Josh Brower
e2dd0f8cf1
Only update rule files if AG
2024-02-28 09:39:23 -05:00
Josh Brower
59af547838
Fix download location
2024-02-27 09:49:54 -05:00
Josh Brower
c6baa4be1b
Airgap Support - Detections module
2024-02-26 16:19:32 -05:00
Doug Burks
52580fb8c4
Merge pull request #12434 from Security-Onion-Solutions/feature/improve-endpoint-columns
...
Add multiple endpoint features
2024-02-26 12:05:30 -05:00
weslambert
1d099f97d2
Update pattern for endpoint diagnostic template
2024-02-26 11:27:56 -05:00
Doug Burks
f8424f3dad
Update defaults.yaml
2024-02-26 11:22:09 -05:00
Doug Burks
c8a95a8706
FEATURE: Add new endpoint dashboards #12428
2024-02-26 09:59:07 -05:00
Doug Burks
4df21148fc
FEATURE: Add default columns for endpoint.events datasets #12425
2024-02-26 09:40:51 -05:00
Doug Burks
ca249312ba
FEATURE: Add new SOC action for Process Info #12421
2024-02-26 09:38:14 -05:00
Josh Brower
66b815d4b2
Merge pull request #12431 from Security-Onion-Solutions/feature/brower-detections
...
Add Detection AutoUpdate config
2024-02-26 08:43:33 -05:00
Josh Brower
a6bb7216f9
Add Detection AutoUpdate config
2024-02-26 08:18:42 -05:00
Josh Brower
77cb5748f6
Merge pull request #12430 from Security-Onion-Solutions/feature/sigma-pipeline
...
Feature/sigma pipeline
2024-02-26 08:00:00 -05:00
Doug Burks
d6cb8ab928
update events_x_process in defaults.yaml
2024-02-23 17:09:40 -05:00
Doug Burks
daf96d7934
fix new eventFields in merged.map.jinja
2024-02-23 17:07:48 -05:00
Doug Burks
58f4fb87d0
fix new eventFields in soc_soc.yaml
2024-02-23 17:06:29 -05:00
Doug Burks
b7ef1e8af1
add more endpoint.events.x fields to soc_soc.yaml
2024-02-23 15:38:53 -05:00
Doug Burks
7da0ccf5a6
add more endpoint.events.x entries to merged.map.jinja
2024-02-23 15:35:53 -05:00
m0duspwnens
573d565976
convert _x_ to . for soc ui to config
2024-02-23 15:03:44 -05:00
Doug Burks
b8baca417b
add endpoint_x_events_x_process to defaults.yaml
2024-02-23 14:03:04 -05:00
Josh Brower
d04aa06455
Fix source.ip
2024-02-22 14:01:02 -05:00
Mike Reeves
e7914fc5a1
Update stenoloss.sh
2024-02-22 12:49:06 -05:00
Josh Brower
c886e72793
Imphash mappings
2024-02-22 08:59:33 -05:00
Josh Brower
0a9022ba6a
Add hash mappings
2024-02-21 17:07:08 -05:00
Josh Patterson
d2f7946377
Merge pull request #12411 from Security-Onion-Solutions/issue/12382
...
nest under policy
2024-02-21 16:28:04 -05:00
m0duspwnens
162785575c
nest under policy
2024-02-21 15:28:24 -05:00
Josh Brower
1952f0f232
Merge remote-tracking branch 'origin/2.4/dev' into kilo
2024-02-21 13:11:49 -05:00
Mike Reeves
89010dacab
Merge pull request #12348 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update soup
2024-02-20 12:10:09 -05:00
Jason Ertel
4b314c8715
replace correlate icon to avoid confusion with searcheng.in
2024-02-20 10:30:09 -05:00
Josh Brower
ffb3cc87b7
Default ruleset; Descriptions
2024-02-16 11:55:10 -05:00
Josh Brower
e4dcb4a8dd
Merge remote-tracking branch 'origin/cogburn/detection_playbooks' into kilo
2024-02-15 17:50:37 -05:00
Corey Ogburn
c64f37ab67
sigmaRulePackages is now a string array
2024-02-15 10:34:07 -07:00
Josh Brower
686304f24a
Merge remote-tracking branch 'origin/2.4/dev' into kilo
2024-02-15 09:47:51 -05:00
m0duspwnens
a2b17d2348
move jinja to top
2024-02-14 14:27:41 -05:00
m0duspwnens
c1f467a068
handle airgap
2024-02-14 14:22:18 -05:00
m0duspwnens
7d5932ee5e
Merge remote-tracking branch 'origin/2.4/dev' into 2450soup
2024-02-14 13:29:39 -05:00
m0duspwnens
79e98e508f
pass in UPDATE_DIR as a pillar
2024-02-14 13:28:12 -05:00
Josh Patterson
cf6266a92b
Merge pull request #12354 from Security-Onion-Solutions/2450soup
...
modify soup to update soup scripts using salt
2024-02-13 16:23:57 -05:00
m0duspwnens
2e9fa2438b
add back comment
2024-02-13 16:19:50 -05:00
Corey Ogburn
a5db9f87dd
Merge branch 'kilo' into cogburn/detection_playbooks
2024-02-13 14:08:44 -07:00
Corey Ogburn
f321e734eb
Added so-detection mapping in elasticsearch
2024-02-13 14:05:27 -07:00
Corey Ogburn
8800b7e878
WIP: Detections Changes
...
Removed some strelka/yara rules from salt.
Removed yara scripts for downloading and updating rules. This will be managed by SOC.
Added a new compile_yara.py script.
Added the strelka repos folder.
2024-02-13 14:05:27 -07:00
Corey Ogburn
031ee078c5
socsigmarepo
...
Need write permissions on the /opt/so/rules dir so I can clone the sigma repo there.
2024-02-13 14:05:27 -07:00
m0duspwnens
00f2374582
fix path for so-firewall
2024-02-13 15:43:02 -05:00
m0duspwnens
468eedfaeb
add soup script update retru
2024-02-13 15:30:24 -05:00
m0duspwnens
88786e8342
use file.copy to preserve perms
2024-02-13 15:05:09 -05:00
Corey Ogburn
c933627a71
Merge branch 'kilo' of github.com:security-onion-solutions/securityonion into kilo
2024-02-13 12:53:29 -07:00
Corey Ogburn
0d297274c8
DetectionComment Mapping Defined
2024-02-13 12:53:18 -07:00
m0duspwnens
141fd49f02
use rsync
2024-02-13 14:27:22 -05:00
m0duspwnens
7112337c85
fix copy
2024-02-13 13:52:14 -05:00
Josh Brower
0c6c6ba2d5
Various UI tweaks
2024-02-13 13:38:43 -05:00