DefensiveDepth
e430de88d3
Change rule updates to 24h
2024-05-13 13:15:06 -04:00
DefensiveDepth
c4c38f58cb
Update descriptions
2024-05-13 13:13:57 -04:00
Mike Reeves
927fe91f25
Merge pull request #13000 from Security-Onion-Solutions/soupz
...
Backup Suricata for migration
2024-05-13 10:12:34 -04:00
Mike Reeves
9d6f6c7893
Update soup
2024-05-13 10:09:35 -04:00
Mike Reeves
28e40e42b3
Update soc_soc.yaml
2024-05-13 09:58:32 -04:00
Mike Reeves
6c71c45ef6
Update soup
2024-05-13 09:55:57 -04:00
Mike Reeves
641899ad56
Backup Suricata for migration and remove advanced from reverselookups
2024-05-13 09:50:14 -04:00
Doug Burks
d120326cb9
Merge pull request #12999 from Security-Onion-Solutions/dougburks-patch-1
...
FEATURE: Add more fields to the SOC Dashboards URL for so-import-pcap #12972
2024-05-13 09:20:01 -04:00
Jason Ertel
154dc605ef
Merge pull request #12994 from Security-Onion-Solutions/jertel/testcy
...
support upgrade tests
2024-05-10 16:57:19 -04:00
Jason Ertel
2a0e33401d
support upgrade tests
2024-05-10 16:54:50 -04:00
m0duspwnens
986cbb129a
pkg not file
2024-05-10 12:33:56 -04:00
m0duspwnens
950c68783c
add pkg policycoreutils-python-utils to idh node
2024-05-10 11:46:00 -04:00
Doug Burks
26cb8d43e1
FIX: so-index-list typo #12988
2024-05-10 08:01:56 -04:00
Doug Burks
a1291e43c3
FIX: so-index-list typo #12988
2024-05-10 07:58:13 -04:00
Jason Ertel
45fd07cdf8
Merge pull request #12987 from Security-Onion-Solutions/jertel/testcy
...
Add quick action to find related alerts for a detection
2024-05-09 18:08:08 -04:00
Jason Ertel
fecd674fdb
Add quick action to find related alerts for a detection
2024-05-09 17:55:41 -04:00
Jason Ertel
dff2de4527
Merge pull request #12984 from Security-Onion-Solutions/jertel/testcy
...
tests will retry on any rule import failure
2024-05-09 15:50:37 -04:00
Jason Ertel
19e1aaa1a6
exclude detection rule errors
2024-05-09 15:45:33 -04:00
m0duspwnens
c864fec70c
allow strelka.manager to run on standalone
2024-05-09 11:53:50 -04:00
m0duspwnens
a74fee4cd0
strelka compiled rules
2024-05-09 11:26:02 -04:00
m0duspwnens
3a99624eb8
seperate manager states for strelka
2024-05-09 10:03:02 -04:00
Mike Reeves
656bf60fda
Merge pull request #12973 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update config.sls
2024-05-08 16:42:19 -04:00
weslambert
01a68568a6
Use state
2024-05-08 16:37:13 -04:00
weslambert
b916465b06
Merge pull request #12974 from Security-Onion-Solutions/fix/strelka_yara
...
Account for 0 active rules and change watch
2024-05-08 15:59:20 -04:00
weslambert
0567b93534
Remove mode
2024-05-08 15:39:59 -04:00
Mike Reeves
ad9fdf064b
Update config.sls
2024-05-08 15:24:29 -04:00
Wes
77e2117051
Account for 0 active rules and change watch
2024-05-08 18:47:52 +00:00
Doug Burks
5b7b6e5fb8
FEATURE: Add more fields to the SOC Dashboards URL for so-import-pcap #12972
2024-05-08 14:00:23 -04:00
Doug Burks
5a5a1e86ac
FIX: Adjust so-import-pcap so that suricata works when it is pcapengine #12969
2024-05-08 13:26:36 -04:00
Josh Patterson
796eefc2f0
Merge pull request #12965 from Security-Onion-Solutions/orchit
...
searchnode installation improvements
2024-05-08 10:24:33 -04:00
m0duspwnens
1862deaf5e
add copyright
2024-05-08 10:14:08 -04:00
m0duspwnens
0d2e5e0065
need repo and docker first
2024-05-08 09:50:01 -04:00
m0duspwnens
5dc098f0fc
remove test file
2024-05-08 08:54:24 -04:00
Mike Reeves
af681881e6
Merge pull request #12963 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Make the url list read only
2024-05-08 08:45:34 -04:00
DefensiveDepth
6d2ecce9b7
remove old yara airgap code
2024-05-08 08:43:37 -04:00
Mike Reeves
326c59bb26
Update soc_idstools.yaml
2024-05-08 08:42:38 -04:00
Mike Reeves
2eee617788
Update soc_idstools.yaml
2024-05-07 17:21:01 -04:00
Corey Ogburn
1da88b70ac
Specify Error Retry Wait and Error Limit for All Detection Engines
...
If a sync errors out, the engine will wait `communityRulesImportErrorSeconds` seconds instead of the usual `communityRulesImportFrequencySeconds` seconds wait.
If `failAfterConsecutiveErrorCount` errors happen in a row when syncing detections to ElasticSearch then the sync is considered a failure and will give up and try again later. This assumes ElasticSearch is the source of the errors and backs of in hopes it'll be able to fix itself.
2024-05-07 10:34:50 -06:00
Jason Ertel
b4817fa062
Merge pull request #12956 from Security-Onion-Solutions/jertel/testcy
...
test regexes for detections
2024-05-07 08:45:38 -07:00
weslambert
2e70d157e2
Add ref
2024-05-07 11:13:51 -04:00
m0duspwnens
5e2e5b2724
Merge remote-tracking branch 'origin/2.4/dev' into orchit
2024-05-07 10:44:14 -04:00
m0duspwnens
dcc1f656ee
predownload logstash and elastic for new searchnode and heavynode
2024-05-07 10:13:51 -04:00
Wes
bee8c2c1ce
Remove watch
2024-05-07 13:21:59 +00:00
Jason Ertel
4ebe070cd8
test regexes for detections
2024-05-06 19:03:12 -04:00
weslambert
a5e89c0854
Merge pull request #12947 from Security-Onion-Solutions/fix/strelka_yara_distributed
...
Fix YARA rules for distributed deployments
2024-05-06 15:53:08 -04:00
weslambert
a25e43db8f
Merge pull request #12948 from Security-Onion-Solutions/fix/strelka_yara_watch
...
Restart Strelka backend when YARA rules change
2024-05-06 15:52:57 -04:00
Josh Brower
b997e44715
Merge pull request #12939 from Security-Onion-Solutions/2.4/detections-airgap
...
Initial airgap support for detections
2024-05-06 15:46:29 -04:00
Wes
1e48955376
Restart when rules change
2024-05-06 19:39:03 +00:00
Wes
5056ec526b
Add compiled directory
2024-05-06 19:27:38 +00:00
m0duspwnens
2431d7b028
Merge branch '2.4/detections-airgap' of https://github.com/Security-Onion-Solutions/securityonion into 2.4/detections-airgap
2024-05-06 15:27:27 -04:00