Suricata and the Shark: suriwire · Suricata and the Shark: suriwire É. Leblond Stamus Networks...

Preview:

Citation preview

Suricata and the Shark: suriwire

É. Leblond

Stamus Networks

July. 03, 2018

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 1 / 7

Get the mascot

Available on Amazon: https://www.amazon.co.uk/Vivid-Arts-Meerkat-Shark-Onesie/dp/B01MAYA3A1

For only 19.99 brexit coins1

1Worth 76745.63 Columbian PesoÉ. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 2 / 7

Get Suricata information in Wireshark

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 3 / 7

Also get extracted metadata

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 4 / 7

Filter is working

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 5 / 7

How it works

Wireshark plugin written in LuaLoad JSON file generated by Suricata (viaTools->Suricata->Activate)Add a new top domain protocol named suricata

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 6 / 7

Questions ?

Thanks toanonymous NSA agentWireshark teamOISF and Suricata team

Contact meel@stamus-networks.comTwitter: @regiteric

Get it, use ithttps://github.com/regit/suriwire

É. Leblond (Stamus Networks) Suricata and the Shark: suriwire July. 03, 2018 7 / 7

Recommended