Commit Graph

6451 Commits

Author SHA1 Message Date
weslambert 2dced35800 Add 'configured_vulns_ext_vars.yar' to exclusion list 2023-02-01 14:24:20 -05:00
m0duspwnens d43346a084 hold python mysql 2023-02-01 14:11:27 -05:00
m0duspwnens 0c4a27d120 lock python36-mysql-1.3.12-2.el7 version 2023-02-01 12:33:19 -05:00
Doug Burks d12aa0ed56 Move host.domain table to end of DHCP tables 2023-01-31 07:14:18 -05:00
Doug Burks 17bcf50ccb update Suricata DHCP parser to set server.address 2023-01-30 15:57:47 -05:00
Doug Burks a96825f43e Update soup for 2.3.210 2023-01-30 09:16:00 -05:00
Doug Burks 0ff519ed2f Update to Elastic 8.6.1 2023-01-26 16:09:13 -05:00
Doug Burks 127533492f Update to Elastic 8.6.1 2023-01-26 16:08:15 -05:00
Doug Burks 672cab858e Continue even if thehive errors 2023-01-12 12:48:16 -05:00
Josh Brower b54f2e8752 Fix mispelling 2023-01-11 10:59:50 -05:00
Josh Brower 1470e120ef Merge pull request #9540 from Security-Onion-Solutions/idhskins
bug fix - idh skins
2023-01-09 15:49:04 -05:00
Josh Brower 2c747ec837 make sure dir is created 2023-01-09 13:46:10 -05:00
Josh Brower 8cb5cd5fee Merge pull request #9214 from Security-Onion-Solutions/idhskins
Custom IDH HTTP Skins
2023-01-06 15:14:14 -05:00
Doug Burks a4bae77973 Merge pull request #9271 from Njinx/dev
so-status runs some code before checking for root privileges
2023-01-04 16:05:34 -05:00
doug 7dcdcc18a5 fix so-common references 2023-01-04 14:28:47 -05:00
doug 3482df5ee1 fix jinja whitespace 2023-01-04 13:33:51 -05:00
doug a67a254edc update Copyright year 2023-01-04 12:44:18 -05:00
Doug Burks e3d32c7871 Improve default sysmon fields and add new network_connection fields 2023-01-04 07:38:18 -05:00
Wes bd114eb1c4 Update RITA beacon parsing 2023-01-03 16:01:35 +00:00
doug 5d060f9832 update Sysmon File dashboard 2022-12-31 14:10:02 -05:00
doug edcbfd17f5 update sysmon parser 2022-12-30 16:20:06 -05:00
Doug Burks 3e1a5b6329 Improve Strelka dashboard 2022-12-21 15:34:06 -05:00
Doug Burks b1709f3ea3 Improve Firewall dashboard 2022-12-21 15:28:41 -05:00
Doug Burks 76a73ea35c Improve Software dashboard 2022-12-21 15:25:19 -05:00
Doug Burks 991a6ec43c Improve Intel dashboard 2022-12-21 15:19:54 -05:00
Doug Burks e2c0607249 Improve FTP dashboard 2022-12-21 14:36:44 -05:00
Doug Burks 82c61e6bc9 improve NIDS Alerts dashboard 2022-12-21 14:32:05 -05:00
Doug Burks 37aa779095 Minor improvements 2022-12-21 13:14:38 -05:00
Doug Burks 9e631ad63d Improve SOC dashboards 2022-12-21 13:04:12 -05:00
Jason Ertel 87cebedc85 Backup the new Kratos location 2022-12-14 14:12:47 -05:00
Jason Ertel e8a8f65ddc fix typo 2022-12-14 12:56:25 -05:00
Jason Ertel a7a15117f0 Improve soup wording when the script itself needs updated 2022-12-14 12:03:47 -05:00
Jason Ertel 865ba4264b Stop backing up kratos since it now lives in /nsm. Ensure kratos is removed when re-installing. 2022-12-14 10:57:24 -05:00
Jason Ertel 6985b0ab27 Move kratos DB to /nsm 2022-12-14 10:50:24 -05:00
Mike Reeves b0d934daf7 Update config.map.jinja 2022-12-13 13:52:13 -05:00
Doug Burks aa08803f03 FIX: so-import utilities should hyperlink to dashboards #9373 2022-12-13 13:23:27 -05:00
Doug Burks bb346d531d FIX: so-import utilities should hyperlink to dashboards #9373 2022-12-13 13:22:53 -05:00
Doug Burks 6c057d0b0a FIX: so-import utilities should hyperlink to dashboards #9373 2022-12-13 12:43:54 -05:00
Doug Burks 47e43e53d9 FIX: so-import utilities should hyperlink to dashboards #9373 2022-12-13 12:43:10 -05:00
Wes 98a1fb96c2 Add test coverage for empty list value 2022-12-13 16:23:16 +00:00
Wes 874bbd2580 Remove extra whitespace 2022-12-13 16:02:46 +00:00
Wes 90dedbb841 Update tests to account for change in 'file_path' value verification 2022-12-13 15:58:35 +00:00
Wes df5dd5fe28 Use new list verification function for 'file_path' 2022-12-13 15:57:43 +00:00
Wes d5ab455485 Add new test for list value verification function 2022-12-13 15:56:58 +00:00
Wes 20b79b7ab0 Add new function to verify list value 2022-12-13 15:56:26 +00:00
Jason Ertel d7dd2d2ef8 Upgrade ES to 8.5.3 2022-12-12 13:43:28 -05:00
weslambert f85fb5ecf9 Remove double quotes to fix issue with file path sourcing from 'localfile.py' 2022-12-08 16:35:24 -05:00
Jason Ertel d48d473f43 Switch back to older style redirect due to incompatibility with Ub 18 2022-12-07 14:06:24 -05:00
Jason Ertel 225b7e359c Use original style due to pgrep conflict with cron 2022-12-07 11:53:42 -05:00
Jason Ertel 7b05627d5c Suricata support for filecheck; reduce cron noise 2022-12-07 07:58:32 -05:00