From 020eb47026d57136a2d12d80dfa2e32629e48008 Mon Sep 17 00:00:00 2001 From: DefensiveDepth Date: Tue, 19 Mar 2024 13:53:37 -0400 Subject: [PATCH] Change Detections defaults --- salt/soc/defaults.yaml | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index de372a98f..6c8234b9a 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1080,7 +1080,7 @@ soc: elastalertengine: allowRegex: '' autoUpdateEnabled: false - communityRulesImportFrequencySeconds: 86400 + communityRulesImportFrequencySeconds: 180 denyRegex: '' elastAlertRulesFolder: /opt/sensoroni/elastalert rulesFingerprintFile: /opt/sensoroni/fingerprints/sigma.fingerprint @@ -1132,8 +1132,9 @@ soc: strelkaengine: allowRegex: '' autoUpdateEnabled: false + communityRulesImportFrequencySeconds: 180 compileYaraPythonScriptPath: /opt/so/conf/strelka/compile_yara.py - denyRegex: '.*' + denyRegex: '' reposFolder: /opt/sensoroni/yara/repos rulesRepos: - repo: https://github.com/Security-Onion-Solutions/securityonion-yara @@ -1141,8 +1142,10 @@ soc: yaraRulesFolder: /opt/sensoroni/yara/rules suricataengine: allowRegex: '' + autoUpdateEnabled: false + communityRulesImportFrequencySeconds: 180 communityRulesFile: /nsm/rules/suricata/emerging-all.rules - denyRegex: '.*' + denyRegex: '' rulesFingerprintFile: /opt/sensoroni/fingerprints/emerging-all.fingerprint client: enableReverseLookup: false