<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Hunting on kimobu</title><link>https://www.kimobu.space/categories/hunting/</link><description>Recent content in Hunting on kimobu</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright Kimo B</copyright><lastBuildDate>Thu, 05 Sep 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://www.kimobu.space/categories/hunting/index.xml" rel="self" type="application/rss+xml"/><item><title>Monitoring Kubernetes with Security Onion</title><link>https://www.kimobu.space/posts/Kubernetes-monitoring-securityonion/</link><pubDate>Thu, 05 Sep 2024 00:00:00 +0000</pubDate><guid>https://www.kimobu.space/posts/Kubernetes-monitoring-securityonion/</guid><description>&lt;h1 id="introduction"&gt;Introduction&lt;/h1&gt;
&lt;p&gt;After adding Kubernetes to my homelab, I wanted to learn how to hack and hunt for malicious activity involving containers. I found &lt;a href="https://madhuakula.com/kubernetes-goat/"&gt;Kubernetes GOAT&lt;/a&gt; which provides a great way to practice hacking. To do the hunting, we need some additional work to enable telemetry on networks, containers, and Kubernetes. In this post I&amp;rsquo;ll walk through how I instrumented my Microk8s cluster to hunt for the hacking actions you can do in the GOAT.&lt;/p&gt;</description></item><item><title>SecurityOnion GPT</title><link>https://www.kimobu.space/posts/SecurityOnion-GPT/</link><pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate><guid>https://www.kimobu.space/posts/SecurityOnion-GPT/</guid><description>&lt;h1 id="introduction"&gt;Introduction&lt;/h1&gt;
&lt;p&gt;I was recently catching up on some conference videos and saw a talk by Roberto Rodriguez on &lt;a href="https://www.youtube.com/watch?v=TiBIP7kWaks&amp;amp;list=PL7ZDZo2Xu3332bKrXyCb0VEg52nqmMAcv&amp;amp;index=31"&gt;Empowering Security Teams with Generative AI: GPT models&lt;/a&gt;. This got me thinking about how to integrate GPT to hunting with Security Onion.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Goals&lt;/strong&gt;:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Summarize activity found in Security Onion&lt;/li&gt;
&lt;li&gt;Enrich activity with MITRE ATT&amp;amp;CK attribution&lt;/li&gt;
&lt;li&gt;Convert English questions to Kibana Query Language to hunt&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In this post, I&amp;rsquo;ll tackle goals 1 and 2. I&amp;rsquo;ll do goal 3 in a separate post. These experiments will be conducted in Jupyter lab.&lt;/p&gt;</description></item></channel></rss>