-
-
-
Hybrid Hunter Alpha 1.1.4 - Feature Parity Release
+
+
+
+
+
Hybrid Hunter Alpha 1.1.4 - Feature Parity Release
+
+
Changes:
-
- Added new in-house auth method [Security Onion Auth](https://github.com/Security-Onion-Solutions/securityonion-auth).
- Web user creation is done via the browser now instead of so-user-add.
- New Logstash pipeline setup. Now uses multiple pipelines.
- New Master + Search node type and well as a Heavy Node type in the install.
- Change all nodes to point to the docker registry on the Master. This cuts down on the calls to dockerhub.
- Zeek 3.0.1
- Elastic 6.8.6
- New SO Start | Stop | Restart scripts for all components (eg. `so-playbook-restart`).
- BPF support for Suricata (NIDS), Steno (PCAP) & Zeek ([Docs](https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/BPF)).
- Updated Domain Stats & Frequency Server containers to Python3 & created new Salt states for them.
- Added so-status script which gives an easy to read look at container status.
- Manage threshold.conf for Suricata using the thresholding pillar.
- The ISO now includes all the docker containers for faster install speeds.
- You now set the password for the onion account during the iso install. This account is temporary and will be removed after so-setup.
- Updated Helix parsers for better compatibility.
- Updated telegraf docker to include curl and jq.
- CVE-2020-0601 Zeek Detection Script.
- ISO Install now prompts you to create a password for the onion user during imaging. This account gets disabled during setup.
- Check out the Hybrid Hunter Quick Start Guide .
-
-
+
+ Added new in-house auth method [Security Onion Auth](https://github.com/Security-Onion-Solutions/securityonion-auth).
+ Web user creation is done via the browser now instead of so-user-add.
+ New Logstash pipeline setup. Now uses multiple pipelines.
+ New Master + Search node type and well as a Heavy Node type in the install.
+ Change all nodes to point to the docker registry on the Master. This cuts down on the calls to dockerhub.
+ Zeek 3.0.1
+ Elastic 6.8.6
+ New SO Start | Stop | Restart scripts for all components (eg. `so-playbook-restart`).
+ BPF support for Suricata (NIDS), Steno (PCAP) & Zeek ([Docs](https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/BPF)).
+ Updated Domain Stats & Frequency Server containers to Python3 & created new Salt states for them.
+ Added so-status script which gives an easy to read look at container status.
+ Manage threshold.conf for Suricata using the thresholding pillar.
+ The ISO now includes all the docker containers for faster install speeds.
+ You now set the password for the onion account during the iso install. This account is temporary and will be removed after so-setup.
+ Updated Helix parsers for better compatibility.
+ Updated telegraf docker to include curl and jq.
+ CVE-2020-0601 Zeek Detection Script.
+ ISO Install now prompts you to create a password for the onion user during imaging. This account gets disabled during setup.
+ Check out the Hybrid Hunter Quick Start Guide .
+
+
-
diff --git a/salt/fleet/osquery-packages.html b/salt/fleet/osquery-packages.html
index c94ba89b9..c1843bf01 100644
--- a/salt/fleet/osquery-packages.html
+++ b/salt/fleet/osquery-packages.html
@@ -8,14 +8,14 @@
-
-
-
-
-
-
Osquery Packages
-
-
Notes
-
- These packages are customized for this specific Fleet install and will only be generated after the Fleet setup script has been run. If you want vanilla osquery packages, you can get them directly from osquery.io
- Packages are not signed.
-
-
Downloads
-
-
-
Known Issues
-
-
-
-
-
+
+
+
+
+
+
+
Osquery Packages
+
+
+
Notes
+
+ These packages are customized for this specific Fleet install and will only be generated after the Fleet setup script has been run. If you want vanilla osquery packages, you can get them directly from osquery.io
+ Packages are not signed.
+
+
+
Downloads
+
+ Generated: N/A
+
+
+ Packages:
+
+
+
+ Config Files:
+
+
+
+
Known Issues
+
+
+
+