Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposed role: debops.ids #159

Open
tobijb opened this issue May 8, 2015 · 1 comment
Open

Proposed role: debops.ids #159

tobijb opened this issue May 8, 2015 · 1 comment

Comments

@tobijb
Copy link

tobijb commented May 8, 2015

Provide default intrusion detection systems like debops.ossec + debops.audit? Leverage ELK stack for audit views and ossec for notifications (email + script)?

Should:

  • Audit user logins
  • Audit known activities (DDOS, Synflood, Auth attempts)
  • Audit custom activities (Watch this file in /opt/secret for changes)
  • Notify for known activities (MD5 change of core lib or executable)
  • Notify for custom activities (if desired)
    ...
@e-alfred
Copy link

e-alfred commented May 4, 2016

Graylog could be used instead of the ELK stack, but this role would be great.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants