Release of the SELKS 7.0 distribution aimed at creating intrusion detection systems

Stamus Networks has released a specialized distribution of SELKS 7.0, designed for deploying intrusion detection and prevention systems, as well as responding to identified threats and monitoring network security. Users are provided with a fully ready-to-use solution for managing network security that can be utilized immediately after download. The distribution supports operation in Live mode and can be launched in virtualization environments or containers. Project developments are distributed under the GPLv3 license. The size of the boot image is 3 GB.

The system is built on a Debian package base and the open IDS platform Suricata. Data is processed using Logstash and stored in an ElasticSearch repository. A web interface implemented over Kibana is provided for monitoring the current status and identified incidents. A web interface Scirius CE is used for managing rules and visualizing associated activity. The package also includes the Arkime packet capture system, the EveBox interface for event evaluation, and the data analyzer CyberChef.

In addition to updating the package base, the new version highlights the following improvements:

  • Formation of a package for deployment in container isolation systems supporting Docker.
  • A fully automated system for replaying activities based on saved logs in PCAP format, which can be used to verify the effectiveness of implemented protective measures, analyze incidents, or during training.
  • An expanded and improved set of filters for threat hunting, enabling quick detection of malicious activity and access violations through searches in Suricata logs and NSM (Network Security Monitor).
  • The CyberChef package has been integrated, allowing for the encoding, decoding, and analysis of data related to events, protocol operations, and records created by Suricata.
  • Six new sections have been added to the Kibana interface for visualization and monitoring of activities related to the SNMP, RDP, SIP, HTTP2, RFB, GENEVE, MQTT, and DCERPC protocols.

Release of the SELKS 7.0 distribution aimed at creating intrusion detection systems
Release of the SELKS 7.0 distribution aimed at creating intrusion detection systems


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster