William Wernert
c864936c15
Merge pull request #3762 from Security-Onion-Solutions/foxtrot
...
Refactor so-ssh-harden
2021-04-05 12:39:51 -04:00
Mike Reeves
f41ee1457b
Merge pull request #3755 from Security-Onion-Solutions/issue/3753
...
FIX: Hunt query for HTTP EXE downloads should work for both Zeek and …
2021-04-05 11:42:45 -04:00
Doug Burks
8ca0626387
FIX: Hunt query for HTTP EXE downloads should work for both Zeek and Suricata #3753
2021-04-05 06:55:40 -04:00
William Wernert
d19c03efef
Refactor search of config lines
...
* Create arrays for each line and loop through them for better code readability
* Add more host key algorithms for removal
* Update regex to look for a comma or EOL at the end of the search term, to avoid missing last item in list
2021-04-02 14:49:22 -04:00
William Wernert
8b8086b91a
Update wording, as the new key tends to be ED25519, not ECDSA
2021-04-02 10:20:28 -04:00
William Wernert
fd57996bc6
Change behavior of adding lines to sshd config
...
* Replace existing lines in cases where a change has already been made
2021-04-02 10:00:27 -04:00
William Wernert
43c31b4e66
Fix script so changes are actually made
2021-04-01 14:56:05 -04:00
William Wernert
fa373e9db0
Merge branch 'fix/ssh-harden-setup' into foxtrot
2021-04-01 11:04:10 -04:00
William Wernert
58989398e0
Merge pull request #3721 from Security-Onion-Solutions/foxtrot
...
Allow user to enter a description during setup
2021-04-01 11:02:23 -04:00
Mike Reeves
c60d4aca16
Merge pull request #3724 from Masaya-A/Fix-https
...
Fix: Connection to ES is "https" from 2.3.40
2021-04-01 10:36:02 -04:00
Mike Reeves
234dec3f63
Merge pull request #3734 from Security-Onion-Solutions/zeekports
...
Reserve ports for Zeek
2021-04-01 10:35:16 -04:00
Mike Reeves
7d489ea34f
Merge pull request #3735 from Security-Onion-Solutions/kilo
...
For hunt quick actions, pipe value to 'escape' operator to escape bac…
2021-04-01 10:35:01 -04:00
Mike Reeves
7c6b037ae5
Reserve ports for Zeek
2021-04-01 10:30:52 -04:00
Mike Reeves
40313fc2f5
Reserve ports for Zeek
2021-04-01 10:29:58 -04:00
Mike Reeves
0d05612393
Reserve ports for Zeek
2021-04-01 10:00:55 -04:00
Masaya-A
bc04cae918
Fix: Connection to ES is "https" from 2.3.40
2021-04-01 16:59:47 +09:00
Masaya-A
908c5f8ef6
Merge pull request #8 from Security-Onion-Solutions/dev
...
Dev Sync 20210401
2021-04-01 16:55:41 +09:00
Josh Patterson
6cebc41353
Merge pull request #3720 from Security-Onion-Solutions/issue/3709
...
https://github.com/Security-Onion-Solutions/securityonion/issues/3709
2021-03-31 16:54:15 -04:00
William Wernert
a8483cb30e
Merge branch 'dev' into foxtrot
2021-03-31 16:02:26 -04:00
William Wernert
dfe5e73608
Merge branch 'feature/node-description' into foxtrot
2021-03-31 16:02:12 -04:00
Josh Brower
2b86241450
Merge pull request #3717 from Security-Onion-Solutions/fix/playbook-timestamps
...
Fix Playbook Alert timestamps
2021-03-31 15:47:11 -04:00
Josh Brower
ef98445560
Fix Playbook Alert timestamps
2021-03-31 15:44:41 -04:00
m0duspwnens
f7e99b4961
https://github.com/Security-Onion-Solutions/securityonion/issues/3709
2021-03-31 15:17:15 -04:00
Jason Ertel
820b01405f
For hunt quick actions, pipe value to 'escape' operator to escape backslashes and double quotes
2021-03-31 14:57:36 -04:00
William Wernert
2a595f03b7
Merge pull request #3630 from Security-Onion-Solutions/foxtrot
...
Add option to configure chrony as an ntp service
2021-03-31 13:41:06 -04:00
William Wernert
761a12ebbb
Fix variable name
2021-03-31 13:32:49 -04:00
William Wernert
1c4ba28336
[fix] host_pillar overwrites the file, so run ntp_pillar after it
2021-03-31 13:28:42 -04:00
Josh Brower
209d348108
Merge pull request #3688 from Security-Onion-Solutions/fix/playbook-sync
...
Fix sensor cleanup & playbook sync scripts
2021-03-31 11:59:27 -04:00
Jason Ertel
cdf3254485
Merge pull request #3708 from Security-Onion-Solutions/newrepo
...
Add Wazuh 4 repo
2021-03-31 09:29:50 -04:00
Mike Reeves
5e25d762c4
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-31 09:28:18 -04:00
Mike Reeves
46865809ed
Fix Automation Testing round 2
2021-03-31 09:28:02 -04:00
Mike Reeves
bb39ccc1aa
Fix Automation Testing
2021-03-31 09:25:21 -04:00
Mike Reeves
0d077b0d49
Merge pull request #3704 from gebhard73/patch-2
...
Update so-index-list
2021-03-31 09:18:29 -04:00
William Wernert
04920dcbed
Merge branch 'dev' into foxtrot
2021-03-31 09:15:17 -04:00
William Wernert
c03e2b2c11
Move ntp server array to its own pillar in the minion sls file
2021-03-31 09:14:40 -04:00
Mike Reeves
5203c25971
Add Wazuh 4 Repo
2021-03-31 09:13:38 -04:00
Mike Reeves
b485531bd8
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-31 09:12:56 -04:00
weslambert
5eb0137c21
Merge pull request #3705 from Security-Onion-Solutions/delta
...
Enforce date type for ingest.timestamp
2021-03-31 08:40:41 -04:00
Wes Lambert
942de130ca
Enforce date type for ingest.timestamp
2021-03-31 12:24:51 +00:00
gebhard73
0b9cf57b5f
Update so-index-list
...
Sort by index name.
2021-03-31 14:22:06 +02:00
Mike Reeves
e92f5c122c
Merge pull request #3689 from Security-Onion-Solutions/kilo
...
Remove incompatible example
2021-03-30 16:08:16 -04:00
William Wernert
177989269f
Better formatting of chrony.conf
2021-03-30 15:50:37 -04:00
William Wernert
fd51b327ee
Add messaging to explain chronyc output to log
2021-03-30 15:23:57 -04:00
William Wernert
be6eb3ed6c
Restart chrony in case it's already running
2021-03-30 14:17:05 -04:00
Josh Brower
679925ebd9
Fix sensor cleanup & playbook sync scripts
2021-03-30 13:29:56 -04:00
weslambert
ff317cdcf1
Merge pull request #3684 from Security-Onion-Solutions/delta
...
Add Elastic scripts
2021-03-30 12:06:00 -04:00
Wes Lambert
7049383ba6
Add Elastic scripts
2021-03-30 15:47:05 +00:00
Mike Reeves
2534ca7eb7
Merge pull request #3633 from Security-Onion-Solutions/newrepo
...
Attempt to use so repo for network install
2021-03-30 11:37:46 -04:00
Mike Reeves
b2138045c0
Merge remote-tracking branch 'remotes/origin/dev' into newrepo
2021-03-30 11:29:22 -04:00
Mike Reeves
fc3fd00216
Fix formatting
2021-03-30 11:28:47 -04:00