Thread Reader
Share this page!
×
Post
Share
Email
Enter URL or ID to Unroll
×
Unroll Thread
You can paste full URL like: https://x.com/threadreaderapp/status/1644127596119195649
or just the ID like: 1644127596119195649
How to get URL link on X (Twitter) App
On the Twitter thread, click on
or
icon on the bottom
Click again on
or
Share Via icon
Click on
Copy Link to Tweet
Paste it above and click "Unroll Thread"!
More info at
Twitter Help
Rasmus Have
@rasmusjhave
IT-security / infosec / detection. Cyber Cyber Cyber. Zeek is better than Suricata. Founder @ Derant. I usually buy LEGO for my kids... and wife.
Subscribe
Save as PDF
Sep 24, 2022
•
13 tweets
•
5 min read
Ok, so I took a look at detecting the LDAP bruteforcer ldapnomnom (
github.com/lkarlslund/lda…
by
@lkarlslund
) with vanilla Zeek (
@Zeekurity
) and vanilla
@Suricata_IDS
(w. ET Open). (Thanks to
@boller
for PCAPs)
Short conclusion: Zeek can detect it, Suricata can't.
#itsecurity
1/12 Zeek unfortunately doesn't have a LDAP protocol decoder in the vanilla install. One is available as a package though, but that's for another thread.
2/12