Suricata is more than just an IDS. This workshop invites you to discover the possibilities offered by this software in incident response, in particular the contextualisation of alerts thanks to metadata extracted from the network before, during and after the alerts. Based on the use of the open-source SELKS distribution, this workshop will offer hands-on exercises focused on analysis and based on real examples.
- Pré-requis :
- The workshop is based on SELKS, a live and installable ISO. A virtualisation solution such as VirtualBox or VMware is required. The virtual machine needs about 6 GB of memory to be fully functional.
- On the technical side, a knowledge of networking concepts and common protocols such as HTTP and TLS is required.
Éric Leblond is an active member of the open-source and security community. He has contributed to the Suricata IDS/IPS since 2009 and is part of the OISF team, the foundation in charge of Suricata's development. He is also a member of the core team of Netfilter, the Linux firewall. In civilian life, he is co-founder and CTO of Stamus Networks, a company that provides Suricata-based solutions.