Skip to content
Discussion options

You must be logged in to vote

I'll focus my responses to features that are already built into Security Onion just to make sure you are aware of them.

I was reading up on Maltrail which looks interesting, could this be accomplished with zeek/suricata or somehow in SO?

Zeek can consume intel via its intel framework:
https://docs.securityonion.net/en/2.3/zeek.html#intel

And then there was Malice which I guess could be used as an off-line VirusTotal?

You can do some file analysis using Strelka:
https://docs.securityonion.net/en/2.3/strelka.html

And still, another was OpenCTI,

Depending on what exactly you're trying to do, Cases may be able to provide some of this functionality:
https://docs.securityonion.net/en/2.3/…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants