3 ms·
Why are they calling it purple if it's really blue? Also, elastic is one of the worst siems you can choose for threat hunting and analysis. The language is inc
by ar9av 4y ago
Why are they calling it purple if it's really blue?
Also, elastic is one of the worst siems you can choose for threat hunting and analysis. The language is incredibly limited, the parsing is confusing, there's no no built in aggregations that make sense, you can only search over one set set of data at a time (no joins). And it's even more limited through the search bar in the kibana GUI. Lastly, it uses techniques that estimate data results for the sake of speed. It does not guarantee full accuracy when returning data.
Arkime full packet capture? Full packet capture relevance has faded greatly since the early 2010s due to encryption. It's all about host based logging like EDR, sysmon and windows event logs, while shored up by specific cloud-based app logs, or pulling forensic artifacts with osquery (or similar). People aren’t writing or looking at suricata rules much anymore, unless you're lucky enough to have an environment being proactively man in the middled, which is rare.
This is a pretty interesting distro, but don't expect to be up to date with modern threat hunting, soc analysis, incident response or threat detection. It could be a nice intro in college, but you'll want to get modern data sets into real siems or DBs asap.
The final thing I have to say is that purple team is not a set of tools. These are all blue teamer tools. Purple team is when a red teamer works directly with a blue teamer to create an attack and watch how the blue team systems and people react when it's happening. It's a drill that captures misses.
- ZeroSolstice 4y agoArkime full packet capture? Full packet capture relevance has faded greatly since the early 2010s due to encryption. It's all about host based logging like EDR, sysmon and windows event logs, while shored up by specific cloud-based app logs, or pulling forensic artifacts with osquery (or similar). People aren’t writing or looking at suricata rules much anymore, unless you're lucky enough to have an environment being proactively man in the middled, which is rare. I have to disagree here. Meta data on an actual session is useful for statistical inference and can be used for pattern matching at a larger scale on the network. IP addresses and file hashes are going to change frequently and be abandoned so sending out block lists to all your EDR software is more reactionary than proactive. Malware delivery/interaction observation through session data such as protocol, packet size, timing can all be used as features for detection. Additionally Suricata rules can be stacked using flowbits to provide correlation and actionable alerting on observed traffic outside of just the payload, url, etc. Lastly, having a data point outside of the end point device within the network is useful in the event of an incident, after all how can you trust logs and events being reported from a system that has been compromised. Arkime also can utilize the eve.json log file from Suricata to tag the same observed traffic allowing you to search by SID. Exporting data is probably one of the bigger features as that allows you to aggregate and analyze the data externally in something like Jupyter notebook. You should check out FloCon put on by CMU. https://resources.sei.cmu.edu/news-events/events/flocon/index.cfm https://resources.sei.cmu.edu/news-events/events/flocon/inde...
- mike_d 4y ago> Why are they calling it purple if it's really blue? Because they plan to offer a purple team training/certification. Kali Linux isn't a $color security distribution, it is a set of open source security tools that act as the student environment for their exam. That is why they continue to devote paid engineer hours to developing it.
- unethical_ban 4y agoWhat do you recommend as an open source full text search log ingestion database vs. Elasticsearch?
- AbraKdabra 4y agoWell, at least if you're gonna bash on Elastic provide some alternatives, we are running Elastic as a SIEM ingesting millions of records per day all for free (albeit we are in the process of aquiring a licence).