Replies: 1 comment
-
One can use BPF to drop all the traffic before it hits suricata so that it doesn't generate alerts. Optional to still log it normally or block it from zeek and stenographer and such also. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
Let's say I have network vulnerability scanner (Nessus for example ) and it makes a lot of noise - thousands of different alerts.
How can I disable all SIDs for that one IP (or few IPs)? Can it be done on SIDs disabling or tresholding level or is it better on BPF?
Thank You again SO Team
Beta Was this translation helpful? Give feedback.
All reactions