Installing & Configuring Suricata

Поделиться
HTML-код
  • Опубликовано: 19 сен 2024
  • This video covers the process of installing and configuring Suricata for intrusion detection. Suricata is a free and open-source threat detection engine. It does this by combining IDS, IPS, and network security monitoring.
    You can register for part 2 of this series for free here: bit.ly/3yJqT3c
    //LINKS
    Suricata: suricata.io/
    Suricata GitHub Repo: github.com/OIS...
    Video Slides: bit.ly/3PHmhk9
    Register For Part 2 Of This Series: bit.ly/3yJqT3c
    Get 100$ In Free Linode Credit: bit.ly/39mrvRM
    //PLATFORMS
    BLOG ►► bit.ly/3qjvSjK
    FORUM ►► bit.ly/39r2kcY
    ACADEMY ►► bit.ly/39CuORr
    //SOCIAL NETWORKS
    TWITTER ►► bit.ly/3sNKXfq
    DISCORD ►► bit.ly/3hkIDsK
    INSTAGRAM ►► bit.ly/3sP1Syh
    LINKEDIN ►► bit.ly/360qwlN
    PATREON ►► bit.ly/365iDLK
    MERCHANDISE ►► bit.ly/3c2jDEn
    //BOOKS
    Privilege Escalation Techniques ►► amzn.to/3ylCl33
    Docker Security Essentials (FREE) ►► bit.ly/3pDcFuA
    //SUPPORT THE CHANNEL
    NordVPN Affiliate Link (73% Off) ►► bit.ly/3DEPbu5
    Get $100 In Free Linode Credit ►► bit.ly/39mrvRM
    Get started with Intigriti: go.intigriti.c...
    //CYBERTALK PODCAST
    Spotify ►► spoti.fi/3lP65jv
    Apple Podcasts ►► apple.co/3GsIPQo
    //WE VALUE YOUR FEEDBACK
    We hope you enjoyed the video and found value in the content. We value your feedback, If you have any questions or suggestions feel free to post them in the comments section or contact us directly via our social platforms.
    //THANK YOU!
    Thanks for watching!
    Благодарю за просмотр!
    Kiitos katsomisesta
    Danke fürs Zuschauen!
    感谢您观看
    Merci d'avoir regardé
    Obrigado por assistir
    دیکھنے کے لیے شکریہ
    देखने के लिए धन्यवाद
    Grazie per la visione
    Gracias por ver
    شكرا للمشاهدة
    -----------------------------------------------------------------------------------
    #Cybersecurity#BlueTeam

Комментарии • 54

  • @DahDaveman
    @DahDaveman 9 месяцев назад +1

    This video can't get enough likes! You helped me work out the bugs in my suricata install, thank you!

  • @primescope6874
    @primescope6874 2 года назад +6

    Great video. You are producing some excellent content as I'm studying cybersecurity. Many thanks and much appreciated. Keep up the good work.

  • @armanqusham5345
    @armanqusham5345 Год назад +1

    Thank you for this detailed video on how to install suricata and configure it. Really helped with my final year project in uni

  • @ChapalPuteh_
    @ChapalPuteh_ 11 месяцев назад +8

    btw, the rules folder for freshly ubuntu vm are stored in usr/share/suricata/rules .. others will face this error when they want to edit the local.rules. Just simply change the mentioned directories ..

    • @umarfarouk7764
      @umarfarouk7764 9 месяцев назад +1

      Thanks a million

    • @hugo_guzman
      @hugo_guzman 5 месяцев назад

      weird, I recently installed ubuntu 22.04, and Suricata, and the rules files are in the /var/lib/suricata/rules directory:
      sudo ls -la /var/lib/suricata/rules/
      total 27580
      drwxr-x--- 2 root root 4096 Mar 27 19:45 .
      drwxr-xr-x 4 root root 4096 Mar 27 19:45 ..
      -rw-r--r-- 1 root root 3228 Mar 27 19:45 classification.config
      -rw-r--r-- 1 root root 28229228 Mar 27 19:45 suricata.rules

  • @samiehessi8163
    @samiehessi8163 Год назад +2

    This was indeed a high quality content. Thanks!

  • @kc_ee
    @kc_ee 2 года назад +2

    You should upload to Rumble as well. I know myself, and a fair chunk of other people are moving away from Google, and I would hate to lose your content.

  • @oshinubirotimirasheed3131
    @oshinubirotimirasheed3131 Год назад

    thank you for sharing this knowledge I look forward to taking more classes from you.

  • @jibraelaryaanentertainment1263
    @jibraelaryaanentertainment1263 Месяц назад

    Just brilliant!!

  • @jiesikkoo7874
    @jiesikkoo7874 3 месяца назад

    Hello, firstly thanks for the video you provided its a big help but i am facing a problem is that the rules i set customly for icmp ping its not working and not generating any alert as you does why is it? your response will be very helpful

  • @FredPhillips32169
    @FredPhillips32169 2 года назад

    Brilliant having the "Register for Part 2" pop up right after an easily edited whoopsie.

