Skip to content

sud0woodo

Binary Enthusiast

Menu
  • Home
  • twitter

Category: Networking

Developing Urgent11 Detection with Suricata

2019-11-13
| No Comments
| Network Analysis, Network Detection, Networking, Vulnerability

Summary In july of 2019 Armis released a technical whitepaper detailing numerous vulnerabilities found in devices running VxWorks. Since this post is not about explaining what VxWorks is, or why the vulnerabilities are so impactful, I will leave you with this link to the post that Armis put out in july. Since I’m developing Suricata […]

Read More »

Posted in <a href="https://sud0woodo.sh/category/networking/network-analysis/" rel="category tag">Network Analysis</a>, <a href="https://sud0woodo.sh/category/networking/network-detection/" rel="category tag">Network Detection</a>, <a href="https://sud0woodo.sh/category/networking/" rel="category tag">Networking</a>, <a href="https://sud0woodo.sh/category/vulnerability/" rel="category tag">Vulnerability</a> Tagged <a href="https://sud0woodo.sh/tag/suricata/" rel="tag">suricata</a>, <a href="https://sud0woodo.sh/tag/urgent11/" rel="tag">urgent11</a> Leave a comment

Suriflaska – Flask server for testing Snort / Suricata rules

2019-04-29
| No Comments
| Development, Network Detection, Networking

This post is a small follow-up on the network detection theme that I have been posting the last couple months. Recently I got more into writing rules for detecting network threats and wanted to create something similar to what is used in some bigger blue team companies. So without going too much in the why’s, […]

Read More »

Posted in <a href="https://sud0woodo.sh/category/development/" rel="category tag">Development</a>, <a href="https://sud0woodo.sh/category/networking/network-detection/" rel="category tag">Network Detection</a>, <a href="https://sud0woodo.sh/category/networking/" rel="category tag">Networking</a> Leave a comment

Building a Go scanner to search externally reachable StarOffice Managers

2019-03-06
| No Comments
| Development, Networking, Vulnerability

This is a little hobby project of mine that I started to get some experience with Go. DISCLAIMER: I am not a programmer and not responsible for your eye sores reading this code. Please do critique the script. Background I want to kick this post off with a little background information about why I decided […]

Read More »

Posted in <a href="https://sud0woodo.sh/category/development/" rel="category tag">Development</a>, <a href="https://sud0woodo.sh/category/networking/" rel="category tag">Networking</a>, <a href="https://sud0woodo.sh/category/vulnerability/" rel="category tag">Vulnerability</a> Leave a comment

Investigating External IP-Lookups from Mailspring

2019-02-11
| No Comments
| Network Analysis, Networking

Last week I was playing around with some PCAPs I made of my home network, trying to correlate what I saw happening in the PCAP with the alerts generated by my SecurityOnion instance. One specific alert triggered over 1000 times in just two days, this doesn’t say much as I happen test a lot of […]

Read More »

Posted in <a href="https://sud0woodo.sh/category/networking/network-analysis/" rel="category tag">Network Analysis</a>, <a href="https://sud0woodo.sh/category/networking/" rel="category tag">Networking</a> Leave a comment

Setting up SecurityOnion for monitoring home networks

2019-02-08
| No Comments
| Network Analysis, Networking

This is a simple post to explain how to set up a SecurityOnion instance for monitoring a home network. NOTE: Do not use this guide for setting up a SecurityOnion instance for monitoring production environments! About SecurityOnion I could write something here myself but the SecurityOnion Github page does this better: Security Onion is a […]

Read More »

Posted in <a href="https://sud0woodo.sh/category/networking/network-analysis/" rel="category tag">Network Analysis</a>, <a href="https://sud0woodo.sh/category/networking/" rel="category tag">Networking</a> Leave a comment

Recent Posts

  • Reversing Adventures: shad0w framework part 3
  • Reversing Adventures: shad0w framework part 2
  • Reversing Adventures: shad0w framework part 1
  • Binary Exploitation Automation with Radare2
  • Developing Urgent11 Detection with Suricata

Archives

Categories

© sud0woodo 2021. Powered by WordPress