Josh Brower
7bdaf9338e
Update Sigma template
2026-08-20 09:31:56 -04:00
Matthew Wright
ea502e29d0
agentic salt annotations
2026-08-13 12:09:59 -04:00
Jason Ertel
a7ddb7a975
Use newer /api/joblookup endpoint
2026-08-10 13:38:41 -04:00
Corey Ogburn
d94c16eea1
Investigator and Engineer Use Gemma
2026-07-28 10:26:29 -06:00
Corey Ogburn
a45ca12076
Change defaults
...
We're no longer using DisplayName as the model identifier. Refactored to use id@adapter.
2026-07-28 10:19:18 -06:00
Mike Reeves
4de8f0208f
Add Gemma configuration to defaults.yaml
2026-07-27 12:15:21 -04:00
Josh Brower
812310088e
Support sigma playbooks for airgap
2026-07-27 10:30:50 -04:00
Josh Brower
120b426a79
Add already_running mapping
2026-07-24 17:23:00 -04:00
Josh Brower
01a873b2d9
Map av to both defender and defend
2026-07-23 13:39:19 -04:00
Mike Reeves
334978ad92
Rename Detection Engineer agent key to DetectionEngineer
...
The agent name is also the agentMapping config key and a SOC setting id
segment, so the space made it awkward to target. Matches the rename in
securityonion-soc.
2026-07-22 11:55:12 -04:00
Josh Brower
963e475d1a
Merge pull request #16087 from Security-Onion-Solutions/sigma-pipeline
...
Broader support for SigmaHQ rules + Elastic Defend logs
2026-07-21 22:05:19 +02:00
Mike Reeves
f3d8bae13d
Merge pull request #16093 from Security-Onion-Solutions/fix/agentic-adapter-resolution
...
Map default agents to model displayName, not id
2026-07-21 15:13:00 -04:00
Mike Reeves
894d323323
Map default agents to model displayName, not id
...
agentMapping values are model displayNames (the canonical selector); the
stock config used the model id, which only resolved via the legacy
id@adapter fallback. Use the Claude Sonnet displayName so agent-to-model
resolution matches the documented contract.
2026-07-21 15:08:24 -04:00
Jason Ertel
4e1935f8a0
postgress updates
2026-07-21 11:58:11 -04:00
Josh Brower
c4c1464b2a
Better support SigmaHQ rules
2026-07-21 10:07:33 -04:00
Josh Patterson
c4295b4e0a
Merge pull request #16071 from Security-Onion-Solutions/saltthangs
...
auto state apply
2026-07-20 08:56:08 -04:00
Josh Brower
48a7d66964
Update baseline agents
2026-07-17 15:20:20 -04:00
Josh Patterson
f958212bea
Merge remote-tracking branch 'origin/3/dev' into saltthangs
2026-07-15 15:07:09 -04:00
Jason Ertel
566f90a0c0
toggle pg metrics
2026-07-10 10:32:25 -04:00
coreyogburn
032d792331
Merge pull request #16030 from Security-Onion-Solutions/feature/agentic
...
Feature/agentic
2026-07-07 14:37:52 -06:00
Josh Patterson
66a1141b84
Merge remote-tracking branch 'origin/3/dev' into saltthangs
2026-07-07 09:02:15 -04:00
Josh Brower
db91ce981d
Add repo names
2026-07-07 07:49:11 -04:00
Josh Brower
9975d36b4f
Merge pull request #16019 from Security-Onion-Solutions/feature/sigma-playbooks
...
support sigma playbooks
2026-07-06 13:17:54 +02:00
Josh Brower
1fe7726aff
Changes from feedback
2026-07-02 14:58:48 -04:00
Corey Ogburn
83cf1f0793
New Client Params for Tool Retries
2026-07-02 10:11:52 -06:00
Corey Ogburn
8675296393
More Agentic Fields
...
