Jason Ertel
|
ad05e75ce7
|
Add new quick actions to SOC config template
|
2020-09-09 00:46:23 -04:00 |
|
Mike Reeves
|
7d524a0723
|
Add Firewall Rule for yum and airgap
|
2020-09-08 18:51:14 -04:00 |
|
Josh Patterson
|
d7016b4557
|
Merge pull request #1298 from Security-Onion-Solutions/issue/1291
Issue/1291
|
2020-09-08 17:40:33 -04:00 |
|
m0duspwnens
|
da34222931
|
makedirs
|
2020-09-08 17:36:27 -04:00 |
|
m0duspwnens
|
eeb6c3128b
|
add salt.master state to manager nodes
|
2020-09-08 17:27:13 -04:00 |
|
m0duspwnens
|
da3d0948b4
|
creating engine to watch the health of the salt mine
|
2020-09-08 16:49:38 -04:00 |
|
Jason Ertel
|
710a2be422
|
Add new so-user-enable script and change so-user-disable to call 'so-user disable' instead of deleting the SOC user
|
2020-09-08 16:24:18 -04:00 |
|
Mike Reeves
|
7c41c31359
|
Fix airgap statement
|
2020-09-08 14:48:37 -04:00 |
|
Mike Reeves
|
7371f9236e
|
Update top.sls
|
2020-09-08 14:18:56 -04:00 |
|
Mike Reeves
|
1aea3f4f85
|
Merge pull request #1297 from Security-Onion-Solutions/experimental
Add Airgap code
|
2020-09-08 09:26:41 -04:00 |
|
weslambert
|
b6b52671e2
|
Merge pull request #1294 from Security-Onion-Solutions/fix/wazuh_agent_name
Fix typo
|
2020-09-05 08:17:09 -04:00 |
|
Wes Lambert
|
f9884606df
|
Fix typo
|
2020-09-05 12:15:55 +00:00 |
|
Jason Ertel
|
f27e5164d0
|
Update to latest kratos; add support for a custom status trait to represent whether a user is locked or not; refactor so-user to use new enable/disable capabilities in SOC; remove 'delete' option from so-user usage to avoid having user lists out of sync across SOC and external apps
|
2020-09-04 17:01:52 -04:00 |
|
Josh Brower
|
351e7761ef
|
Merge pull request #1292 from Security-Onion-Solutions/bugfix/playbook-rulesets
Update SOCtopus.conf
|
2020-09-04 14:15:18 -04:00 |
|
Josh Brower
|
39cc7151a5
|
Update SOCtopus.conf
|
2020-09-04 14:14:53 -04:00 |
|
Doug Burks
|
f8e68c82e4
|
downgrade to Mono 4.2.1.102 and NetworkMiner 2.4
|
2020-09-04 10:12:28 -04:00 |
|
Doug Burks
|
c050003b5a
|
Install file-roller for opening zip files
|
2020-09-04 07:14:01 -04:00 |
|
Doug Burks
|
a2265fac4f
|
NetworkMiner has a compatibility issue with Mono 6 right now
|
2020-09-04 06:50:22 -04:00 |
|
Doug Burks
|
1fc64d3eef
|
so-analyst should install gedit
|
2020-09-03 16:46:14 -04:00 |
|
Josh Patterson
|
c71a154e81
|
Merge pull request #1288 from Security-Onion-Solutions/quickfix/standalonetop
add elasticsearch to standalone top
|
2020-09-03 15:55:43 -04:00 |
|
m0duspwnens
|
05b8b71af2
|
add elasticsearch to standalone top
|
2020-09-03 15:54:24 -04:00 |
|
Mike Reeves
|
b2ee757db2
|
Airgap Time
|
2020-09-03 10:35:12 -04:00 |
|
weslambert
|
b10dd40376
|
Merge pull request #1287 from Security-Onion-Solutions/fix/suri_home_net
Change HOME_NET and EXTERNAL_NET defaults
|
2020-09-03 08:15:51 -04:00 |
|
weslambert
|
8db8dcb71a
|
Change HOME_NET and EXTERNAL_NET defaults
|
2020-09-03 08:15:14 -04:00 |
|
Mike Reeves
|
9745191f19
|
Add Airgap State
|
