General Description
The RedSocks application normalizes RedSocks events and enables you to analyze the data using reports, alerts, and pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Release Details
Fields |
Details |
---|---|
Name |
RedSocks |
Version |
5.0.1 |
Supported On |
LogPoint v6.7.0 and later |
Release Date |
2020-05-14 |
Document Date |
2020-05-14 |
Download | |
SHA256 |
955da2491325c0c5187d2a3e355dd902fb3cbac8057141039e3b72418c7a995c |
Package Details
The application consists of the following components:
-
Dashboard Package
- LP_RedSocks
-
Report Package
- LP_RedSocks
-
Alert Packages
- LP_RedSocks Bad Neighborhood Detection
- LP_RedSocks Backdoor Connection
- LP_RedSocks FileSharing using 4Shared
- LP_RedSocks FileSharing using WeTransfer
- LP_RedSocks FileSharing using PicoFile
- LP_RedSocks FileSharing using Torrent
- LP_RedSocks Ransomware Connection
- LP_RedSocks Blacklist URL Detection
- LP_RedSocks FileSharing using FileHippo
- LP_RedSocks Tor Connection
- LP_RedSocks Trojan Connection
- LP_RedSocks Sinkhole Detection
-
Normalization Package
- LP_RedSocks
-
Search Template
- LP_RedSocks
-
Compiled Normalizer
- RedSocksCEFCompiledNormalizer
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Screenshots
Installation
Follow these steps to install the RedSocks v5.0.1 application:
- Download the RedSocks package from the Download section above.
- Add RedSocks as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Supported Device
The supported device of RedSocks with LogPoint in this configuration is:
- Redsocks v3.7.0 alpha1
Log Format
Expected Log Format
<Key>:<Value> separated by comma delimiter
Log Samples
<10>[RedSocks alert] 1.1.1.1:49164 > 192.168.xx.xx:443/TCP, source MAC address: xx:xx:xx:xx:xx:xx, destination hostname: xyz.com, exporter IP address: ::xxxx:xx.x.x.xx, observation domain ID: 1, time: 2017-0e8-31 09:30:30, description: RSxxx - Access Network - abc, category: Bad Hood, threat level: 3
<10>[RedSocks alert] 1.1.1.1:33430 > 3.x.x.x:30001/TCP, source MAC address: xx:xx:xx:xx:xx:xx, destination hostname: abc.net, exporter IP address: ::xxxx:xx.x.x.xx, observation domain ID: 2, time: 2017-07-25 09:03:50, description: RSxxx - Malware Connecting IP, category: Controller, threat level: 1
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Release Details
Fields |
Details |
---|---|
Name |
RedSocks |
Version |
3.3.0 |
Supported On |
LogPoint v6.0.0 to v6.6.6 |
Release Date |
2020-xx-xx |
Document Date |
2020-xx-xx |
Download | |
SHA256 |
3ba01fc2ce25ea7fb41553ea7ce2c40a2c66ce882997990bc14e51fe1f018da1 |
Package Details
The application consists of the following components:
-
Dashboard Package
- LP_RedSocks
-
Report Package
- LP_RedSocks
-
Alert Packages
- LP_RedSocks Bad Neighborhood Detection
- LP_RedSocks Backdoor Connection
- LP_RedSocks FileSharing using 4Shared
- LP_RedSocks FileSharing using WeTransfer
- LP_RedSocks FileSharing using PicoFile
- LP_RedSocks FileSharing using Torrent
- LP_RedSocks Ransomware Connection
- LP_RedSocks Blacklist URL Detection
- LP_RedSocks FileSharing using FileHippo
- LP_RedSocks Tor Connection
- LP_RedSocks Trojan Connection
- LP_RedSocks Sinkhole Detection
-
Normalization Package
- LP_RedSocks
-
Search Template
- LP_RedSocks
-
Compiled Normalizer
- RedSocksCEFCompiledNormalizer
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Screenshots
Installation
Follow these steps to install the RedSocks v3.3.0 application:
- Download the RedSocks package from the Download section above.
- Add RedSocks as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Supported Device
The supported device of RedSocks with LogPoint in this configuration is:
- Redsocks v3.7.0 alpha1
Log Format
Expected Log Format
<Key>:<Value> separated by comma delimiter
Log Samples
<10>[RedSocks alert] 1.1.1.1:49164 > 192.168.xx.xx:443/TCP, source MAC address: xx:xx:xx:xx:xx:xx, destination hostname: xyz.com, exporter IP address: ::xxxx:xx.x.x.xx, observation domain ID: 1, time: 2017-0e8-31 09:30:30, description: RSxxx - Access Network - abc, category: Bad Hood, threat level: 3
<10>[RedSocks alert] 1.1.1.1:33430 > 3.x.x.x:30001/TCP, source MAC address: xx:xx:xx:xx:xx:xx, destination hostname: abc.net, exporter IP address: ::xxxx:xx.x.x.xx, observation domain ID: 2, time: 2017-07-25 09:03:50, description: RSxxx - Malware Connecting IP, category: Controller, threat level: 1
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any queries or require assistance, please feel free to contact our support team:
Email: servicedesk@logpoint.com
Phone: +45 7060 6100
Best regards,
Comments
Article is closed for comments.