Merge remote-tracking branch 'origin/cogburn/detection_playbooks' into kilo

This commit is contained in:
Josh Brower
2024-02-15 17:50:37 -05:00

View File

@@ -64,7 +64,7 @@ soc:
icon: fa-external-link-alt icon: fa-external-link-alt
target: _blank target: _blank
links: links:
- 'https://{:sublime.url}/messages/{:sublime.message_group_id}' - 'https://{:sublime.url}/messages/{:sublime.message_group_id}'
- name: actionProcessAncestors - name: actionProcessAncestors
description: actionProcessAncestorsHelp description: actionProcessAncestorsHelp
icon: fa-people-roof icon: fa-people-roof
@@ -1012,7 +1012,8 @@ soc:
communityRulesImportFrequencySeconds: 180 communityRulesImportFrequencySeconds: 180
elastAlertRulesFolder: /opt/sensoroni/elastalert elastAlertRulesFolder: /opt/sensoroni/elastalert
rulesFingerprintFile: /opt/sensoroni/fingerprints/sigma.fingerprint rulesFingerprintFile: /opt/sensoroni/fingerprints/sigma.fingerprint
sigmaRulePackages: core sigmaRulePackages:
- core
elastic: elastic:
hostUrl: hostUrl:
remoteHostUrls: [] remoteHostUrls: []