依照邦友https://ithelp.ithome.com.tw/articles/10209300
因為Critical Stack client not fetching lists這個issue,改用Alienvault-OTX
https://github.com/Security-Onion-Solutions/security-onion/wiki/Alienvault-OTX
註冊
https://otx.alienvault.com
Key
安裝client,並輸入Key
wget https://raw.githubusercontent.com/weslambert/securityonion-otx/master/securityonion-otx
sudo bash securityonion-otx
測試方式
vim /opt/bro/share/bro/policy/bro-otx/otx.dat
新增一筆
google.com Intel::DOMAIN Test-Google-Intel https://google.com T
查看是否有錯誤訊息(有可能表示上面規則有錯)
tail /nsm/bro/logs/current/reporter.log
curl google.com