In Hot Pursuit: Hunting with Metadata for Recently Disclosed CVEs

Поделиться
HTML-код
  • Опубликовано: 11 июл 2024
  • Presented at SuriCon 2022 by Peter Manev
    When a new CVE (e.g. Log4J, Printing Nightmare, Fellina) with broad applicability and/or serious consequences is announced, security teams often face tremendous pressure from management to answer basic questions about the impact on their organization: Are we vulnerable? Have we been targeted? Have we been breached? The great news is that if Suricata has been deployed in the network, these questions can be answered fairly quickly even if there are no signatures for it. In this talk, we look under the hood to identify the components of Suricata that can be used to spot specific CVE exploits and what developers and rule writers can do to make this easier for users.
  • РазвлеченияРазвлечения

Комментарии •