Mike Reeves
2f3b92887b
Merge pull request #12714 from Security-Onion-Solutions/2.3.300
...
2.3.300
2024-04-01 11:26:43 -04:00
Mike Reeves
d15678f638
Update VERIFY_ISO.md
2024-04-01 11:25:29 -04:00
Mike Reeves
93c29bc1da
2.3.300
2024-04-01 11:22:31 -04:00
Mike Reeves
56263675f6
Merge pull request #12692 from Security-Onion-Solutions/2.3.300
...
2.3.300
2024-03-29 09:55:15 -04:00
Mike Reeves
1599e69851
2.3.300
2024-03-29 09:43:50 -04:00
weslambert
5ae7e27ace
Merge pull request #12677 from Security-Onion-Solutions/fix/strelka_yara_ignore
...
Ignore more rules
2024-03-27 16:17:34 -04:00
weslambert
945d2abeed
Ignore more rules
2024-03-27 16:13:30 -04:00
Doug Burks
68eb2d3ceb
Merge pull request #12614 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.300
2024-03-19 16:48:25 -04:00
Doug Burks
595f965183
Update soup for 2.3.300
2024-03-19 16:44:01 -04:00
Jason Ertel
834d18b77c
Merge pull request #12603 from Security-Onion-Solutions/jertel/ld
...
reschedule lock jobs
2024-03-18 09:41:21 -04:00
Jason Ertel
4849da1c11
Merge branch 'master' into jertel/ld
2024-03-18 09:31:17 -04:00
Jason Ertel
fbbddc2aaf
Merge pull request #12602 from Security-Onion-Solutions/jertel/lock
...
re-schedule lock jobs
2024-03-18 09:29:04 -04:00
Jason Ertel
4b24500b79
re-schedule lock jobs
2024-03-18 07:37:42 -04:00
Mike Reeves
f6a765addc
Merge pull request #12467 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update VERSION
2024-02-29 14:13:44 -05:00
Mike Reeves
8b56c0a744
Update VERSION
2024-02-29 14:12:35 -05:00
Mike Reeves
b31d38e734
Merge pull request #12463 from Security-Onion-Solutions/dev
...
2.3.290
2024-02-29 14:07:11 -05:00
Mike Reeves
b1db4137d0
Merge pull request #12462 from Security-Onion-Solutions/2.3.290
...
2.3.290
2024-02-29 09:15:41 -05:00
Mike Reeves
44ef164713
2.3.290
2024-02-29 09:08:37 -05:00
Jason Ertel
43f7dce297
Merge pull request #12407 from Security-Onion-Solutions/jertel/mergem
...
Jertel/mergem
2024-02-21 13:18:08 -05:00
Jason Ertel
4e4a4686f1
Merge branch 'master' into jertel/mergem
2024-02-21 13:14:29 -05:00
Jason Ertel
b5f44e48ab
Merge pull request #12403 from Security-Onion-Solutions/jertel/disctemplate
...
add message at top for clickable link
2024-02-21 12:42:04 -05:00
Jason Ertel
a44448519b
add message at top for clickable link
2024-02-21 10:53:50 -05:00
Jason Ertel
6245ee9a5b
Merge branch 'master' into jertel/disctemplate
2024-02-21 10:43:28 -05:00
Jason Ertel
49ca970076
add message at top for clickable link
2024-02-21 10:41:28 -05:00
Jason Ertel
f49fb7cbae
Merge pull request #12401 from Security-Onion-Solutions/jertel/disctemplate
...
template improvements
2024-02-21 10:39:03 -05:00
Jason Ertel
7692c9be53
template improvements
2024-02-21 10:36:07 -05:00
Jason Ertel
25ef12cdc5
Merge pull request #12395 from Security-Onion-Solutions/jertel/mergemaster
...
Jertel/mergemaster
2024-02-21 07:18:22 -05:00
Jason Ertel
2967adca90
Merge branch 'master' into jertel/mergemaster
2024-02-20 16:56:14 -05:00
Jason Ertel
d198458366
Merge pull request #12392 from Security-Onion-Solutions/jertel/glm_master
...
thread locking
2024-02-20 16:55:16 -05:00
Jason Ertel
9e98b409a5
thread locking
2024-02-20 16:00:41 -05:00
Doug Burks
ba8f729976
Merge pull request #12335 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.290
2024-02-09 11:18:59 -05:00
Doug Burks
5b67795c23
Update soup for 2.3.290
2024-02-09 11:12:43 -05:00
Jason Ertel
483bf60ae3
Merge pull request #12233 from Security-Onion-Solutions/jertel/23guidelines
...
