<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Suricata · ArchWorks</title><link>https://archworks.co/tags/suricata/</link><description/><language>en</language><lastBuildDate>Sun, 03 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://archworks.co/tags/suricata/index.xml" rel="self" type="application/rss+xml"/><item><title>Detecting HTTPS, WebSocket, and QUIC tunnels (and pivoting)</title><link>https://archworks.co/docs/detecting-encrypted-tunnels/</link><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><guid isPermaLink="true">https://archworks.co/docs/detecting-encrypted-tunnels/</guid><description>The defensive counterpart: how to catch encrypted tunnels - REALITY, VLESS-over-WebSocket, DoH, QUIC/MASQUE - with self-hosted, open-source tooling. Threat model and obfuscation levels, a controls-vs-evasions matrix, production Suricata/Zeek/RITA detections, alerting policies, and a response runbook.</description></item></channel></rss>