2020-09-02 16:17:44 -04:00 |
|
weslambert
|
870e042c4c
|
Merge pull request #1285 from Security-Onion-Solutions/fix/so_stop_start_restart
Require at least one arg for start/stop/restart scripts
|
2020-09-02 14:58:19 -04:00 |
|
Wes Lambert
|
770aaf415c
|
Require at least on arg for start/stop/restart scripts
|
2020-09-02 18:55:59 +00:00 |
|
Jason Ertel
|
0142f43493
|
Add so-user-disable script which deletes the SOC user and disables the users in Fleet, TheHive, and Cortex
|
2020-09-02 13:54:50 -04:00 |
|
m0duspwnens
|
9d85b3223f
|
fix note about localrules
|
2020-09-02 11:46:48 -04:00 |
|
Josh Patterson
|
066c795e71
|
Merge pull request #1279 from Security-Onion-Solutions/fix/redhat
move redhat with centos
|
2020-09-02 09:12:44 -04:00 |
|
m0duspwnens
|
1f8f197066
|
move redhat with centos
|
2020-09-02 09:12:05 -04:00 |
|
weslambert
|
d35cca7fc5
|
Merge pull request #1278 from Security-Onion-Solutions/fix/elastalert_extra_hosts
Add manager to hosts file
|
2020-09-02 07:44:49 -04:00 |
|
weslambert
|
5d920885e0
|
Add manager to hosts file
|
2020-09-02 07:43:55 -04:00 |
|
Josh Patterson
|
7fa083069d
|
Merge pull request #1277 from Security-Onion-Solutions/issue/968
Issue/968
|
2020-09-01 15:43:22 -04:00 |
|
m0duspwnens
|
08ca2055dc
|
fix telegraf file input for zeek log
|
2020-09-01 15:34:06 -04:00 |
|
m0duspwnens
|
93f30a2064
|
fix telegraf config
|
2020-09-01 15:29:29 -04:00 |
|
m0duspwnens
|
b13b07eddf
|
add newline to end
|
2020-09-01 15:10:56 -04:00 |
|
m0duspwnens
|
01777c64d9
|
fix influxtime
|
2020-09-01 14:58:48 -04:00 |
|
m0duspwnens
|
b6d66bddfc
|
add redis to proper node types. grafana dahsboard changes. change zeek_restart to not use telegraf socket but read from file instead
|
2020-09-01 14:38:10 -04:00 |
|
Josh Brower
|
6cd0d16b91
|
Merge pull request #1276 from Security-Onion-Solutions/feature/import-wel
Initial support for evtx import
|
2020-09-01 13:48:12 -04:00 |
|
Josh Brower
|
a79d0319cd
|
Initial support for evtx import
|
2020-09-01 13:47:27 -04:00 |
|
Mike Reeves
|
951fe2ac69
|
Create repo
|
2020-09-01 11:26:33 -04:00 |
|
Mike Reeves
|
9cff7c1427
|
Enable airgap functions
|
2020-09-01 11:24:22 -04:00 |
|
Mike Reeves
|
643dab12d0
|
Enable airgap
|
2020-09-01 11:09:33 -04:00 |
|
Josh Patterson
|
67766745a4
|
Merge pull request #1275 from Security-Onion-Solutions/fix/redhat
resolve issue with salt state if os is redhat
|
2020-09-01 10:44:59 -04:00 |
|
m0duspwnens
|
2fee151bff
|
resolve issue with salt state if os is redhat
|
2020-09-01 10:43:21 -04:00 |
|
m0duspwnens
|
ada1c81ab7
|
manager and standalone dashboard changes
|
2020-09-01 10:40:20 -04:00 |
|
Jason Ertel
|
ff5d1cd815
|
Expand nginx body size limit to 2.5GB to handle 2G PCAPs from sensors
|
2020-09-01 10:07:28 -04:00 |
|
Doug Burks
|
45c0a7ac77
|
Kernel messages can overwrite whiptail screen #812
Kernel messages can overwrite whiptail screen #812
|
2020-09-01 08:55:34 -04:00 |
|
m0duspwnens
|
a1a7b36319
|
merge with dev and resolve conflict
|
2020-08-31 16:05:34 -04:00 |
|