OTRF / 2021-OceanLotus-workshop

MIT License
18 stars 4 forks source link

Research Network Visibility Options #11

Closed plugxor closed 3 years ago

plugxor commented 3 years ago

Youtube video on setup: https://www.youtube.com/watch?v=ZYr8Uc3PJJQ

https://docs.amazonaws.cn/en_us/vpc/latest/mirroring/traffic-mirroring-filter.html#create-traffic-mirroring-filter

https://docs.amazonaws.cn/en_us/vpc/latest/mirroring/tm-example-open-source.html

Network tap requires using NITRO instances. IDK what NITRO is but based on simple searches seems like a more featured EC2 or EC2 2.0.

Since this is possible I recommend we setup Zeek and Suricata to monitor the network.

plugxor commented 3 years ago

Please look into Google Cloud Network Visibility Options as well.

CptOfEvilMinions commented 3 years ago

https://github.com/OTRF/macos-workshops/blob/main/terraform/public_ec2.tf#L131

This has been implemented in Terraform. Only requirement is all EC2 instances need to be using the NITRO system which is t3