DShield Traffic Analysis using ELK, (Thu, Mar 6th)

SANS Internet Storm Center, InfoCON: green 2025-03-05


Using the Kibana interface, sometimes it can be difficult to find traffic of interest since there can be so much of it. The 3 logs used for traffic analysis are cowrie, webhoneypot and the firewall logs. Other options to add to the honeypot are packet capture, netflow and Zeek.



From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green


Date tagged:

03/05/2025, 21:14

Date published:

03/05/2025, 19:54