Update 2-4.yml
2024-01-23 10:07:35 -05:00
Doug Burks
1a9350f60b
Update 2-4.yml
2024-01-23 10:05:59 -05:00
Doug Burks
f4afda0975
Merge pull request #12232 from Security-Onion-Solutions/dougburks-patch-1
...
Improve Github Discussions template for 2.4 category
2024-01-23 09:57:40 -05:00
Doug Burks
137372337c
Update 2-4.yml
2024-01-23 09:51:45 -05:00
Mike Reeves
1521532c60
Merge pull request #11880 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-11-28 15:33:48 -05:00
Mike Reeves
ada32967dc
Update VERSION
2023-11-28 15:30:49 -05:00
Mike Reeves
d5d2b5fbc7
Merge pull request #11879 from Security-Onion-Solutions/dev
...
2.3.280
2023-11-28 15:21:56 -05:00
Mike Reeves
84d6fcb752
Merge pull request #11878 from Security-Onion-Solutions/2.3.280
...
2.3.280
2023-11-28 15:00:34 -05:00
Mike Reeves
de9e9a2716
2.3.280
2023-11-28 14:58:25 -05:00
Josh Patterson
cec6cff19d
Merge pull request #11874 from Security-Onion-Solutions/23souphs
...
so-nginx watch managerssl to restart if changed
2023-11-27 12:48:06 -05:00
m0duspwnens
7311d6480c
so-nginx watch managerssl to restart if changed
2023-11-27 12:15:09 -05:00
Josh Patterson
f967c8e362
Merge pull request #11873 from Security-Onion-Solutions/23souphs
...
enable highstate after starting minion
2023-11-27 11:12:45 -05:00
m0duspwnens
cfad6414d2
enable highstate after starting minion
2023-11-27 11:10:39 -05:00
Josh Patterson
0fdaed9cf7
Merge pull request #11864 from Security-Onion-Solutions/import/suriinterface
...
suricata interface None if so-import
2023-11-22 10:42:43 -05:00
m0duspwnens
1dc88781f1
suricata interface None if so-import
2023-11-22 10:11:34 -05:00
Mike Reeves
0cfb8b0816
Merge pull request #11834 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update signing_policies.conf
2023-11-20 15:59:21 -05:00
Mike Reeves
c0968d3843
Update signing_policies.conf
2023-11-20 15:57:29 -05:00
Mike Reeves
3b133e87cd
Merge pull request #11831 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update signing_policies.conf
2023-11-20 15:19:42 -05:00
Mike Reeves
fee9b61ce9
Update soup
2023-11-20 15:14:25 -05:00
Mike Reeves
57612c69fe
Update signing_policies.conf
2023-11-20 15:11:50 -05:00
Mike Reeves
94accb0e8c
Update signing_policies.conf
2023-11-20 15:09:13 -05:00
Josh Patterson
3b8d1d470e
Merge pull request #11798 from Security-Onion-Solutions/m0duspwnens-patch-1
...
Update soup
2023-11-15 15:23:46 -05:00
Josh Patterson
c624a44b0e
Update soup
...
add quote
2023-11-15 15:19:54 -05:00
weslambert
bc509a0aa9
Merge pull request #11772 from Security-Onion-Solutions/upgrade/elastic_8_10_4
...
Elastic 8.10.4
2023-11-13 09:36:49 -05:00
Doug Burks
ee0ef3217f
Merge pull request #11771 from Security-Onion-Solutions/dougburks-patch-1
...
Add EOL warning to README.md
2023-11-13 09:18:50 -05:00
weslambert
18e319cbe3
Elastic 8.10.4
2023-11-13 09:17:33 -05:00
Doug Burks
3316e1261d
Add EOL warning to README.md
2023-11-13 09:16:25 -05:00
weslambert
b7cf44466c
Elastic 8.10.4
2023-11-13 09:16:23 -05:00
Mike Reeves
e321aa52a5
Merge pull request #11749 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update soup
2023-11-09 10:49:34 -05:00
Mike Reeves
07df045e79
Update soup
2023-11-09 10:38:53 -05:00
Mike Reeves
7b11ddb032
Update soup
2023-11-09 10:25:16 -05:00
Jorge Reyes
ac4428940e
Merge pull request #11561 from Security-Onion-Solutions/2.3/zeek6
...
Zeek 6 upgrade
2023-10-23 09:25:21 -04:00
reyesj2
a9457d5f53
Remove external community-id replaced with Zeek 6 built in community-id.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-17 16:02:16 -04:00
Jason Ertel
3672701dde
Merge pull request #11506 from Security-Onion-Solutions/jertel-patch-1
...
