Send all exe and similar files to strelka #10764
-
Hi I have a hopefully easy question, I have a tremendous amount of ingest space for the nsm partition on my drive. I want to make security onion send of the exes and similar files to strelka to be processed and examined by strelka, mainly to have the hash of each file. How would I go about doing this? I'm on the latest version of security onion 2.3 (2.3.260 as of the time of posting). |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 6 replies
-
By default Zeek should be extracting |
Beta Was this translation helpful? Give feedback.
-
If you check in SOC/Hunt, what do you see for |
Beta Was this translation helpful? Give feedback.
-
Are you sure you are seeing .exe files on http? https will not get carved since it is encrypted like. |
Beta Was this translation helpful? Give feedback.
You'd need to intercept the traffic with something like PolarProxy or an enterprise tap or SSL interception device.