#ElastAlert

Security Onion 🧅​securityonion@infosec.exchange
2024-05-29

Security Onion 2.4.70 now available including our new Detections interface and much more!

Tune your:
☑️#NIDS rules for #Suricata
☑️#Sigma rules for #ElastAlert
☑️#YARA rules for #Strelka

Take your #DetectionEngineering game to a new level!

blog.securityonion.net/2024/05

acrypthash👨🏻‍💻acrypthash@infosec.exchange
2023-08-24

Wow that meme post from the other day was by far my most popular toot. I definitely was not expecting that, but I appreciate that our community supports the same kind of humor :D

I have been doing lots of work with Elastalert the past few days:
github.com/Yelp/elastalert

It's been super fun! I am porting over certain threat detection alerts over to a slack channel. Utilizing Elastalert allows me to do it for free. The only catch is you have to hand build the YAML files, but honestly it's been a great learning experience. I highly recommend it anyone using ELK and wants alerting!

#security #ELK #elastalert

acrypthash👨🏻‍💻acrypthash@infosec.exchange
2023-06-23

I think the best part about the false positive alert that fired tonight for a developer account getting domain admin was my boss posting an xzibit meme at the end. :ablobcatbongokeyboard:

#security #elastalert #siem #elk #memes

Martin Boller :debian: :tux: :freebsd: :windows: :mastodon:itisiboller@infosec.exchange
2018-12-16

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst