defensivedepth
|
9475211417
|
Refactor Navigator for Detections
|
2024-12-09 16:31:51 -05:00 |
|
reyesj2
|
9bc20c26bb
|
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into reyesj2/es-integ-tmp
|
2024-12-06 14:29:25 -06:00 |
|
Jorge Reyes
|
14cb41ea87
|
Merge pull request #14001 from Security-Onion-Solutions/reyesj2/zeekvpn
add openvpn & ipsec support to Zeek
|
2024-12-06 12:06:02 -06:00 |
|
Jorge Reyes
|
edd90cbed4
|
Merge pull request #14004 from Security-Onion-Solutions/reyesj2/logcheck
file extract zeek v7
|
2024-12-06 10:28:15 -06:00 |
|
reyesj2
|
1de20e9d43
|
fix zeek file extract
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-12-06 09:55:56 -06:00 |
|
reyesj2
|
ad8b339a3b
|
fix error due to null reference
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-12-06 09:07:16 -06:00 |
|
reyesj2
|
9532f21c7b
|
check zeek reporter.log
|
2024-12-05 13:49:44 -06:00 |
|
reyesj2
|
754d28e95d
|
add openvpn & ipsec support to Zeek
|
2024-12-05 09:52:55 -06:00 |
|
reyesj2
|
e3b7d82a8f
|
remove all non-core integrations from elasticfleet:packages pillar
|
2024-12-03 08:56:56 -06:00 |
|
reyesj2
|
888145a2ed
|
remove optional integrations from defaults.yaml & soc_elasticsearch.yaml
|
2024-12-03 08:55:43 -06:00 |
|
Josh Brower
|
726bdd8735
|
Merge pull request #13995 from Security-Onion-Solutions/feature/msi
fix path
|
2024-12-02 14:49:22 -05:00 |
|
defensivedepth
|
5b9f6b2d52
|
fix path
|
2024-12-02 14:42:56 -05:00 |
|
Josh Brower
|
aabff98bea
|
Merge pull request #13989 from Security-Onion-Solutions/feature/msi
Generate MSI
|
2024-12-02 09:17:45 -05:00 |
|
defensivedepth
|
aade3db80d
|
Generate MSI
|
2024-11-28 07:00:23 -05:00 |
|
Jorge Reyes
|
129c10dde5
|
Merge pull request #13981 from Security-Onion-Solutions/reyesj2/integ
|
2024-11-26 00:55:31 -06:00 |
|
reyesj2
|
993d56cb58
|
ti_rapid7*
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-25 15:51:49 -06:00 |
|
reyesj2
|
efa6a533c3
|
add missing ilm to index template
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-25 15:47:47 -06:00 |
|
Josh Brower
|
04ffdf9b15
|
Merge pull request #13958 from Security-Onion-Solutions/2.4/autoenablesigma
More flexibility for AutoEnable Sigma rules
|
2024-11-21 09:47:49 -05:00 |
|
defensivedepth
|
f61bf1bd67
|
Remove adv
|
2024-11-21 09:15:29 -05:00 |
|
defensivedepth
|
b1c4e32123
|
Remove duplicate option
|
2024-11-21 09:11:44 -05:00 |
|
defensivedepth
|
8958da83b3
|
Deprecate instead
|
2024-11-20 18:00:26 -05:00 |
|
defensivedepth
|
3fcf197bc1
|
Tweak structure
|
2024-11-19 11:54:15 -05:00 |
|
Jason Ertel
|
532dfd7f5a
|
Merge pull request #13966 from Security-Onion-Solutions/jertel/wip
MFA issuer name shouldn't be an advanced setting
|
2024-11-19 09:35:26 -05:00 |
|
Jason Ertel
|
92ddf2ec6c
|
MFA issuer name shouldn't be an advanced setting
|
2024-11-19 09:27:26 -05:00 |
|
coreyogburn
|
a703f46a0a
|
Merge pull request #13961 from Security-Onion-Solutions/cogburn/engine-update-config
Add Annotations to Existing Detections Options
|
2024-11-18 14:46:04 -07:00 |
|
Corey Ogburn
|
d86c009f55
|
Add Annotations to Existing Detections Options
The autoUpdateEnabled setting has been present for awhile and now have annotations.
