, to security

People tend to forget that without NDR there's little to no visibility in an OT environment. But this is true for IT too.

#ICS #SCADA #NDR #XDR #Network #Detection #Endpoint #OT #Security #Zeek #IT #Visibility

mmguero, to infosec

I'm very proud to announce the release of Malcolm v23.05.0! This was a big release!

This is the first version of Malcolm that can be deployed with Kubernetes, although improvements in this area will continue in coming releases. (Please let us know what issues or suggestions you have via the issue tracker or via email to malcolm@inl.gov.)

The Malcolm documentation has been improved and now includes a detailed End-to-end Malcolm and Hedgehog Linux ISO Installation document.

A new ICSNPP-Synchrophasor parser for Synchrophasor Data Transfer for Power Systems (IEEE C37.118) has been integrated.

We've also got a plethora of component version updates, including Arkime to v4.3.0, Capa to v5.1.0, Fluent Bit to v2.1.2, NetBox to v3.5.0, NGINX to v1.22.1, Supercronic to v0.2.24, Suricata to v6.0.10, Yara to v4.3.0, and Zeek to v5.2.1.

Check out the release on GitHub or grab my ISO builds at malcolm.fyi.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines