-
|
As an analyst, it would be really useful to be able to submit individual files to Strelka for scanning. While Zeek automatically submits files to Strelka, it can only do so for files that traverse the network, and only for files that were transmitted in plain-text. For example, files transmitted via TLS cannot be effectively scanned. The idea is, if an analyst discovers a suspicious file, they could manually submit it to Strelka and get a scan result back. Additionally, this would make testing new YARA rules in the Detections module much easier. I have two different ideas for making this possible:
Thanks for all of the hard work you all do to make Security Onion as awesome as it is! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
|
A file can be place in |
Beta Was this translation helpful? Give feedback.
A file can be place in
/nsm/strelka/unprocessed/and Strelka will `analyze.