Wes Lambert
05549a2362
Add Zeek intel.dat
2020-11-02 21:36:44 +00:00
m0duspwnens
7e090b0894
dont echo salt minion config file to prevent mysql.pass from showing in sosetup.log
2020-11-02 16:23:34 -05:00
weslambert
8a645edb34
Merge pull request #1788 from Security-Onion-Solutions/feature/nids_rules
...
Allow for muliple files for rules
2020-11-02 16:05:53 -05:00
Wes Lambert
24a54a326c
Allow for muliple files for rules
2020-11-02 21:03:45 +00:00
Jason Ertel
184d163d65
Do not persist the Cortex PID file; This allows Cortex to recover from non-graceful container shutdowns, such as a power loss event on the host machine
2020-11-02 15:04:13 -05:00
weslambert
bb0cf9b8c7
Merge pull request #1784 from Security-Onion-Solutions/fix/strelka_exif_parsing
...
Fix/strelka exif parsing
2020-11-02 14:32:45 -05:00
Wes Lambert
3113d5fbdb
Format scan.exiftool as text
2020-11-02 19:31:14 +00:00
Wes Lambert
6420ee0310
Update parsing for scan.exiftool
2020-11-02 19:28:12 +00:00
William Wernert
033f5dbb9c
[fix] Use (mostly) absolute path when adding to PATH
2020-11-02 14:25:46 -05:00
William Wernert
1c4abcef15
[fix] Kill all jobs before checking if we can reach the salt master
2020-11-02 14:25:02 -05:00
Jason Ertel
2acb930a2e
fix: Remove crontab for automation installs
2020-11-02 11:08:45 -05:00
weslambert
37c630d6ab
Merge pull request #1776 from Security-Onion-Solutions/bugfix/af-packet-ring-size
...
Match max-pending-packets size
2020-11-02 08:39:21 -05:00
weslambert
71a260a000
Match max-pending-packets size
2020-11-02 08:38:45 -05:00
jtgreen-cse
6359e03ba6
fix for Windows events via osquery
...
This change was required to properly let Windows events flow through their specific pipelines. Otherwise, the `temp` field stays around and gets ingested in ES.
2020-10-29 15:03:13 -04:00
William Wernert
b489fee8b5
Merge pull request #1738 from Security-Onion-Solutions/bugfix/nginx-redirect
...
Bugfix/nginx redirect
2020-10-29 14:33:38 -04:00
William Wernert
91221c4332
[revert] Move proxy_pass back to ip
2020-10-29 10:23:12 -04:00
William Wernert
3abd1c9f16
[fix] Configure soctopus to use url_base
2020-10-28 16:08:19 -04:00
Mike Reeves
b14c1d0999
Merge pull request #1713 from Security-Onion-Solutions/logstashbind
...
Add a place where custom logstash certs can go
2020-10-28 15:27:26 -04:00
Mike Reeves
13be0da484
Add a place where custom logstash certs can go
2020-10-28 15:26:41 -04:00
Mike Reeves
3385d98a2a
Merge pull request #1712 from Security-Onion-Solutions/logstashbind
...
Add a place where custom logstash certs can go
2020-10-28 15:26:08 -04:00
Mike Reeves
361b13dc88
Add a place where custom logstash certs can go
2020-10-28 15:25:00 -04:00
Jason Ertel
98c669e80b
Disable nginx server version and TLSv1.0/TLSv1.1
2020-10-28 14:29:29 -04:00
William Wernert
b02d434a0e
[fix] Change any scripts using auth headers to url_base
2020-10-28 12:29:09 -04:00
William Wernert
3ee9f23d26
[fix] Use url_base in sensoroni.json instead of manager hostname
2020-10-28 12:28:34 -04:00
Jason Ertel
348c2feee2
Prevent usage of dollar signs in admin passwords during setup
2020-10-28 11:07:05 -04:00
Mike Reeves
b238c492e4
Update so-functions
2020-10-28 10:50:10 -04:00
Mike Reeves
97207bd006
Merge pull request #1702 from Security-Onion-Solutions/dockernet
...
Custom Docker IP Range
2020-10-28 10:48:56 -04:00
Mike Reeves
bed70ab6bf
Update whiptail menu for docker question
2020-10-28 10:19:15 -04:00
Mike Reeves
8173cb589b
Update whiptail menu for docker question
2020-10-28 10:17:53 -04:00
Mike Reeves
563a606e0e
Upodate dockernet menu
2020-10-28 10:14:14 -04:00
Mike Reeves
8d952eca7e
Upodate dockernet menu
2020-10-28 10:12:07 -04:00
Mike Reeves
8f7dffea4b
Upodate dockernet menu
2020-10-28 10:10:43 -04:00
weslambert
7ea8dc84b6
Merge pull request #1696 from Security-Onion-Solutions/feature/wazuh-user-mods
...
Add Wazuh user management scripts
2020-10-28 08:24:15 -04:00
Wes Lambert
453247971e
Add Wazuh user management scripts
2020-10-28 12:22:50 +00:00
Mike Reeves
741e17a637
add bip for docker
2020-10-27 18:21:53 -04:00
Mike Reeves
fedf334ee9
add bip for docker
2020-10-27 18:21:09 -04:00
Mike Reeves
8fee19ee1b
add bip for docker
2020-10-27 18:01:48 -04:00
Mike Reeves
697bc53aec
Dockernet Modifications
2020-10-27 15:08:34 -04:00
Jason Ertel
5a705fc0f2
Add Hunt quick action for hunted events, grouping by dataset and module
2020-10-27 12:30:33 -04:00
William Wernert
7b17b4abc7
Merge pull request #1680 from Security-Onion-Solutions/feature/setup-fixes
...
Feature/setup fixes
2020-10-27 12:17:21 -04:00
William Wernert
a043bc7cc4
[fix] Second if to elif
2020-10-27 12:16:19 -04:00
William Wernert
72dc267ab5
[fix] Menu sizing fixes
2020-10-27 12:14:44 -04:00
William Wernert
970be4d530
[fix] Change cd to relative
...
Since the script already changes to the correct dir, we can work from relative directories now.
2020-10-27 12:13:07 -04:00
Jason Ertel
474c4e54b4
Ensure labels and icons are associated with all quick actions
2020-10-27 12:04:57 -04:00
Mike Reeves
d4dd4aa416
Add missing comma in daemon.json
2020-10-27 11:25:45 -04:00
William Wernert
5054138be9
[feat] Add analyst option + add back helix option
2020-10-27 11:21:03 -04:00
William Wernert
83c23dd5de
[fix] Remove old got_root call
2020-10-27 11:20:39 -04:00
Mike Reeves
42e00514f5
Adding docker net setting
2020-10-27 11:09:14 -04:00
William Wernert
e75f8ba257
[fix] Move root check to top of so-setup
2020-10-27 09:39:29 -04:00
William Wernert
564ac3a4ff
Merge pull request #980 from Security-Onion-Solutions/feature/nginx-update
...
Feature/nginx update
2020-10-27 09:29:43 -04:00