Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Is OpenSnitch worth it? #1405

Discussion options

Has anyone used OpenSnitch, the Linux app level firewall?

Is it useful for spotting data exfiltration?

Can it scale or integrate with SIEM tools?

You must be logged in to vote

Well, restricting outbound connections by binary seems an effective way to detect and stop malicious activity:

https://www.reddit.com/r/archlinux/comments/1me632m/is_this_another_aur_infect_package/

#1290

So yes, totally worth it.

Yes, you can integrate it with SIEM tools: https://github.com/evilsocket/opensnitch/wiki/SIEM-integration

Replies: 1 comment 1 reply

Comment options

Well, restricting outbound connections by binary seems an effective way to detect and stop malicious activity:

https://www.reddit.com/r/archlinux/comments/1me632m/is_this_another_aur_infect_package/

#1290

So yes, totally worth it.

Yes, you can integrate it with SIEM tools: https://github.com/evilsocket/opensnitch/wiki/SIEM-integration

You must be logged in to vote
1 reply
Comment options

Okay. Thank you

I'll work on it ASAP

Answer selected by hatscode
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet

AltStyle によって変換されたページ (->オリジナル) /