RedSocks
ArchivedThe RedSocks application normalizes RedSocks events and enables you to analyze the data using reports, alerts, and pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Release Details
Package Details
- Dashboard Package
- LP_RedSocks
- Report Package
- LP_RedSocks
- Alert Packages
- LP_RedSocks Bad Neighborhood Detection
- LP_RedSocks Backdoor Connection
- LP_RedSocks FileSharing using 4Shared
- LP_RedSocks FileSharing using WeTransfer
- LP_RedSocks FileSharing using PicoFile
- LP_RedSocks FileSharing using Torrent
- LP_RedSocks Ransomware Connection
- LP_RedSocks Blacklist URL Detection
- LP_RedSocks FileSharing using FileHippo
- LP_RedSocks Tor Connection
- LP_RedSocks Trojan Connection
- LP_RedSocks Sinkhole Detection
- Normalization Package
- LP_RedSocks
- Search Template
- LP_RedSocks
- Compiled Normalizer
- RedSocksCEFCompiledNormalizer
Enhancement
Installation
Follow these steps to install the RedSocks v5.0.1 application:
- Download the RedSocks package from the Download section above.
- Add RedSocks as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Past Release
For LogPoint v6.0.0 to v6.6.6 ▾
Enhancement
Log Format
Expected Log Format
<Key>:<Value> separated by comma delimiter
Log Samples
<10>[RedSocks alert] 1.1.1.1:49164 > 192.168.xx.xx:443/TCP, source MAC address: xx:xx:xx:xx:xx:xx, destination hostname: xyz.com, exporter IP address: ::xxxx:xx.x.x.xx, observation domain ID: 1, time: 2017-0e8-31 09:30:30, description: RSxxx - Access Network - abc, category: Bad Hood, threat level: 3
<10>[RedSocks alert] 1.1.1.1:33430 > 3.x.x.x:30001/TCP, source MAC address: xx:xx:xx:xx:xx:xx, destination hostname: abc.net, exporter IP address: ::xxxx:xx.x.x.xx, observation domain ID: 2, time: 2017-07-25 09:03:50, description: RSxxx - Malware Connecting IP, category: Controller, threat level: 1
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.