datboyblu3 / Vile-The-Purple-Ranger

Using Terraform and Ansible to build and configure the overall infrastructure, this repo will be a cyber range for red teams to carry out attacks and for blue teams to counter with detections and mitigations.
MIT License
3 stars 0 forks source link

Create Suricata IDS/IPS #11

Open datboyblu3 opened 6 months ago

datboyblu3 commented 6 months ago

Tasks

Install and configure the Suricata IDS/IPS device according to Wazuh's "Network IDS integration" documentation.

Summary:

"Wazuh integrates with a network-based intrusion detection system (NIDS) to enhance threat detection by monitoring network traffic. In this use case, we demonstrate how to integrate Suricata with Wazuh. Suricata can provide additional insights into your network's security with its network traffic inspection capabilities."