Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Using Custom Rules and Scripts #436

Open
mmguero opened this issue Nov 5, 2024 · 0 comments
Open

Using Custom Rules and Scripts #436

mmguero opened this issue Nov 5, 2024 · 0 comments
Labels
carving Relating to carving (extraction) of files from traffic and the scanning of those files suricata Relating to Malcolm's use of Suricata train-configuration Training topic relating to installation or configuration training Related to developing and releasing Malcolm training zeek Relating to Malcolm's use of Zeek

Comments

@mmguero
Copy link
Collaborator

mmguero commented Nov 5, 2024

@mmguero cloned issue idaholab/Malcolm#361 on 2024-01-15:

For what topic would you like to see training developed?

Go over how to use custom configuraiton for Suricata, YARA, Zeek, etc.

What format would be best suited for this training?

A video

Is there existing Malcolm documentation that could be improved by including this topic?

Custom Rules and Scripts

@mmguero mmguero added carving Relating to carving (extraction) of files from traffic and the scanning of those files suricata Relating to Malcolm's use of Suricata train-configuration Training topic relating to installation or configuration training Related to developing and releasing Malcolm training zeek Relating to Malcolm's use of Zeek labels Nov 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
carving Relating to carving (extraction) of files from traffic and the scanning of those files suricata Relating to Malcolm's use of Suricata train-configuration Training topic relating to installation or configuration training Related to developing and releasing Malcolm training zeek Relating to Malcolm's use of Zeek
Projects
Status: No status
Development

No branches or pull requests

1 participant