BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

News🩹 Patch
🩹 PatchSANS ISC·13d ago

Recent DShield SIEM Update, (Tue, Jul 14th)

The last update to the DShield SIEM [ 4 ] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs. The following have been added to the DShield SIEM to provide additional information about what the DShield sensor [ 1 ] is receiving. These 2-addition installed in the DShield sensor provide direct collection of TTY logs [ 2 ] and Suricata [3 ] which are now reported to the DShield SIEM. The TTY logs are parsed and uploaded daily at 23:58Z which can be reviewed in the DShield - Traffic Analysis tab to match the TTY Log Hashes and shows which actor ran any series of commands while logged in the sensor. The TTY logs are base64 encoded before they are sent to the SIEM and decoded by Kibana upon review. TTY logs in base64 format: transaction.id: 021d88f11b09defc8756e1bd6eabaea8113b3fbf917c9bd4fef4f546a1c9512a event.hash: ZWNobyAtZSAieCFcbjBPc0NsT21WU0JGOVxuME9zQ2xPbVZTQkY5InxwYXNzd2R8YmFzaC1iYXNoOiBFbnRlcjogY29tbWFuZCBub3QgZm91bmQK transaction.id: 02caa940d3e30057af8235125c8376b2394622118344516895b045a6fe9b5ecb event.hash: ZWNobyAtZSAiMTIzXG53QjV1clY4NXFxa1dcbndCNXVyVjg1cXFrVyJ8cGFzc3dkfGJhc2gtYmFzaDogRW50ZXI6IGNvbW1hbmQgbm90IGZvdW5kCg== transaction.id: 052b36a73707754c7d49814cdc1f32fef3f72d334a7479f78f11c3229c1599d9 event.hash: ZWNobyAtZSAieCFcbkNLbGFOS0lOdWlYalxuQ0tsYU5LSU51aVhqInxwYXNzd2R8YmFzaC1iYXNoOiBFbnRlcjogY29tbWFuZCBub3QgZm91bmQK The TTY logs are parsed once per day and uploaded directly into DShield SIEM with filebeat. The BASH script needs to be installed and configure according to the GitHub page [ 2 ] to provide a transcript of the activity reviewed in Kibana. The addition of Suricata [ 3 ] is also available in the DShield dashboards and linked to all other logs. An updated dashboard now contains these changes to reflect the ability to share between sub-dashboard most of the queries selected (i.e. selecting an IP will replicate everywhere). The dashboard also has a Threat Map that can be used to view the logs traffic activity in movement . Jesse and I are at SANSFIRE, if you are onsite, come tonight at the SANSFIRE 2026 Honeypot Workshop in Independence A - West (Level 5B) at 6:45 PM. [1] https://isc.sans.edu/honeypot.html [2] https://github.com/bruneaug/DShield-SIEM/blob/main/AddOn/TTYLogs_To_DShield-SIEM.md [3] https://github.com/bruneaug/DShield-SIEM/blob/main/AddOn/Configure_Suricata.md [4] https://isc.sans.edu/diary/DShield+SIEM+Docker+Updates/32276 [5] https://github.com/bruneaug/DShield-SIEM/tree/main ----------- Guy Bruneau IPSS Inc. My GitHub Page Twitter: GuyBruneau gbruneau at isc dot sans dot edu (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Sign in to read the full article

Create a free account to access all news, downloads, and community features

Originally published by SANS ISC

Source: https://isc.sans.edu/diary/rss/33156

This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.

Shared on IT-Hub by admin