suriwire

Wireshark plugin to display Suricata analysis info

  • 所有者: regit/suriwire
  • 平台:
  • 許可證: GNU General Public License v3.0
  • 分類:
  • 主題:
  • 喜歡:
    0
      比較:

Github星跟蹤圖

========
Suriwire

Introduction

Suriwire is a plugin for wireshark that allow you to display
suricata alert and protocol information as element of the
protocol dissection.

.. image:: https://github.com/regit/suriwire/raw/master/doc/suriwire.png
:alt: wireshark screenshot with suriwire generated info
:align: center

Suriwire has parsing for the following events:

  • Alerts
  • HTTP
  • fileinfo
  • TLS
  • SSH
  • SMB

For example, the preceding screenshot shows how it is possible to search for
TLS session where the subject of the certificate matches a certain string.

Installation

Copy or link suriwire.lua to your wireshark plugin directory. For a user,
this is ~/.wireshark/plugins/.

Suriwire depends on cjson JSON library with a fallback on dkjson library.

Usage

Run externally suricata on the pcap file you study to create a
suitable alert file. You need to use the EVE output format.
To specify a directory to output files to, you can use the -l
flag in suricata ::

suricata -r sample.pcap -l log/

Then you will be able to use the log/eve.json file.

In wireshark, open the pcap file and go to Tools->Suricata->Activate.
Then enter the name of the EVE file. This will parse again the file adding
all Suricata generated information.

You can also indicate which EVE file to parse at start by running something
like: ::

SURIWIRE_EVE_FILE=log2/eve.json wireshark sample.pcap

You will now find information about the alerts and other events:

  • In the detail of a packet under Suricata analysis element
  • In Analyse->Expert Info Composite

You can also filter on the suricata protocol. The protocol has
fields like suricata.alert.sid and suricata.tls.subject which can be used
in filter.

If you reuse the same eve.json file, you can set the default path in the
protocol preferences inside wireshark.

More information on https://home.regit.org/software/suriwire.

主要指標

概覽
名稱與所有者regit/suriwire
主編程語言Lua
編程語言Lua (語言數: 1)
平台
許可證GNU General Public License v3.0
所有者活动
創建於2011-09-28 23:12:52
推送於2021-11-05 07:46:02
最后一次提交2021-11-04 13:56:26
發布數3
最新版本名稱suriwire-0.3 (發布於 )
第一版名稱suriwire-0.1 (發布於 2014-06-16 11:36:49)
用户参与
星數94
關注者數3
派生數12
提交數51
已啟用問題?
問題數2
打開的問題數2
拉請求數1
打開的拉請求數0
關閉的拉請求數0
项目设置
已啟用Wiki?
已存檔?
是復刻?
已鎖定?
是鏡像?
是私有?