RE: https://infosec.exchange/@suricata/115583672707664579
Suricata events enriched with #sysmon process info = #Pikksilm. Based on experiences from the #LockedShields cyber battlefield. Definitely recommended to see that tool and presentation.
Also talk about #ICS , #modbus and datasets by @reverseics brings good ideas and examples of #suricata rules.
