Commit Graph

9073 Commits

Author SHA1 Message Date
Mike Reeves b5f1733e97 Merge pull request #12513 from Security-Onion-Solutions/newsuripcap
Change Factoring for so-minion pcap disk space
2024-03-07 10:14:34 -05:00
m0duspwnens 70f3ce0536 change how maxfiles is calculated 2024-03-06 17:32:06 -05:00
reyesj2 17a75d5bd2 Run stig post remediate scan against default ol9 scap-security-guide.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
2024-03-06 17:19:01 -05:00
m0duspwnens 583227290f fix max-files calc 2024-03-06 15:18:22 -05:00
m0duspwnens cf232534ca move suricata.pcap to suricata.config.outputs.pcap-log 2024-03-06 14:42:07 -05:00
Mike Reeves 7f1e786e3d Consolidate PCAP settings 2024-03-06 12:56:09 -05:00
Jason Ertel 8f36a8a4b6 Merge pull request #12514 from Security-Onion-Solutions/jertel/annotations
detections annotations
2024-03-06 11:10:21 -05:00
Jason Ertel 1cbac11fae detections annotations 2024-03-06 11:08:03 -05:00
Mike Reeves ad12093429 Fix percent calc 2024-03-06 11:05:06 -05:00
Jason Ertel 167aff24f6 detections annotations 2024-03-06 11:03:52 -05:00
Josh Brower 9e671621db Merge pull request #12510 from Security-Onion-Solutions/2.4/excludedetections
Add Exclusion toggle
2024-03-06 10:56:29 -05:00
Mike Reeves 4dfa1a5626 Move Suricata around 2024-03-06 10:35:10 -05:00
Mike Reeves a63fca727c Update soc_suricata.yaml 2024-03-06 10:02:06 -05:00
Mike Reeves f58c104d89 Update so-minion 2024-03-06 09:51:56 -05:00
Jason Ertel 5acefb5d18 Merge pull request #12511 from Security-Onion-Solutions/jertel/annotations
PCAP annotations
2024-03-06 08:40:24 -05:00
Jason Ertel 0f12297f50 add new pcap annotations 2024-03-06 08:19:42 -05:00
Jason Ertel 12653eec8c add new pcap annotations 2024-03-06 08:14:33 -05:00
Josh Brower 1b47537a3f Add Exclusion toggle 2024-03-06 07:16:50 -05:00
Josh Patterson eaef076eba Update so-minion 2024-03-05 17:52:24 -05:00
Josh Patterson ac9db8a392 Merge branch '2.4/dev' into jppsensoroni 2024-03-05 17:51:32 -05:00
m0duspwnens 5687fdcf57 fix pcapspace function 2024-03-05 17:46:43 -05:00
Jason Ertel 4b5f00cef4 fix oinkcodes with leading zeros 2024-03-05 16:42:20 -05:00
weslambert 185a160df0 Merge pull request #12500 from Security-Onion-Solutions/feature/additional_integrations_5
Additional Integrations #5
2024-03-05 16:12:05 -05:00
Mike Reeves a686d46322 Update so-minion 2024-03-05 15:09:02 -05:00
Mike Reeves 6eb608c3f5 Update so-minion 2024-03-05 15:05:03 -05:00
m0duspwnens c0d19e11b9 fix } placement 2024-03-05 10:07:32 -05:00
m0duspwnens 1a58aa61a0 only import pcap and suricata if sensor 2024-03-05 09:54:40 -05:00
m0duspwnens 08f2b8251b add GLOBALS.is_sensor 2024-03-05 09:53:35 -05:00
weslambert bed42208b1 Add journald integration 2024-03-05 09:49:55 -05:00
weslambert d8e8933ea0 Add AWS Security Hub template 2024-03-05 09:25:41 -05:00
weslambert d85ac39e28 Add AWS Inspector template 2024-03-05 09:23:17 -05:00
weslambert 1514f1291e Add AWS GuardDuty template 2024-03-05 09:21:48 -05:00
weslambert b64d61065a Add AWS Cloudfront template 2024-03-05 09:19:43 -05:00
Mike Reeves 58d222284e Merge pull request #12271 from Security-Onion-Solutions/suripcap
Suricata PCAP
2024-03-04 17:27:38 -05:00
Mike Reeves fe238755e9 Fix df 2024-03-04 16:52:51 -05:00
Mike Reeves 018e099111 Modify setup 2024-03-04 14:53:15 -05:00
Josh Brower f28f269bb1 Fix FIM 2024-03-04 07:38:32 -05:00
Josh Brower f3dce66f03 Merge pull request #12482 from Security-Onion-Solutions/2.4/sigma-pipeline
2.4/sigma pipeline
2024-03-01 15:29:13 -05:00
Josh Brower d832158cc5 Drop Hashes field 2024-03-01 15:26:02 -05:00
Josh Brower b017157d21 Add antivirus mapping 2024-03-01 14:04:56 -05:00
Jorge Reyes d911b7bfc4 Merge pull request #12469 from Security-Onion-Solutions/reyesj2-patch-4
FIX: EA installers not downloadable from SOC & fix logging
2024-02-29 16:21:44 -05:00
reyesj2 53761d4dba FIX: EA installers not downloadable from SOC + fix stg logging
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
2024-02-29 16:15:26 -05:00
Mike Reeves 1fe8f3d9e4 Merge pull request #12405 from Security-Onion-Solutions/repochange
Manage the repo files
2024-02-29 14:01:48 -05:00
Josh Brower aa3b917368 Merge pull request #12456 from Security-Onion-Solutions/feature/detections-airgap
Feature/detections airgap
2024-02-28 09:41:13 -05:00
Josh Brower e2dd0f8cf1 Only update rule files if AG 2024-02-28 09:39:23 -05:00
weslambert df3943b465 Daily rollover 2024-02-27 17:24:27 -05:00
Josh Patterson d5fc6ddd2c Merge pull request #12449 from Security-Onion-Solutions/issue/12391
Issue/12391
2024-02-27 15:38:33 -05:00
m0duspwnens fcc0f9d14f redo classifications 2024-02-27 13:20:58 -05:00
Josh Brower 59af547838 Fix download location 2024-02-27 09:49:54 -05:00
Josh Brower c6baa4be1b Airgap Support - Detections module 2024-02-26 16:19:32 -05:00