Skip to content

Dump Suricata SMB-related payload in "user-friendlier" format

License

Notifications You must be signed in to change notification settings

aelth/suricata-smb-print

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 

Repository files navigation

suricata-smb-print

License

Dumping SMB payload in printable format (payload-printable) can be extremely handy for detecting lateral movement and exact binaries/scripts that were transferred or used by the attacker. Unfortunately, printable SMB payload is not easily readable because of the lossy format and binary nature of the protocol itself.

This script beautifies the output and creates more condensed output more suitable for both manual and automatic triage.

Raw logs: Raw

Beautified logs: Beautified

About

Dump Suricata SMB-related payload in "user-friendlier" format

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages