8.3. Procedure to put a GCap into operation
A - Introduction
After configuring the GCap, this procedure describes how to start operating the GCap.
To perform this procedure, you must perform all the steps described in the following sections:
B - Prerequisites
User: setup
C - Preliminary operations
Perform the Procedure to configure the GCap for the first connection
Activate the required
`monx`capture interfaces: refer to Procedure to manage the `monx` capture interface settings
D - Procedure to be followed on the GCap
- Start the detection engine: refer to Manage the detection engine tableThe system displays the following command prompt:
Monitoring DOWN gcap-name (gcap-cli)
The command prompt indicates the status of the detection engine : here it is stopped. - Enter the command
monitoring-engine start
- Validate
- Wait for the engine to be up and running
- Check the status of the detection engineThe system displays the following command prompt:
[Monitoring UP] gcap-name (gcap-cli)
The command prompt indicates the status of the detection engine : here it is started
E - Procedure to be carried out on the GCenter
Apply a ruleset to the GCap
Enable or disable the shellcode detection
Enable or disable powershell detection
Configure the Sigflow specific parameters, namely Base variables, Net variables and File rules management