Skip to content
Discussion options

You must be logged in to vote

Open the 'Hunt' interface and search for password or cleartext
You can do the same search in Kibana if you prefer that interface.

And yes, the default Suricata rules should flag such things. I've seen that on my network before and it alerted me to take actions to install Cert's on my systems that needed them.
https://doc.emergingthreats.net/bin/view/Main/WebSearch?search=cleartext&scope=all&web=Main

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@innovate-support
Comment options

@ihatecascardo
Comment options

Answer selected by ihatecascardo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants