Analysis using Gephi with DShield Sensor Data, (Wed, Jan 7th)

SANS Internet Storm Center, InfoCON: green 2026-01-08

Summary:

I&#;x26;#;39;m always looking for new ways of manipulating the data captured by my DShield sensor [1]. This time I used Gephi [2] and Graphiz [3] a popular and powerful tool for visualizing and exploring relationships between nodes, to examine the relationship between the source IP, filename and which sensor got a copy of the file. I queried the past 30 days of data stored in my ELK [4] database in Kibana using ES|QL [5][6] to query and export the data and import the result into Gephi.

Link:

https://isc.sans.edu/diary/rss/32608

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

01/08/2026, 01:45

Date published:

01/07/2026, 19:13