Mike Reeves
d43cb3e133
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-04-05 10:48:01 -04:00
m0duspwnens
534dbf9761
change the upgrade command - https://github.com/Security-Onion-Solutions/securityonion/issues/3501
2021-04-05 09:07:00 -04:00
Doug Burks
8ca0626387
FIX: Hunt query for HTTP EXE downloads should work for both Zeek and Suricata #3753
2021-04-05 06:55:40 -04:00
Jason Ertel
e430be1017
Enable Flux compatibility mode to prepare for eventual migration to 2.0
2021-04-02 16:36:29 -04:00
William Wernert
d19c03efef
Refactor search of config lines
...
* Create arrays for each line and loop through them for better code readability
* Add more host key algorithms for removal
* Update regex to look for a comma or EOL at the end of the search term, to avoid missing last item in list
2021-04-02 14:49:22 -04:00
William Wernert
8b8086b91a
Update wording, as the new key tends to be ED25519, not ECDSA
2021-04-02 10:20:28 -04:00
William Wernert
fd57996bc6
Change behavior of adding lines to sshd config
...
* Replace existing lines in cases where a change has already been made
2021-04-02 10:00:27 -04:00
William Wernert
43c31b4e66
Fix script so changes are actually made
2021-04-01 14:56:05 -04:00
William Wernert
fa373e9db0
Merge branch 'fix/ssh-harden-setup' into foxtrot
2021-04-01 11:04:10 -04:00
m0duspwnens
5cda35db0a
change defaults for testing - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-04-01 10:45:54 -04:00
Mike Reeves
c60d4aca16
Merge pull request #3724 from Masaya-A/Fix-https
...
Fix: Connection to ES is "https" from 2.3.40
2021-04-01 10:36:02 -04:00
Mike Reeves
234dec3f63
Merge pull request #3734 from Security-Onion-Solutions/zeekports
...
Reserve ports for Zeek
2021-04-01 10:35:16 -04:00
Mike Reeves
7d489ea34f
Merge pull request #3735 from Security-Onion-Solutions/kilo
...
For hunt quick actions, pipe value to 'escape' operator to escape bac…
2021-04-01 10:35:01 -04:00
Mike Reeves
7c6b037ae5
Reserve ports for Zeek
2021-04-01 10:30:52 -04:00
Mike Reeves
40313fc2f5
Reserve ports for Zeek
2021-04-01 10:29:58 -04:00
m0duspwnens
4f3b3a787c
change defaults for testing, remove measurements list since cq uses wildcard now - https://github.com/Security-Onion-Solutions/securityonion/issues/3264
2021-04-01 10:18:29 -04:00
Mike Reeves
0d05612393
Reserve ports for Zeek
2021-04-01 10:00:55 -04:00
Masaya-A
bc04cae918
Fix: Connection to ES is "https" from 2.3.40
2021-04-01 16:59:47 +09:00
Mike Reeves
88eab86528
Manage the repo files
2021-03-31 17:07:30 -04:00
Mike Reeves
9645988555
Manage the repo files
2021-03-31 17:06:26 -04:00
Mike Reeves
1509722185
Manage the repo files
2021-03-31 17:04:56 -04:00
Mike Reeves
bfc5bb011f
Manage the repo files
2021-03-31 17:03:52 -04:00
Mike Reeves
13421bb04b
Manage the repo files
2021-03-31 16:59:15 -04:00
Josh Patterson
6cebc41353
Merge pull request #3720 from Security-Onion-Solutions/issue/3709
...
https://github.com/Security-Onion-Solutions/securityonion/issues/3709
2021-03-31 16:54:15 -04:00
Mike Reeves
f387c4327a
Manage the repo files
2021-03-31 16:53:20 -04:00
Mike Reeves
358f397535
Manage the repo files
2021-03-31 16:50:43 -04:00
Mike Reeves
9b84a92ced
Manage the repo files
2021-03-31 16:47:04 -04:00
Josh Brower
2b86241450
Merge pull request #3717 from Security-Onion-Solutions/fix/playbook-timestamps
...
Fix Playbook Alert timestamps
2021-03-31 15:47:11 -04:00
Josh Brower
ef98445560
Fix Playbook Alert timestamps
2021-03-31 15:44:41 -04:00
m0duspwnens
f7e99b4961
https://github.com/Security-Onion-Solutions/securityonion/issues/3709
2021-03-31 15:17:15 -04:00
Jason Ertel
820b01405f
For hunt quick actions, pipe value to 'escape' operator to escape backslashes and double quotes
2021-03-31 14:57:36 -04:00
William Wernert
2a595f03b7
Merge pull request #3630 from Security-Onion-Solutions/foxtrot
...
Add option to configure chrony as an ntp service
2021-03-31 13:41:06 -04:00
Mike Reeves
89922a439e
Move repo files
2021-03-31 12:37:33 -04:00
Josh Brower
209d348108
Merge pull request #3688 from Security-Onion-Solutions/fix/playbook-sync
...
Fix sensor cleanup & playbook sync scripts
2021-03-31 11:59:27 -04:00
Mike Reeves
0d077b0d49
Merge pull request #3704 from gebhard73/patch-2
...
Update so-index-list
2021-03-31 09:18:29 -04:00
William Wernert
04920dcbed
Merge branch 'dev' into foxtrot
2021-03-31 09:15:17 -04:00
Wes Lambert
942de130ca
Enforce date type for ingest.timestamp
2021-03-31 12:24:51 +00:00
gebhard73
0b9cf57b5f
Update so-index-list
...
Sort by index name.
2021-03-31 14:22:06 +02:00
Mike Reeves
e92f5c122c
Merge pull request #3689 from Security-Onion-Solutions/kilo
...
Remove incompatible example
2021-03-30 16:08:16 -04:00
m0duspwnens
8e55e0b994
start graphing data from so_long_term
2021-03-30 13:36:52 -04:00
Josh Brower
679925ebd9
Fix sensor cleanup & playbook sync scripts
2021-03-30 13:29:56 -04:00
Wes Lambert
7049383ba6
Add Elastic scripts
2021-03-30 15:47:05 +00:00
Mike Reeves
2534ca7eb7
Merge pull request #3633 from Security-Onion-Solutions/newrepo
...
Attempt to use so repo for network install
2021-03-30 11:37:46 -04:00
Mike Reeves
09064baf71
Update so-common
2021-03-30 11:21:19 -04:00
Mike Reeves
5f5a53b8bb
Push repolist to dev null
2021-03-30 11:14:58 -04:00
m0duspwnens
30c6d4756a
change default long term resolution to 5m
2021-03-30 09:38:37 -04:00
Mike Reeves
1a58479f39
Fix acng passthrough
2021-03-29 15:15:34 -04:00
m0duspwnens
d1150f150f
loop through the rps
2021-03-29 10:59:18 -04:00
m0duspwnens
e0f4abaa09
try to do it with just 1 cq, modify defaults for testing
2021-03-29 10:36:56 -04:00
William Wernert
d81d4e7474
Merge branch 'dev' into foxtrot
2021-03-29 09:36:38 -04:00