Actions
Feature #7101
openeve: add number of flowbits in protocol records and alerts
Effort:
Difficulty:
Label:
Description
Very useful for hunting can be the number of flowbits present in a protocol log or alert.
Details: https://www.stamus-networks.com/blog/suricata-threat-hunting-fundamentals.
The suggestion is to have a simple key/value added to the JSON logs indicating number of flowbits present.
This can also be achieved via SIEM aggregations but if present in the logs it enables for more detection formulas and mechanisms.
Updated by Jason Ish 4 months ago
- Related to Task #2167: tracking: eve enhancements added
Updated by Lukas Sismis 4 months ago
- Status changed from New to Feedback
- Assignee changed from OISF Dev to Peter Manev
Updated by Victor Julien 4 months ago
- Subject changed from add number of flowbits in protocol JSON logs and alerts to eve: add number of flowbits in protocol records and alerts
Actions