Defense Tools Flashcards

1
Q

What is Suricata?

A

open-source IDS, IPS, and network security monitoring (NSM) tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Suricata used for?

A

monitor and analyze network traffic in real-time to detect and respond to security threats and anomalies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Snort?

A

open-source network IDS/IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Snort used for?

A

monitoring and analyzing network traffic to detect and respond to security threats and anomalies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Zeek?

A

open-source network security monitoring and analysis platform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Zeek used for?

A

passively monitor network traffic and generate detailed logs and metadata that provide deep insights into network activity, security events, and potential threats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the Uncoder.io tool used for?

A

transform Sigma rules, IOC lists, and other platform query syntaxes into custom hunting queries prepared for execution in SIEM and XDR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What IOCs are supported by Uncoder.io?

A
  • IPs
  • Domains
  • URLs
  • Hashes
  • Emails
  • Files
How well did you know this?
1
Not at all
2
3
4
5
Perfectly