ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    IDS?

    Scheduled Pinned Locked Moved IT Discussion
    18 Posts 6 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IRJI
      IRJ @gjacobse
      last edited by

      @gjacobse said in IDS?:

      https://mangolassi.it/topic/10086/intrusion-detection-system-experience-snort-or-others

      AlienVault uses a snort plugin to capture .pcap files of questionable events.

      We were recently able to find and kill a trojan using AlienVault. Sophos did not detect it, but AlienVault did. I opened up the pcap file and wireshark and could see that PC sending out data to Germany on an unusual port number.

      1 Reply Last reply Reply Quote 1
      • stacksofplatesS
        stacksofplates
        last edited by

        Our new systems are going to have aide running. Just going to have a cronjob run the aide check every so often.

        IRJI 1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ @stacksofplates
          last edited by

          @stacksofplates said in IDS?:

          Our new systems are going to have aide running. Just going to have a cronjob run the aide check every so often.

          How soon do you want to find out if someone is doing something malicious? Are you alerted every 10 minutes, few hours, days, etc?

          Also how long do you keep logs?

          These are some of the IDS questions I find very hard to find out any information. Not many are willing to talk about how long they keep they logs, etc.

          stacksofplatesS 1 Reply Last reply Reply Quote 0
          • stacksofplatesS
            stacksofplates @IRJ
            last edited by

            @IRJ said in IDS?:

            @stacksofplates said in IDS?:

            Our new systems are going to have aide running. Just going to have a cronjob run the aide check every so often.

            How soon do you want to find out if someone is doing something malicious? Are you alerted every 10 minutes, few hours, days, etc?

            Also how long do you keep logs?

            These are some of the IDS questions I find very hard to find out any information. Not many are willing to talk about how long they keep they logs, etc.

            It's probably going to run every hour. It's an air gapped network. Logs are kept for a year.

            1 Reply Last reply Reply Quote 0
            • travisdh1T
              travisdh1
              last edited by

              I've been using AlienVault's OSSIM, basically the open source version. It's been good so far, but I just deployed the agents to each server/workstation and haven't setup any custom rules, so it just uses the rules for currently known threats.

              IRJI 1 Reply Last reply Reply Quote 0
              • IRJI
                IRJ @travisdh1
                last edited by

                @travisdh1 said in IDS?:

                I've been using AlienVault's OSSIM, basically the open source version. It's been good so far, but I just deployed the agents to each server/workstation and haven't setup any custom rules, so it just uses the rules for currently known threats.

                Do you find the agents useful? I am still testing the agents in a test environment.

                travisdh1T 1 Reply Last reply Reply Quote 0
                • travisdh1T
                  travisdh1 @IRJ
                  last edited by

                  @IRJ said in IDS?:

                  @travisdh1 said in IDS?:

                  I've been using AlienVault's OSSIM, basically the open source version. It's been good so far, but I just deployed the agents to each server/workstation and haven't setup any custom rules, so it just uses the rules for currently known threats.

                  Do you find the agents useful? I am still testing the agents in a test environment.

                  OSSIM would be useless without them for me, honestly. without custom rules, or some way to get data besides the login, OSSIM is kinda crippled.

                  IRJI 1 Reply Last reply Reply Quote 0
                  • IRJI
                    IRJ @travisdh1
                    last edited by

                    @travisdh1 said in IDS?:

                    @IRJ said in IDS?:

                    @travisdh1 said in IDS?:

                    I've been using AlienVault's OSSIM, basically the open source version. It's been good so far, but I just deployed the agents to each server/workstation and haven't setup any custom rules, so it just uses the rules for currently known threats.

                    Do you find the agents useful? I am still testing the agents in a test environment.

                    OSSIM would be useless without them for me, honestly. without custom rules, or some way to get data besides the login, OSSIM is kinda crippled.

                    You use them for file integrity and registry change reporting, correct?

                    travisdh1T 1 Reply Last reply Reply Quote 0
                    • travisdh1T
                      travisdh1 @IRJ
                      last edited by

                      @IRJ said in IDS?:

                      @travisdh1 said in IDS?:

                      @IRJ said in IDS?:

                      @travisdh1 said in IDS?:

                      I've been using AlienVault's OSSIM, basically the open source version. It's been good so far, but I just deployed the agents to each server/workstation and haven't setup any custom rules, so it just uses the rules for currently known threats.

                      Do you find the agents useful? I am still testing the agents in a test environment.

                      OSSIM would be useless without them for me, honestly. without custom rules, or some way to get data besides the login, OSSIM is kinda crippled.

                      You use them for file integrity and registry change reporting, correct?

                      Yes. Mine has an internet connection, so it also gets the latest threat updates from the public pool.

                      IRJI 1 Reply Last reply Reply Quote 0
                      • IRJI
                        IRJ @travisdh1
                        last edited by

                        @travisdh1 said in IDS?:

                        @IRJ said in IDS?:

                        @travisdh1 said in IDS?:

                        @IRJ said in IDS?:

                        @travisdh1 said in IDS?:

                        I've been using AlienVault's OSSIM, basically the open source version. It's been good so far, but I just deployed the agents to each server/workstation and haven't setup any custom rules, so it just uses the rules for currently known threats.

                        Do you find the agents useful? I am still testing the agents in a test environment.

                        OSSIM would be useless without them for me, honestly. without custom rules, or some way to get data besides the login, OSSIM is kinda crippled.

                        You use them for file integrity and registry change reporting, correct?

                        Yes. Mine has an internet connection, so it also gets the latest threat updates from the public pool.

                        You do the updates through SSH, right?

                        1 Reply Last reply Reply Quote 1
                        • IRJI
                          IRJ
                          last edited by

                          Sorry for so many questions. I have never used the open source version.

                          travisdh1T 1 Reply Last reply Reply Quote 0
                          • travisdh1T
                            travisdh1 @IRJ
                            last edited by

                            @IRJ said in IDS?:

                            Sorry for so many questions. I have never used the open source version.

                            No problem. I'm not responding as fast anymore because some imaging jobs finished.

                            @IRJ said in IDS?:

                            @travisdh1 said in IDS?:

                            @IRJ said in IDS?:

                            @travisdh1 said in IDS?:

                            @IRJ said in IDS?:

                            @travisdh1 said in IDS?:

                            I've been using AlienVault's OSSIM, basically the open source version. It's been good so far, but I just deployed the agents to each server/workstation and haven't setup any custom rules, so it just uses the rules for currently known threats.

                            Do you find the agents useful? I am still testing the agents in a test environment.

                            OSSIM would be useless without them for me, honestly. without custom rules, or some way to get data besides the login, OSSIM is kinda crippled.

                            You use them for file integrity and registry change reporting, correct?

                            Yes. Mine has an internet connection, so it also gets the latest threat updates from the public pool.

                            You do the updates through SSH, right?

                            Yep. You just might get introduced to my basic update script on the 16th.

                            1 Reply Last reply Reply Quote 1
                            • 1 / 1
                            • First post
                              Last post