Categorization of Addresses #11470
Replies: 1 comment
-
This is not a direct feature of Security Onion, but what you could do is ingest data from say MISP or AbuseCH through an elasticagent integration. https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest-enriching-data.html |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I'm new to security onion and have recently set it up at home. I've been wondering if there is there a way to add categorization of ip addresses to security onion? It would be nice if I could at a glance know if a particular address is associated with C&C, porn, malware, etc.
Beta Was this translation helpful? Give feedback.
All reactions