SANS Stormcast Friday, September 12th, 2025: DShield SIEM Update; Another Sonicwall Warning; Website Keystroke Logging
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 September 2025
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, September 12, 2025 edition of the Sands Internet Storms Centers. |
| 0:11.5 | Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.3 | And this episode is brought you by the sands.edu undergraduate certificate program in |
| 0:22.8 | cybersecurity fundamentals. Today's diary is an update from Ghee about the D-Shield seam |
| 0:31.9 | that, well, Ghee maintains and actually he created it as well. One of the great things about running a honeypot is, well, awareness about all the attacks |
| 0:41.5 | that your network may be exposed to. |
| 0:44.8 | This scene provides you with a real pretty graphical user interface, |
| 0:50.0 | summarizing the attacks that are hitting your honey pot and allowing you to eventually dig into |
| 0:56.3 | the data more easily without having to break out your command line skills. And just the |
| 1:02.5 | visualization itself is pretty nice and also provides quite a bit of value, I think, |
| 1:08.5 | particular to better understand how the attacks are breaking down. |
| 1:12.9 | There's geographic maps that you can look at. |
| 1:17.7 | There are various sort of port statistics and such that are being summarized here. |
| 1:23.0 | Now, the nice thing about this seam is that it's actually entirely inside Docker containers. |
| 1:29.6 | And that makes it really easy to update. You essentially just remove the old Docker containers |
| 1:34.7 | and then create new ones and you are up to date. So if you're using this tool, well, |
| 1:41.8 | take a look at it. If you're not using it, well, take a look at it and see if you like it. |
| 1:48.5 | It does require a little bit more processing power than you usually have, like, on the |
| 1:53.1 | basic Raspberry Pies. |
| 1:55.0 | But if you are running your honeypot inside a virtual machine or on a little bit of more |
| 2:00.1 | powerful system, it'll certainly |
| 2:02.4 | work. It uses Elk, Elk, Elasticsearch, Logstash, Kibana, and those familiar with these |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

