IDH-Alarms - exempt IP-addresses of vulnerability scanners from generating false positives #12547
-
Hi, I was thinking about a BPF, but where should I put the BPF? BPF for PCAP, BPF for Zeek or BPF for Suricata? Thanks much in advance for any clue. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 7 replies
-
Sorry, just to be clear -- the alerts are being generated by Playbook (your vulnerability scanners interacting with the honeypot services) or by Suricata (the traffic from your scanners to the honeypot node)? |
Beta Was this translation helpful? Give feedback.
-
Thanks @GitGoodGod - definitely helps getting out those false alarms triggered by vulnerability scans :-) |
Beta Was this translation helpful? Give feedback.
so i havn't tested it myself, i will in a bit.
i just put in the ignore list in the default.yaml file for IDH, which is fine, but i think if you upgrade node it wont save it.
im thinking it might have to look like this perhaps ?
i'll test it out myself as well at some point.