Up and running with Stratoshark in 5 minutes
Blog post from Sysdig
Stratoshark, developed by Wireshark founder Gerald Combs and Falco creator Loris Degioanni, is a tool that extends Wireshark's network packet analysis capabilities to the cloud by integrating with the Falco ecosystem. It enables users to conduct forensic investigations on system calls and cloud logs with the precision that Wireshark has provided for over 25 years. By leveraging the familiar Wireshark workflow, Stratoshark allows security practitioners to analyze modern data sources and threats effectively. The tool is open-source and free to use, and it runs locally on the user's device. Installation is straightforward, requiring minimal setup, and it integrates with tools like Sysdig for system call capture. Stratoshark provides detailed forensic data, allowing users to investigate potential security incidents deeply, such as identifying cryptominers in a cloud environment. The tool aims to empower the community with robust resources to tackle modern security challenges and invites collaboration and contribution from users through platforms like Discord.