Posted
about 13 years
ago
Bro_IDS: @aboutsecurity Have you looked in the software log too? HTTP user-agents for local hosts and lots more.
|
Posted
about 13 years
ago
Bro_IDS: Bro Exchange 2012: Dates finalized. Meet other Bro users and the Bro Team on Aug 7-8 in Boulder, CO. http://t.co/JEl87aAZ
|
Posted
about 13 years
ago
by
Robin Sommer
|
Posted
about 13 years
ago
Bro_IDS: @taosecurity @mcholste I believe those fingerprints are SHA1 hashes of the certs which isn't support in Bro 2.0. Should be there in 2.1
|
Posted
about 13 years
ago
Bro_IDS: “@netresec: @taosecurity @Bro_IDS http://t.co/bpCKkz2w. Can @Bro_IDS do this?” < Yes, we're working on making it do even better now too.
|
Posted
about 13 years
ago
Bro_IDS: @taosecurity If you are extracting files, then you could search the files. Eventually we should have more extensive data for cases like this
|
Posted
about 13 years
ago
Bro_IDS: @taosecurity Unfortunately we would currently only catch it if it was used for SSL, not code signing.
|
Posted
about 13 years
ago
Bro_IDS: RT @taosecurity: If you're running a #NSM shop with #securityonion and @Bro_IDS or #Sguil you could check logs and/or pcap for artifacts ...
|
Posted
about 13 years
ago
Bro_IDS: RT @mcholste: Wow, new @Bro_IDS input http://t.co/vlvaMYwB provides a great path for fully auto Suricata > ELSA > CIF > Bro
|
Posted
over 13 years
ago
Bro_IDS: Another development update: Use the new Input Framework to read your external data into Bro on the fly. http://t.co/KySFpla0
|