mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
add default ruleset
This commit is contained in:
@@ -1586,6 +1586,14 @@ soc:
|
|||||||
insecureSkipVerify: false
|
insecureSkipVerify: false
|
||||||
readOnly: true
|
readOnly: true
|
||||||
deleteUnreferenced: true
|
deleteUnreferenced: true
|
||||||
|
- name: ABUSECH-SSLBL
|
||||||
|
deleteUnreferenced: true
|
||||||
|
description: 'Abuse.ch SSL Blacklist'
|
||||||
|
enabled: false
|
||||||
|
license: CC0-1.0
|
||||||
|
readOnly: true
|
||||||
|
sourcePath: https://sslbl.abuse.ch/blacklist/sslblacklist_tls_cert.tar.gz
|
||||||
|
sourceType: url
|
||||||
- name: local-rules
|
- name: local-rules
|
||||||
id: local-rules
|
id: local-rules
|
||||||
description: "Local custom rules from files (*.rules) in a directory on the filesystem"
|
description: "Local custom rules from files (*.rules) in a directory on the filesystem"
|
||||||
|
|||||||
@@ -159,7 +159,7 @@ surithresholding:
|
|||||||
- source: salt://suricata/files/threshold.conf
|
- source: salt://suricata/files/threshold.conf
|
||||||
- user: 940
|
- user: 940
|
||||||
- group: 940
|
- group: 940
|
||||||
- contents: 'This file is managed by Security Onion. Do not modify by hand.'
|
- onlyif: salt://suricata/files/threshold.conf
|
||||||
|
|
||||||
suriclassifications:
|
suriclassifications:
|
||||||
file.managed:
|
file.managed:
|
||||||
|
|||||||
Reference in New Issue
Block a user