Skip to main content

EveBox 0.29.0 Released

· 2 min read

EveBox 0.29.0 has been released. This is a smaller maintenance release focused on the event view, with richer event details, clickable rule references, and fixes for Suricata 8 events, plus more reliable SQLite backup and restore.

Richer Event Details​

The event view now has dedicated details panels for DNS, TLS, SSH, MQTT, QUIC, and mDNS events.

  • DNS shows the query, record type, response code, and answers and authorities. This replaces the old DNS column, which did not understand the Suricata 8 DNS record format and could render "undefined" for the query.
  • TLS shows SNI, version, ALPNs, certificate subject, issuer, serial, fingerprint and validity, along with JA4, JA3, and JA3S hashes.
  • SSH shows client and server software versions and HASSH hashes.
  • MQTT shows the message types in the transaction, with type-specific details such as client ID, topic, payload, and QoS.
  • QUIC shows SNI, version, ALPN, JA4, JA3, and extension count.
  • mDNS shows type, flags, queries, answers, and additionals, with per-record formatting for PTR, SRV, A/AAAA, and TXT.

Events without a dedicated panel now fall back to showing the scalar fields of the event object, so the details panel is never empty.

Clickable Rule References​

Rule references in the alert details of the event view are now links for known reference types such as url and cve. When Suricata 8 alert.references entries are present, the sensor's own resolution takes precedence.

SQLite Dump and Load Preserve Workflow State​

evebox sqlite dump now includes archived and escalated state as evebox.archived/evebox.escalated tags, along with the EveBox history, so workflow state survives a dump and restore into SQLite or Elasticsearch. evebox sqlite load now also restores escalated state.

Simpler Agent Identity​

Agent identity now comes from the agent authentication key: the key's name is stamped on submitted events (evebox.agent.id) and used on the packet capture control channel. The agent agent-id option and --agent-id flag are now ignored, so there is one less value to keep in sync between the sensor and the server.

Other Improvements​

  • Boolean values in event details no longer render as empty cells.
  • The experimental JA4 report and JA4db integration have been removed, as the upstream service is no longer available.
  • Dependency updates.

Installing​

Download EveBox 0.29.0 from the downloads page, or install with a single command.

Linux:

curl -sSf https://evebox.org/install.sh | sh

Windows PowerShell:

irm https://evebox.org/install.ps1 | iex