mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Add analyze feature
This commit is contained in:
5
salt/sensoroni/files/analyzers/virustotal.py
Normal file
5
salt/sensoroni/files/analyzers/virustotal.py
Normal file
@@ -0,0 +1,5 @@
|
||||
def main():
|
||||
print '{"foo":"bar","summary":"something here"}'
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
0
salt/sensoroni/files/analyzers/whois/__init__.py
Normal file
0
salt/sensoroni/files/analyzers/whois/__init__.py
Normal file
BIN
salt/sensoroni/files/analyzers/whois/__init__.pyc
Normal file
BIN
salt/sensoroni/files/analyzers/whois/__init__.pyc
Normal file
Binary file not shown.
5
salt/sensoroni/files/analyzers/whois/whois.py
Normal file
5
salt/sensoroni/files/analyzers/whois/whois.py
Normal file
@@ -0,0 +1,5 @@
|
||||
def main():
|
||||
print '{"result":{ "requestId": "something-generated-by-whois", "someother_field": "more data" }, "summary": "botsrv.btc-goblin.ru"}'
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -2,6 +2,8 @@
|
||||
{%- set DESCRIPTION = salt['pillar.get']('sensoroni:node_description', '') %}
|
||||
{%- set MODEL = salt['grains.get']('sosmodel', '') %}
|
||||
{%- set ADDRESS = salt['pillar.get']('sensoroni:node_address') %}
|
||||
{%- set ANALYZE_TIMEOUT_MS = salt['pillar.get']('sensoroni:analyze_timeout_ms', 900000) %}
|
||||
{%- set ANALYZE_PARALLEL_LIMIT = salt['pillar.get']('sensoroni:analyze_parallel_limit', 5) %}
|
||||
{%- set SENSORONIKEY = salt['pillar.get']('global:sensoronikey', '') %}
|
||||
{%- set CHECKININTERVALMS = salt['pillar.get']('sensoroni:node_checkin_interval_ms', 10000) %}
|
||||
{%- set ROLE = grains.id.split('_') | last %}
|
||||
@@ -24,6 +26,10 @@
|
||||
"serverUrl": "https://{{ URLBASE }}/sensoroniagents",
|
||||
"verifyCert": false,
|
||||
"modules": {
|
||||
"analyze": {
|
||||
"timeoutMs": {{ ANALYZE_TIMEOUT_MS }},
|
||||
"parallelLimit": {{ ANALYZE_PARALLEL_LIMIT }},
|
||||
},
|
||||
"importer": {},
|
||||
"statickeyauth": {
|
||||
"apiKey": "{{ SENSORONIKEY }}"
|
||||
|
||||
@@ -18,6 +18,13 @@ sensoroniagentconf:
|
||||
- mode: 600
|
||||
- template: jinja
|
||||
|
||||
analyzersdir:
|
||||
file.directory:
|
||||
- name: /opt/so/conf/soc/analyzers
|
||||
- user: 939
|
||||
- group: 939
|
||||
- makedirs: True
|
||||
|
||||
sensoronilog:
|
||||
file.directory:
|
||||
- name: /opt/so/log/sensoroni
|
||||
@@ -25,6 +32,15 @@ sensoronilog:
|
||||
- group: 939
|
||||
- makedirs: True
|
||||
|
||||
analyzerscripts:
|
||||
file.recurse:
|
||||
- name: /opt/so/conf/soc/analyzers
|
||||
- user: 939
|
||||
- group: 939
|
||||
- file_mode: 755
|
||||
- template: jinja
|
||||
- source: salt://sensoroni/files/analyzers
|
||||
|
||||
so-sensoroni:
|
||||
docker_container.running:
|
||||
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-soc:{{ VERSION }}
|
||||
@@ -35,6 +51,7 @@ so-sensoroni:
|
||||
- /nsm/import:/nsm/import:rw
|
||||
- /nsm/pcapout:/nsm/pcapout:rw
|
||||
- /opt/so/conf/sensoroni/sensoroni.json:/opt/sensoroni/sensoroni.json:ro
|
||||
- /opt/so/conf/sensoroni/analyzers:/opt/sensoroni/analyzers:ro
|
||||
- /opt/so/log/sensoroni:/opt/sensoroni/logs:rw
|
||||
- watch:
|
||||
- file: /opt/so/conf/sensoroni/sensoroni.json
|
||||
|
||||
@@ -217,6 +217,7 @@
|
||||
"case": {
|
||||
"mostRecentlyUsedLimit": 5,
|
||||
"renderAbbreviatedCount": 30,
|
||||
"analyzerNodeId": "{{ grains.host | lower }}",
|
||||
"presets": {
|
||||
"artifactType": {{ presets_artifacttype | json }},
|
||||
"category": {{ presets_category | json }},
|
||||
|
||||
Reference in New Issue
Block a user