update
This commit is contained in:
BIN
doc/ElasticStackImport/15-HayabusaDashboard-StackManagement.png
Normal file
BIN
doc/ElasticStackImport/15-HayabusaDashboard-StackManagement.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 131 KiB |
BIN
doc/ElasticStackImport/16-HayabusaDashboard-Import.png
Normal file
BIN
doc/ElasticStackImport/16-HayabusaDashboard-Import.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 481 KiB |
BIN
doc/ElasticStackImport/17-HayabusaDashboard-1.png
Normal file
BIN
doc/ElasticStackImport/17-HayabusaDashboard-1.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 652 KiB |
BIN
doc/ElasticStackImport/18-HayabusaDashboard-2.png
Normal file
BIN
doc/ElasticStackImport/18-HayabusaDashboard-2.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 704 KiB |
@@ -79,13 +79,7 @@ The default Discover view should look similar to this:
|
||||
|
||||

|
||||
|
||||
You can get an overview of when the events happened and frequency of events by looking at the histogram at top. You can filter with KQL to search for certain events and alerts. For example:
|
||||
* `Level: "critical"`: Just show critical alerts.
|
||||
* `Level: "critical" or Level: "high"`: Show high and critical alerts.
|
||||
* `NOT Level:info`: Do not show informational events, only alerts.
|
||||
* `*LatMov*`: Show events and alerts related to lateral movement.
|
||||
* `"Password Spray"`: Only show specific attacks such as "Password Spray".
|
||||
* `"LID: 0x8724ead"`: Display all activity associated with Logon ID 0x8724ead.
|
||||
You can get an overview of when the events happened and frequency of events by looking at the histogram at top.
|
||||
|
||||
On the left side sidebar, you can select with fields you want to display in columns:
|
||||
|
||||
@@ -99,6 +93,38 @@ Your Discover view should now look like this:
|
||||
|
||||

|
||||
|
||||
You can filter with KQL to search for certain events and alerts. For example:
|
||||
* `Level: "critical"`: Just show critical alerts.
|
||||
* `Level: "critical" or Level: "high"`: Show high and critical alerts.
|
||||
* `NOT Level:info`: Do not show informational events, only alerts.
|
||||
* `*LatMov*`: Show events and alerts related to lateral movement.
|
||||
* `"Password Spray"`: Only show specific attacks such as "Password Spray".
|
||||
* `"LID: 0x8724ead"`: Display all activity associated with Logon ID 0x8724ead.
|
||||
|
||||
## Hayabusa Dashboard
|
||||
|
||||
https://qiita.com/kzzzzo2/items/ead8ccc77b7609143749
|
||||
We have exported a simple Hayabusa Dashboard in JSON to download [here](https://github.com/Yamato-Security/hayabusa/blob/main/doc/ElasticStackImport/HayabusaDashboard.ndjson)
|
||||
|
||||
To import the dashboard, open the left sidebar and click `Stack Management` under `Management`.
|
||||
|
||||

|
||||
|
||||
After clicking `Saved Objects`, please click `Import` in the upper right-hand corner and import the Hayabusa Dashboard JSON file you downloaded.
|
||||
|
||||

|
||||
|
||||
You should now be able to use the dashboard shown below:
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
## Future Plans
|
||||
|
||||
We plan on creating Hayabusa logstash parsers and dashboard pre-built for SOF-ELK so that all you will need to do is copy the CSV results file to a directory in order to ingest the logs.
|
||||
|
||||
## Acknowledgements
|
||||
|
||||
Much of this documentation was taken from the blog write-up in Japanese from @kzzzzo2 [here](https://qiita.com/kzzzzo2/items/ead8ccc77b7609143749).
|
||||
|
||||
Many thanks to @kzzzzo2!
|
||||
4
doc/ElasticStackImport/HayabusaDashboard.ndjson
Normal file
4
doc/ElasticStackImport/HayabusaDashboard.ndjson
Normal file
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user