Update VERSION
2023-10-11 09:26:32 -04:00
Jason Ertel
07ed2cb3da
Update VERSION
2023-10-10 21:35:48 -04:00
Mike Reeves
3839e52401
Merge pull request #11374 from Security-Onion-Solutions/dev
...
2.3.270
2023-10-06 16:40:28 -04:00
Mike Reeves
b005a10a8e
Merge pull request #11373 from Security-Onion-Solutions/2.3.270
...
2.3.270
2023-09-22 12:59:04 -04:00
Mike Reeves
752ff5917f
2.3.270
2023-09-22 12:45:46 -04:00
Mike Reeves
815e5d53a6
Merge pull request #11367 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-09-21 09:40:58 -04:00
Mike Reeves
a967db8152
Update soup
2023-09-21 09:38:05 -04:00
Jason Ertel
7835cb6a7a
Merge pull request #11360 from Security-Onion-Solutions/jertel/vol
...
Jertel/vol
2023-09-20 08:29:43 -04:00
Jason Ertel
07b92eef9e
vol sprawl
2023-09-19 17:22:42 -04:00
Jason Ertel
8855619453
vol sprawl
2023-09-19 12:52:28 -04:00
Doug Burks
7763218b71
Merge pull request #11287 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.270
2023-09-11 09:08:21 -04:00
Doug Burks
29f12fac90
Update soup for 2.3.270
2023-09-11 09:05:19 -04:00
Doug Burks
1a9f8f0bc2
Merge pull request #11228 from Security-Onion-Solutions/master
...
Merge master to dev for updated 2.4 discussion template
2023-08-31 10:19:45 -04:00
Doug Burks
3e5f354d8b
Merge pull request #11227 from Security-Onion-Solutions/dougburks-patch-1
...
Update 2-4.yml discussion template with additional fields for CPU, RAM, and storage
2023-08-31 10:16:55 -04:00
Doug Burks
a1b76d2cd3
Update 2-4.yml
2023-08-31 10:12:47 -04:00
weslambert
43e402fad4
Merge pull request #11187 from Security-Onion-Solutions/fix/kibana_migration_version
...
Remove migration version
2023-08-28 11:48:58 -04:00
weslambert
170b408feb
Remove migration version
2023-08-28 11:26:35 -04:00
weslambert
e55725cca4
Merge pull request #11183 from Security-Onion-Solutions/feature/elastic_8_8_2
...
Elastic 8.8.2
2023-08-28 09:49:34 -04:00
weslambert
2b9f6b26d8
Elastic 8.8.2
2023-08-28 09:42:23 -04:00
weslambert
f10b67599e
Elastic 8.8.2
2023-08-28 09:41:36 -04:00
Doug Burks
ea03613df3
Merge pull request #11103 from Security-Onion-Solutions/master
...
Merge 2.4 discussion template to dev
2023-08-18 16:21:45 -04:00
Doug Burks
8ffb6b9e1c
Merge pull request #11102 from Security-Onion-Solutions/dougburks-patch-1
...
Create template for Github Discussions in the 2.4 Category
2023-08-18 16:19:04 -04:00
Doug Burks
ffadd4aa42
Create 2-4.yml
2023-08-18 16:13:31 -04:00
Mike Reeves
78ccea12b1
Merge pull request #10919 from Security-Onion-Solutions/master
...
Soup
2023-08-02 12:27:08 -04:00
Doug Burks
8bef5a84f7
Merge pull request #10916 from Security-Onion-Solutions/supersoup
...
Supersoup
2023-08-02 11:58:58 -04:00
Mike Reeves
679775a7d0
Add supersoup mode
2023-08-02 11:21:28 -04:00
Mike Reeves
3f5f93059e
Add supersoup mode
2023-08-02 11:20:23 -04:00
Mike Reeves
d2ae8f81e1
Add supersoup mode
2023-08-02 10:49:51 -04:00
Mike Reeves
fcc369d4b9
Add supersoup mode
2023-08-02 10:46:54 -04:00
Mike Reeves
9bb28fd0b5
Add supersoup mode
2023-08-02 10:31:55 -04:00
Mike Reeves
93c5e6a9e8
Add supersoup mode
2023-08-02 09:49:14 -04:00
Mike Reeves
6a7e756a37
Add supersoup mode
2023-08-02 09:47:35 -04:00
Mike Reeves
f6b9dec2ae
Add supersoup mode
2023-08-02 09:45:29 -04:00
Mike Reeves
37386057d9
Merge pull request #10622 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-06-20 14:52:03 -04:00
Mike Reeves
800945c3b6
Update VERSION
2023-06-20 14:50:29 -04:00
Mike Reeves
b56c0c5e64
Merge pull request #10621 from Security-Onion-Solutions/dev
...
2.3.260
2023-06-20 14:36:16 -04:00
Mike Reeves
01b986cd50
Merge pull request #10620 from Security-Onion-Solutions/2.3.260
...
2.3.260
2023-06-20 09:37:56 -04:00
Mike Reeves
3e862151f3
2.3.260
2023-06-20 09:18:30 -04:00
Doug Burks
15b3982930
Merge pull request #10610 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.260
2023-06-16 13:10:42 -04:00
Doug Burks
3d687f0404
Update soup for 2.3.260
2023-06-16 12:55:52 -04:00
weslambert
e74c2fa1b0
Merge pull request #10605 from Security-Onion-Solutions/fix/analyzer_dependencies
...
Update dependencies
2023-06-16 07:51:50 -04:00
Wes
ffc91393e7
Update pulsedive dependencies
2023-06-15 22:14:41 +00:00
Wes
d0ab2db312
Update dependencies
2023-06-15 21:03:40 +00:00
weslambert
4906068c7f
Merge pull request #10495 from Security-Onion-Solutions/foxtrot
...
Update requests and whoisit
2023-06-05 10:53:49 -04:00
Wes
ef8eece53b
Update dependencies
2023-06-05 13:45:44 +00:00
weslambert
660a50c08d
Update whoisit to 2.7.0
2023-06-03 08:53:02 -04:00
Wes
5d326a3c32
Update dependencies
2023-06-01 16:26:04 +00:00
weslambert
2a907d3de3
Update version to 2.3.260
2023-06-01 12:04:35 -04:00
weslambert
33134b1814
Update requests and whist
2023-06-01 12:03:58 -04:00
weslambert
b0962da758
Update version to 2.3.0-foxtrot
2023-05-31 08:50:51 -04:00
weslambert
8148fd9e56
Merge pull request #10434 from Security-Onion-Solutions/foxtrot
...
Strelka 0.23.05.22 - Remove ScanRuby scanner
2023-05-26 12:45:03 -04:00
weslambert
1ee332b55b
Update version to 2.3.260
2023-05-26 08:31:11 -04:00
weslambert
873632ec4f
Remove ScanRuby scanner
2023-05-25 17:23:44 -04:00
weslambert
f8068d7975
Update version to 2.3.0-foxtrot
2023-05-25 16:14:29 -04:00
weslambert
a79ebea5c3
Update version value to 2.3.250-foxtrot
2023-05-25 15:29:07 -04:00
weslambert
2fdc3874ca
Update version to foxtrot
2023-05-25 14:35:52 -04:00
Mike Reeves
7f52c2015d
Merge pull request #10408 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-05-22 15:25:05 -04:00
Mike Reeves
548e1e6937
Update VERSION
2023-05-22 15:23:52 -04:00
Mike Reeves
c949101d0f
Merge pull request #10406 from Security-Onion-Solutions/dev
...
2.3.250
2023-05-22 15:14:23 -04:00
Mike Reeves
7c1f19b91f
Merge pull request #10405 from Security-Onion-Solutions/2.3.250
...
2.3.250
2023-05-22 11:39:40 -04:00
Mike Reeves
598d6b025e
2.3.250
2023-05-22 11:37:13 -04:00
Jason Ertel
4d0d0714a5
Merge pull request #10401 from Security-Onion-Solutions/jertel/fixwhoisit
...
use the same requests version that's already packaged with the analyzer
2023-05-20 08:45:29 -04:00
Jason Ertel
cb0c078955
use the same requests version that's already packaged with the analyzer
2023-05-19 23:56:39 -04:00
Jason Ertel
aa426244bf
Merge pull request #10394 from Security-Onion-Solutions/jertel/fixwhoisit
...
fix lib dependency issue with whoisit
2023-05-19 14:34:32 -04:00
Jason Ertel
97b2ae8d82
fix lib dependency issue with whoisit
2023-05-19 14:23:12 -04:00
Doug Burks
7047125759
Merge pull request #10386 from Security-Onion-Solutions/2.3/elastic-8.7.1
...
