Defense Tools Flashcards
What is Suricata
?
open-source IDS, IPS, and network security monitoring (NSM) tool
What is Suricata
used for?
monitor and analyze network traffic in real-time to detect and respond to security threats and anomalies
What is Snort
?
open-source network IDS/IPS
What is Snort
used for?
monitoring and analyzing network traffic to detect and respond to security threats and anomalies
What is Zeek
?
open-source network security monitoring and analysis platform
What is Zeek
used for?
passively monitor network traffic and generate detailed logs and metadata that provide deep insights into network activity, security events, and potential threats
What is the Uncoder.io
tool used for?
transform Sigma rules, IOC lists, and other platform query syntaxes into custom hunting queries prepared for execution in SIEM and XDR
What IOCs are supported by Uncoder.io
?
- IPs
- Domains
- URLs
- Hashes
- Emails
- Files