Commit Graph

1249 Commits

Author SHA1 Message Date
Wes Lambert
d66eca1db4 add Bro extracted directory 2019-12-16 20:45:14 +00:00
Mike Reeves
e49de63460 Helix - Final Parser Fixes 2019-12-13 13:59:29 -05:00
Mike Reeves
fdbb223155 Helix - Add geo 2019-12-13 11:52:43 -05:00
Mike Reeves
e263d72813 Setup - Add sensor pillar to Helix 2019-12-13 11:46:30 -05:00
Mike Reeves
4c89cb50bb Setup - update Helix Script 2019-12-12 23:12:08 -05:00
Mike Reeves
d8d94b7dc5 Helix - Add API Key Option 2019-12-12 20:46:30 -05:00
Mike Reeves
b04da4562c Merge pull request #163 from m0duspwnens/master
reverting for Security-Onion-Solutions#111
2019-12-12 16:54:36 -05:00
m0duspwnens
349d8f4bd7 reverting for https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/111 2019-12-12 16:40:24 -05:00
m0duspwnens
cc7de9aee2 reverting for https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/111 2019-12-12 16:36:22 -05:00
m0duspwnens
481d52a5a8 reverting for https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/111 2019-12-12 16:21:57 -05:00
Mike Reeves
79d48f9e77 Logstash - Fix helix output typeo 2019-12-12 15:17:19 -05:00
Mike Reeves
70acb23976 Merge pull request #161 from weslambert/tcpreplay
add initial tcpreplay state
2019-12-12 15:10:51 -05:00
Mike Reeves
bd9b1957ba Logstash - Fix helix output 2019-12-12 14:12:51 -05:00
Wes Lambert
c47d163a32 add initial tcpreplay state 2019-12-11 19:39:03 +00:00
Mike Reeves
989641eb5a Setup - Fix prompts and disable onion user if iso 2019-12-11 13:44:40 -05:00
Mike Reeves
96bf8f66ff SSL - Fix helix mode ssl certs 2019-12-10 17:04:18 -05:00
Mike Reeves
72b481855f Setup - add jq and fix eval calculation of failure 2019-12-10 16:50:23 -05:00
Mike Reeves
c83decc0a0 Helix - add firewall for mode helix 2019-12-10 14:44:10 -05:00
Mike Reeves
7386d800ae Helix - add filebeat config for helix 2019-12-10 14:06:20 -05:00
Mike Reeves
e134071295 Helix - Change Parsers for Helix 2019-12-10 13:50:27 -05:00
Mike Reeves
c46c539277 Helix - fix suricata.yml 2019-12-10 11:24:56 -05:00
Mike Reeves
fe042ed2bb Filebeat State - Fix watch statement to only change on yml 2019-12-10 10:59:35 -05:00
Mike Reeves
ce517dfebc Helix Mode - Fix SSL so Filebeat works properly 2019-12-10 10:40:28 -05:00
Mike Reeves
ae3c428941 Helix Logstash Changes 2019-12-10 10:02:41 -05:00
Mike Reeves
54fd5254c0 Merge pull request #158 from m0duspwnens/master
changes for FireEye Helix integration
2019-12-09 17:22:34 -05:00
m0duspwnens
4874e540da changes for FireEye Helix integration 2019-12-09 17:18:12 -05:00
Mike Reeves
4c4cdb7189 Helix changes and Wazuh 2019-12-09 16:27:03 -05:00
Mike Reeves
3904c19333 Change Variables to UperCase 2019-12-09 10:04:14 -05:00
m0duspwnens
599341483e adding api key for Helix 2019-12-09 09:59:28 -05:00
Mike Reeves
362cd0487f Additional Helix Support 2019-12-09 09:52:52 -05:00
Mike Reeves
897e009231 Salt Top file for helix sensor 2019-12-08 19:21:16 -05:00
Mike Reeves
d454216a4b Merge pull request #151 from m0duspwnens/master
update OS patch restart needed MOTD
2019-12-06 15:03:07 -05:00
Mike Reeves
100bcdd81d Merge pull request #152 from weslambert/master
Initial support for pre-loading custom fields in TheHive
2019-12-06 15:02:31 -05:00
Mike Reeves
880f57c424 Merge pull request #153 from defensivedepth/master
Playbook - scripts
2019-12-06 15:02:17 -05:00
Josh Brower
d27de7c8be Update init.sls 2019-12-05 16:54:33 -05:00
Josh Brower
65ddac4535 Playbook - add cron job for so-playbook-sync 2019-12-05 16:50:58 -05:00
Josh Brower
7721e913ec Create so-playbook-ruleupdate 2019-12-05 16:36:29 -05:00
Josh Brower
84485b7f79 Create so-playbook-sync 2019-12-05 16:34:30 -05:00
Mike Reeves
91f67cb62f Misc Script - Redis Count 2019-12-05 15:09:45 -05:00
Wes Lambert
65a5a2e64a pre-load custom reputation field 2019-12-05 17:41:19 +00:00
m0duspwnens
6040633a8c update OS patch restart needed MOTD 2019-12-05 12:38:46 -05:00
Mike Reeves
a4ff015c04 Merge pull request #150 from m0duspwnens/master
revert Ubuntu to Salt py2.7
2019-12-05 10:47:32 -05:00
m0duspwnens
fb0fc1120b revert Ubuntu to Salt py2.7 2019-12-05 10:41:21 -05:00
Wes Lambert
b58b3afa35 add auto_analyze_alerts option 2019-12-05 03:22:10 +00:00
Wes Lambert
79e1ac5336 add webhook 2019-12-04 18:39:58 +00:00
Wes Lambert
5eb0a4f19c update SOCtopus conf 2019-12-04 03:12:02 +00:00
Mike Reeves
ffaadcf1ca Merge pull request #145 from defensivedepth/fleetfixes
Fleet - Fix path issues
2019-11-26 11:43:45 -05:00
Josh Brower
f36d7b6926 Update so-fleet-setup.sh 2019-11-26 10:28:48 -05:00
Mike Reeves
aafa99ec4e Merge pull request #143 from defensivedepth/playbook-alert-tweaks
Playbook - thehive alert name change
2019-11-26 09:58:39 -05:00
Mike Reeves
d9f21ebcb8 Merge pull request #144 from m0duspwnens/master
patch motd changes and py3 salt ubuntu
2019-11-26 09:58:23 -05:00