The big agentic switch, a specific maxDelegationDepth, and the agentMapping dict
2026-07-01 15:04:42 -06:00
Matthew Wright
23f04e2866
maxSubSessionTokens and maxDelegationDepth config settings
2026-07-01 15:02:21 -06:00
reyesj2
868b217549
update default hunt query
2026-07-01 11:37:46 -05:00
Josh Brower
2a6cc58306
Simplify mappings
2026-07-01 09:07:02 -04:00
Josh Brower
9217670bab
support sigma playbooks
2026-06-30 16:21:01 -04:00
Josh Patterson
d71e80cf66
Merge remote-tracking branch 'origin/3/dev' into saltthangs
2026-06-23 10:32:32 -04:00
Jason Ertel
ae1ddf3817
es|ql defaults
2026-06-15 12:33:08 -04:00
Josh Patterson
33a116357d
Merge remote-tracking branch 'origin/3/dev' into saltthangs
2026-06-10 08:56:17 -04:00
Jason Ertel
61e72c89e4
postgres updates
2026-06-03 09:49:53 -04:00
Jason Ertel
7ca2313255
move to securityonion db
2026-06-03 09:05:23 -04:00
Josh Patterson
d48a22e37e
Merge pull request #15944 from Security-Onion-Solutions/jertel/wip
...
Jertel/wip
2026-05-28 14:01:42 -04:00
Josh Patterson
93ffce98d7
add onionconfig and postgres modules to soc config
2026-05-27 15:07:25 -04:00
Josh Patterson
730c828bec
Merge remote-tracking branch 'origin/jertel/wip' into saltthangs
2026-05-19 10:23:45 -04:00
Jason Ertel
936295f1c4
Merge branch '3/dev' into jertel/wip
2026-05-13 17:28:25 -04:00
Jason Ertel
61ca60a94c
prep for soc db config
2026-05-13 17:28:07 -04:00
Josh Patterson
84decc1db6
Merge remote-tracking branch 'origin/3/dev' into saltthangs
2026-05-13 14:09:15 -04:00
Josh Brower
006ac31109
Merge pull request #15579 from marcopedrinazzi/3/dev
...
New Sigma rules pipeline mapping for M365 and Fortigate
2026-05-11 21:03:53 +02:00
Josh Brower
e1d830da76
proc_creation per OS type
2026-05-08 09:11:24 -04:00
Josh Patterson
17849d8758
Merge remote-tracking branch 'origin/3/dev' into saltthangs
2026-04-28 15:49:22 -04:00
Mike Reeves
2dcded6cca
drop postgres module from soc defaults injection
...
The soc binary on 3/dev does not register a postgres module, so injecting
postgres into soc.config.server.modules makes soc abort at launch with
'Module does not exist: postgres'. The soc-side module is staged on
feature/postgres but is not landing this release. Drop the injection
until the module ships; salt/postgres state and pillars are unchanged.
2026-04-28 15:46:56 -04:00
Josh Patterson
034711d148
Merge remote-tracking branch 'origin/3/dev' into saltthangs
2026-04-28 10:47:29 -04:00
Mike Reeves
fa8162de02
Merge pull request #15749 from Security-Onion-Solutions/feature/postgres
...
Add so-postgres Salt states and infrastructure
2026-04-28 10:15:47 -04:00
Josh Patterson
070d150420
readonly soc and kratos enabled
2026-04-24 13:56:35 -04:00
Jason Ertel
71da27dc8e
fix template annotation
2026-04-20 17:02:25 -04:00
Mike Reeves
8225d41661
Harden postgres secrets, TLS enforcement, and admin tooling
...
- Deliver postgres super and app passwords via mounted 0600 secret files
(POSTGRES_PASSWORD_FILE, SO_POSTGRES_PASS_FILE) instead of plaintext env
vars visible in docker inspect output
- Mount a managed pg_hba.conf that only allows local trust and hostssl
scram-sha-256 so TCP clients cannot negotiate cleartext sessions
- Restrict postgres.key to 0400 and ensure owner/group 939
- Set umask 0077 on so-postgres-backup output
- Validate host values in so-stats-show against [A-Za-z0-9._-] before SQL
interpolation so a compromised minion cannot inject SQL via a tag value
- Coerce postgres:telegraf:retention_days to int before rendering into SQL
- Escape single quotes when rendering pillar values into postgresql.conf
- Own postgres tooling in /usr/sbin as root:root so a container escape
cannot rewrite admin scripts
- Gate ES migration TLS verification on esVerifyCert (default false,
matching the elastic module's existing pattern)
2026-04-20 12:36:17 -04:00