UPGRADE: Elastic 8.7.1 #10269
2023-05-18 15:27:10 -04:00
Doug Burks
43f73abd4d
Update so-kibana-config-load
2023-05-18 15:18:27 -04:00
Doug Burks
51a8684850
Update config_saved_objects.ndjson
2023-05-18 15:17:36 -04:00
Doug Burks
b3c5239787
Merge pull request #10333 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.250
2023-05-11 08:28:53 -04:00
Doug Burks
0f562279ee
Update soup for 2.3.250
2023-05-11 07:26:58 -04:00
weslambert
834f45c0f2
Merge pull request #10286 from Security-Onion-Solutions/fix/strelka_ignore_yara_rules
...
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-08 11:58:11 -04:00
weslambert
d4cf9efeca
Merge pull request #10303 from Security-Onion-Solutions/fix/kibana_pivot_to_pcap_url
...
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 11:55:22 -04:00
Doug Burks
c620983b4a
Merge pull request #10299 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:47:49 -04:00
Wes
ed19c139ea
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 13:44:36 +00:00
Doug Burks
af85c6261b
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:41:26 -04:00
weslambert
e9f58269cd
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-04 16:13:59 -04:00
Jason Ertel
208c3d96e9
Merge pull request #10266 from Security-Onion-Solutions/jertel/aws
...
more detection improvements
2023-05-02 08:17:13 -04:00
Jason Ertel
1e888a5d9e
more detection improvements
2023-05-02 07:56:11 -04:00
Jason Ertel
f7ae8d449e
Merge pull request #10259 from Security-Onion-Solutions/jertel/simplifycd
...
simplify cloud detection
2023-05-01 11:33:26 -04:00
Jason Ertel
195274bb11
Merge branch 'dev' into jertel/simplifycd
2023-05-01 11:29:39 -04:00
Jason Ertel
a0ac1d2274
simplify cloud detection
2023-05-01 11:04:43 -04:00
Mike Reeves
3dd39c7f59
Merge pull request #10234 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2023-04-26 14:41:04 -04:00
Mike Reeves
ba846bbf35
Update VERSION
2023-04-26 14:39:31 -04:00
Mike Reeves
0baf8e9471
Merge pull request #10227 from Security-Onion-Solutions/dev
...
2.3.240
2023-04-26 14:31:56 -04:00
Mike Reeves
e30fec7af0
Merge pull request #10226 from Security-Onion-Solutions/2.3.240
...
2.3.240
2023-04-26 09:58:18 -04:00
Mike Reeves
884f5cd3a6
2.3.240
2023-04-26 09:55:19 -04:00
Jason Ertel
11babd2f1c
Merge pull request #10221 from Security-Onion-Solutions/jertel/imdsv2to
...
timeout more quickly on aws imdsv2 detection
2023-04-26 07:59:13 -04:00
Jason Ertel
b440ab5c02
timeout more quickly on aws imdsv2 detection
2023-04-26 07:57:23 -04:00
Jason Ertel
91d667c3ad
Merge pull request #10200 from Security-Onion-Solutions/jertel/imdsv2_23
...
Detect cloud install on forced imdsv2 instances
2023-04-25 09:46:39 -04:00
Jason Ertel
f04c01b28c
Merge pull request #10204 from Security-Onion-Solutions/jertel/2.3.240_soup
...
soup update for 2.3.240
2023-04-25 09:46:28 -04:00
Jason Ertel
71ab8ddf1d
soup update for 2.3.240
2023-04-25 09:42:14 -04:00
Jason Ertel
f1f79d55dc
Detect cloud install on forced imdsv2 instances
2023-04-24 16:26:23 -04:00
Mike Reeves
db1bd16758
Merge pull request #10142 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-04-17 10:56:59 -04:00
Mike Reeves
ef73834d58
Update VERSION
2023-04-17 10:55:38 -04:00
Mike Reeves
3891548d6d
Merge pull request #10141 from Security-Onion-Solutions/dev
...
2.3.230 Release
2023-04-17 10:47:32 -04:00
Mike Reeves
9d6ed8b9b2
Merge pull request #10140 from Security-Onion-Solutions/2.3.230
...
2.3.230
2023-04-17 10:26:59 -04:00
Mike Reeves
ef92815a08
2.3.230
2023-04-17 10:22:39 -04:00
Doug Burks
19b5cdcb0e
Merge pull request #10119 from Security-Onion-Solutions/2.3/fix-suricata-dns
...
