All tools

Defensive / Blue

Suricata

Network IDS/IPS and network security monitoring engine.

advanced
Linux
Defense

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Detecting attack traffic in lab or production networks.

How

Configure capture interface; load rules; review eve.json alerts.

Why

Understand what your scans look like to defenders.

Commands & usage

sudo suricata -c /etc/suricata/suricata.yaml -i eth0
tail -f /var/log/suricata/fast.log

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

ids
network
blue

Related in Defensive / Blue