Jason Ertel
3b447b343f
fix typo
2025-04-17 11:51:45 -04:00
Jason Ertel
d0375d3c7e
fix typo
2025-04-17 11:51:21 -04:00
Jason Ertel
b607689993
improve regex
2025-04-17 11:47:52 -04:00
Jason Ertel
8f1e528f1c
improve regex
2025-04-17 11:09:39 -04:00
Jason Ertel
366e39950a
subord annotations; ensure node reboots occur in background
2025-04-16 15:55:16 -04:00
Jason Ertel
b99bb0b004
support options field on actions
2025-04-04 11:19:30 -04:00
Jason Ertel
9c455badb9
support background actions via config UI
2025-04-03 13:08:44 -04:00
Jason Ertel
2af05b9a23
switch back to colon for better clarity
2025-03-07 08:24:19 -05:00
Doug Burks
3037dc7c38
Update soc_soc.yaml to fix previous change
2025-03-07 07:13:27 -05:00
Mike Reeves
14e95f4898
Update soc_soc.yaml
2025-03-06 21:01:45 -05:00
Mike Reeves
bad0031829
Update soc_soc.yaml
2025-03-06 20:58:23 -05:00
Mike Reeves
03ebc2d86e
Add Actions
2025-03-05 15:58:10 -05:00
Mike Reeves
3021ed5d36
Add Actions
2025-03-05 15:56:26 -05:00
Mike Reeves
b51aa56e86
Some things I thought were bools are not bools
2025-03-05 15:15:26 -05:00
Mike Reeves
b01fb733a9
Some things I thought were bools are not bools
2025-03-05 14:56:26 -05:00
Mike Reeves
2ffaf2f601
Add hunt queries
2025-02-27 12:42:03 -05:00
Mike Reeves
4696152f78
Add hunt queries
2025-02-27 12:31:51 -05:00
Mike Reeves
a0944f8359
Add hunt queries
2025-02-27 12:17:57 -05:00
Mike Reeves
1fdbe987b8
Add hunt queries
2025-02-27 12:15:37 -05:00
Mike Reeves
40303c2d78
Add hunt queries
2025-02-27 12:10:59 -05:00
Mike Reeves
4b5048bd80
Add hunt queries
2025-02-27 11:57:57 -05:00
Mike Reeves
9d31050907
roll back SOC changes
2025-02-27 11:32:59 -05:00
Mike Reeves
e930d1dec6
roll back SOC changes
2025-02-27 11:28:06 -05:00
Mike Reeves
1d3bae4a7a
Add additional entries for actions
2025-02-27 11:15:51 -05:00
Mike Reeves
d950e4ebb3
Add additional entries for actions
2025-02-27 11:11:56 -05:00
Mike Reeves
3ba82bd5a4
Fix actions
2025-02-27 11:04:47 -05:00
Mike Reeves
6c00cdd726
Fix healthlink
2025-02-26 16:15:00 -05:00
Mike Reeves
8bc500e4da
soc
2025-02-26 14:16:42 -05:00
Mike Reeves
25217c3262
soc
2025-02-26 14:14:25 -05:00
Mike Reeves
0c2797ecdc
soc
2025-02-26 13:49:30 -05:00
Mike Reeves
101f6e744a
sensoroni
2025-02-26 13:44:35 -05:00
Mike Reeves
c5e0b8a42e
sensoroni
2025-02-26 13:40:24 -05:00
Mike Reeves
2bc2e86b01
actions
2025-02-26 13:36:16 -05:00
Mike Reeves
6fec217068
actions
2025-02-26 13:34:32 -05:00
Jason Ertel
9dafa062f8
annotation/config updates
2025-02-25 17:00:41 -05:00
Corey Ogburn
23ebe966e0
Added Large Values Warning
...
maxBulkEscalateEvents now has a warning that large values may run into other limits.
2025-02-04 10:33:04 -07:00
Corey Ogburn
d0fa6eaf83
New Limit on Bulk Creating Related Events
...
Used by the UI and API to hint at a user that not every event will be attached to a case. Supports values up to 10,000 (the default limit on the number of documents returned by a single ES search).
2025-02-03 14:20:33 -07:00
Joshua Brower
dcdf31eee8
Fix folder perm
2025-01-10 16:15:17 -05:00
Joshua Brower
a2caf7425d
Add config options
2025-01-07 13:22:14 -05:00
Josh Brower
04ffdf9b15
Merge pull request #13958 from Security-Onion-Solutions/2.4/autoenablesigma
...
More flexibility for AutoEnable Sigma rules
2024-11-21 09:47:49 -05:00
defensivedepth
f61bf1bd67
Remove adv
2024-11-21 09:15:29 -05:00
defensivedepth
b1c4e32123
Remove duplicate option
2024-11-21 09:11:44 -05:00
defensivedepth
8958da83b3
Deprecate instead
2024-11-20 18:00:26 -05:00
Corey Ogburn
d86c009f55
Add Annotations to Existing Detections Options
...
The autoUpdateEnabled setting has been present for awhile and now have annotations.
2024-11-18 14:35:55 -07:00
defensivedepth
56d6857cd6
Addl customization for autoenable sigma
2024-11-18 09:03:17 -05:00
Corey Ogburn
52a144c052
Added Help Link to Annotation for IgnoredSidRanges
2024-11-05 12:11:17 -07:00
Corey Ogburn
25d55feeef
More Detailed Description
2024-11-05 11:41:14 -07:00
Corey Ogburn
69dd35c30a
Add Option for Ignoring Ranges of SIDs in Suricata Integrity Check
2024-11-04 14:31:53 -07:00
Corey Ogburn
ad0b0a5e95
Refactor to String
...
To accomodate the config screen, the annotation now specifies it as a multiline string with a yaml syntax. The user can edit the yaml to add or remove queries. The UI will parse the YAML before use.
Also updated the IntegrityFailure queries to specify table columns more relevant to a sync failure than the default ones.
2024-10-24 11:18:47 -06:00
Corey Ogburn
c77b0afd8e
Move to Client/Detections
...
Added a basic annotation.
2024-10-24 11:18:47 -06:00