Cyber Threat Hunting in NNA

This support forum board is for support questions relating to Nagios Network Analyzer, our network traffic and bandwidth analysis solution.
Locked
alopera
Posts: 47
Joined: Fri Dec 21, 2018 5:08 am

Cyber Threat Hunting in NNA

Post by alopera »

I want create querys for Cyber Threat Hunting using the data of NNA.
For example (a stupid example), detect the ping of death with netflow

is there anything done?
User avatar
mbellerue
Posts: 1403
Joined: Fri Jul 12, 2019 11:10 am

Re: Cyber Threat Hunting in NNA

Post by mbellerue »

This is usually accomplished with queries. Check out this article for more information.
https://support.nagios.com/kb/article/n ... es-74.html

There area a couple of example queries that come with NNA. One of which is checking for common bot net ports being accessed. As long as you know what you're looking for, you should be able to query for it.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.

Be sure to check out our Knowledgebase for helpful articles and solutions!
alopera
Posts: 47
Joined: Fri Dec 21, 2018 5:08 am

Re: Cyber Threat Hunting in NNA

Post by alopera »

Yes, I know
I want more examples (botnets) for use in NNA.
is there more examples?
benjaminsmith
Posts: 5324
Joined: Wed Aug 22, 2018 4:39 pm
Location: saint paul

Re: Cyber Threat Hunting in NNA

Post by benjaminsmith »

Hi @alopera,

Please see PM.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.

Be sure to check out our Knowledgebase for helpful articles and solutions!
Locked