Security Onion 2.4.70 now available including our new Detections interface and much more!

Tune your:
β˜‘οΈ#NIDS rules for #Suricata
β˜‘οΈ#Sigma rules for #ElastAlert
β˜‘οΈ#YARA rules for #Strelka

Take your #DetectionEngineering game to a new level!

https://blog.securityonion.net/2024/05/security-onion-2470-now-available.html

Security Onion 2.4.70 now available including our new Detections interface and much more!

Security Onion 2.4.70 is now available! It includes some new features for our fellow defenders including our new Detections interface to hel...

TryHackMe | Threat Intelligence for SOC

Learn how to utilise Threat Intelligence to improve the Security Operations pipeline.

TryHackMe

Wow that meme post from the other day was by far my most popular toot. I definitely was not expecting that, but I appreciate that our community supports the same kind of humor :D

I have been doing lots of work with Elastalert the past few days:
https://github.com/Yelp/elastalert

It's been super fun! I am porting over certain threat detection alerts over to a slack channel. Utilizing Elastalert allows me to do it for free. The only catch is you have to hand build the YAML files, but honestly it's been a great learning experience. I highly recommend it anyone using ELK and wants alerting!

#security #ELK #elastalert

GitHub - Yelp/elastalert: Easy & Flexible Alerting With ElasticSearch

Easy & Flexible Alerting With ElasticSearch. Contribute to Yelp/elastalert development by creating an account on GitHub.

GitHub

I think the best part about the false positive alert that fired tonight for a developer account getting domain admin was my boss posting an xzibit meme at the end. 

#security #elastalert #siem #elk #memes