That brings up a good point. The dropping malicious communications part. Does suricata in it’s default asus configuration, do any dropping or does it simply alert?
.
I don't know its current status; I could never get the earlier version to actually drop test connections/content.
IMHO dropping mischief is essential - I don't want to look at a log the next morning and see that something untoward occured during the night.