TCP
Best of 2025: NOT-So-Great Firewall: China Blocks the Web for 74 Min.
Richi Jennings | | censorship, china, Denial of Service, Denial of Service (DoS) attacks, denial of service attacks, denial of service vulnerability, Denial-of-Service (DoS), Government Censorship, Great Firewall of China, HTTPS, HTTPS connection, internet censorship, online censorship, Pakistan, Peoples Republic of China, port 443, SB Blogwatch, State Censorship, TCP, TCP/IP, The Great Firewall, Transmission Control Protocol (TCP) vulnerabilities
HTTPS connections on port 443 received forged replies. Chinese web users couldn’t access websites outside the People’s Republic yesterday. The outage lasted an hour and a quarter—with no explanation. Nobody’s sure whether it ...
Security Boulevard
NOT-So-Great Firewall: China Blocks the Web for 74 Min.
Richi Jennings | | censorship, china, Denial of Service, Denial of Service (DoS) attacks, denial of service attacks, denial of service vulnerability, Denial-of-Service (DoS), Government Censorship, Great Firewall of China, HTTPS, HTTPS connection, internet censorship, online censorship, Pakistan, Peoples Republic of China, port 443, SB Blogwatch, State Censorship, TCP, TCP/IP, The Great Firewall, Transmission Control Protocol (TCP) vulnerabilities
Xi Whiz: HTTPS connections on port 443 received forged replies ...
Security Boulevard
Telegram Zeek, you’re my main notice
Yacin Nadji | | Corelight Labs, Corelight@Home, NetControl, network detection response, Network Security, network security monitoring, network traffic analysis, network visibility, Notice Framework, TCP, Telegram, Zeek
Notices in Zeek Zeek’s Notice Framework enables network operators to specify how potentially interesting network findings can be reported. This decoupling of detection and reporting highlights Zeek’s flexibility: a notice-worthy event in ...
Pcaps and the Tools That Love Them Part 2 of ???
There's more to a primitive under the surface, and once we discover what it's actually doing, it opens up a whole new way for us to inspect and filter packets. Lets use the ...
Introducing the Cloud Sensor for GCP
Vijit Nair | | Announcements, aws, google, Google GCP, Google Kubernetes, IaaS, json, Kafka, Microsoft Azure, MTU, Product, SIEM, SOC, Splunk, Suricata, syslog, TAPs, TCP, Terraform, vpc, Zeek
By Vijit Nair, Sr. Director, Product Management, Corelight Visibility is paramount in securing your cloud environment – as the adage goes, you cannot protect what you do not see. However, comprehensive visibility ...
Who’s your fridge talking to at night?
Gary Fisk | | Announcements, Corelight@Home, COVID-19, Elastic, home networks, Humio, Industry, json, Kafka, Linux, NDR, network security monitoring, open source, Raspberry Pi, redis, SANS, Seth Hall, Splunk, Suricata, syslog, TCP, Zeek
By Gary Fisk, Sales Engineer, Corelight I love origin stories – the tales of grand plans, unforeseen circumstances, and necessity that creates something new. These strange times have resulted in something new ...
Small, fast and easy. Pick any three.
Seth Hall | | AArch64, Announcements, Corelight, encrypted traffic collection, encryption, json, Kafka, Linux, Product, Raspberry Pi, software, Splunk, ssl, Suricata, TCP, TLS, vm, Zeek, ZeekWeek
By Seth Hall, Co-Founder & Chief Evangelist, Corelight Zeek has been the darling of security defenders looking to get deep visibility into network traffic. Over the last two decades, Zeek has become ...
Community detection: CVE-2020-16898
Ben Reardon | | Bad Neighbor, Corelight Labs, CVE-2020-16898, DoS, ESNET, GitHub, ICMP, IPv6, mcafee, Microsoft, pcap, PoC, REC, Remote Code Execution, RFC4443, RFC8106, TCP, Windows, Zeek, ZeekWeek
By Ben Reardon, Corelight Security Researcher This month’s Microsoft Patch Tuesday included a severe Remote Code Execution vulnerability in the way that Windows TCP/IP handles IPv6 “Router Advertisement” ICMP messages. Due to ...
Community ID support for Wireshark
Christian Kreibich | | Community ID, json, NDR, network detection response, Network Security, network security monitoring, pcap, Product, python, TCP, tshark, Wireshark, Zeek
By Christian Kreibich, Principal Engineer, Corelight The past few weeks have seen several developments around Community ID, our open standard for rendering network traffic flow tuples into a concise textual representation. I’d ...
Mixed VLAN tags and BPF syntax
Richard Bejtlich | | Berkeley Packet Filter, BPF syntax, dns, Linux, Network Security, network security monitoring, network visibility, port 443, Raspberry Pi, SPAN port, TCP, tcpdump, Ubiquiti, VLAN, Wireshark, Zeek
By Richard Bejtlich, Principal Security Strategist, Corelight This post contains a warning and a solution for anyone using BPF syntax when filtering traffic for network security monitoring. Introduction I have been writing ...

