running ids rules on tracee-ebpf #2967
Unanswered
Ofekitach
asked this question in
Questions and Help
Replies: 1 comment
-
Indeed it is possible to write IDS rules similar to the those you pointed to, but one would have to convert them to either go or rego first, and use the matching tracee-ebpf events to write those rules. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I was wondering, if you can run tracee-rules on certain events, why not running ids rules (like:snort, zeek...) on accept\connect\bind events.
example of rules set:
https://rules.emergingthreats.net/open/suricata/rules/
Beta Was this translation helpful? Give feedback.
All reactions