Change Detections defaults

This commit is contained in:
DefensiveDepth
2024-03-19 13:53:37 -04:00
parent 4237210f0b
commit 020eb47026

View File

@@ -1080,7 +1080,7 @@ soc:
elastalertengine: elastalertengine:
allowRegex: '' allowRegex: ''
autoUpdateEnabled: false autoUpdateEnabled: false
communityRulesImportFrequencySeconds: 86400 communityRulesImportFrequencySeconds: 180
denyRegex: '' denyRegex: ''
elastAlertRulesFolder: /opt/sensoroni/elastalert elastAlertRulesFolder: /opt/sensoroni/elastalert
rulesFingerprintFile: /opt/sensoroni/fingerprints/sigma.fingerprint rulesFingerprintFile: /opt/sensoroni/fingerprints/sigma.fingerprint
@@ -1132,8 +1132,9 @@ soc:
strelkaengine: strelkaengine:
allowRegex: '' allowRegex: ''
autoUpdateEnabled: false autoUpdateEnabled: false
communityRulesImportFrequencySeconds: 180
compileYaraPythonScriptPath: /opt/so/conf/strelka/compile_yara.py compileYaraPythonScriptPath: /opt/so/conf/strelka/compile_yara.py
denyRegex: '.*' denyRegex: ''
reposFolder: /opt/sensoroni/yara/repos reposFolder: /opt/sensoroni/yara/repos
rulesRepos: rulesRepos:
- repo: https://github.com/Security-Onion-Solutions/securityonion-yara - repo: https://github.com/Security-Onion-Solutions/securityonion-yara
@@ -1141,8 +1142,10 @@ soc:
yaraRulesFolder: /opt/sensoroni/yara/rules yaraRulesFolder: /opt/sensoroni/yara/rules
suricataengine: suricataengine:
allowRegex: '' allowRegex: ''
autoUpdateEnabled: false
communityRulesImportFrequencySeconds: 180
communityRulesFile: /nsm/rules/suricata/emerging-all.rules communityRulesFile: /nsm/rules/suricata/emerging-all.rules
denyRegex: '.*' denyRegex: ''
rulesFingerprintFile: /opt/sensoroni/fingerprints/emerging-all.fingerprint rulesFingerprintFile: /opt/sensoroni/fingerprints/emerging-all.fingerprint
client: client:
enableReverseLookup: false enableReverseLookup: false