share_log

Stamus Networks Marks Decade of SELKS Open-Source Tool With New Edition

Stamus Networks Marks Decade of SELKS Open-Source Tool With New Edition

Stamus Networks用新版SELKS开源工具庆祝其10周年纪念
PR Newswire ·  06/13 09:00

Free Suricata-based threat detection and hunting platform builds on open-source legacy with powerful new capabilities

基于 Suricata 的免费威胁检测和狩猎平台建立在开源遗产的基础上,具有强大的新功能

INDIANAPOLIS and PARIS, June 13, 2024 /PRNewswire/ -- Stamus Networks, a global provider of high-performance network-based threat detection and response systems, today announced the general availability of SELKS 10, the latest version of its turnkey Suricata-based network intrusion detection/protection (IDS/IPS), network security monitoring (NSM) and threat hunting system. The new edition, which commemorates SELKS' 10th anniversary, builds on its open-source legacy with powerful new features that enable organizations to enhance network detection and security monitoring.

印第安纳波利斯和巴黎,2024 年 6 月 13 日 /PRNewswire/-- Stamus 网络是基于网络的高性能威胁检测和响应系统的全球提供商,今天宣布全面上市 卖出 10,其基于SuriCata的统包式网络入侵检测/防护(IDS/IPS)、网络安全监控(NSM)和威胁搜寻系统的最新版本。新版本是为了纪念 SELKS 的 10第四 周年纪念,建立在其开源遗产的基础上,具有强大的新功能,使组织能够增强网络检测和安全监控。

Created in 2014 and available for free, SELKS is a suitable production-grade IDS/IPS and NSM solution for small-to-medium sized organizations. Because all the data available in SELKS is generated by the Suricata engine, it is widely used by network security practitioners, researchers, educators, students and hobbyists to explore what is possible with Suricata IDS/IPS/NSM and the network protocol monitoring logs and alerts it produces.

SELKS创建于2014年,免费提供,是一款适合中小型组织的生产级IDS/IPS和NSM解决方案。由于SELKS中的所有可用数据均由Suricata引擎生成,因此网络安全从业人员、研究人员、教育工作者、学生和业余爱好者广泛使用它来探索Suricata IDS/IPS/NSM及其生成的网络协议监控日志和警报所能带来的可能性。

"We originally created SELKS 10 years ago as a tool to showcase the power of Suricata, and it evolved into a complete and truly useful system for smaller organizations that don't have the extensive budget and resources that enterprises do," said Peter Manev, co-founder and chief strategy officer, Stamus Networks. "Believing every organization should have the opportunity to secure their business from cyber threats, we chose to invest in SELKS to help those that can't afford a commercial solution. SELKS 10 is the latest demonstration of our continued commitment to empowering defenders with the resources they need to elevate their network monitoring and threat hunting capabilities."

Stamus Networks联合创始人兼首席战略官彼得·马内夫表示:“我们最初在10年前创建SELKS是为了展示Suricata的力量,现在它已发展成为一个完整而真正有用的系统,适用于没有像企业那样大量预算和资源的小型组织。”“我们相信每个组织都应该有机会保护其业务免受网络威胁,因此我们选择投资SELKS,以帮助那些负担不起商业解决方案的人。SELKS 10是我们持续致力于为防御者提供提升网络监控和威胁捕猎能力所需的资源的最新体现。”

Key enhancements in SELKS 10 include:

SELKS 10 的主要增强功能包括:

  • User interface harmonized with the Stamus Security Platform (SSP) - The SELKS user interface has been updated to incorporate the latest capabilities of SSP, the company's commercial solution. The simplified user experience delivers consolidated threat detection and hunting and evidence views, which provides rapid insights from millions of network security events.
  • Conditional packet capture - SELKS 10 can now capture packets (PCAP) associated with alerts. Users have access to critical network forensic data that may be used for investigation, training or threat intelligence sharing without dedicating substantial storage resources required for full-time packet capture.
  • Arkime version 5.0 features - SELKS 10 adds the latest capabilities of Arkime bulk search, improved session detail display, unified configurations, unified authentication, JA4 support, additional multi-viewer support and offline PCAP retrieval improvements.
  • PostgreSQL database - SELKS 10 is now using a PostgreSQL database instead of SQLite to fix known issues, augment capabilities, improve scalability and prepare for future evolution.
  • 与 Stamus 安全平台协调的用户界面 (SSP) -SELKS用户界面已更新,纳入了该公司的商业解决方案SSP的最新功能。简化的用户体验可提供整合的威胁检测、搜寻和证据视图,从而从数百万个网络安全事件中快速获得见解。
  • 有条件的数据包捕获 -SELKS 10 现在可以捕获与警报相关的数据包 (PCAP)。用户可以访问可用于调查、培训或威胁情报共享的关键网络取证数据,而无需专用于全时数据包捕获所需的大量存储资源。
  • Arkime 版本 5.0 功能 -SELKS 10 添加了 Arkime 批量搜索的最新功能、改进的会话详细信息显示、统一配置、统一身份验证、JA4 支持、额外的多画面支持和离线 PCAP 检索改进。
  • PostgreSQL 数据库 -SELKS 10现在使用PostgreSQL数据库而不是SQLite来修复已知问题、增强功能、提高可扩展性并为未来的发展做准备。

SELKS is maintained by Stamus Labs, the company's open-source software and threat research team. In addition to its extensive contributions to Suricata itself, the Stamus Labs team has a rich history of open-source involvement, including introducing a set of free newly registered domain threat intelligence feeds optimized for Suricata as well as the Suricata Language Server to help streamline the rule writing process. Additionally, the team has provided a free Suricata ruleset specifically focused on detecting lateral movement in Microsoft Windows environments and published a "Security Analyst's Guide to Suricata."

SELKS 由以下人员维护 Stamus 实验室,该公司的开源软件和威胁研究小组。除了对Suricata本身的广泛贡献外,Stamus Labs团队还拥有丰富的开源参与历史,包括推出了一套免费的 新注册的域名威胁情报源 针对 Suricata 进行了优化,还有 Suricata 语言服务器 帮助简化规则编写过程。此外,该团队还提供了 免费的 Suricata 规则集 专门研究检测微软Windows环境中的横向移动,并发布了”安全分析师的 Suricata 指南。”

Additional Resources

其他资源

  • To learn more about SELKS 10 features, read this blog article.
  • To learn more about the 10 year history of SELKS, read last week's blog.
  • To download SELKS, visit: .
  • 要了解有关 SELKS 10 功能的更多信息, 阅读这篇博客文章
  • 要了解有关SELKS10年历史的更多信息, 阅读上周的博客
  • 要下载 SELKS,请访问:

About Stamus Networks:
Stamus Networks believes in a world where defenders are heroes, and a future where those they protect remain safe. As organizations face threats from well-funded adversaries, we relentlessly pursue solutions that make the defender's job easier and more impactful. The global leader in Suricata-based network security solutions, Stamus Networks helps enterprise security teams know more, respond sooner and mitigate their risk with insights gathered from cloud and on-premise network activity. Our Stamus Security Platform combines the best of intrusion detection (IDS), network security monitoring (NSM), and network detection and response (NDR) systems into a single solution that exposes serious and imminent threats to critical assets and empowers rapid response. For more information visit: stamus-networks.com.

关于 Stamus 网络:
Stamus Networks相信一个捍卫者是英雄的世界,以及他们所保护的人可以保持安全的未来。当组织面临来自资金充足的对手的威胁时,我们坚持不懈地寻求使防御者的工作更轻松、更具影响力的解决方案。Stamus Networks是基于Suricata的网络安全解决方案的全球领导者,通过从云和本地网络活动中收集的见解,帮助企业安全团队了解更多,更快地做出响应并降低风险。我们的 Stamus 安全平台将最佳的入侵检测 (IDS)、网络安全监控 (NSM) 和网络检测与响应 (NDR) 系统整合到一个解决方案中,该解决方案可暴露关键资产面临的严重和迫在眉睫的威胁,并实现快速响应。欲了解更多信息,请访问: stamus-网络.com

SOURCE Stamus Networks

来源 Stamus 网络

声明:本内容仅用作提供资讯及教育之目的,不构成对任何特定投资或投资策略的推荐或认可。 更多信息
    抢沙发