TOoSmOotH
|
9b6822f325
|
DNS Suricata parser
|
2020-06-03 20:40:57 -04:00 |
|
TOoSmOotH
|
702a14e90c
|
DNS Suricata parser
|
2020-06-03 20:40:10 -04:00 |
|
Mike Reeves
|
3211a8a5e0
|
SMTP from fix
|
2020-06-03 11:52:24 -04:00 |
|
Mike Reeves
|
c5d6381933
|
SMTP for suricata
|
2020-06-03 11:16:43 -04:00 |
|
Mike Reeves
|
126d1598ee
|
SNMP for suricata
|
2020-06-03 11:03:23 -04:00 |
|
Mike Reeves
|
25aae21cf6
|
Trying to get decoded packet
|
2020-06-02 15:06:39 -04:00 |
|
Mike Reeves
|
b507b87871
|
Trying to get decoded packet
|
2020-06-02 14:49:07 -04:00 |
|
Mike Reeves
|
fb68506418
|
Add mor suricata ingest parser types
|
2020-06-02 14:42:15 -04:00 |
|
Mike Reeves
|
3096d8d988
|
Add mor suricata ingest parser types
|
2020-06-02 14:34:38 -04:00 |
|
Mike Reeves
|
0ea2252b5b
|
Add Suricata Flow pipeline
|
2020-06-02 13:40:46 -04:00 |
|
Mike Reeves
|
617f60d472
|
Fix Syntax
|
2020-06-02 12:01:26 -04:00 |
|
Mike Reeves
|
e63f39a9c4
|
Rename dataset
|
2020-06-02 11:58:14 -04:00 |
|
Mike Reeves
|
d47acd1d80
|
Change suricata to hit suricata.common
|
2020-06-02 11:41:13 -04:00 |
|
Jason Ertel
|
42683ddb67
|
always restart acng and registry containers when docker restarts
|
2020-06-02 09:12:25 -04:00 |
|
Jason Ertel
|
07c0075fc0
|
Upgrade containerd.io and docker-ce to match ISO rpms
|
2020-06-02 08:43:06 -04:00 |
|
Jason Ertel
|
9d5f4049b5
|
Avoid filtering NIC when it's an empty string
|
2020-06-02 05:52:03 -04:00 |
|
Mike Reeves
|
307cbe4b77
|
Couple of QOL scripts
|
2020-06-01 20:48:25 -04:00 |
|
m0duspwnens
|
1737b46abb
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-06-01 12:15:00 -04:00 |
|
Doug Burks
|
80d1814f10
|
remove event.module:zeek to make queries more generic
|
2020-06-01 12:00:33 -04:00 |
|
Mike Reeves
|
03f34404b1
|
Suricata 5 Meta Data
|
2020-06-01 11:03:43 -04:00 |
|
Wes Lambert
|
51f5d64ef6
|
Rename tunnel_parents
|
2020-06-01 13:51:32 +00:00 |
|
Wes Lambert
|
d7ce3d4719
|
fix naming of uid field for tunnel
|
2020-06-01 12:52:57 +00:00 |
|
Doug Burks
|
f559621f00
|
add x509 issuer and subject groupby queries
|
2020-06-01 07:48:50 -04:00 |
|
Doug Burks
|
46dc5f42e9
|
combine two http queries into one with multiple groupby
|
2020-06-01 07:30:08 -04:00 |
|
m0duspwnens
|
5ddfb7ccce
|
fix merge conflicts
|
2020-05-29 17:31:07 -04:00 |
|
m0duspwnens
|
4dfb58a98c
|
change how whitelist script determines if wazuh is enabled
|
2020-05-29 17:22:39 -04:00 |
|
m0duspwnens
|
17879ad88c
|
add nginx state to searchnode in salt/top
|
2020-05-29 17:01:43 -04:00 |
|
m0duspwnens
|
15fc97e516
|
adding suricata.master state to mastersearch - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-29 13:11:55 -04:00 |
|
m0duspwnens
|
6db8470de7
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-05-29 13:09:49 -04:00 |
|
m0duspwnens
|
3143643692
|
add navigator to master if enabled
|
2020-05-29 13:05:26 -04:00 |
|
m0duspwnens
|
2db2054cce
|
update instructions in logstash customer pipelines and templates - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-29 10:58:53 -04:00 |
|
Wes Lambert
|
4059121dd6
|
fix framed_addr field
|
2020-05-29 11:55:18 +00:00 |
|
m0duspwnens
|
40fa5293bf
|
move fileserve update to suricata.master
|
2020-05-28 15:54:11 -04:00 |
|
Wes Lambert
|
7f75050682
|
Add basic Zeek stats script
|
2020-05-28 17:54:15 +00:00 |
|
weslambert
|
b835c2e27e
|
Update for exact match (ex. thehive, thehive-es, thehive-cortex)
|
2020-05-28 13:17:31 -04:00 |
|
weslambert
|
12f426d4f4
|
Move eve.json to /nsm
|
2020-05-28 12:59:41 -04:00 |
|
Wes Lambert
|
869bfb947d
|
add master to SOCtopus hosts file
|
2020-05-28 16:45:48 +00:00 |
|
weslambert
|
d2263db0ff
|
Update init.sls
|
2020-05-28 12:11:08 -04:00 |
|
m0duspwnens
|
4f15de8b77
|
refresh salt fileserver if suricata rule symlink is created
|
2020-05-28 12:00:22 -04:00 |
|
Wes Lambert
|
b7d7747f65
|
allow syslog
|
2020-05-28 13:56:02 +00:00 |
|
Mike Reeves
|
8304d91b0b
|
Merge branch 'dev' into feature/suri5
|
2020-05-28 09:41:28 -04:00 |
|
Wes Lambert
|
d2b93d531e
|
Basic syslog config
|
2020-05-28 12:36:29 +00:00 |
|
Wes Lambert
|
5afc05feb2
|
Update FB init for syslog
|
2020-05-28 12:35:22 +00:00 |
|
Wes Lambert
|
b9bdca509e
|
update Filebeat config for syslog
|
2020-05-28 12:33:41 +00:00 |
|
Doug Burks
|
f3efafc9ca
|
combine two notice queries into one query with multiple groupby
|
2020-05-28 08:01:33 -04:00 |
|
Doug Burks
|
60cc3e9675
|
remove address from DHCP leases query
|
2020-05-28 07:50:52 -04:00 |
|
m0duspwnens
|
59cc927878
|
Merge remote-tracking branch 'remotes/origin/dev' into issue/749
|
2020-05-27 15:56:38 -04:00 |
|
weslambert
|
6a935b5452
|
Hive to TheHive
|
2020-05-27 15:43:41 -04:00 |
|
m0duspwnens
|
12a6da928f
|
create /opt/so/saltstack/local/salt/suricata - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749
|
2020-05-27 15:00:11 -04:00 |
|
m0duspwnens
|
40f04ef6d0
|
merge with dev and fix conflicts
|
2020-05-27 13:54:08 -04:00 |
|