Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. My suricon talk got accepted

My suricon talk got accepted

Scheduled Pinned Locked Moved Uncategorized
8 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • da_667@infosec.exchangeD This user is from outside of this forum
    da_667@infosec.exchangeD This user is from outside of this forum
    da_667@infosec.exchange
    wrote last edited by
    #1

    My suricon talk got accepted

    I'm doing a double-header on some new suricata features I've been messing with recently, along with a discussion on exploit reproduction for detection engineers.

    gl0ck@infosec.exchangeG da_667@infosec.exchangeD neurovagrant@masto.deoan.orgN 3 Replies Last reply
    1
    0
    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
    • da_667@infosec.exchangeD da_667@infosec.exchange

      My suricon talk got accepted

      I'm doing a double-header on some new suricata features I've been messing with recently, along with a discussion on exploit reproduction for detection engineers.

      gl0ck@infosec.exchangeG This user is from outside of this forum
      gl0ck@infosec.exchangeG This user is from outside of this forum
      gl0ck@infosec.exchange
      wrote last edited by
      #2

      @da_667 W00P W00P

      1 Reply Last reply
      0
      • da_667@infosec.exchangeD da_667@infosec.exchange

        My suricon talk got accepted

        I'm doing a double-header on some new suricata features I've been messing with recently, along with a discussion on exploit reproduction for detection engineers.

        da_667@infosec.exchangeD This user is from outside of this forum
        da_667@infosec.exchangeD This user is from outside of this forum
        da_667@infosec.exchange
        wrote last edited by
        #3

        for some of the new features, I definitely want to highlight the availability of websocket protocol support. I also plan on talking about nDPI features, and how the requires keyword will make experimenting with new features in the ET ruleset fairly easy.

        The second half of the presentation is a sort of (somewhat) live presentation on some stuff I do when I have access to a proof of concept exploit. What do you do when you have proof of concept code, but don't have easy access to the software or the device that is actually vulnerable? Turns out, getting a pcap for these cases isn't very difficult, and gives you what you need to write rules for it.

        da_667@infosec.exchangeD 1 Reply Last reply
        0
        • da_667@infosec.exchangeD da_667@infosec.exchange

          for some of the new features, I definitely want to highlight the availability of websocket protocol support. I also plan on talking about nDPI features, and how the requires keyword will make experimenting with new features in the ET ruleset fairly easy.

          The second half of the presentation is a sort of (somewhat) live presentation on some stuff I do when I have access to a proof of concept exploit. What do you do when you have proof of concept code, but don't have easy access to the software or the device that is actually vulnerable? Turns out, getting a pcap for these cases isn't very difficult, and gives you what you need to write rules for it.

          da_667@infosec.exchangeD This user is from outside of this forum
          da_667@infosec.exchangeD This user is from outside of this forum
          da_667@infosec.exchange
          wrote last edited by
          #4

          fuck, now I have to write a slide deck.

          da_667@infosec.exchangeD rajiv@infosec.exchangeR fritzadalis@infosec.exchangeF 3 Replies Last reply
          0
          • da_667@infosec.exchangeD da_667@infosec.exchange

            fuck, now I have to write a slide deck.

            da_667@infosec.exchangeD This user is from outside of this forum
            da_667@infosec.exchangeD This user is from outside of this forum
            da_667@infosec.exchange
            wrote last edited by
            #5

            but on the bright side, I get to go to Lisbon, Portugal.

            also FUCK. I should probably learn a little bit of Portuguese.

            1 Reply Last reply
            0
            • da_667@infosec.exchangeD da_667@infosec.exchange

              fuck, now I have to write a slide deck.

              rajiv@infosec.exchangeR This user is from outside of this forum
              rajiv@infosec.exchangeR This user is from outside of this forum
              rajiv@infosec.exchange
              wrote last edited by
              #6

              @da_667 LOL. guess what I am doing right now. I will create a 15 slides deck. which my manager will reduce down to 8 slides, his manager down to 4 and at the final presentation it will be one line in someone else's slide deck.

              story of our lives 😞

              1 Reply Last reply
              0
              • da_667@infosec.exchangeD da_667@infosec.exchange

                My suricon talk got accepted

                I'm doing a double-header on some new suricata features I've been messing with recently, along with a discussion on exploit reproduction for detection engineers.

                neurovagrant@masto.deoan.orgN This user is from outside of this forum
                neurovagrant@masto.deoan.orgN This user is from outside of this forum
                neurovagrant@masto.deoan.org
                wrote last edited by
                #7

                @da_667 congrats!

                1 Reply Last reply
                0
                • da_667@infosec.exchangeD da_667@infosec.exchange

                  fuck, now I have to write a slide deck.

                  fritzadalis@infosec.exchangeF This user is from outside of this forum
                  fritzadalis@infosec.exchangeF This user is from outside of this forum
                  fritzadalis@infosec.exchange
                  wrote last edited by
                  #8

                  @da_667
                  Wing it.

                  1 Reply Last reply
                  0
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups