PCAPs for Testingο
The easiest way to download pcap files for testing is our so-test tool. Alternatively, you could manually download pcaps from one or more of the following locations:
https://github.com/zeek/zeek/tree/master/testing/btest/Traces
https://www.ll.mit.edu/r-d/datasets/2000-darpa-intrusion-detection-scenario-specific-datasets
https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Public_Data_Sets
You can download pcap files from the links above using a standard web browser or from the command line using a tool like wget
or curl
.
Replayο
You can use tcpreplay
to replay any standard pcap to the sniffing interface of your Security Onion sensor.
Importο
A drawback to using tcpreplay is that itβs replaying the pcap as new traffic and thus the timestamps that you see in Security Onion Console (SOC) and other interfaces do not reflect the original timestamps from the pcap. To avoid this, you can import the pcap using the Grid page.