Rasmus Have Profile picture
IT-security / infosec / detection. Cyber Cyber Cyber. Zeek is better than Suricata. Founder @ Derant. I usually buy LEGO for my kids... and wife.
Sep 24, 2022 13 tweets 5 min read
Ok, so I took a look at detecting the LDAP bruteforcer ldapnomnom (github.com/lkarlslund/lda… by @lkarlslund) with vanilla Zeek (@Zeekurity) and vanilla @Suricata_IDS (w. ET Open). (Thanks to @boller for PCAPs)

Short conclusion: Zeek can detect it, Suricata can't.

#itsecurity
1/12 Zeek unfortunately doesn't have a LDAP protocol decoder in the vanilla install. One is available as a package though, but that's for another thread.

2/12