Skip to content
Discussion options

You must be logged in to vote

So the solution in my case would be to just disable steno completely?

The really depends on what you want to be able to accomplish once you have the alert. The real reason full pcap is there is for what happens before and after the alert. If you apply this to a scenario where you get an alert that tells you a reverse shell has been opened and you are only saving pcaps on alerts, you now have PCAP of the actor opening a shell. What you miss after that is the possible C2 activity coming from that machine or RAR files leaving the network with the plans of the deathstar. All things that if you don't have exact rules for you would never see. You would have meta data about them sending large …

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
1 reply
@fuomag9
Comment options

Comment options

You must be logged in to vote
2 replies
@fuomag9
Comment options

@TOoSmOotH
Comment options

Answer selected by TOoSmOotH
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
4 participants