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 11:00:13 -04:00
Doug Burks
272b345892
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 10:52:37 -04:00
Mike Reeves
7fad9d60ef
Merge pull request #10113 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2023-04-12 10:32:43 -04:00
Mike Reeves
46fc62b8dc
Update init.sls
2023-04-12 10:29:54 -04:00
Doug Burks
ca9a93a4b0
Merge pull request #9998 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.230
2023-03-24 12:38:39 -04:00
Doug Burks
aa2e18fca9
Update soup for 2.3.230
2023-03-24 12:31:51 -04:00
Mike Reeves
7e4ce7b81d
Merge pull request #9877 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2023-03-01 16:37:14 -05:00
Mike Reeves
e5c0058dd1
Update HOTFIX
2023-03-01 16:36:08 -05:00
Mike Reeves
07c5b541a3
Merge pull request #9876 from Security-Onion-Solutions/master
...
Master to Dev
2023-03-01 16:35:48 -05:00
Mike Reeves
b756b8ea32
Merge pull request #9873 from Security-Onion-Solutions/hotfix/2.3.220
...
Hotfix/2.3.220
2023-03-01 16:32:49 -05:00
Mike Reeves
5b46e57ae1
Merge pull request #9875 from Security-Onion-Solutions/hotfix23220
...
Hotfix for 2.3.220
2023-03-01 16:14:26 -05:00
Mike Reeves
924009afb8
Hotfix for 2.3.220
2023-03-01 16:11:38 -05:00
Mike Reeves
8f5bacc510
Merge pull request #9874 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2023-03-01 14:52:04 -05:00
Mike Reeves
d5e48a7eca
Update init.sls
2023-03-01 14:50:55 -05:00
Mike Reeves
6346a92f0f
Merge pull request #9872 from Security-Onion-Solutions/hotfix23220
...
Hotfix for 2.3.220
2023-03-01 14:20:47 -05:00
Mike Reeves
13a566a9a2
Hotfix for 2.3.220
2023-03-01 14:19:04 -05:00
Mike Reeves
063c6599d8
Hotfix for 2.3.220
2023-03-01 14:17:22 -05:00
weslambert
9fb315c99d
Merge pull request #9870 from Security-Onion-Solutions/fix/curator_configuration_update_8.0.x
...
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 10:19:32 -05:00
Wes
6e0891e586
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 15:16:52 +00:00
Mike Reeves
3a96d59899
Merge pull request #9869 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2023-03-01 10:10:47 -05:00
Mike Reeves
5fa945956e
Update HOTFIX
2023-03-01 10:09:19 -05:00
Mike Reeves
b0aab96cf5
Merge pull request #9858 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-02-27 09:40:39 -05:00
Mike Reeves
11def72790
Update VERSION
2023-02-27 09:39:52 -05:00
Mike Reeves
2ca2724a4c
Merge pull request #9857 from Security-Onion-Solutions/dev
...
2.3.220
2023-02-27 09:35:14 -05:00
Mike Reeves
884883a225
Merge pull request #9856 from Security-Onion-Solutions/2.3.220
...
2.3.220
2023-02-27 09:26:28 -05:00
Mike Reeves
5c8ba3af65
2.3.220
2023-02-27 09:23:33 -05:00
Josh Brower
4b5d314adf
Merge pull request #9833 from Security-Onion-Solutions/FleetDMConfigFix
...
Remove unsupported config option
2023-02-21 16:36:58 -05:00
Josh Brower
6e637f559c
Remove unsupported config option
2023-02-21 16:35:11 -05:00
Doug Burks
cc5304e9f7
Merge pull request #9806 from Security-Onion-Solutions/2.3/upgrade-elastic-8.6.2
...
2.3/upgrade elastic 8.6.2
2023-02-17 08:03:01 -05:00
Doug Burks
002403055d
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:04:57 -05:00
Doug Burks
b80b80e825
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:03:47 -05:00
Josh Brower
c539d53a02
Merge pull request #9791 from Security-Onion-Solutions/fleetsapassword
...
Fix edge case
2023-02-15 15:30:49 -05:00
Josh Brower
3a22978c2b
Fix password gen edge case
2023-02-15 15:25:35 -05:00
Doug Burks
5b1461e9a1
Merge pull request #9782 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.220
2023-02-14 08:44:09 -05:00
Doug Burks
69f889dbd9
Update soup for 2.3.220
2023-02-14 08:42:35 -05:00
Josh Brower
aefe1cceb8
Merge pull request #9758 from Security-Onion-Solutions/fleetupgrade
...
Fix link for FleetDM standalone nodes
2023-02-09 14:10:45 -05:00
Josh Brower
b7e97eceb3
Fix link for FleetDM standalone nodes
2023-02-09 14:08:48 -05:00
Josh Brower
450e02e874
Merge pull request #9749 from Security-Onion-Solutions/fleetdm-fix
...
