Commit Graph

4984 Commits

Author SHA1 Message Date
Jason Ertel cf5b1245ea Add configurable flags to enable/disable dismiss and escalate buttons 2020-10-05 09:16:17 -04:00
weslambert 771d091d6e Merge pull request #1446 from Security-Onion-Solutions/feature/wazuh_severity
Add event.severity and event.severity_label config for Wazuh alerts
2020-10-05 08:52:20 -04:00
Wes Lambert 77d31cb289 Add event.severity and event.severity_label config for Wazuh alerts 2020-10-05 12:50:29 +00:00
weslambert 203e84d2cf Update comma verbiage for HOME_NET in whiptail menu 2020-10-05 08:08:22 -04:00
Josh Brower 7b05cf4266 Merge pull request #1443 from Security-Onion-Solutions/feature/training-req
Feature/training req
2020-10-04 21:37:03 -04:00
Josh Brower 8a78485906 Config Playbook SOC Alerts 2020-10-04 21:35:42 -04:00
Josh Brower c80b6ce104 Add so-allow-view and playbook event.sev.label 2020-10-04 20:39:21 -04:00
m0duspwnens 467e5b34cc analyst node changes 2020-10-02 16:40:25 -04:00
m0duspwnens 20307b703e analyst node changes 2020-10-02 16:21:31 -04:00
m0duspwnens 6a0f04d24a analyst node changes 2020-10-02 16:14:15 -04:00
m0duspwnens 5a5007c07d analyst node changes 2020-10-02 15:50:49 -04:00
m0duspwnens fde6f128ab analyst node changes 2020-10-02 15:26:13 -04:00
m0duspwnens 1be3323265 analyst node changes 2020-10-02 15:25:42 -04:00
m0duspwnens 47762816a7 analyst node changes 2020-10-02 14:57:22 -04:00
m0duspwnens 40647ce54c analyst node changes 2020-10-02 14:40:15 -04:00
William Wernert 8310559273 Merge pull request #1440 from Security-Onion-Solutions/feature/generate-playbook-api-key
Feature/generate playbook api key
2020-10-02 14:37:58 -04:00
William Wernert 2a100c0dcc Add OLD_ prefix + only update rules if playbook enabled 2020-10-02 14:34:30 -04:00
William Wernert d0c267ca90 Fix sed command to not delete lines after match 2020-10-02 14:31:16 -04:00
William Wernert 54da2b869c Add OLD_ db init files for soup compatibility 2020-10-02 14:12:23 -04:00
William Wernert ab662e9b81 Merge branch 'dev' into feature/generate-playbook-api-key
# Conflicts:
#	salt/common/tools/sbin/soup
2020-10-02 13:48:52 -04:00
William Wernert db12b6f3c6 Remove salt call to automation_user_create 2020-10-02 13:17:57 -04:00
William Wernert 96d32fda51 Add old api key to pillar during soup 2020-10-02 13:16:58 -04:00
Mike Reeves 15f0c98281 Fix Formatting 2020-10-02 13:06:03 -04:00
m0duspwnens d0da7ade6a analyst node changes 2020-10-02 12:15:00 -04:00
m0duspwnens c4e0fa0939 analyst node changes 2020-10-02 12:12:28 -04:00
m0duspwnens e11717c4d0 analyst node changes 2020-10-02 11:28:53 -04:00
m0duspwnens 76a13e99da new wallpaper 2020-10-02 10:12:36 -04:00
William Wernert 20fd757847 Run playbook-ruleupdate after soctopus is running 2020-10-02 10:05:10 -04:00
William Wernert 39e14b3910 Merge branch 'dev' into feature/generate-playbook-api-key 2020-10-02 08:39:09 -04:00
Mike Reeves c7fcdc8084 Merge pull request #1438 from Security-Onion-Solutions/socyaml
Socyaml
2020-10-01 18:08:33 -04:00
Mike Reeves 4991ea8de3 Jason made me rename json 2020-10-01 18:07:06 -04:00
Mike Reeves 36ccece724 commas gone crazy 2020-10-01 18:02:06 -04:00
Mike Reeves a0432e97b0 Python print ftl 2020-10-01 17:57:56 -04:00
m0duspwnens 733b1376c5 analyst node changes 2020-10-01 17:53:20 -04:00
Mike Reeves 490278a4c3 Add alert events filed 2020-10-01 17:49:17 -04:00
Mike Reeves bd5efbabd9 Fix Mode 2020-10-01 17:43:43 -04:00
Mike Reeves 8fa426f265 Cleanup sync 2020-10-01 17:41:55 -04:00
Mike Reeves 9d9d3aac53 Switch to JSON from yaml 2020-10-01 17:37:57 -04:00
Mike Reeves 744a8bca73 More json for soc 2020-10-01 17:30:23 -04:00
Mike Reeves 8a41636e7f More json for soc 2020-10-01 17:28:45 -04:00
Mike Reeves dc79dca7fe More json for soc 2020-10-01 17:25:51 -04:00
Mike Reeves 1c55f738ec More json for soc 2020-10-01 17:23:29 -04:00
William Wernert e98012ae2c Fix jinja and change state orrder in setup 2020-10-01 17:16:26 -04:00
Mike Reeves 92fa33159e More json for soc 2020-10-01 17:12:08 -04:00
m0duspwnens 72c6fe2184 analyst node changes 2020-10-01 17:05:59 -04:00
Mike Reeves 5730c85988 More json for soc 2020-10-01 17:04:15 -04:00
Mike Reeves 63be0734c9 More json for soc 2020-10-01 17:00:25 -04:00
Mike Reeves 5653828154 More json for soc 2020-10-01 16:57:04 -04:00
weslambert 2d2f4de337 Merge pull request #1437 from Security-Onion-Solutions/fix/kib_scripted_thehive
Update scripted field for TheHive case
2020-10-01 16:54:02 -04:00
Wes Lambert 8a81a5148b Update scripted field for TheHive case 2020-10-01 20:52:57 +00:00