  • @tareq06
    @tareq06 8 месяцев назад

    Thank you sir... You made my day

  • @richardbranson8117
    @richardbranson8117 2 года назад +1

    love this man

  • @m-electronics5977
    @m-electronics5977 Год назад

    First: A big thanksgiving for that great video(s) about Suricata und IDS, now I unterstand it also👍👍👍
    But when I want to monitor(not Control) all the traffic that are going in and out of my network I must run the Suricata IDS on a Firewall or router or something like this where the traffic goes trough?

  • @firebeasth8009
    @firebeasth8009 2 года назад +2

    Thanks for this!

    • @sexualsmile
      @sexualsmile 2 года назад

      Its finally here
      ruclips.net/user/shortsNlhBppjxnqs?feature=share

  • @hassanahmed87987
    @hassanahmed87987 2 года назад +1

    When you'll upload next video of suricata??

  • @slevinhyde3212
    @slevinhyde3212 6 месяцев назад

    Definitely is quality content

  • @0xr1kk07
    @0xr1kk07 2 года назад +4

    Hi sir, can you also do a tutorial on ELK installation please. Thank you

    • @kryptonic010
      @kryptonic010 2 года назад +2

      I agree. You know we like to see pretty graphs.

  • @hanishhanish4861
    @hanishhanish4861 2 года назад +1

    Really great !

  • @rafaelhengky8915
    @rafaelhengky8915 9 месяцев назад

    Hi. I managed to install Suricata on VMWare and it has successfully captured ping/icmp packet destinate to it. But it didn't capture any network traffic. Any suggestion?

  • @raymencliff4296
    @raymencliff4296 2 года назад +1

    I like always your video

  • @tyalva1814
    @tyalva1814 Год назад

    I get an error for the update at 11:14 mark [ERRCODE: SC_ERR_CONF_YAML_ERROR(242)] - The configuration file must begin with the following two lines: %YAML 1.1 and ---

  • @0xr1kk07
    @0xr1kk07 2 года назад +2

    Thank you!

  • @Tottte
    @Tottte 6 месяцев назад

    If there are idiots out there like me. You are not supposed to write "1" in the beginning of the rule. You can check the there is any syntax error of the rule with "suricata -c /etc/suricata/suricata.yaml -i [INTERFACE]"

  • @goodboy-mn2qp
    @goodboy-mn2qp 4 месяца назад

    it's very helpful

  • @OthmanAlikhan
    @OthmanAlikhan Год назад

    Thanks for the video =)

  • @Polalis12
    @Polalis12 Год назад

    When I install suricata I do not have config files in /etc/suricata. How to fix that?

  • @dedisubandi3391
    @dedisubandi3391 Год назад

    Great video!!!!!

  • @dedisubandi3391
    @dedisubandi3391 Год назад

    Great video..!!!!

  • @salindabandara4471
    @salindabandara4471 2 года назад +1

    Hello sir. I try update my rule set in suricata. But after give the update-suricata command i got the following error. Err Code: SC_ERR_CONF_YAML_ERROR(242)
    Can you help me to how to handle this error

    • @dhehibiali3283
      @dhehibiali3283 2 года назад +2

      Hi Salinda
      Did you find a solution for this error
      thank you

  • @m-electronics5977
    @m-electronics5977 Год назад

    But Suricata doesn't have a Web UI? I think I saw something about that

  • @onecarry1532
    @onecarry1532 Год назад

    Beautiful!

  • @ae_world_Akash
    @ae_world_Akash 2 года назад +1

    Hi sir I am new subscriber

  • @FredPhillips32169
    @FredPhillips32169 2 года назад

    If you are trying to make the flow ID lees predictable then don't use the default seed of 0.

  • @FredPhillips32169
    @FredPhillips32169 2 года назад

    External_Net != Home_net what about broadcast & multicast?

    • @8080VB
      @8080VB Год назад

      uhh? if you provide the correct gateway/CIDR . everything should be good .

  • @goodboy-mn2qp
    @goodboy-mn2qp 4 месяца назад

    عاشت ايدك

  • @sotecluxan4221
    @sotecluxan4221 2 года назад +1

    Great!

  • @ChapalPuteh_
    @ChapalPuteh_ 11 месяцев назад

    tq sir

  • @atanumondal7879
    @atanumondal7879 Год назад

    14:00

  • @fairyTaleAnimations
    @fairyTaleAnimations 2 года назад +1

    F

  • @MaxesSig8
    @MaxesSig8 2 года назад +1

    first comment

  • @reskun
    @reskun 7 месяцев назад

    would give 100 likes if I could

  • @whothefoxcares
    @whothefoxcares 9 месяцев назад

    I saw the logs. I'm a lumberjack and you're not 🙂 zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz.

  • @sexualsmile
    @sexualsmile 2 года назад

    Its finally here
    ruclips.net/user/shortsNlhBppjxnqs?feature=share

  • @marcostiantoni
    @marcostiantoni Год назад +1

    Thank you for the video. I have the rules only in /usr/share/suricata/rules. How can I get in them in default-rule-path: /var/lib/suricata/rules?

    • @swarajyamdeepakraj-kz4pd
      @swarajyamdeepakraj-kz4pd 9 месяцев назад

      i am also facing the same problem. How you managed>??

    • @marcosfleitas9605
      @marcosfleitas9605 7 месяцев назад +1

      actually all your rules that are in /usr/share/suricata/rules are compiled in /var/lib/suricata/rules suricata.rules