DefensiveDepth
|
d19c1a514b
|
Detections backup script
|
2024-05-22 15:12:23 -04:00 |
|
Jason Ertel
|
ca6e2b8e22
|
Merge pull request #13054 from Security-Onion-Solutions/jertel/eaconfig
fix elastalert settings
|
2024-05-21 18:38:03 -04:00 |
|
Jason Ertel
|
8af3158ea7
|
fix elastalert settings
|
2024-05-21 18:28:21 -04:00 |
|
Josh Brower
|
8b011b8d7e
|
Merge pull request #13053 from Security-Onion-Solutions/2.4/alertsefaults
Add rule.uuid to default groupbys
|
2024-05-21 17:54:27 -04:00 |
|
DefensiveDepth
|
f9e9b825cf
|
Removed unneeded groupby
|
2024-05-21 17:53:20 -04:00 |
|
DefensiveDepth
|
3992ef1082
|
Add rule.uuid to default groupbys
|
2024-05-21 17:45:56 -04:00 |
|
weslambert
|
556fdfdcf9
|
Merge pull request #13052 from Security-Onion-Solutions/fix/add_rule_uuid
Add rule.uuid for YARA matches
|
2024-05-21 17:09:49 -04:00 |
|
weslambert
|
f4490fab58
|
Add rule.uuid for YARA matches
|
2024-05-21 17:05:39 -04:00 |
|
weslambert
|
5aaf44ebb2
|
Merge pull request #13049 from Security-Onion-Solutions/fix/detections_alerts_component_template
Exclude detections from template name matching
|
2024-05-21 13:45:19 -04:00 |
|
weslambert
|
deb140e38e
|
Exclude detections from template name matching
|
2024-05-21 13:38:52 -04:00 |
|
Jason Ertel
|
3de6454d4f
|
Merge pull request #13047 from Security-Onion-Solutions/jertel/eaconfig
Jertel/eaconfig
|
2024-05-21 13:34:20 -04:00 |
|
Jason Ertel
|
d57cc9627f
|
exclude false positives related to detections
|
2024-05-21 13:31:50 -04:00 |
|
Jason Ertel
|
8ce19a93b9
|
exclude false positives related to detections
|
2024-05-21 13:29:20 -04:00 |
|
Jason Ertel
|
d315b95d77
|
elastalert settings
|
2024-05-21 07:15:19 -04:00 |
|
Doug Burks
|
6172816f61
|
Merge pull request #13044 from Security-Onion-Solutions/dougburks-patch-1
Update README.md with new Detections screenshot number
|
2024-05-21 06:49:35 -04:00 |
|
Doug Burks
|
03826dd32c
|
Update README.md with new Detections screenshot number
|
2024-05-21 06:43:07 -04:00 |
|
Jason Ertel
|
b7a4f20c61
|
elastalert settings
|
2024-05-20 20:11:30 -04:00 |
|
Jason Ertel
|
02b4d37c11
|
elastalert settings
|
2024-05-20 20:00:31 -04:00 |
|
Jason Ertel
|
f8ce039065
|
elastalert settings
|
2024-05-20 19:58:12 -04:00 |
|
Jason Ertel
|
e2d0b8f4c7
|
elastalert settings
|
2024-05-20 19:38:36 -04:00 |
|
Jason Ertel
|
8a3061fe3e
|
elastalert settings
|
2024-05-20 19:36:06 -04:00 |
|
Jason Ertel
|
c594168b65
|
elastalert settings
|
2024-05-20 19:05:43 -04:00 |
|
Jason Ertel
|
31fdf15ce1
|
Merge branch '2.4/dev' into jertel/eaconfig
|
2024-05-20 18:59:35 -04:00 |
|
Jason Ertel
|
6b2219b7f2
|
elastalert settings
|
2024-05-20 18:52:37 -04:00 |
|
coreyogburn
|
64144b4759
|
Merge pull request #13041 from Security-Onion-Solutions/cogburn/integrity-checker-annotations
Annotate integrityCheckFrequencySeconds per det engine
|
2024-05-20 14:52:38 -06:00 |
|
Corey Ogburn
|
6e97c39f58
|
Marked as Advanced
|
2024-05-20 14:52:05 -06:00 |
|
Corey Ogburn
|
026023fd0a
|
Annotate integrityCheckFrequencySeconds per det engine
|
2024-05-20 14:35:11 -06:00 |
|
Jorge Reyes
|
d7ee89542a
|
Merge pull request #13040 from Security-Onion-Solutions/lkscript
