<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-signature">Hey all,<br>
<br>
First time posting to the list, and I've been meaning to send this
out for a long time.<br>
<br>
We developed a tool at the University of Minnesota a few years
back designed to do more lightweight simplified suricata rule
management with integration into git for version tracking. The
result is that we wrote mob-boss to fit our needs.<br>
<br>
It's distributed under the GPL license and can be found here:
<a class="moz-txt-link-freetext" href="https://github.com/codeweaver33/mob-boss">https://github.com/codeweaver33/mob-boss</a><br>
It was written largely by myself with help from Brandon Lattin
(former UofM employee now at Amazon) and Luke Young (now at
LinkedIn).<br>
<br>
Useful features:<br>
<br>
- Integration into git for version tracking of rules.<br>
- Designed for use by a cluster of sensors, but can easily be used
on a single sensor<br>
- Simplifies turning on and off rules via a rule_state.conf file<br>
- Light weight and simple<br>
<br>
Not sure if it's useful to anyone, but figured I'd share it just
in case it helps anyone else out. Feel free to email me with
questions, or open issues/pull requests on the project.<br>
<br>
-- <br>
<b>Dillon Bogenreif</b><br>
University Information Security<br>
University of Minnesota<br>
<a class="moz-txt-link-abbreviated" href="mailto:dbogenre@umn.edu">dbogenre@umn.edu</a><br>
612-624-5762 (office)<br>
GWAPT, GPEN</div>
</body>
</html>