Suricata Tutorial FloCon 2016 Agenda ● Setup ● Introduction to Suricata ● Suricata as a SSL monitor ● Suricata as a passive DNS probe ● Suricata as a flow probe ● Suricata as a malware detector VirtualBox setup ● File -> Preferences ○ Apple: ‘VirtualBox -> Preferences’ ● Network -> Host Only Network (tab) ● Add network vboxnet0 VirtualBox Port Forwards ● 2222 SSH ● 5601 Kibana4 ● 5636 Evebox ● 800