mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Update README.md
This commit is contained in:
committed by
William Wernert
parent
eca8cf5502
commit
a48baf528b
59
README.md
59
README.md
@@ -1,33 +1,44 @@
|
|||||||
## Hybrid Hunter Alpha 1.1.4 - Feature Parity Release
|
## Hybrid Hunter Beta 1.2.1 - Beta 1
|
||||||
|
|
||||||
### Changes:
|
### Changes:
|
||||||
|
|
||||||
- Added new in-house auth method [Security Onion Auth](https://github.com/Security-Onion-Solutions/securityonion-auth).
|
- Full support for Ubuntu 18.04. 16.04 is no longer supported for Hybrid Hunter.
|
||||||
- Web user creation is done via the browser now instead of so-user-add.
|
- Introduction of the Security Onion Console. Once logged in you are directly taken to the SOC.
|
||||||
- New Logstash pipeline setup. Now uses multiple pipelines.
|
- New authentication using Kratos.
|
||||||
- New Master + Search node type and well as a Heavy Node type in the install.
|
- During install you must specify how you would like to access the SOC ui. This is for strict cookie security.
|
||||||
- Change all nodes to point to the docker registry on the Master. This cuts down on the calls to dockerhub.
|
- Ability to list and delete web users from the SOC ui.
|
||||||
- Zeek 3.0.1
|
- The soremote account is now used to add nodes to the grid vs using socore.
|
||||||
- Elastic 6.8.6
|
- Community ID support for Zeek, osquery, and Suricata. You can now tie host events to connection logs!
|
||||||
- New SO Start | Stop | Restart scripts for all components (eg. `so-playbook-restart`).
|
- Elastic 7.6.1 with ECS support.
|
||||||
- BPF support for Suricata (NIDS), Steno (PCAP) & Zeek ([Docs](https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/BPF)).
|
- New set of Kibana dashboards that align with ECS.
|
||||||
- Updated Domain Stats & Frequency Server containers to Python3 & created new Salt states for them.
|
- Eval mode no longer uses Logstash for parsing (Filebeat -> ES Ingest)
|
||||||
- Added so-status script which gives an easy to read look at container status.
|
- Ingest node parsing for osquery-shipped logs (osquery, WEL, Sysmon).
|
||||||
- Manage threshold.conf for Suricata using the thresholding pillar.
|
- Fleet standalone mode with improved Web UI & API access control.
|
||||||
- The ISO now includes all the docker containers for faster install speeds.
|
- Improved Fleet integration support.
|
||||||
- You now set the password for the onion account during the iso install. This account is temporary and will be removed after so-setup.
|
- Playbook now has full Windows Sigma community ruleset builtin.
|
||||||
- Updated Helix parsers for better compatibility.
|
- Automatic Sigma community rule updates.
|
||||||
- Updated telegraf docker to include curl and jq.
|
- Playbook stability enhancements.
|
||||||
- CVE-2020-0601 Zeek Detection Script.
|
- Zeek health check. Zeek will now auto restart if a worker crashes.
|
||||||
- ISO Install now prompts you to create a password for the onion user during imaging. This account gets disabled during setup.
|
- zeekctl is now managed by salt.
|
||||||
|
- Grafana dashboard improvements and cleanup.
|
||||||
|
- Moved logstash configs to pillars.
|
||||||
|
- Salt logs moved to /opt/so/log/salt.
|
||||||
|
- Strelka integrated for file-oriented detection/analysis at scale
|
||||||
|
|
||||||
## Version 1.1.4 ISO Download
|
### Known issues:
|
||||||
|
|
||||||
[HH1.1.4-46.ISO](https://download.securityonion.net/file/Hybrid-Hunter/HH-1.1.4-46.iso)
|
- Updating users via the SOC ui is known to fail. To change a user, delete the user and re-add them.
|
||||||
|
- Due to the move to ECS, the current Playbook plays may not alert correctly at this time.
|
||||||
|
- The osquery MacOS package does not install correctly.
|
||||||
|
|
||||||
MD5: ACF6B4586E8EE7D1938FB2C028DFC987
|
|
||||||
SHA1: C29B4F3748604196357EC7262BF071177E696D86
|
## Version 1.2.1 Beta 1 ISO Download
|
||||||
SHA256: 4D977B650196441294D53372F248B50C23E933B8FBEC5CC5BAB569DFEF31E7E8
|
|
||||||
|
[HH1.2.1-6.ISO](https://download.securityonion.net/file/Hybrid-Hunter/HH-1.2.1-6.iso)
|
||||||
|
|
||||||
|
MD5: D7E66CA8AAC37E70E2A2F7BB12EB3C23
|
||||||
|
SHA1: D91D921896F9ADA600EBA0ADAA548D8630B5341F
|
||||||
|
SHA256: D69E327597AB429DCE13C1177BCE6C1FAD934E78A09F73D14778C2CAE616557B
|
||||||
|
|
||||||
### Warnings and Disclaimers
|
### Warnings and Disclaimers
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user