|
2024-11-18 14:35:55 -07:00 |
|
defensivedepth
|
56d6857cd6
|
Addl customization for autoenable sigma
|
2024-11-18 09:03:17 -05:00 |
|
Jason Ertel
|
52bc9be6b6
|
Merge pull request #13956 from Security-Onion-Solutions/jertel/wip
ignore fp from hydra
|
2024-11-17 18:23:54 -05:00 |
|
Jason Ertel
|
918f26962a
|
ignore fp from hydra
|
2024-11-17 12:21:06 -05:00 |
|
Jason Ertel
|
3bf7870729
|
Merge pull request #13955 from Security-Onion-Solutions/jertel/wip
soup corrections
|
2024-11-16 21:31:08 -05:00 |
|
Jason Ertel
|
0eebe48492
|
soup corrections
|
2024-11-16 21:20:24 -05:00 |
|
Mike Reeves
|
e02cb30f1b
|
Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev
|
2024-11-16 20:41:31 -05:00 |
|
Mike Reeves
|
d005f0d7d6
|
Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main
|
2024-11-16 20:41:20 -05:00 |
|
Jason Ertel
|
cc44558f40
|
Merge pull request #13954 from Security-Onion-Solutions/jertel/wip
revert prev commit
|
2024-11-16 12:08:49 -05:00 |
|
Jason Ertel
|
73521dd7a7
|
revert prev commit
|
2024-11-16 11:09:44 -05:00 |
|
Jorge Reyes
|
3041d7d2b1
|
Merge pull request #13951 from Security-Onion-Solutions/reyesj2/integ
additional integrations
|
2024-11-15 15:02:04 -06:00 |
|
Jason Ertel
|
b6ab5249f1
|
Merge pull request #13953 from Security-Onion-Solutions/jertel/wip
Connect API upgrades
|
2024-11-15 14:32:37 -05:00 |
|
Jason Ertel
|
dc838e7148
|
connect
|
2024-11-15 14:25:52 -05:00 |
|
Jason Ertel
|
f290e52fbd
|
connect
|
2024-11-15 14:25:11 -05:00 |
|
Jason Ertel
|
e4de376394
|
connect api
|
2024-11-15 13:42:02 -05:00 |
|
reyesj2
|
44ec237447
|
additional integration support - cisco secure email gateway - rapid7 threat command
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-15 11:39:01 -06:00 |
|
Jorge Reyes
|
ec5a6aec41
|
Merge pull request #13946 from Security-Onion-Solutions/foxtrot
Zeek 7 w/ http2
|
2024-11-14 14:52:48 -06:00 |
|
Josh Patterson
|
7f96d20eb4
|
Merge pull request #13944 from Security-Onion-Solutions/saltbootstrap
update bootstrap-salt
|
2024-11-14 10:25:16 -05:00 |
|
Jorge Reyes
|
dfd9108f39
|
Merge pull request #13945 from Security-Onion-Solutions/2.4/dev
2.4/dev
|
2024-11-14 09:13:00 -06:00 |
|
Jorge Reyes
|
e07c1e6958
|
Merge pull request #13943 from Security-Onion-Solutions/zeek7
add http2
|
2024-11-14 09:11:08 -06:00 |
|
reyesj2
|
1113c3924f
|
zeek http2
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-14 09:09:23 -06:00 |
|
m0duspwnens
|
b1ddaa7211
|
support installing specified version for rhel variants. remove bootstrap -x python3 since not needed
|
2024-11-14 09:07:41 -05:00 |
|
Jorge Reyes
|
ff00ddeb3c
|
Merge pull request #13935 from Security-Onion-Solutions/ilm-detection
|
2024-11-13 15:07:29 -06:00 |
|
reyesj2
|
ba7a6dbbf0
|
Remove tuning/defaults "Remove in v7.1 The policy/tuning/defaults package is deprecated. The options set here are now the defaults for Zeek in general."
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-12 18:37:46 -06:00 |
|
reyesj2
|
f3a88de0c3
|
so-(case/detection)history uses same ilm policy as so-(case/detection)
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-11-12 16:28:01 -06:00 |
|