EveBox 0.29.0 Released
EveBox 0.29.0 has been released. This is a smaller maintenance release focused on the event view, with richer event details, clickable rule references, and fixes for Suricata 8 events, plus more reliable SQLite backup and restore.
Richer Event Details
The event view now has dedicated details panels for DNS, TLS, SSH, MQTT, QUIC, and mDNS events.
- DNS shows the query, record type, response code, and answers and authorities. This replaces the old DNS column, which did not understand the Suricata 8 DNS record format and could render "undefined" for the query.
- TLS shows SNI, version, ALPNs, certificate subject, issuer, serial, fingerprint and validity, along with JA4, JA3, and JA3S hashes.
- SSH shows client and server software versions and HASSH hashes.
- MQTT shows the message types in the transaction, with type-specific details such as client ID, topic, payload, and QoS.
- QUIC shows SNI, version, ALPN, JA4, JA3, and extension count.
- mDNS shows type, flags, queries, answers, and additionals, with per-record formatting for PTR, SRV, A/AAAA, and TXT.
Events without a dedicated panel now fall back to showing the scalar fields of the event object, so the details panel is never empty.
Clickable Rule References
Rule references in the alert details of the event view are now links
for known reference types such as url and cve. When Suricata 8
alert.references entries are present, the sensor's own resolution
takes precedence.
SQLite Dump and Load Preserve Workflow State
evebox sqlite dump now includes archived and escalated state as
evebox.archived/evebox.escalated tags, along with the EveBox
history, so workflow state survives a dump and restore into SQLite or
Elasticsearch. evebox sqlite load now also restores escalated state.
Simpler Agent Identity
Agent identity now comes from the agent authentication key: the key's
name is stamped on submitted events (evebox.agent.id) and used on
the packet capture control channel. The agent agent-id option and
--agent-id flag are now ignored, so there is one less value to keep
in sync between the sensor and the server.
Other Improvements
- Boolean values in event details no longer render as empty cells.
- The experimental JA4 report and JA4db integration have been removed, as the upstream service is no longer available.
- Dependency updates.
Installing
Download EveBox 0.29.0 from the downloads page, or install with a single command.
Linux:
curl -sSf https://evebox.org/install.sh | sh
Windows PowerShell:
irm https://evebox.org/install.ps1 | iex