EXTERNAL_NET defaults to "any" #1913
-
Was tracking down some false positives and noticed that the default setting for suricata is EXTERNAL_NET: any .
|
Beta Was this translation helpful? Give feedback.
Answered by
dougburks
Nov 14, 2020
Replies: 1 comment
-
|
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
dougburks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
EXTERNAL_NET
toany
to improve your ability to detect lateral movement.https://docs.securityonion.net/en/2.3/suricata.html?highlight=external_net#configuration