Thanks to Brad Duncan for sharing these pcaps!
https://www.malware-traffic-analysis.net/2021/06/16/index.html
We did a quick analysis of the pcaps on the latest version of Security Onion via so-import-pcap:
https://docs.securityonion.net/en/2.3/so-import-pcap.html
Here are some of the interesting Suricata alerts, Zeek logs, and HTTP transcripts:
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.