[Workshop] Threat Hunting with SELKS and Suricata 6

No ratings

Presented at Pass-the-SALT 2022 by

Threat hunting with network data can be done with Suricata that combines a signature based IDS with network security monitoring capabilities. In this workshop we will show through SELKS usage. SELKS is a complete network threat hunting stack based on Suricata and Elasticsearch. We will use some of the recent capabilities of Suricata like dataset to show that it goes far beyond the traditional role of an IDS. Organization note: registration to the workshop will be done directly on-site during the event. Nothing to do on-line. With this workshop, attendees will get a good understanding of Suricata generated data and of some of its main features. By working an network trace, we will see how it is possible to understand a network, discover threats and deploy detection at the organization level. Prerequisites: hardware requirements for the attendees is a computer with at least 2 cores and 9 Gb of memory running preferably under Linux but Windows or MacOS X should work. Maximum of 15 participants.