Hola Cominidad, estoy analizando el trafico suricata con el stack de Elastic, y mi duda es sobre las alertas que genera suricata.
Su ayuda interpretando cada alerta y por que surgen. Gracias.
ET INFO UPnP Discovery Search Response vulnerable UPnP device 1
SURICATA HTTP unable to match response to request
ET USER_AGENTS Go HTTP Client User-Agent
SURICATA STREAM Packet with invalid timestamp
SURICATA HTTP too many warnings
SURICATA STREAM excessive retransmissions
Meerkat alerts - explanation and interpretation
Hello Cominidad, I am analyzing the suricata traffic with the Elastic stack, and my question is about the alerts that meerkat generates.
Your help in interpreting each alert and why they arise. Thanks.
ET INFO UPnP Discovery Search Response vulnerable UPnP device 1
SURICATA HTTP unable to match response to request
ET USER_AGENTS Go HTTP Client User-Agent
SURICATA STREAM Packet with invalid timestamp
SURICATA HTTP too many warnings
SURICATA STREAM excessive retransmissions