FleetDM Upgrade Fix
2023-02-09 09:30:22 -05:00
Josh Brower
09bebf08d6
Fix FleetDM SOC Link
2023-02-09 09:10:50 -05:00
Josh Brower
4dd54cea6c
Use correct variable name
2023-02-08 16:58:47 -05:00
Josh Brower
e07f4bd0ed
Workaround for FleetDM PW Req
2023-02-08 13:03:33 -05:00
Mike Reeves
6adb586bb4
Merge pull request #9734 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-02-07 09:07:06 -05:00
Mike Reeves
2f99821736
Update VERSION
2023-02-07 09:05:16 -05:00
Mike Reeves
db27c22158
Merge pull request #9730 from Security-Onion-Solutions/dev
...
2.3.210
2023-02-07 08:58:36 -05:00
Mike Reeves
2ff284fc7f
Merge pull request #9729 from Security-Onion-Solutions/2.3.210
...
2.3.210
2023-02-06 16:36:06 -05:00
Mike Reeves
5d0a3ef205
2.3.210
2023-02-06 16:32:45 -05:00
Mike Reeves
ac9c10dd3a
2.3.210
2023-02-06 15:46:27 -05:00
weslambert
d4d67b545d
Merge pull request #9699 from Security-Onion-Solutions/fix/strelka_yara_exclusion
...
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:38:29 -05:00
weslambert
2dced35800
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:24:20 -05:00
Josh Patterson
c2a04a79c5
Merge pull request #9697 from Security-Onion-Solutions/23mysqlpy
...
23mysqlpy
2023-02-01 14:17:24 -05:00
m0duspwnens
d43346a084
hold python mysql
2023-02-01 14:11:27 -05:00
m0duspwnens
0c4a27d120
lock python36-mysql-1.3.12-2.el7 version
2023-02-01 12:33:19 -05:00
Doug Burks
b4530ffffe
Merge pull request #9681 from Security-Onion-Solutions/fix/suricata-dhcp-parsing-2.3
...
2.3: Improve Suricata DHCP parsing and dashboard
2023-01-31 10:18:49 -05:00
Doug Burks
d12aa0ed56
Move host.domain table to end of DHCP tables
2023-01-31 07:14:18 -05:00
Doug Burks
17bcf50ccb
update Suricata DHCP parser to set server.address
2023-01-30 15:57:47 -05:00
Doug Burks
48401f6a3f
Merge pull request #9675 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.210
2023-01-30 09:17:47 -05:00
Doug Burks
a96825f43e
Update soup for 2.3.210
2023-01-30 09:16:00 -05:00
Doug Burks
2d48ae7bca
Merge pull request #9656 from Security-Onion-Solutions/2.3/elastic-8.6.1
...
UPGRADE: Elastic 8.6.1 #9594 (2.3)
2023-01-26 16:24:33 -05:00
Doug Burks
0ff519ed2f
Update to Elastic 8.6.1
2023-01-26 16:09:13 -05:00
Doug Burks
127533492f
Update to Elastic 8.6.1
2023-01-26 16:08:15 -05:00
Mike Reeves
7d4b4a8bd4
Merge pull request #9585 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-01-17 09:40:46 -05:00
Mike Reeves
e9fa84d71b
Update VERSION
2023-01-17 09:39:35 -05:00
Mike Reeves
cd8cf4a1ac
Merge pull request #9578 from Security-Onion-Solutions/dev
...
2.3.200
2023-01-17 09:26:23 -05:00
Mike Reeves
9718e61a6a
Merge pull request #9576 from Security-Onion-Solutions/2.3.200
...
2.3.200
2023-01-13 16:12:20 -05:00
Mike Reeves
22ec638e85
2.3.200
2023-01-13 16:08:27 -05:00
Doug Burks
7b0c22f967
Merge pull request #9568 from Security-Onion-Solutions/fix/soup-thehive-errors
...
soup should continue even if thehive errors
2023-01-12 13:28:41 -05:00
Doug Burks
672cab858e
Continue even if thehive errors
2023-01-12 12:48:16 -05:00
Josh Brower
29312d595b
Merge pull request #9559 from Security-Onion-Solutions/idh-skins
...
Fix mispelling
2023-01-11 11:04:29 -05:00
Josh Brower
b54f2e8752
Fix mispelling
2023-01-11 10:59:50 -05:00
Josh Brower
1470e120ef
Merge pull request #9540 from Security-Onion-Solutions/idhskins
...
bug fix - idh skins
2023-01-09 15:49:04 -05:00
Josh Brower
2c747ec837
make sure dir is created
2023-01-09 13:46:10 -05:00
Josh Brower
8cb5cd5fee
Merge pull request #9214 from Security-Onion-Solutions/idhskins
...
