Coder Social home page Coder Social logo

gradiuscypher / grids Goto Github PK

View Code? Open in Web Editor NEW
63.0 9.0 24.0 541 KB

My network monitoring solution and tools that go along with it.

License: MIT License

Shell 26.86% Python 36.08% Dockerfile 37.06%
security ids monitoring infosec networking

grids's Introduction

grIDS

My network monitoring solution and tools that go along with it. This setup is designed to be contained in an all-in-one sort of system, but services can be separated into individual hosts if you have a higher load that requires more resources.

The goal for this project is to help people combine multiple open-source tools to have a useful network monitoring solution. Within this project, I'll also include custom scripts that help make this system even more useful.

Feedback, corrections, and suggestions are welcomed and appreciated. Reach out to me on Twitter or here on Github as an Issue.

Manual Configuration Steps

Wiki

To get started with configuring the system, follow the steps found in the Wiki. Each of the Configuration sections walks you through the parts of building a working all-in-one IDS system.

Docker Configuration Steps

To deploy the NSM via Docker containers, follow the instructions found under the Docker Configuration section of the Wiki.

Screenshots

Screenshots of some Kibana Dashboards that have been created and powered using this setup

DASH1 DASH2

Future Additions + Modifications + Ideas

This is a list of future tools that could be added to this toolset for even more features. Also includes modifications.

Features

  • Sysmon logging
  • Bro logging
  • Centralized Logging
  • Webhook integration for alerts
  • FPC and usability tools
  • Pi-Hole DNS service
  • Include EveBox for alerting
  • Include Scirius rule management.

Modifications

  • Performance tuning for Elastic Stack
  • Performance tuning of Suricata - spread load between CPU threads

Ideas

  • IDS Sensor on a Raspberry Pi
  • Spreading services out among hosts, multiple sensor configuration and management
  • Setting up an iptables sensor
  • Setting up a hardware network tap
  • Process for upgrading/updating the OS

grids's People

Contributors

airencracken avatar gradiuscypher avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

grids's Issues

Python tooling for rule updates

Need to put together some tools for updating the Suricata rules in the Docker container.

Also need to consider actually tuning the rules and picking particular sections of ET's rulesets. Could also write a script to help users pick the right rulesets.

Automated Setup Scripts

Automated scripts for each section of setup, using something like Chef/Ansible preferred.

Suricata is configured to a specific interface

Suricata is configured to use a specific interface name. This will more than likely not match other's hardware, so we need a way to change the interface name, either during a script or letting the user know they need to change the interface name.

Logstash not generating index

On the docker configuration when i launch the logstash container it doesnt create an index in kibana.

Ignoring the 'pipelines.yml' file because modules or command line options are specified.
No persistent UUID file found. Generating new UUID.
Untitled

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.