Theory – Analyzing IDS Logs & Alerts

November 11, 2025 @ 11:10 - 11:50

  • Workshop 2

About Session

  • • Generating alerts with simulated attacks (e.g., Nmap scans)
  • • Generating logs via PCAPs
  • • Understanding Snort and Suricata alert logs
  • • Analyzing Zeek logs for deeper network insights
  • • Visualizing results in Kibana

Speakers

K. Reid Wightman

K. Reid Wightman

Vulnerability Researcher, Dragos
Oscar Delgado

Oscar Delgado

Senior Industrial Consultant, Dragos