-
-
Notifications
You must be signed in to change notification settings - Fork 587
Is OpenSnitch worth it? #1405
-
Has anyone used OpenSnitch, the Linux app level firewall?
Is it useful for spotting data exfiltration?
Can it scale or integrate with SIEM tools?
Beta Was this translation helpful? Give feedback.
All reactions
Well, restricting outbound connections by binary seems an effective way to detect and stop malicious activity:
https://www.reddit.com/r/archlinux/comments/1me632m/is_this_another_aur_infect_package/
So yes, totally worth it.
Yes, you can integrate it with SIEM tools: https://github.com/evilsocket/opensnitch/wiki/SIEM-integration
Replies: 1 comment 1 reply
-
Well, restricting outbound connections by binary seems an effective way to detect and stop malicious activity:
https://www.reddit.com/r/archlinux/comments/1me632m/is_this_another_aur_infect_package/
So yes, totally worth it.
Yes, you can integrate it with SIEM tools: https://github.com/evilsocket/opensnitch/wiki/SIEM-integration
Beta Was this translation helpful? Give feedback.
All reactions
-
Okay. Thank you
I'll work on it ASAP
Beta Was this translation helpful? Give feedback.