Commit Graph

906 Commits

Author SHA1 Message Date
Mike Reeves
657ddc42a8 Playbook - Add flag for runtime 2019-09-27 10:40:28 -04:00
Josh Brower
4352b1ebf6 Updated Kibana NIDS SID Drilldown dashboard 2019-09-26 11:11:18 -04:00
Mike Reeves
1dd59e92e4 Common Module - Fix nginx for websockets 2019-09-25 16:58:15 -04:00
Mike Reeves
063f9012d1 PCAP Module - Fix sensoroni logging 2019-09-25 16:21:02 -04:00
Josh Brower
563378e2a4 Merge pull request #108 from defensivedepth/playbook
Playbook & SOCtopus init edits
2019-09-25 15:28:58 -04:00
Josh Brower
d9713cc14a Playbook & SOCtopus init edits 2019-09-25 15:18:18 -04:00
Mike Reeves
d979be82fb Hive Module - New Version 2019-09-25 13:16:49 -04:00
Josh Brower
f69a5212ff Merge pull request #106 from defensivedepth/playbook
Playbook and Navigator - initial salt config
2019-09-25 13:07:44 -04:00
Josh Brower
909e35ec3b Playbook and Navigator - initial salt config 2019-09-25 13:04:53 -04:00
Mike Reeves
58073cd04f Hive Module - Fix ES 2019-09-25 11:43:30 -04:00
Mike Reeves
db7920710b Hive Module - Temp remove init 2019-09-25 10:34:46 -04:00
Josh Brower
bc788a3d35 Playbook - initial commit 2019-09-24 20:09:20 -04:00
Wes Lambert
5bd77a5177 update log path 2019-09-24 20:37:07 +00:00
Wes Lambert
497edcbe45 update Filebeat log config 2019-09-24 19:38:06 +00:00
Mike Reeves
1fc4cca2ad Hive Module - update version 2019-09-24 15:23:12 -04:00
Mike Reeves
b0b76c1809 Filebeat - Roll back version 2019-09-24 14:15:00 -04:00
Mike Reeves
5e2cc08039 PCAP Module - Update steno image 2019-09-24 14:05:20 -04:00
doug
cb899943aa incoming bro_tunnel logs should go to bro_tunnels 2019-09-24 14:00:22 -04:00
Josh Brower
eb10914969 Update nids2hive.yaml 2019-09-24 12:32:59 -04:00
Mike Reeves
b1f582d218 Logstash Module - 1.1.1 2019-09-24 11:22:07 -04:00
Mike Reeves
e6ea6b4d73 Wazuh Module - Fix gid error 2019-09-24 11:07:38 -04:00
Mike Reeves
e080dcfe80 Filebeat Module - Update to 1.1.1 2019-09-24 11:03:48 -04:00
Mike Reeves
590827b08c Suricata Module - Suricata 4.1.5 2019-09-24 10:26:55 -04:00
Wes Lambert
2784542cdb update Elastalert config 2019-09-23 22:39:43 +00:00
doug
8472b24a67 parse Bro logs using Elasticsearch ingest node 2019-09-23 16:04:23 -04:00
Wes Lambert
965ee6f922 remove duplicate alerter 2019-09-23 14:43:54 +00:00
Wes Lambert
5419bd6f08 update config for Elastalert 2019-09-23 14:43:14 +00:00
Mike Reeves
6d14a94765 Logstash Module - Fix watch 2019-09-20 16:31:23 -04:00
Mike Reeves
50c074bb4e Logstash Module - Add more watches 2019-09-19 15:46:46 -04:00
Mike Reeves
06cc8e7236 OSSEC Module - Fix User Creation 2019-09-19 13:44:28 -04:00
Mike Reeves
b68391acd0 cmd.script - Fix location 2019-09-19 10:22:10 -04:00
Mike Reeves
9421e4d8e2 Merge pull request #97 from defensivedepth/nids
Add rule_signature mapping
2019-09-19 08:56:05 -04:00
Mike Reeves
a9113a99a6 cmd.script cleanup 2019-09-19 08:52:44 -04:00
Josh Brower
9a4eadc967 Add rule_signature mapping 2019-09-19 08:30:33 -04:00
Wes Lambert
9a53cfd5ff update path 2019-09-18 19:47:39 +00:00
Wes Lambert
1f8fd7ddd1 fix typo 2019-09-18 19:42:02 +00:00
Wes Lambert
30d732e18f sync default Elastalert rules 2019-09-18 19:37:47 +00:00
Wes Lambert
3f07d7de91 add files 2019-09-09 20:28:31 +00:00
Wes Lambert
a1998a8aa2 update to allow use of custom modules and local config 2019-09-09 20:23:37 +00:00
Mike Reeves
f1ae2617c2 Filebeat Module - Change log dir mapping 2019-08-14 08:44:54 -04:00
Mike Reeves
5ca2db8407 Filebeat Module - Create Log dir to fix permissions 2019-08-13 10:07:40 -04:00
Mike Reeves
a9f592a53b Filebeat Module - Move logging to the top 2019-08-13 09:37:41 -04:00
Mike Reeves
e36b178e1c Filebeat Module - Change logging to error 2019-08-13 09:27:38 -04:00
Mike Reeves
7688691dbc Bro Module - redirect packet loss to file 2019-08-07 15:00:22 -04:00
Mike Reeves
4e41a8ef0a Bro Module - Fix version to 1.1.0 2019-08-07 14:53:40 -04:00
Mike Reeves
60d2845185 1.1.0 updates 2019-08-07 13:49:43 -04:00
Mike Reeves
a9370ea886 idstools module - Fix script name 2019-07-25 13:31:26 -04:00
Mike Reeves
1fc389a1b9 idstools module - add cron job to update rules 2019-07-25 12:49:54 -04:00
Mike Reeves
9f48ea683c Common Module - remove auth for thehive 2019-07-24 09:05:08 -04:00
Mike Reeves
8804a43463 Firewall Module - Add so-allow 2019-07-23 10:08:09 -04:00