Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
squert – an open source UI for NSM data
Search
paulh
April 17, 2015
Technology
70
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
squert – an open source UI for NSM data
AtlSecCon, Halifax. 2015
paulh
April 17, 2015
More Decks by paulh
See All by paulh
Beginners Guide to OSINT
paulh
1
430
squert - an open source UI for NSM data
paulh
0
370
System Compliance on a Budget
paulh
0
59
Internet Safety
paulh
0
140
Situational Awareness with Open Source Tools
paulh
0
120
Network Security Monitoring with Open Source Tools
paulh
0
200
Other Decks in Technology
See All in Technology
【Snowflake Summit 2026 Recap!!】Snowflake Summit Deep Dive: Security & Governance
civitaspo
1
180
新しいVibe Codingと”自走”について
watany
6
320
AIはどのように 組織のアジリティを変えるのか?
junki
3
790
Bucharest Tech Week 2026 - Reinventing testing practices in the AI era
edeandrea
PRO
1
160
Oracle AI Database@Google Cloud:サービス概要のご紹介
oracle4engineer
PRO
6
1.5k
AIエージェントが名古屋の猛暑からあなたを守る
happysamurai294
0
120
【NRUG vol.18】KubernetesにおけるNew Relicデータ取得量削減の考え方
nrug_member
0
120
機械学習を「社会実装」するということ 2026年夏版 / Social Implementation of Machine Learning June 2026 Version
moepy_stats
5
2.4k
Kiroで書いた 設計書 が AI レビューの 採点基準 になる
ezaki
0
110
GitHub Copilot 最新アップデート – 「一歩先」の実践活用術
moulongzhang
2
350
FinOps × AIエージェントで実現する コストインシデントの自動調査
oasis1994liveforever
0
140
RAG を使わないという選択肢
tatsutaka
1
230
Featured
See All Featured
Joys of Absence: A Defence of Solitary Play
codingconduct
1
390
How GitHub (no longer) Works
holman
316
150k
Fantastic passwords and where to find them - at NoRuKo
philnash
52
3.7k
The Myth of the Modular Monolith - Day 2 Keynote - Rails World 2024
eileencodes
28
3.5k
Jess Joyce - The Pitfalls of Following Frameworks
techseoconnect
PRO
1
170
A brief & incomplete history of UX Design for the World Wide Web: 1989–2019
jct
2
400
Being A Developer After 40
akosma
91
590k
Marketing to machines
jonoalderson
1
5.4k
HU Berlin: Industrial-Strength Natural Language Processing with spaCy and Prodigy
inesmontani
PRO
0
410
How Fast Is Fast Enough? [PerfNow 2025]
tammyeverts
3
610
What does AI have to do with Human Rights?
axbom
PRO
1
2.2k
Leo the Paperboy
mayatellez
7
1.8k
Transcript
None
None
None
None
None
None
None
None
5 to 10 MHz FTW! READY 10 PRINT HELLO ATLSECCON!
“ ” 20 GOTO 10 RUN
None
and security?
IRC PHRACK 2600 QUAKE HACKING EXPLORING BUGTRAQ #hack Road trip!
vegas
squert – an open source web interface for NSM data
paul halliday | AtlSecCon, Halifax 2015
we are going to talk about project history ~$ echo
'Big Data' | sed 's/Big/Just plain old/' interface design and UX
Sguil: The Analyst Console for Network Security Monitoring < tcl/tk
> sguild New York Toronto Halifax Tokyo ALERT! ALERT! ALERT! Analyst console(s) ACKNOWLEDGED
21 Locations 13 Campuses 2 Data Centers ..links, links, and
more links
so why make squert?
“Written By Analysts, For Analysts”
p r o b l e m no analysts lack
of summary information no visuals or helpers
s o l u t i o n
version 0.1.0 < php >
version 0.6.0 ip2c.tcl – afrinic | apnic | arin |
lacnic | ripe -> to MySQL
then in 2008 NSM in minutes! batteries included, no assembly
required enter
version 0.9.0
p r o b l e m static content missing
basic functionality no workflow
client server what's up? architecture fail questions answers
None
???
version 1.0.0 < js > missing a ton of stuff
-but- ready to grow
the data
Suricata: Open source Intrusion Detection System ids_agent disk sguild MySQL
client pcap_agent packet capture unified log realtime event context
Bro: Open source Network Security Monitor disk sguild MySQL client
bro_agent intel.log notice.log realtime event
Syslog-ng: Environment logs disk ElasticSearch client logstash LOGS syslog-ng context
The Bro Intel Framework #fields indicator indicator_type meta.source meta.url meta.do_notice
meta.if_in 000007.ru Intel::DOMAIN MalwareDomains http://malwaredomains.com/files/justdomains F - 01100001 00100000 01110111 01101000 01101111 01101100 01100101 00100000 01100010 01110101 01101110 01100011 01101000 00100000 01101111 01100110 00100000 01100100 01100001 01110100 01100001 00100000 01101000 01100101 01110010 01100101 00100001 00100001 intel metadata controls Intel::ADDR Intel::URL Intel::SOFTWARE Intel::EMAIL Intel::DOMAIN Intel::USER_NAME Intel::FILE_HASH Intel::FILE_NAME Intel::CERT_HASH Intel Types Intel.log !
where can I get intel? Search GitHub Reports (parsers available)
Critical Stack Intel Marketplace :)
None
None
None
the interface
using filters ip 10.0.0.5,192.168.0.6,172.16.0.7 stvl shell: explicit:
creating filters
None
Working in the queue when we first saw this grouped
by Signature grouped by IP
None
context menu
None
results pulled in from ElasticSearch
context menu
adding items to the context menu
Alert classification
summary tab
None
None
None
None
views tab
None
None
Twitter: @01110000 GitHub: int13h Thanks! www.pintumbler.org