Jason Ertel
|
9d5f4049b5
|
Avoid filtering NIC when it's an empty string
|
2020-06-02 05:52:03 -04:00 |
|
Mike Reeves
|
307cbe4b77
|
Couple of QOL scripts
|
2020-06-01 20:48:25 -04:00 |
|
Josh Brower
|
4b14ecf1d9
|
Fleet standalone fixes
|
2020-06-01 16:36:32 -04:00 |
|
Mike Reeves
|
45d17c5148
|
Pillarize Suricata Round 1
|
2020-06-01 14:53:04 -04:00 |
|
m0duspwnens
|
1737b46abb
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-06-01 12:15:00 -04:00 |
|
Doug Burks
|
80d1814f10
|
remove event.module:zeek to make queries more generic
|
2020-06-01 12:00:33 -04:00 |
|
Mike Reeves
|
03f34404b1
|
Suricata 5 Meta Data
|
2020-06-01 11:03:43 -04:00 |
|
Wes Lambert
|
51f5d64ef6
|
Rename tunnel_parents
|
2020-06-01 13:51:32 +00:00 |
|
Wes Lambert
|
d7ce3d4719
|
fix naming of uid field for tunnel
|
2020-06-01 12:52:57 +00:00 |
|
Doug Burks
|
f559621f00
|
add x509 issuer and subject groupby queries
|
2020-06-01 07:48:50 -04:00 |
|
Doug Burks
|
46dc5f42e9
|
combine two http queries into one with multiple groupby
|
2020-06-01 07:30:08 -04:00 |
|
m0duspwnens
|
5ddfb7ccce
|
fix merge conflicts
|
2020-05-29 17:31:07 -04:00 |
|
m0duspwnens
|
4dfb58a98c
|
change how whitelist script determines if wazuh is enabled
|
2020-05-29 17:22:39 -04:00 |
|
m0duspwnens
|
17879ad88c
|
add nginx state to searchnode in salt/top
|
2020-05-29 17:01:43 -04:00 |
|
m0duspwnens
|
15fc97e516
|
adding suricata.master state to mastersearch - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-29 13:11:55 -04:00 |
|
m0duspwnens
|
6db8470de7
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-05-29 13:09:49 -04:00 |
|
m0duspwnens
|
3143643692
|
add navigator to master if enabled
|
2020-05-29 13:05:26 -04:00 |
|
m0duspwnens
|
2db2054cce
|
update instructions in logstash customer pipelines and templates - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-29 10:58:53 -04:00 |
|
Wes Lambert
|
4059121dd6
|
fix framed_addr field
|
2020-05-29 11:55:18 +00:00 |
|
m0duspwnens
|
40fa5293bf
|
move fileserve update to suricata.master
|
2020-05-28 15:54:11 -04:00 |
|
Wes Lambert
|
7f75050682
|
Add basic Zeek stats script
|
2020-05-28 17:54:15 +00:00 |
|
Josh Brower
|
aeb71bb8f0
|
Simplified setup script
|
2020-05-28 13:21:25 -04:00 |
|
weslambert
|
b835c2e27e
|
Update for exact match (ex. thehive, thehive-es, thehive-cortex)
|
2020-05-28 13:17:31 -04:00 |
|
weslambert
|
12f426d4f4
|
Move eve.json to /nsm
|
2020-05-28 12:59:41 -04:00 |
|
Wes Lambert
|
869bfb947d
|
add master to SOCtopus hosts file
|
2020-05-28 16:45:48 +00:00 |
|
weslambert
|
d2263db0ff
|
Update init.sls
|
2020-05-28 12:11:08 -04:00 |
|
m0duspwnens
|
4f15de8b77
|
refresh salt fileserver if suricata rule symlink is created
|
2020-05-28 12:00:22 -04:00 |
|
Josh Brower
|
e53e891bd6
|
Fleet reactor - Typo fix
|
2020-05-28 11:36:38 -04:00 |
|
Wes Lambert
|
b7d7747f65
|
allow syslog
|
2020-05-28 13:56:02 +00:00 |
|
Mike Reeves
|
8304d91b0b
|
Merge branch 'dev' into feature/suri5
|
2020-05-28 09:41:28 -04:00 |
|
Wes Lambert
|
d2b93d531e
|
Basic syslog config
|
2020-05-28 12:36:29 +00:00 |
|
Wes Lambert
|
5afc05feb2
|
Update FB init for syslog
|
2020-05-28 12:35:22 +00:00 |
|
Wes Lambert
|
b9bdca509e
|
update Filebeat config for syslog
|
2020-05-28 12:33:41 +00:00 |
|
Doug Burks
|
f3efafc9ca
|
combine two notice queries into one query with multiple groupby
|
2020-05-28 08:01:33 -04:00 |
|
Doug Burks
|
60cc3e9675
|
remove address from DHCP leases query
|
2020-05-28 07:50:52 -04:00 |
|
m0duspwnens
|
59cc927878
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-05-27 15:56:38 -04:00 |
|
weslambert
|
6a935b5452
|
Hive to TheHive
|
2020-05-27 15:43:41 -04:00 |
|
Josh Brower
|
11c641fd1b
|
Initial support - integrated Fleet setup
|
2020-05-27 15:34:14 -04:00 |
|
m0duspwnens
|
12a6da928f
|
create /opt/so/saltstack/local/salt/suricata - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-27 15:00:11 -04:00 |
|
m0duspwnens
|
40f04ef6d0
|
merge with dev and fix conflicts
|
2020-05-27 13:54:08 -04:00 |
|
Wes Lambert
|
b80eb5f73b
|
Add Hive/ES/Cortex scripts
|
2020-05-27 17:43:17 +00:00 |
|
Wes Lambert
|
b26f6826dd
|
Rename Hive to TheHive in several places
|
2020-05-27 17:17:55 +00:00 |
|
Wes Lambert
|
d56bc4c167
|
fix path
|
2020-05-27 17:01:05 +00:00 |
|
Wes Lambert
|
3684cdf1c6
|
Update FB and LS
|
2020-05-27 17:00:09 +00:00 |
|
Wes Lambert
|
e78a3f3278
|
update Suricata config
|
2020-05-27 16:59:26 +00:00 |
|
Wes Lambert
|
b7a0f79038
|
Update Suricata init
|
2020-05-27 16:58:31 +00:00 |
|
m0duspwnens
|
693000afa8
|
remove addtotab templates and move surirulelink - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-27 12:30:12 -04:00 |
|
m0duspwnens
|
446e0f6f4c
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-05-27 10:09:36 -04:00 |
|
m0duspwnens
|
7eb02d2af3
|
move suri rule symlink
|
2020-05-27 10:09:23 -04:00 |
|
weslambert
|
f3809cb93d
|
Wrap with quotes
|
2020-05-27 08:31:14 -04:00 |
|