4 ms·
Arkime full packet capture? Full packet capture relevance has faded greatly since the early 2010s due to encryption. It's all about host based logging like
by ZeroSolstice 4y ago
Arkime full packet capture? Full packet capture relevance has faded greatly
since the early 2010s due to encryption. It's all about host based logging like
EDR, sysmon and windows event logs, while shored up by specific cloud-based app
logs, or pulling forensic artifacts with osquery (or similar). People aren’t
writing or looking at suricata rules much anymore, unless you're lucky enough
to have an environment being proactively man in the middled, which is rare.
I have to disagree here. Meta data on an actual session is useful for statistical inference and can be used for pattern matching at a larger scale on the network. IP addresses and file hashes are going to change frequently and be abandoned so sending out block lists to all your EDR software is more reactionary than proactive. Malware delivery/interaction observation through session data such as protocol, packet size, timing can all be used as features for detection. Additionally Suricata rules can be stacked using flowbits to provide correlation and actionable alerting on observed traffic outside of just the payload, url, etc. Lastly, having a data point outside of the end point device within the network is useful in the event of an incident, after all how can you trust logs and events being reported from a system that has been compromised. Arkime also can utilize the eve.json log file from Suricata to tag the same observed traffic allowing you to search by SID. Exporting data is probably one of the bigger features as that allows you to aggregate and analyze the data externally in something like Jupyter notebook.
You should check out FloCon put on by CMU. https://resources.sei.cmu.edu/news-events/events/flocon/index.cfm https://resources.sei.cmu.edu/news-events/events/flocon/inde...