Stamus Networks has released a specialized distribution, Clear NDR 1.0, designed for deploying network intrusion detection and prevention systems, as well as organizing responses to identified threats and monitoring network security. Users are provided with a ready-to-use solution for managing network security that can be utilized immediately after downloading. The distribution supports operation in Live mode and launching in virtualization environments or containers. Project developments are distributed under the GPLv3 license. The size of the boot image is 3.9 GB.
The distribution is built on a Debian package base and utilizes the open attack detection system Suricata. Incoming data from various sources is stored in OpenSearch. To track the current status and identified incidents, a web interface is provided, implemented on top of the Kibana interface. Stamus's web interface is used for managing rules and visualizing related activities. It also includes a system for capturing, storing, and indexing network packets Arkime, an interface for assessing past events EveBox, and a data collector Fluentd.
For the last 10 years, the distribution was developed under the name SELKS, but it has been renamed Clear NDR after the product was recognized as ready for use in operational solutions for small and medium enterprises, as well as splitting the distribution into Community and Enterprise editions. The Enterprise version features integration with machine learning systems, enhanced traffic classification tools, integration with third-party threat response systems, daily updates of intrusion detection rules, and technical support.
Key Changes:
- Three deployment options: an ISO image with a graphical interface for those who prefer configuration via GUI, an ISO image with a console environment for servers, and a version for launching in isolated containers.
- The Suricata network intrusion detection and prevention system has been updated to the 8.x branch.
- A transition has been made from the data search, analysis, and storage platform Elasticsearch to the OpenSearch 2 fork.
- Support for the MCP (Model Context Protocol) has been added for integration with AI platforms, allowing AI assistants to access collected data and tools in Clear NDR.
- The web interface now features new dashboard panels and data visualization modules. Over 400 visualization modules and 58 new dashboard panels have been introduced.
- Support for automatic processing of threat intelligence streams has been added, eliminating the need for manual rule writing for Suricata.

- The incident response process has been accelerated. Now you can access evidence associated with an incident, such as logs, traffic stream recordings, identified file operations, and PCAP dumps, with just two clicks.

- Integration of the user interface with other systems has been enabled.

- Enhanced capabilities for managing data retention have been implemented.
- A notification mechanism for updates and new releases has been integrated.
Source: opennet.ru



