Filter
Exclude
Time range
-
Near
عبدالله محمد القحطاني retweeted
9 Jun 2025
1
6
1,141
Day 38 – #100DaysOfCybersecurity 🔐 Today, I continued working on my NIDS project and focused on configuring and troubleshooting Suricata. I ran into several challenges that highlighted how fragile IDS visibility can be when misconfigured. Challenges I encountered: - My IDS sensor interface was not in promiscuous mode, so it couldn’t see traffic traversing the infrastructure (victim) server. → Attacks were happening, but Suricata had no visibility. - Suricata logs were stored in pretty-printed JSON, which made correlation and CLI parsing with tools like jq harder than with line-delimited JSON. - I initially bound Suricata to the wrong network interface, so no alerts were generated even though rules were correct. - My custom SSH detection rule failed due to HOME_NET misconfiguration, causing Suricata to treat the victim as out-of-scope. - Debugging required repeated restarts and config validation, reinforcing how small misconfigurations can completely break IDS visibility. Key takeaway: Today’s work reinforced that an IDS is only effective if: - It is listening on the correct interface - It has proper network visibility - Its logs are usable for analysis Even when attacks are occurring, detection fails if the sensor cannot see or correctly interpret the traffic. These challenges gave me hands-on insight into real-world NIDS tuning and troubleshooting, and they set a strong foundation for improving my detection logic and log analysis in the next phase of the project. Next: Refine rules, fix logging format, and begin correlating Suricata alerts with attacker activity. On to Day 39. 🛡️📊 @jay_hunts @ireteeh @segoslavia #RedTeamer #NIDS #Suricata #SOC #CyberSecurityLab #LearningInPublic #100DaysOfCybersecurity
3
4
9
297
Proud Moment for GSFC University! Cyber Security Lab Launched – Where Innovation Meets Vigilance We’re thrilled to unveil the Cyber Security Lab, an ambitious initiative by the Department of Computer Engineering, School of Technology, GSFC University #CyberSecurityLab
3
59
Cybersecurity virtual lab in VMware Fusion on M1 Mac - Part 7: Setting up Wazuh (SIEM/XDR) on Ubuntu This walk through covers setting up Wazuh SIEM/XDR unified solution for security monitoring and incident response in a lab environment #CybersecurityLab #Wazuh #SIEM #XDR #EDR
3
146
Cybersecurity virtual lab in VMware Fusion on M1 Mac - Part 6: Setting up MySQL Server on Ubuntu This walk through covers setting up MySQL Server on Ubuntu 24.04.2 LTS #CybersecurityLab #MySQL
2
106
Cybersecurity virtual lab in VMware Fusion on M1 Mac - Part 5: Setting up Apache HTTP Server on Ubuntu This walk through covers setting up Apache HTTP Server on Ubuntu 24.04.2 LTS #CybersecurityLab #Apache2 #Apache #HTTPServer
2
103
Cybersecurity virtual lab in VMware Fusion on M1 Mac - Part 4: Configuring Suricata on the Debian IDS/IPS This walk through covers configuring Suricata in IDS mode on the Debian firewall #CybersecurityLab #Suricata #IDS #IPS
2
96
Here's a 360 tour of Wisconsin International University College's cutting-edge Cybersecurity & Digital Forensics Lab - where the next generation of digital defenders is trained. #wiuc #CyberSecurityLab #DigitalForensics #tech #360View
2
115
Cybersecurity virtual lab in VMware Fusion on M1 Mac - Part 3: Configuring nftables on the Debian firewall This walk through covers configuring nftables on the Debian firewall #CybersecurityLab #nftables
2
112
Cybersecurity virtual lab in VMware Fusion on M1 Mac - Part 2: Testing/troubleshooting network connectivity This walk through covers configuring firewall NAT rules using the command line and testing/troubleshooting network connectivity #CybersecurityLab #network #troubleshooting
2
86
Cybersecurity virtual lab in VMware Fusion on M1 Mac - Part 1: Lab design and configuring interfaces This walk through covers the lab design, setting up the VMware Fusion network and virtual switch, and configuring the interfaces of the network devices #CybersecurityLab #VMware
2
78
Photo Highlight: The New Cybersecurity Laboratory sponsored by Mr. Emmanuel Sekyere Asiedu, the CEO of Virtual Infosec Africa Photo Credit: Highest Point Experience #cybersecurity #cybersecuritylab #VirtualAfrica
9
194
8 Nov 2023
@STAexcels has a cutting-edge #CybersecurityLab, equipped with the latest tech and simulations. Ready to dive into real-world scenarios, hands-on training, and expert guidance? Join us on the frontlines of digital defense! 💻🛡️ #Cybersecurity #TechInnovation #SecureTheFuture
1
2
36
Il 31 maggio non perdere l'appuntamento con l'evento "ANATOMIA DI UN ATTACCO INFORMATICO", organizzato in collaborazione con @Certego_IRT, @Fortinet , #ClubBIT e #CyberSecurityLab, che si svolgerà presso UNIS&F LAB dalle ore 9:00! vem.com/eventi/anatomia-atta…
1
1
Live from "Research Driven Education in Cybersecurity" as part of #CyberSecurityLab at #Intersecexpo with the speaker Dr. Ernesto Damiani, Khalifa University Center for Cyber Physical Systems (C2PS) & Professor, Electrical Engineering and Computer Science, Khalifa University
1
CYBERSECURITY LAB @ INTERSEC 2022 Monday 17/01/2022 I will be speaker at #CyberSecurityLab @ #Intersec2022 talking about the role of #CyberSecurity in reducing the #gendergaps. intersec.ae.messefrankfurt.c… @Intersecexpo #paneldiscussion #sofiascozzari #hackmanac
2
2
Being a part of a community feels good, but being a part of Nasscom makes it even more exciting. Expecting a lot of fruitful days with Nasscom #nasscom #nasscomcommunity #cybersecurity #vulnerability #security #it #informationtechnology #wattlecorp #cybersecuritylab #kozhikode
4
Increase speed 🚀 of obtaining #certification in order to comply with the time to market of the #ICT products is one of the major challenges ahead. Is #automation the future? #jtsec #ICCC21 #Commoncriteria #cybersecuritylab #cybersecuritystandard jtsec.es/blog-entry/99/is-au…
1
2
Es ist @CyberSecMonth. Bei Reply sind wir bereit: Entdecke unser neuestes #CybersecurityLab powered by #SpikeReply! Entdecke, wie sich Unternehmen heute gegen Cyberangriffe wappnen müssen und vereinbare einen Besuch: bit.ly/CybersecurityLab_TWDE #CyberSecMonth
1
2