Jump to content

4 Screenshots

About This File

The EveBox + OpenSearch + OpenSSL Console — Host Edition extends an existing WinSuricata Headless sensor into a centralized security management and analytics platform. It deploys and configures EveBox, OpenSearch, OpenSSL-based PKI infrastructure, HTTPS/TLS security, centralized event storage, and the supporting Windows services required to transform the local Suricata EVE JSON event stream into a centralized alert management and analysis environment. The Host Edition builds directly on the WinSuricata Headless Edition and does not replace the underlying Suricata detection engine.

The WinSuricata Host also provides the central integration point for Remote Nodes. Registered Remote Nodes can securely forward applicable Suricata alert telemetry to the Host using Host-generated authentication and TLS/PKI configuration, allowing multiple WinSuricata sensors to be monitored through a centralized EveBox and OpenSearch environment. Together, EveBox, OpenSearch, OpenSSL, and the WinSuricata PKI infrastructure provide centralized event storage, search, visualization, sensor management, authenticated Remote Node communication, and certificate validation and recovery while preserving Suricata's local detection and EVE JSON generation on each sensor.

Complete installation instructions, deployment requirements, verification procedures, troubleshooting information, architecture details, and the final deployment checklist are included in the `README-INSTALL.txt` file contained within this package. Please review the included documentation before beginning the installation and retain it for future administration and troubleshooting.

PACKAGE SECURITY & INTEGRITY

Before extracting or installing the package, verify the downloaded ZIP file against the published SHA-1 hash to confirm that the archive has not been corrupted or altered.

	Archive Password : w1nsn03t.c0m
	SHA-1 Hash       : AFF01040248980F9524F419E0E4FD1B69293EB6B

To verify the package in Windows, run the following command from Command Prompt or PowerShell, replacing the filename if necessary:

certutil -hashfile "EveBox-OpenSearch-Host-Installer.zip" SHA1

The calculated SHA-1 value must match the published value exactly. If the hash does not match, do not extract or install the package. Obtain a new copy from the authorized distribution source and perform the verification again.


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.