LLMNR/NBT-NS Poisoning and SMB Relay

170 views
Skip to first unread message

Mikayel Mikayelyan

unread,
Feb 29, 2024, 11:56:43 AM2/29/24
to Wazuh | Mailing List
Hi all, how can i detect LLMNR attack in Wazuh and how can i connect T1557.001 framework in Wazuh with suricata 

Eli Josue Rodriguez

unread,
Mar 1, 2024, 3:46:39 PM3/1/24
to Wazuh | Mailing List
Hello Mikayel! Sorry for the late response. Let me research some information for you. At the moment, I could give you this which is about Suricata and Wazuh.

Eli Josue Rodriguez

unread,
Mar 8, 2024, 6:28:51 PM3/8/24
to Wazuh | Mailing List
Hello again! I was investigating and asking about your request, despite not having an exact solution, I can give you a couple of things that can direct you to what you want.

You should look to see if Suricata detects this type of attack (probably yes) or perhaps this can help Suricata detect that attack you mention.

As I also told you in the previous comment, it is possible to configure Suricata and Wazuh, I leave you again the links where you can review them and try them.


Then, you must create your custom rule/decoder to alert. To create the custom rule/decoder you can rely on our wazuh guide in which we explain how to do it.

In addition, T1557.001 is a section within the Mitre matrix. This matrix describes attacks, techniques that hackers commonly use, in this it is the same, you must create your own rules that detect these techniques.

You can also check our guide for Mitre configuration https://documentation.wazuh.com/current/user-manual/ruleset/mitre.html

I hope this can give you a little guidance on what you want to do.

Best,
Reply all
Reply to author
Forward
0 new messages