119 Followers
97 Following
232 Posts
Developer in the open source infosec land and at @suricata. A little socially akward. I create EveBox, an event manager for Suricata. Compulsive Rust and C developer. OISF board member.
Twitterhttps://twitter.com/jasonish
GitHubhttps://github.com/jasonish
Workhttps://suricata.io
Abouthttps://jasonish.org/about/
EveBoxhttps://evebox.org
Viewing #remcos alerts from FlowCarp in @ish's #EveBox
https://netresec.com/?b=2659fc0
Remcos Alerts from FlowCarp in EveBox

There is a wonderful little web based alert and event front-end called EveBox, which renders Eve JSON formatted data to a graphical user interface. This blog post demonstrates how EveBox can be used to show alert and flow information that FlowCarp has extracted from a Remcos malware infection. Remco[...]

Netresec
@netresec I see I need to make the "narrow" display a better!
@lattera my dream is a laptop with a qmk keyboard. But 16” is just a little large.
@krisajenkins So we’ve reinvented man pages!
@joeress I used AI to port a Linux app to Windows. I learned the Windows APIs faster, and with good examples due to the AI and was able to ask questions. All very much faster than hunting through documentation I’m not that familiar with. But I have a 30 year foundation here. It’s also incredibly good for asking questions about code and to use as a learning tool. I feel this aspect goes under appreciated.

If you're heading to RSA Conference 2026, come find Dr. Kelley Misata!

She'll be there March 23–26 and would love to connect with the Suricata community and consortium members. She's also bringing Suricata goodies!

Come say hello or send us a message: suricata.io/our-story/contact/

2 accepted talks about #Suricata :)

I'll be talking @suricata at:

@bsidesgrunn on April 17th (https://bsidesgrunn.org/)

and:

@nluug on May 7th (https://nluug.nl/evenementen/nluug/voorjaarsconferentie-2026/)

Hope to see you there!

BSides Groningen – BSides Groningen

10K curl downloads per year

The Linux Foundation, the organization that we want to love but that so often makes that a hard bargain, has created something they call "Insights" where they gather lots of metrics on Open Source project. I held back so I never blogged and taunted OpenSSF for their scorecard attempts that were always lame and misguided. … Continue reading 10K curl downloads per year β†’

daniel.haxx.se

worked with the tcpdump folks on an updated set of examples for the tcpdump man page https://www.tcpdump.org/manpages/tcpdump.1.html#lbAF

the idea is that if you've forgotten how tcpdump's basic flags work, you can find a quick reference in the man page!

tcpdump(1) man page | TCPDUMP & LIBPCAP