Commit Graph

1310 Commits

Author SHA1 Message Date
Josh Brower b5bf12f8c8 Zeek - bpf fixup 2020-01-31 15:06:57 -05:00
Josh Brower f5efc68825 Merge pull request #289 from Security-Onion-Solutions/feature/so-status
feature/so-status
2020-01-31 14:02:15 -05:00
Josh Brower c96a95e526 SO Scripts - fixes 2020-01-31 12:41:01 -05:00
m0duspwnens 6b580eaba9 evalmode fix 2020-01-30 17:54:24 -05:00
m0duspwnens 68e7dcfba0 evalfix 2020-01-30 17:38:48 -05:00
m0duspwnens 88967c2512 evalfix 2020-01-30 17:36:38 -05:00
m0duspwnens d94065fa00 evalfix 2020-01-30 17:09:06 -05:00
William Wernert 025c1972cd Merge pull request #288 from Security-Onion-Solutions/hotfix/auth-init
hotfix/auth-init
2020-01-30 16:34:24 -05:00
Mike Reeves 1e0d0d74e1 Fix Eval Event Pickup x2 2020-01-30 16:16:21 -05:00
Mike Reeves c32b2726fa Fix Eval Event Pickup 2020-01-30 16:10:59 -05:00
Mike Reeves 59d6b7cb8a Add log paths 2020-01-30 16:00:57 -05:00
Mike Reeves 048c77695d Fix Filebeat 2020-01-30 15:47:51 -05:00
William Wernert 746bd99f99 Merge branch 'dev' into feature/so-status 2020-01-30 12:41:41 -05:00
William Wernert f839f38553 Fix for jinja error 2020-01-30 12:40:39 -05:00
William Wernert 5dec2b1c87 Move auth init.sls to docker registry 2020-01-30 12:39:09 -05:00
Mike Reeves 21e374c82e Fix SSL State 2020-01-30 11:10:52 -05:00
Josh Brower 3fdc5fbef4 Dep Bro and enabled Zeek BPF 2020-01-30 09:45:02 -05:00
Wes Lambert 3277ca185e Update Zeek config 2020-01-29 22:09:32 +00:00
weslambert eba02ef3b4 Merge pull request #279 from Security-Onion-Solutions/features/heavynode
Features/heavynode
2020-01-29 17:07:00 -05:00
m0duspwnens 07df8bff7e add filebeat features back 2020-01-29 17:00:39 -05:00
m0duspwnens 0d22502072 changes to filebeat for heavynode 2020-01-29 16:45:04 -05:00
Josh Brower a75949e062 Merge pull request #274 from Security-Onion-Solutions/fix/elastic_clear
so-elastic-clear: Set IP in script
2020-01-29 15:49:16 -05:00
Wes Lambert aa3fc72565 Change bro to zeek 2020-01-29 18:56:21 +00:00
m0duspwnens bd5b597aed heavynode 2020-01-29 12:56:25 -05:00
m0duspwnens 306cc1127b heavynode 2020-01-29 12:56:25 -05:00
Wes Lambert ef83d812d2 Set IP 2020-01-29 17:41:56 +00:00
Josh Brower 5213c19e44 Suricata - logfile fix 2020-01-29 09:30:03 -05:00
Mike Reeves bd395b8356 Update filebeat.yml 2020-01-28 22:20:21 -05:00
weslambert 101c2a93d1 Merge pull request #269 from Security-Onion-Solutions/feature/so-status
feature/so-status
2020-01-28 22:13:47 -05:00
Josh Brower 3925ed52c7 Suricata - BPF hotfix 2020-01-28 22:02:18 -05:00
Mike Reeves bf1187ad60 Merge pull request #270 from Security-Onion-Solutions/feature/bpf-zeek
Zeek - Initial BPF Support
2020-01-28 21:49:03 -05:00
Mike Reeves 357cfcbe78 Merge pull request #266 from Security-Onion-Solutions/fix/elastalert_indices
Update config.yaml for Elastalert shard/replica changes
2020-01-28 21:47:07 -05:00
Josh Brower aa2fbc2d53 Zeek - Initial BPF support 2020-01-28 21:44:42 -05:00
Mike Reeves 745a92f217 Merge pull request #259 from Security-Onion-Solutions/fix/wazuh_whitelist
Don't restart when running whitelist script
2020-01-28 21:44:06 -05:00
William Wernert 5bd037e88c Initial so-status script 2020-01-28 21:42:47 -05:00
William Wernert 50d4693a09 Merge branch 'dev' into feature/script-fixes 2020-01-28 21:39:41 -05:00
Josh Brower 492ad7035b Merge pull request #268 from Security-Onion-Solutions/feature/nsm_clear
Feature/nsm clear
2020-01-28 21:01:04 -05:00
Wes Lambert 48ebc5e2e3 Fix data checks 2020-01-29 01:13:40 +00:00
Wes Lambert 5e0299e7bb Add PCAP stop|start|restart scripts 2020-01-29 01:11:22 +00:00
Wes Lambert 41e5c6ae90 Add data deletion scripts 2020-01-29 00:57:58 +00:00
Wes Lambert 8b415b9db4 Update config.yaml for Elastalert shard/replica changes 2020-01-28 23:55:06 +00:00
Mike Reeves 149c10435e Merge pull request #264 from Security-Onion-Solutions/feature/bpf-suricata
Suricata - Initial bpf support
2020-01-28 18:20:45 -05:00
Josh Brower 86689edf24 Merge branch 'dev' into feature/bpf-steno 2020-01-28 18:18:17 -05:00
Josh Brower ae087c5552 Steno BPF tweaks 2020-01-28 16:53:19 -05:00
Josh Brower f536e89064 Suricata bpf cleanup 2020-01-28 16:12:46 -05:00
Josh Brower 8204ffdd05 Suricata bpf - docker bind bpf file 2020-01-28 15:51:13 -05:00
Josh Brower 5403dab027 Suricata - Initial bpf support 2020-01-28 15:48:40 -05:00
Wes Lambert c22753a8fb Don't restart when running whitelist script 2020-01-28 19:42:59 +00:00
Mike Reeves de369494ed Merge pull request #252 from Security-Onion-Solutions/feature/bpf-steno
Steno BPF - cleanup & simplify
2020-01-28 10:18:23 -05:00
Mike Reeves aeafc82677 Merge pull request #256 from Security-Onion-Solutions/fix/wazuh_restart
Update Wazuh scripts
2020-01-28 10:17:42 -05:00