-
Notifications
You must be signed in to change notification settings - Fork 521
Pcaps
Security Onion 16.04 comes with several pcap samples in /opt/samples/
.
-
https://github.com/bro/bro/tree/master/testing/btest/Traces
-
https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Public_Data_Sets
-
https://github.com/markofu/hackeire/tree/master/2011/pcap
-
http://www.defcon.org/html/links/dc-ctf.html (You have to follow some of the links, which redirect to competitor blogs but there's lots of goodness).
-
https://github.com/bro/bro/tree/master/testing/btest/Traces
You can use tcpreplay
to replay any of these pcaps on your Security Onion sensor. For example, please see
here for a quick, easy use-case and what you should see in the Sguil console.
so-test
will use tcpreplay
to replay all pcap samples in /opt/samples
to your sniffing interface.
A drawback to using tcpreplay is that it's replaying the pcap as new traffic and thus the timestamps that you see in Kibana, Squert, and Sguil do not reflect the original timestamps from the pcap. To avoid this, a new tool was developed called so-import-pcap.
- Introduction
- Use Cases
- Hardware Requirements
- Release Notes
- Download/Install
- Booting Issues
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthrough
- Videos
- Architecture
- Cheat Sheet
- Conference
- Elastic Stack
- Elastic Architecture
- Elasticsearch
- Logstash
- Kibana
- ElastAlert
- Curator
- FreqServer
- DomainStats
- Docker
- Redis
- Data Fields
- Beats
- Pre-Releases
- ELSA to Elastic
- Network Configuration
- Proxy Configuration
- Firewall/Hardening
- Email Configuration
- Integrating with other systems
- Changing IP Addresses
- NTP
- Managing Alerts
- Managing Rules
- Adding Local Rules
- Disabling Processes
- Filtering with BPF
- Adjusting PF_RING for traffic
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs