Wes Lambert
|
942de130ca
|
Enforce date type for ingest.timestamp
|
2021-03-31 12:24:51 +00:00 |
|
Josh Brower
|
71ae5b60ea
|
Update Sigmac mappings and config for IPs and ports
|
2021-03-16 09:32:40 -04:00 |
|
Josh Brower
|
5fe025318b
|
Update Sigmac mappings and config for IPs and ports
|
2021-03-15 15:53:00 -04:00 |
|
Josh Brower
|
548f67ca6f
|
Initial support for Live Queries in Hunt
|
2021-03-04 18:21:13 -05:00 |
|
Josh Brower
|
d2a74c80e2
|
Update .security analyzer
|
2021-02-17 16:37:31 -05:00 |
|
Wes Lambert
|
3113d5fbdb
|
Format scan.exiftool as text
|
2020-11-02 19:31:14 +00:00 |
|
Wes Lambert
|
af9daa4d71
|
Intel mapping enforcement and winlog.verion
|
2020-10-15 12:42:33 +00:00 |
|
Wes Lambert
|
b55ffa44f8
|
Fix module,dataset rename
|
2020-10-10 00:01:37 +00:00 |
|
Wes Lambert
|
019bec992d
|
Add Strelka YARA matches as alerts
|
2020-10-06 12:19:44 +00:00 |
|
Josh Brower
|
8a78485906
|
Config Playbook SOC Alerts
|
2020-10-04 21:35:42 -04:00 |
|
Wes Lambert
|
36019727b3
|
Ensure IPs are typed as IP and ports as integer
|
2020-09-29 18:20:15 +00:00 |
|
Josh Brower
|
1cf7301db4
|
Adds new .security analyzed subfield
|
2020-08-26 05:11:42 -04:00 |
|
Josh Brower
|
15efe77e06
|
Ingest Parsing Update for Sysmon/WEL
|
2020-08-06 13:11:47 -04:00 |
|
Jason Ertel
|
d2df405cf0
|
so-import-pcap improvements: Ensure PCAP filenames with spaces are handled properly; Provide link directly to the imported logs, filtered by import ID; Require sudo access to run so-import-pcap
|
2020-07-21 11:07:09 -04:00 |
|
m0duspwnens
|
57bf23d83c
|
move templates from logstash to elasticsearch
|
2020-07-14 16:07:46 -04:00 |
|