suricata and the shark: suriwire · suricata and the shark: suriwire É. leblond stamus networks...

7
Suricata and the Shark: suriwire É. Leblond Stamus Networks July. 03, 2018 É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 1/7

Upload: others

Post on 27-Jun-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Suricata and the Shark: suriwire · Suricata and the Shark: suriwire É. Leblond Stamus Networks July. 03, 2018 É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July

Suricata and the Shark: suriwire

É. Leblond

Stamus Networks

July. 03, 2018

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 1 / 7

Page 2: Suricata and the Shark: suriwire · Suricata and the Shark: suriwire É. Leblond Stamus Networks July. 03, 2018 É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July

Get the mascot

Available on Amazon: https://www.amazon.co.uk/Vivid-Arts-Meerkat-Shark-Onesie/dp/B01MAYA3A1

For only 19.99 brexit coins1

1Worth 76745.63 Columbian PesoÉ. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 2 / 7

Page 3: Suricata and the Shark: suriwire · Suricata and the Shark: suriwire É. Leblond Stamus Networks July. 03, 2018 É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July

Get Suricata information in Wireshark

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 3 / 7

Page 4: Suricata and the Shark: suriwire · Suricata and the Shark: suriwire É. Leblond Stamus Networks July. 03, 2018 É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July

Also get extracted metadata

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 4 / 7

Page 5: Suricata and the Shark: suriwire · Suricata and the Shark: suriwire É. Leblond Stamus Networks July. 03, 2018 É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July

Filter is working

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 5 / 7

Page 6: Suricata and the Shark: suriwire · Suricata and the Shark: suriwire É. Leblond Stamus Networks July. 03, 2018 É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July

How it works

Wireshark plugin written in LuaLoad JSON file generated by Suricata (viaTools->Suricata->Activate)Add a new top domain protocol named suricata

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 6 / 7

Page 7: Suricata and the Shark: suriwire · Suricata and the Shark: suriwire É. Leblond Stamus Networks July. 03, 2018 É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July

Questions ?

Thanks toanonymous NSA agentWireshark teamOISF and Suricata team

Contact [email protected]: @regiteric

Get it, use ithttps://github.com/regit/suriwire

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 7 / 7