---
title: Scirius 2.0 is here to get your Suricata easier, faster, stronger
description: Scirius 2.0 is here to get your Suricata easier, faster, stronger
image: https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-11-26-58.png
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# Scirius 2.0 is here to get your Suricata easier, faster, stronger

 by [Eric Leblond](https://www.stamus-networks.com/blog/author/eric-leblond) | Mar 14, 2018 | [SELKS](https://www.stamus-networks.com/blog/tag/selks), [Open Source](https://www.stamus-networks.com/blog/tag/open-source), [Suricata](https://www.stamus-networks.com/blog/tag/suricata), [Stamus Security Platform](https://www.stamus-networks.com/blog/tag/stamus-security-platform)

![](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-11-26-58.png)

Stamus Networks is proud to announce the availability of Scirius Community Edition 2.0. This is the first release of the 2.0 branch that features a brand new user interface and new features such as lateral movement and target transformations. Both modify signatures to improve them. Lateral movement uses an algorithm to enlarge the signature IP address filter to detect attacks in the internal networks. Target transformation implement an other algorithm to add target keyword to signatures thus helping to find and visualize attack paths.

Scirius 2.0.0 now features an automated addition of any of the sources defined in the public ruleset list published by the [OISF](https://www.oisf.net/):

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-11-26-58-300x164.png?width=300&height=164&name=Screenshot-from-2018-03-14-11-26-58-300x164.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-11-26-58.png?hsLang=en)

So you can now add to your ruleset a new feed/source in two clicks. That's really easier compared to the form based method where a series of fields as to be entered. The addition process itself is also faster. The parsing and update time of a ruleset like [ET Pro](https://www.proofpoint.com/us/threat-insight/et-pro-ruleset) has been improved to be three times faster in this version.

As you may have noticed, Scirius 2.0.0 interface is really different from one from the previous versions:

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-11-27-21-300x96.png?width=300&height=96&name=Screenshot-from-2018-03-14-11-27-21-300x96.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-11-27-21.png?hsLang=en)

Scirius is now using the [Patternfly](https://www.patternfly.org/) framework to provide a consistent interface and usability oriented components. Usability has also been improved by the integration of the documentation in the interface.

On [Suricata](https://www.stamus-networks.com/simplifying-suricata?hsLang=en) related side, the most important change is the handling of transformations. Scirius can now modify the signatures through a transformation:

[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-11-31-53-300x220.png?width=300&height=220&name=Screenshot-from-2018-03-14-11-31-53-300x220.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-11-31-53.png?hsLang=en)

Currently two transformations are available and they aim at making Suricata's detection capabilities stronger:

##### Lateral Movement

Lateral movement transformation modifies signatures to have them detect lateral movement. As signatures are often written with the EXTERNAL_NET and HOME_NET variables, this means they won’t match if both sides of a flow are in the HOME_NET. Thus, lateral movements are not detected. This transformation changes EXTERNAL_NET to any to be able to detect lateral movements. Scirius propose per ruleset, per categories and per signature changes. One of the value proposed is auto that use an algorithm that trigger the substitution if the signature verifies some properties.

##### Target Keyword

The second substitution is the addition of the [target keyword](https://github.com/OISF/suricata/pull/2767) donated by Stamus Networks. Available since Suricata 4.0, the target keyword can be used to tell which side of a flow triggering a signature is the target. If this key is present then related events are enhanced to contain the source and target of the attack. Once more the user can choose the value of the option or let Scirius determine what side to use via an algorithm using signature properties.

For the eye candy fans, pktcity is now part of Scirius. This 3D webGL visualization interface is now available as part of the new dashboards:  
[![](https://www.stamus-networks.com/hs-fs/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-12-03-45-300x156.png?width=300&height=156&name=Screenshot-from-2018-03-14-12-03-45-300x156.png)](https://www.stamus-networks.com/hubfs/Imported_Blog_Media/Screenshot-from-2018-03-14-12-03-45.png?hsLang=en)

Finally, for the list addicts, here is Scirius 2.0.0 changelog:

- Rule transformation with lateral movement and target
- Support of OISF public sources for easier setup
- Convert documentation to sphinx and integrate it in interface
- Rework of interface with Patternfly components
- Link to [Onyphe](https://www.onyphe.io/) to get IP informations
- Rules parsing optimization
- More dashboards including pktcity webGL visualization
- Initial REST API to interact with Scirius from outside

Scirius 2.0.0 is [available on github](https://github.com/StamusNetworks/scirius/releases/tag/scirius-2.0.0). Debian packages for SELKS are also available. Users of Scirius Enterprise Edition will get access to this feature in the upcoming 29 release.

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2018%2F03%2F14%2Fscirius-2-0-is-here-to-get-your-suricata-easier-faster-stronger%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2018%2F03%2F14%2Fscirius-2-0-is-here-to-get-your-suricata-easier-faster-stronger%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2018%2F03%2F14%2Fscirius-2-0-is-here-to-get-your-suricata-easier-faster-stronger%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2018%2F03%2F14%2Fscirius-2-0-is-here-to-get-your-suricata-easier-faster-stronger%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2018%2F03%2F14%2Fscirius-2-0-is-here-to-get-your-suricata-easier-faster-stronger%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2F2018%2F03%2F14%2Fscirius-2-0-is-here-to-get-your-suricata-easier-faster-stronger%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Eric Leblond](https://www.stamus-networks.com/hubfs/Stamus_Eric_Square-1.jpg)

#### Eric Leblond

 Éric Leblond is the co-founder and chief technology officer (CTO) at Stamus Networks. He sits on the board of directors at Open Network Security Foundation (OISF). Éric has more than 15 years of experience as co-founder and technologist of cybersecurity software companies and is an active member of the security and open-source communities. He has worked on the development of Suricata – the open-source network threat detection engine – since 2009 and is part of the Netfilter Core team, responsible for the Linux kernel's firewall layer. Eric is a respected expert and speaker on all things network security. Éric resides in Escalles, France.

[**](https://www.linkedin.com/in/ericleblond) [** ](https://twitter.com/Regiteric)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![Suricata Language Server 2.0 Now Available from Stamus Networks](https://www.stamus-networks.com/hubfs/SN-SLS-2-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

### [Suricata Language Server 2.0: Major Update with Workspace Intelligence](https://www.stamus-networks.com/blog/suricata-language-server-2.0?hsLang=en)

We're excited to announce version 2.0 of the Suricata Language Server, featuring workspace-wide...

[![Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/hubfs/SLS-1.3-18-Dec-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

### [Suricata Language Server 1.3.0: Automated PCAP Testing, Multi-Version Support, and Syntax Highlighting](https://www.stamus-networks.com/blog/suricata-language-server-1.3-automated-pcap-testing-and-multi-version-support?hsLang=en)

[Suricata Language Server](https://www.stamus-networks.com/suricata-language-server?hsLang=en) 1.3.0 is now available and it surfs on the concept of magic comment...

[![](https://www.stamus-networks.com/hubfs/SLS-1.1.0-13-Nov-2025.jpg) ](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

### [Suricata Language Server 1.1.0 Reduces Installation Requirements with Docker Container Mode](https://www.stamus-networks.com/blog/suricata-language-server-1.1.0-reduces-installation-requirements-with-docker-container-mode?hsLang=en)

Writing and validating Suricata signatures shouldn't require wrestling with complex installation...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.