linux-malware-detect
Suricata
linux-malware-detect | Suricata | |
---|---|---|
4 | 23 | |
1,121 | 4,121 | |
- | 4.1% | |
4.5 | 9.9 | |
7 months ago | 2 days ago | |
Shell | C | |
GNU General Public License v3.0 only | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
linux-malware-detect
-
Who does check linux distros of malware - open source
Linux has (free) tools to improve security and detect/remove malware: Lynis,Chkrootkit,Rkhunter,ClamAV,Vuls,LMD,radare2,Yara,ntopng,maltrail,Snort,Suricata...
-
WordPress store customers info getting compromised help
Unfortunately yes. On the plus side, this will help ensure they can't get in again. One more thing to add that list... You can use maldet to check for malware/compromised files. It's not the best malware scanner, but it's free and can help find malware in other hidden folders/files: https://www.rfxn.com/projects/linux-malware-detect/
-
What affordable anti-malware suites are available for Zorin Lite?
there is also linux-malware-detect - maldet -- https://www.rfxn.com/projects/linux-malware-detect/ [github repo] -- which can work in tangent with what you mentioned, ClamAV, but is not a requirement for operation..
-
Good way to backup systemctl services?
when the package being installed is intended to be ran as a systemd service, the PKGBUILD file, which we'll reference maldet's as an example, contains a line with a command, see line 107, that places the service file, in our case this file into the location specified, /usr/lib/systemd/system/maldet.service.
Suricata
- Aho-Corasick Algorithm
-
Suricata VS zeek - a user suggested alternative
2 projects | 2 Jan 2024
-
Who does check linux distros of malware - open source
Linux has (free) tools to improve security and detect/remove malware: Lynis,Chkrootkit,Rkhunter,ClamAV,Vuls,LMD,radare2,Yara,ntopng,maltrail,Snort,Suricata...
-
Risks of hosting a website out of my house
Monitoring & Active Measures - Exporting firewall events to an external time-series database like I describe above is good to see who is touching your firewall or accessing your web site. Using an Intrusion Detection System / Intrusion Prevention System (IDS/IPS) such as open-source Suricata, which is a free package on pfSense, and deploying file system integrity monitoring, such as the open-source Wazuh on the exposed server are also good approaches to protecting yourself.
-
SIEM or IDPS for Homelab on rPi 3b
You could try running Suricata
-
Detecting Hackers in the network
Check out https://suricata.io/
-
Where can I get hands on practice for cybersecurity as a beginner over internet for free?
Suricata: https://suricata.io/ IDS/IPS
-
Server Hardening
Active Measures - Includes (IDS/IPS) such as open-source Suricata or Snort on pfSense, and File Integrity Monitoring (FIM), such as the commercial Tripwire and dated, open-source Tripwire, or the open-source Wazuh installed on servers. These can be combined into a Security Information and Event Management (SIEM) system like the open-source solution, Security Onion. Wazuh itself has evolved into a SIEM.
-
Help with server build
Active measures may include an intrusion detection system / intrusion prevention systems (IDS/IPS) such as open-source Suricata on the firewall, and installing file system integrity monitoring, such as the open-source Wazuh on the exposed server. These are combined in one open-source solution, Security Onion
- Need Help - Network Monitor & Security
What are some alternatives?
clamav - ClamAV - Documentation is here: https://docs.clamav.net
Wazuh - Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
svntogit-packages - Automatic import of svn 'packages' repo (read-only mirror)
Fail2Ban - Daemon to ban hosts that cause multiple authentication errors
crowdsec - CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.
OSSEC - OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
pfSense - Main repository for pfSense
maltrail - Malicious traffic detection system
Snort - Snort++
OSQuery - SQL powered operating system instrumentation, monitoring, and analytics.
arkime - Arkime is an open source, large scale, full packet capturing, indexing, and database system.
docker-zeek - Run zeek with zeekctl in docker