Doug Burks
|
ec0cf71c3f
|
add opcua_binary_opensecure_channel to so-zeek-logs
|
2022-11-26 17:00:32 -05:00 |
|
doug
|
73adc571de
|
add more zeek ics parsers
|
2022-11-26 10:36:49 -05:00 |
|
Doug Burks
|
692ec05b2d
|
fix opcua_binary_activate_session in hunt.eventfields.json
|
2022-11-25 17:51:25 -05:00 |
|
Doug Burks
|
00078fd9e5
|
add opcua_binary_activate_session_diagnostic_info to hunt.eventfields.json
|
2022-11-25 17:47:41 -05:00 |
|
Doug Burks
|
13c8fb0004
|
add ecat_coe_info to hunt.eventfields.json
|
2022-11-25 17:45:28 -05:00 |
|
Doug Burks
|
920b16e494
|
add ecat_dev_info to hunt.eventfields.json
|
2022-11-25 17:42:59 -05:00 |
|
Doug Burks
|
d98c57510a
|
add opcua_binary_activate_session_locale_id to hunt.eventfields.json
|
2022-11-25 17:39:17 -05:00 |
|
Doug Burks
|
58aa730437
|
add opcua_binary_create_session_endpoints to hunt.eventfields.json
|
2022-11-25 17:37:10 -05:00 |
|
Doug Burks
|
f36da68009
|
add opcua_binary_create_subscription to hunt.eventfields.json
|
2022-11-25 17:35:02 -05:00 |
|
Doug Burks
|
0091675ab6
|
fix opcua_binary_get_endpoints_description in hunt.eventfields.json
|
2022-11-25 17:32:30 -05:00 |
|
Doug Burks
|
83d25a97d3
|
add opcua_binary_get_endpoints_description to hunt.eventfields.json
|
2022-11-25 16:01:40 -05:00 |
|
Doug Burks
|
e536568c8a
|
add opcua_binary_activate_session to hunt.eventfields.json
|
2022-11-25 15:59:17 -05:00 |
|
Doug Burks
|
a00eb9071f
|
add opcua_binary_get_endpoints to hunt.eventfields.json
|
2022-11-25 15:57:35 -05:00 |
|
Doug Burks
|
c39cd9a290
|
add opcua_binary_browse_result to hunt.eventfields.json
|
2022-11-25 15:55:59 -05:00 |
|
Doug Burks
|
cb5483d401
|
add opcua_binary_create_session to hunt.eventfields.json
|
2022-11-25 15:53:09 -05:00 |
|
Doug Burks
|
fab0d17314
|
add opcua_binary_browse_description to hunt.eventfields.json
|
2022-11-25 15:51:49 -05:00 |
|
Doug Burks
|
465e6c4605
|
add opcua_binary_create_session_user_token to hunt.eventfields.json
|
2022-11-25 15:48:11 -05:00 |
|
Doug Burks
|
a119d6a842
|
add opcua_binary_get_endpoints_user_token to hunt.eventfields.json
|
2022-11-25 15:46:35 -05:00 |
|
Doug Burks
|
be8ce43b74
|
add opcua_binary_browse to hunt.eventfields.json
|
2022-11-25 15:44:22 -05:00 |
|
Doug Burks
|
b2a33d4800
|
add opcua_binary_browse_response_references to hunt.eventfields.json
|
2022-11-25 15:41:48 -05:00 |
|
Doug Burks
|
78fac49e66
|
add opcua_binary_read to hunt.eventfields.json
|
2022-11-25 15:39:58 -05:00 |
|
Doug Burks
|
ca08989404
|
add cip_io to hunt.eventfields.json
|
2022-11-25 15:37:21 -05:00 |
|
Doug Burks
|
4ed757916e
|
add opcua_binary_status_code_detail to hunt.eventfields.json
|
2022-11-25 15:35:17 -05:00 |
|
Doug Burks
|
676c543178
|
