Josh Brower
3d478b92b2
Merge pull request #12294 from Security-Onion-Solutions/jppffa
...
Jppffa
2024-02-01 09:47:18 -05:00
Josh Brower
e090518b59
Refactor script
2024-02-01 09:46:53 -05:00
weslambert
91c1e595ef
Merge pull request #12297 from Security-Onion-Solutions/feature/pipeline_config_ui
...
Manage custom Elasticsearch and Logstash pipelines in UI
2024-02-01 09:18:30 -05:00
Wes
1818e134ca
Change numbers for Logstash
2024-02-01 14:01:55 +00:00
Wes
182667bafb
Change numbers for Elasticsearch
2024-02-01 13:59:23 +00:00
Josh Brower
49b5788ac1
add bindings
2024-02-01 07:21:49 -05:00
Josh Brower
881d6b313e
Update VERSION - kilo
2024-01-31 17:04:11 -05:00
Josh Brower
db057b4dfa
Merge pull request #12296 from Security-Onion-Solutions/cogburn/detection_playbooks
...
Cogburn/detection playbooks
2024-01-31 16:48:51 -05:00
Wes
136097f981
Custom Logstash pipeline annotations
2024-01-31 21:47:09 +00:00
Wes
bc502cc065
Custom Elasticserach pipeline annotations
2024-01-31 21:46:33 +00:00
m0duspwnens
ae32ac40c2
add fleet node nginx to docker annotations
2024-01-31 16:28:45 -05:00
m0duspwnens
2f03248612
use different nginx defaults for so-fleet node hosting artifacts
2024-01-31 16:25:09 -05:00
Mike Reeves
a094d1007b
Merge pull request #12293 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
fix salt lock for airgap version mismatches
2024-01-31 16:21:16 -05:00
Mike Reeves
341ff5b564
Update so-functions
2024-01-31 16:18:51 -05:00
Josh Brower
0fe96bfc2d
switch to symlink
2024-01-31 16:17:40 -05:00
Wes
4672a5b8eb
Custom pipeline configuration in UI
2024-01-31 20:18:17 +00:00
Wes
1853dc398b
Custom pipeline configuration
2024-01-31 20:17:33 +00:00
Wes
bc75be9402
Custom pipelines in UI
2024-01-31 20:16:48 +00:00
Wes
cd4bd6460a
Custom pipelines
2024-01-31 20:16:18 +00:00
Corey Ogburn
585147d1de
Added so-detection mapping in elasticsearch
2024-01-31 10:39:47 -07:00
Mike Reeves
0d01d09d2e
fix pcap paths
2024-01-31 09:15:35 -05:00
Pete
1192dbd530
also remove intca symlink
...
The symlink is created in init.sls; it should be removed here.
2024-01-31 09:01:56 -05:00
Mike Reeves
00289c201e
fix pcap paths
2024-01-31 08:58:57 -05:00
Corey Ogburn
858166bcae
WIP: Detections Changes
...
Removed some strelka/yara rules from salt.
Removed yara scripts for downloading and updating rules. This will be managed by SOC.
Added a new compile_yara.py script.
Added the strelka repos folder.
2024-01-30 15:43:51 -07:00
m0duspwnens
4be1214bab
pcap engine logic for sensoroni
2024-01-30 16:53:57 -05:00
Corey Ogburn
0fa4d92f8f
socsigmarepo
...
Need write permissions on the /opt/so/rules dir so I can clone the sigma repo there.
2024-01-30 14:49:05 -07:00
m0duspwnens
8a25748e33
grammar
2024-01-30 16:06:24 -05:00
m0duspwnens
8b503e2ffa
telegraf dont run stenoloss script if suricata is pcap engine
2024-01-30 15:58:11 -05:00
Jorge Reyes
4dd0b4a4fd
Merge pull request #12283 from Security-Onion-Solutions/reyesj2-patch-6
...
Remove remediate from initial oscap scan
2024-01-30 15:56:13 -05:00
reyesj2
b5ffa186fb
Remove remediate from initial oscap scan
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-30 15:54:23 -05:00
m0duspwnens
f32cb1f115
fix find to work with steno and suri pcap
2024-01-30 15:48:10 -05:00
m0duspwnens
8ed66ea468
disable stenographer if suricata is pcap engine
2024-01-30 15:22:32 -05:00
m0duspwnens
0522dc180a
map pcap dir to container. enable pcap-log in map
2024-01-30 13:39:35 -05:00
m0duspwnens
37dcb84a09
add missing comma
2024-01-30 10:50:01 -05:00
m0duspwnens
d118ff4728
add GLOBALS.pcap_engine
2024-01-29 16:54:08 -05:00
Mike Reeves
88d2ddba8b
add placeholder for telegraf
2024-01-29 15:53:54 -05:00
Mike Reeves
ab551a747d
Threads placeholder logic
2024-01-29 15:44:57 -05:00
Mike Reeves
88c01a22d6
Add annotation logic
2024-01-29 15:27:28 -05:00
Mike Reeves
0c969312e2
Add Globals
2024-01-29 15:22:20 -05:00
Mike Reeves
5b05aec96a
Target sspecific minion
2024-01-29 14:56:51 -05:00
Mike Reeves
1a2245a1ed
Add so-minion modifications
2024-01-29 13:44:53 -05:00
Josh Brower
0d08bb0a91
Finalize script
2024-01-29 11:37:28 -05:00
Jorge Reyes
cb5e111a00
Merge pull request #12267 from Security-Onion-Solutions/reyesj2-patch-6
...
Update soup
2024-01-29 10:22:35 -05:00
reyesj2
7c08b348aa
Add comment for soup update w/ STIGs enabled
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-29 10:16:34 -05:00
Josh Brower
afa98fa147
update artifacts URL automatically
2024-01-28 14:20:52 -05:00
Josh Brower
1847e5c3c0
Enable nginx on Fleet Node
2024-01-28 11:37:18 -05:00
Josh Brower
cfc33b1a34
Sync Elastic Agent Artifacts
2024-01-28 10:12:25 -05:00
weslambert
dc5ea89255
Merge pull request #12260 from Security-Onion-Solutions/fix/endpoint_diagnostic
...
Add template for endpoint.diagnostic.collection
2024-01-26 16:13:30 -05:00
reyesj2
c4301d7cc1
Soup script update locations
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 15:51:06 -05:00
reyesj2
91c7b8144d
soup logic
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 15:43:42 -05:00