A way for analysts without sensor creds to pull Strelka files? #9263
-
Security Onion 2.3.130 With our current setup, our sensor administrators pull alerted strelka files for the analysts using WinSCP or similar. Is there a current or built-in way for the analysts to grab those files themselves through the SOC or Kibana? |
Beta Was this translation helpful? Give feedback.
Answered by
dougburks
Dec 2, 2022
Replies: 1 comment 1 reply
-
One option would be to pivot to full packet capture and then extract the file: |
Beta Was this translation helpful? Give feedback.
1 reply
Answer selected by
samanosuke26
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
One option would be to pivot to full packet capture and then extract the file:
https://docs.securityonion.net/en/2.3/pcap.html