diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 04ef707af..1296fe48e 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1445,7 +1445,7 @@ soc: default: - repo: https://github.com/Security-Onion-Solutions/securityonion-resources license: Elastic-2.0 - folder: sigma + folder: sigma/stable community: true rulesetName: securityonion-resources - repo: file:///nsm/rules/custom-local-repos/local-sigma @@ -1455,7 +1455,7 @@ soc: airgap: - repo: file:///nsm/rules/detect-sigma/repos/securityonion-resources license: Elastic-2.0 - folder: sigma + folder: sigma/stable community: true rulesetName: securityonion-resources - repo: file:///nsm/rules/custom-local-repos/local-sigma @@ -1465,7 +1465,7 @@ soc: sigmaRulePackages: - core - emerging_threats_addon - useEsql: true + useEsql: false esqlCaseInsensitive: true esqlQueryDelaySeconds: 30 esqlCorrelationAllowanceSeconds: 600 diff --git a/salt/soc/files/soc/sigma_so_pipeline.yaml b/salt/soc/files/soc/sigma_so_pipeline.yaml index 910e0d7c6..1cf8a6920 100644 --- a/salt/soc/files/soc/sigma_so_pipeline.yaml +++ b/salt/soc/files/soc/sigma_so_pipeline.yaml @@ -129,6 +129,9 @@ transformations: valid_hash_algos: ["MD5", "SHA1", "SHA256", "SHA512", "IMPHASH"] field_prefix: "file" drop_algo_prefix: False + # ecs_windows has already renamed Hashes; pySigma 1.5+ only parses the fields listed here + field_to_parse: + - winlog.event_data.Hashes field_name_conditions: - type: include_fields fields: diff --git a/salt/soc/merged.map.jinja b/salt/soc/merged.map.jinja index a1b25ff1e..e86eef635 100644 --- a/salt/soc/merged.map.jinja +++ b/salt/soc/merged.map.jinja @@ -85,6 +85,18 @@ {% do SOCMERGED.config.server.update({'airgapEnabled': false}) %} {% endif %} +{# Sigma correlations require ES|QL: load the community correlations and offer correlation authoring only when it is on #} +{% set use_esql = SOCMERGED.config.server.modules.elastalertengine.useEsql %} +{% for repo in SOCMERGED.config.server.modules.elastalertengine.rulesRepos %} +{% if repo.get('rulesetName') == 'securityonion-resources' and repo.get('folder') in ['sigma', 'sigma/stable'] %} +{% do repo.update({'folder': 'sigma' if use_esql else 'sigma/stable'}) %} +{% endif %} +{% endfor %} +{% if not use_esql %} +{% do SOCMERGED.config.server.client.detection.templateDetections.pop('elastalert_correlation', None) %} +{% do SOCMERGED.config.server.client.detections.update({'queries': SOCMERGED.config.server.client.detections.queries | rejectattr('name', 'equalto', 'Detection Type - Sigma (Elastalert) - Correlations') | list}) %} +{% endif %} + {# Define the postgresmetrics module if telegraf is setup to only use Postgres #} {% if TELEGRAFMERGED.output != 'INFLUXDB' and PG_USER and PG_PASS %} {% do SOCMERGED.config.server.modules.update({ diff --git a/salt/soc/soc_soc.yaml b/salt/soc/soc_soc.yaml index 2aa54627b..36774f63f 100644 --- a/salt/soc/soc_soc.yaml +++ b/salt/soc/soc_soc.yaml @@ -400,7 +400,7 @@ soc: advanced: False helpLink: sigma useEsql: - description: "(Pre-release) Use Elasticsearch Piped Query Language (ES|QL) instead of EQL (Elastic Query Language) for Elasticsearch queries. The Sigma converter will output ES|QL instead of EQL, allowing support for correlations. Switching back to EQL is not supported for correlations: they stay enabled but stop running until ES|QL is turned on again." + description: "(Pre-release) Use Elasticsearch Piped Query Language (ES|QL) instead of EQL (Elastic Query Language) for Elasticsearch queries. The Sigma converter will output ES|QL instead of EQL, allowing support for correlations. Switching back to EQL is not supported for correlations." global: True advanced: True forcedType: bool