About This File
The WinSuricata Core Edition provides the foundational Windows sensor and detection engine for the WinSuricata deployment framework. It installs and configures the Suricata IDS/IPS engine, Npcap packet capture, rule management infrastructure, Windows service integration, and supporting system components required to inspect network traffic and generate the Suricata EVE JSON event stream. The installation operates independently and does not require EveBox or OpenSearch, making it the core sensor layer upon which the remaining WinSuricata deployment options are built.
Once operational, the Headless Edition provides the complete local detection pipeline from network packet capture through Suricata inspection and EVE JSON event generation, together with the WinSuricata Operations Console, rule update management, diagnostics, service monitoring, and recovery utilities. The resulting eve.json event stream can then be consumed by the EveBox Standalone Console — SQLite Edition, the EveBox + OpenSearch + OpenSSL — Host Edition, or the EveBox Remote Node Agent — OpenSearch Edition, allowing the same core sensor installation to serve as a standalone sensor, centralized Host, or Remote Node foundation.
Complete installation instructions, deployment requirements, verification procedures, troubleshooting information, architecture details, and the final deployment checklist are included in the `README-INSTALL.txt` file contained within this package. Please review the included documentation before beginning the installation and retain it for future administration and troubleshooting.
PACKAGE SECURITY & INTEGRITY
Before extracting or installing the package, verify the downloaded ZIP file against the published SHA-1 hash to confirm that the archive has not been corrupted or altered.
Archive Password : w1nsn03t.c0m SHA-1 Hash : 3640180B836E3B64DC234DD94D3C44DBEA56A5B0
To verify the package in Windows, run the following command from Command Prompt or PowerShell, replacing the filename if necessary:
certutil -hashfile "WinSuricata-Headless-Installer.zip" SHA1
The calculated SHA-1 value must match the published value exactly. If the hash does not match, do not extract or install the package. Obtain a new copy from the authorized distribution source and perform the verification again.
