-
Windows Defender is throwing up a "Severe" warning about the Security Onion ISO file. Defender is saying the ISO contains a backdoor and notes the file Not sure if this is expected but there aren't any notes, at least that I could find, on the Security Onion pages that the ISO might cause Windows Defender to throw warnings. If this is expected, it may be worthwhile to add a warning added to the I verified the ISO via SHA256 sum (matches) and via GPG key (received "Good signature..."). Environmental Details:
|
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 1 reply
-
I've updated the Download page in our documentation to include a warning about this: |
Beta Was this translation helpful? Give feedback.
-
@dougburks |
Beta Was this translation helpful? Give feedback.
-
|
Beta Was this translation helpful? Give feedback.
SecurityOnion\agrules\strelka\yara\thor-webshells.yar
is not a backdoor. It is a yara ruleset that looks for backdoors. You can review the file here:https://github.com/Neo23x0/signature-base/blob/master/yara/thor-webshells.yar
I've updated the Download page in our documentation to include a warning about this:
https://docs.securityonion.net/en/2.3/download.html