Corey Ogburn
8f81c9eb68
Updating config for Detection(s)
2024-02-02 11:49:58 -07:00
Josh Brower
fe196b5661
Add SOC Config for Detections
2024-02-01 12:22:50 -05:00
Josh Brower
49b5788ac1
add bindings
2024-02-01 07:21:49 -05:00
Corey Ogburn
585147d1de
Added so-detection mapping in elasticsearch
2024-01-31 10:39:47 -07:00
Corey Ogburn
858166bcae
WIP: Detections Changes
...
Removed some strelka/yara rules from salt.
Removed yara scripts for downloading and updating rules. This will be managed by SOC.
Added a new compile_yara.py script.
Added the strelka repos folder.
2024-01-30 15:43:51 -07:00
Corey Ogburn
0fa4d92f8f
socsigmarepo
...
Need write permissions on the /opt/so/rules dir so I can clone the sigma repo there.
2024-01-30 14:49:05 -07:00
Jorge Reyes
4dd0b4a4fd
Merge pull request #12283 from Security-Onion-Solutions/reyesj2-patch-6
...
Remove remediate from initial oscap scan
2024-01-30 15:56:13 -05:00
reyesj2
b5ffa186fb
Remove remediate from initial oscap scan
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-30 15:54:23 -05:00
Jorge Reyes
cb5e111a00
Merge pull request #12267 from Security-Onion-Solutions/reyesj2-patch-6
...
Update soup
2024-01-29 10:22:35 -05:00
reyesj2
7c08b348aa
Add comment for soup update w/ STIGs enabled
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-29 10:16:34 -05:00
reyesj2
c4301d7cc1
Soup script update locations
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 15:51:06 -05:00
reyesj2
91c7b8144d
soup logic
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 15:43:42 -05:00
reyesj2
2e026b637d
Update soup to retry modified salt command on failure to update soup scripts.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-26 11:36:33 -05:00
reyesj2
cd6e387bcb
remove --local from soup common.soup_scripts update.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-25 16:15:53 -05:00
Wes
12ab6338db
Add diagnostic
2024-01-25 20:16:52 +00:00
weslambert
cd54d4becb
Fix indent
2024-01-25 13:57:02 -05:00
weslambert
5f1c76f6ec
endpoint.diagnostic.collection
2024-01-25 09:46:25 -05:00
weslambert
d2d70d1c5b
Merge pull request #12250 from Security-Onion-Solutions/fix/scan_pe_flags
...
Fix PE Flags
2024-01-24 14:29:23 -05:00
Jason Ertel
9f17bd2255
lks/fps
2024-01-24 11:17:32 -05:00
Wes
8426aad56d
Text mapping for scan.pe.flags
2024-01-24 15:10:42 +00:00
Wes
d23d367058
Make scan.pe.flags a string
2024-01-24 15:08:38 +00:00
weslambert
4d7af21dd5
Fix quote
2024-01-23 13:55:37 -05:00
weslambert
8348506acc
Merge pull request #12240 from Security-Onion-Solutions/upgrade/strelka_0.24.01.18
...
UPGRADE: Strelka 0.24.01.18
2024-01-23 13:50:15 -05:00
weslambert
1698d95efe
Use PLACEHOLDER for key values
2024-01-23 13:45:26 -05:00
weslambert
72319e33db
Avoid leak test triggering
2024-01-23 12:38:09 -05:00
weslambert
34bb37e415
Merge pull request #12227 from Security-Onion-Solutions/feature/rita_logs
...
RITA Logs
2024-01-23 12:32:32 -05:00
Wes
3bcb0bc132
Update defaults
2024-01-23 17:18:54 +00:00
Jorge Reyes
d25a2d4c30
Merge pull request #12230 from Security-Onion-Solutions/reyesj2-patch-sl
...
Handle non-zero
2024-01-23 08:31:48 -05:00
reyesj2
350b0df3bf
Handle non-zero
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-22 22:48:15 -05:00
Wes
5542db0aac
Leave package version null
2024-01-22 21:07:46 +00:00
Wes
b08db3e05a
Add RITA policy
2024-01-22 20:16:43 +00:00
Wes
80a3942245
Rename RITA pipelines
2024-01-22 20:15:48 +00:00
Wes
7118cc8dee
Add additional integration SOC configuration
2024-01-19 22:04:07 +00:00
Wes
05aa8b013a
Add additional integration to templates
2024-01-19 22:02:39 +00:00
Wes
d0457cb61e
Add additional integrations to defaults
2024-01-19 22:00:38 +00:00
Jorge Reyes
c2b44985c7
Merge pull request #12220 from Security-Onion-Solutions/reyesj2-patch-sl
...
Disable stigs setting/verifying umask is set to 077. Known issue with …
2024-01-19 16:06:10 -05:00
reyesj2
8f8c250ed3
Disable stigs setting/verifing umask is set to 077. Known issue with running SOUP
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 16:04:21 -05:00
Mike Reeves
efe8cfda95
Update suricata.common
2024-01-19 13:39:28 -05:00
Mike Reeves
08486e279c
Update suricata.common
2024-01-19 13:36:43 -05:00
reyesj2
2b6927da82
Add stig pillar dir during soup
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 09:55:23 -05:00
reyesj2
ca4f2f1dd6
Add creation of additional pillars to soup for stig state
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-19 08:31:20 -05:00
reyesj2
07602076f1
Update telegraf script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 16:48:16 -05:00
reyesj2
caf4036dbf
Update features check
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 16:06:53 -05:00
reyesj2
65d46ea27d
Merge remote-tracking branch 'remotes/origin/2.4/dev' into reyesj2-patch-sl
2024-01-18 12:24:35 -05:00
reyesj2
67445de4ee
Remove need for stig script
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-18 12:24:01 -05:00
Jorge Reyes
6a8bf0b953
Merge pull request #12202 from Security-Onion-Solutions/reyesj2-patch-sl
...
Add stig state
2024-01-18 09:25:21 -05:00
weslambert
33d74098bd
Merge pull request #12201 from Security-Onion-Solutions/fix/suricata_ike
...
Add Suricata IKE pipeline
2024-01-17 16:50:19 -05:00
reyesj2
df921892a3
Remove post scan from remediate log.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 16:23:20 -05:00
reyesj2
739feb25a4
Add telegraf script to import featuresdetected
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 15:55:00 -05:00
reyesj2
4e6924610d
Add additional status checks to so-common-status-check for telegraf
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2024-01-17 15:37:52 -05:00