add opcua_binary to hunt.eventfields.json
|
2022-11-25 15:33:13 -05:00 |
|
Doug Burks
|
33a478ff59
|
fix zeek ics logs in so-zeek-logs
|
2022-11-25 09:40:48 -05:00 |
|
Doug Burks
|
2ada4712bc
|
fix zeek ics logs in so-zeek-logs
|
2022-11-25 09:37:52 -05:00 |
|
Doug Burks
|
fad6c46e7c
|
fix zeek ics logs in so-zeek-logs
|
2022-11-25 09:35:00 -05:00 |
|
Doug Burks
|
9f5e75b302
|
add software to so-zeek-logs
|
2022-11-25 07:27:50 -05:00 |
|
Doug Burks
|
3f62cddc3b
|
change . to _
|
2022-11-23 12:21:12 -05:00 |
|
Doug Burks
|
085420997c
|
move status_code before status_code.link_id
|
2022-11-23 12:11:04 -05:00 |
|
Doug Burks
|
0a1d0d35c8
|
fix description
|
2022-11-23 11:33:31 -05:00 |
|
Doug Burks
|
9ee96f2280
|
fix description
|
2022-11-23 11:32:09 -05:00 |
|
doug
|
bc620b7def
|
fix zeek opcua pipelines
|
2022-11-23 10:56:32 -05:00 |
|
Doug Burks
|
08d5f494ab
|
Merge pull request #9208 from Security-Onion-Solutions/dougburks-patch-1
Initial dashboards for stun, tds, wireguard, and ics
|
2022-11-22 16:04:12 -05:00 |
|
weslambert
|
3a64362887
|
Remove extra space used during testing
|
2022-11-22 15:47:16 -05:00 |
|
Wes
|
e77a60bcbf
|
Add missing OPCUA 'activate_session' pipelines
|
2022-11-22 20:44:48 +00:00 |
|
Doug Burks
|
7caf827b77
|
add ecat_aoe_info to hunt.eventfields.json
|
2022-11-22 13:33:06 -05:00 |
|
Doug Burks
|
f40ccb7eff
|
add bacnet_discovery to hunt.eventfields.json
|
2022-11-22 13:27:26 -05:00 |
|
Doug Burks
|
e0cd550820
|
update ecat_arp_info in hunt.eventfields.json
|
2022-11-22 13:23:45 -05:00 |
|
Doug Burks
|
4e5106c863
|
update ecat_arp_info in hunt.eventfields.json
|
2022-11-22 13:21:33 -05:00 |
|
Doug Burks
|
5a107c63b8
|
add source.mac and destination.mac to dashboards.queries.json
|
2022-11-22 13:16:47 -05:00 |
|
Doug Burks
|
8a9a13865c
|
add ecat_registers to hunt.eventfields.json
|
2022-11-22 13:12:24 -05:00 |
|
Doug Burks
|
9cd6273beb
|
update ecat_log_address in hunt.eventfields.json
|
2022-11-22 13:10:46 -05:00 |
|
Doug Burks
|
724b26228c
|
add ecat_log_address to hunt.eventfields.json
|
2022-11-22 13:09:27 -05:00 |
|
weslambert
|
3c054fd133
|
Fix spelling of 'wireguard.responses' field name
|
2022-11-22 13:02:43 -05:00 |
|
Doug Burks
|
24ee38369f
|
add cotp to hunt.eventfields.json
|
2022-11-22 12:49:33 -05:00 |
|
weslambert
|
8e17c23659
|
Fix format/speliing for 'enip.status_code' field name
|
2022-11-22 12:05:03 -05:00 |
|
weslambert
|
92170941f0
|
Fix spelling for 'stun.class' field name
|
2022-11-22 12:04:07 -05:00 |
|
Doug Burks
|
10ac789fbf
|
add profinet_dce_rpc to hunt.eventfields.json
|
2022-11-22 11:08:24 -05:00 |
|
Doug Burks
|
db58a35562
|
add profinet to hunt.eventfields.json
|
2022-11-22 11:07:03 -05:00 |
|