Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider subscribing to shadowserver for reports about our networks #1403

Open
naved001 opened this issue Oct 3, 2024 · 5 comments
Open
Assignees
Labels
research This task is primarily about information discovery security Label for Security Issues

Comments

@naved001
Copy link

naved001 commented Oct 3, 2024

Shadowserver can monitor networks for free and send daily/weekly/monthly reports about any security vulnerabilities on hosts on a network. CSAIL will usually forward us reports from shadowserver but we don't get any notifications like this from the NEU network (129.10.5.0/24) or the BU network (192.12.185.0/24).

I think we should consider subscribing to these alerts for those networks. I am not sure if there are any downsides besides giving them explicit permission to scan hosts on our network.

https://www.shadowserver.org/what-we-do/network-reporting/get-reports/

@naved001 naved001 added research This task is primarily about information discovery security Label for Security Issues labels Oct 3, 2024
@msdisme
Copy link

msdisme commented Oct 7, 2024

@hakasapl @larsks

@hakasapl
Copy link

hakasapl commented Oct 9, 2024

My understanding is that this run externally from our infrastructure right? If so then I have no concerns, and I think we should buy it. If we have to run a daemon for it ourselves it would be good if they had support for the netgate firewall (pfsense pro)

@naved001
Copy link
Author

naved001 commented Oct 9, 2024

@hakasapl yes, it's externally run and it's free so no need to pay for it.

@hakasapl
Copy link

hakasapl commented Oct 9, 2024

Oh, it's free? That's great

@naved001
Copy link
Author

I sent an email to NEU folks and see if they already have any network security reports and if they are okay with us subscribing to shadowserver.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
research This task is primarily about information discovery security Label for Security Issues
Projects
None yet
Development

No branches or pull requests

3 participants