Create helper script for tpm enrollment
|
2024-05-20 15:25:50 -04:00 |
|
reyesj2
|
6fac6eebce
|
Helper script for enrolling tpm into luks
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-20 14:37:54 -04:00 |
|
coreyogburn
|
3c3497c2fd
|
Merge pull request #13039 from Security-Onion-Solutions/cogburn/integrity-check
Add Default IntegrityCheck Frequency Values
|
2024-05-20 11:26:30 -06:00 |
|
Corey Ogburn
|
fcc72a4f4e
|
Add Default IntegrityCheck Frequency Values
|
2024-05-20 11:23:25 -06:00 |
|
coreyogburn
|
28dea9be58
|
Merge pull request #13037 from Security-Onion-Solutions/cogburn/comp-report-path-change
Change Compilation Report Path
|
2024-05-17 15:48:52 -06:00 |
|
Corey Ogburn
|
0cc57fc240
|
Change Compilation Report Path
Move compilation report path to /opt/so/state and mount that foulder in SOC
|
2024-05-17 15:47:23 -06:00 |
|
weslambert
|
17518b90ca
|
Merge pull request #13036 from Security-Onion-Solutions/fix/yara_compile_report
Create YARA compile report for SOC integrity check
|
2024-05-17 16:15:21 -04:00 |
|
weslambert
|
d9edff38df
|
Create compile report for SOC integrity check
|
2024-05-17 16:10:10 -04:00 |
|
Jason Ertel
|
300d8436a8
|
Merge pull request #13035 from Security-Onion-Solutions/jertel/eaconfig
add support for custom alerters
|
2024-05-17 15:01:54 -04:00 |
|
Jason Ertel
|
1c4d36760a
|
add support for custom alerters
|
2024-05-17 14:49:39 -04:00 |
|
reyesj2
|
34a5985311
|
Create tpm enrollment script
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
|
2024-05-16 21:14:57 -04:00 |
|
Josh Patterson
|
aa0163349b
|
Merge pull request #13031 from Security-Onion-Solutions/issue/13021
Issue/13021
|
2024-05-16 16:40:17 -04:00 |
|
Josh Patterson
|
572b8d08d9
|
Merge branch '2.4/dev' into issue/13021
|
2024-05-16 16:39:17 -04:00 |
|
m0duspwnens
|
cc6cb346e7
|
fix issue/13030
|
2024-05-16 16:31:45 -04:00 |
|
m0duspwnens
|
b54632080e
|
check if exists in override before popping
|
2024-05-16 16:04:17 -04:00 |
|
Josh Patterson
|
44d3468f65
|
Merge pull request #13029 from Security-Onion-Solutions/revert-13028-issue/13021
Revert "dont merge policy from global_overrides if not defined in default index_settings"
|
2024-05-16 15:48:05 -04:00 |
|
Josh Patterson
|
9d4668f4d3
|
Revert "dont merge policy from global_overrides if not defined in default index_settings"
|
2024-05-16 15:45:55 -04:00 |
|
Josh Patterson
|
da2ac4776e
|
Merge pull request #13028 from Security-Onion-Solutions/issue/13021
dont merge policy from global_overrides if not defined in default index_settings
|
2024-05-16 14:33:51 -04:00 |
|
m0duspwnens
|
9796354b48
|
dont merge policy from global_overrides if not defined in default index_settings
|
2024-05-16 14:27:32 -04:00 |
|
Jason Ertel
|
aa32eb9c0e
|
Merge pull request #13025 from Security-Onion-Solutions/jertel/suridp
exclude detect-parse errors
|
2024-05-15 19:21:30 -04:00 |
|
Jason Ertel
|
4771810361
|
exclude detect-parse errors
|
2024-05-15 19:10:50 -04:00 |
|
Mike Reeves
|
52f27c00ce
|
Merge pull request #13024 from Security-Onion-Solutions/TOoSmOotH-patch-7
Update soup
|
2024-05-15 18:07:28 -04:00 |
|
Mike Reeves
|
ab9ec2ec6b
|
Update soup
|
2024-05-15 18:04:01 -04:00 |
|