Custom IDH HTTP Skins
2023-01-06 15:14:14 -05:00
Doug Burks
a4bae77973
Merge pull request #9271 from Njinx/dev
...
so-status runs some code before checking for root privileges
2023-01-04 16:05:34 -05:00
Doug Burks
96a568f57f
Merge pull request #9515 from Security-Onion-Solutions/fix/so-common-references-2.3
...
fix so-common references
2023-01-04 14:31:57 -05:00
doug
7dcdcc18a5
fix so-common references
2023-01-04 14:28:47 -05:00
Doug Burks
10fc8de9f9
Merge pull request #9513 from Security-Onion-Solutions/fix/jinja-whitespace-2.3
...
fix jinja whitespace 2.3
2023-01-04 13:56:17 -05:00
doug
3482df5ee1
fix jinja whitespace
2023-01-04 13:33:51 -05:00
Doug Burks
9ea3d6bb1f
Merge pull request #9512 from Security-Onion-Solutions/fix/copyright-year-2023
...
Update Copyright year
2023-01-04 12:50:30 -05:00
doug
a67a254edc
update Copyright year
2023-01-04 12:44:18 -05:00
Doug Burks
08a5a9ab31
Merge pull request #9510 from Security-Onion-Solutions/fix/sysmon-fields-2.3
...
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:58:04 -05:00
Doug Burks
e3d32c7871
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:38:18 -05:00
weslambert
20d6ce1ce9
Merge pull request #9501 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_rita_beacon
...
Update RITA beacon parsing
2023-01-03 11:13:55 -05:00
Wes
bd114eb1c4
Update RITA beacon parsing
2023-01-03 16:01:35 +00:00
Doug Burks
55c6fc422b
Merge pull request #9497 from Security-Onion-Solutions/fix/sysmon-parsing-2.3
...
FIX: Sysmon logs are missing event.category and event.dataset #8194
2023-01-03 08:56:16 -05:00
doug
5d060f9832
update Sysmon File dashboard
2022-12-31 14:10:02 -05:00
doug
edcbfd17f5
update sysmon parser
2022-12-30 16:20:06 -05:00
Doug Burks
ff4850d9ce
Merge pull request #9452 from Security-Onion-Solutions/feature/improve-dashboards-2.3
...
FEATURE: Improve SOC Dashboards #9450 2.3
2022-12-21 15:46:21 -05:00
Doug Burks
3e1a5b6329
Improve Strelka dashboard
2022-12-21 15:34:06 -05:00
Doug Burks
b1709f3ea3
Improve Firewall dashboard
2022-12-21 15:28:41 -05:00
Doug Burks
76a73ea35c
Improve Software dashboard
2022-12-21 15:25:19 -05:00
Doug Burks
991a6ec43c
Improve Intel dashboard
2022-12-21 15:19:54 -05:00
Doug Burks
e2c0607249
Improve FTP dashboard
2022-12-21 14:36:44 -05:00
Doug Burks
82c61e6bc9
improve NIDS Alerts dashboard
2022-12-21 14:32:05 -05:00
Doug Burks
37aa779095
Minor improvements
2022-12-21 13:14:38 -05:00
Doug Burks
9e631ad63d
Improve SOC dashboards
2022-12-21 13:04:12 -05:00
Jason Ertel
fe6a55b58e
Merge pull request #9393 from Security-Onion-Solutions/jertel/soup23200
...
Move Kratos DB to /nsm
2022-12-14 14:26:19 -05:00
Jason Ertel
87cebedc85
Backup the new Kratos location
2022-12-14 14:12:47 -05:00
Jason Ertel
e66c995b1f
remove apparently unused reactor reference
2022-12-14 13:50:20 -05:00
Jason Ertel
e8a8f65ddc
fix typo
2022-12-14 12:56:25 -05:00
Jason Ertel
a7a15117f0
Improve soup wording when the script itself needs updated
2022-12-14 12:03:47 -05:00
Jason Ertel
865ba4264b
Stop backing up kratos since it now lives in /nsm. Ensure kratos is removed when re-installing.
2022-12-14 10:57:24 -05:00
Jason Ertel
6985b0ab27
Move kratos DB to /nsm
2022-12-14 10:50:24 -05:00
Mike Reeves
6e4912f759
Merge pull request #9385 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Highlander Config for Kibana
2022-12-13 13:54:30 -05:00
Mike Reeves
b0d934daf7
Update config.map.jinja
2022-12-13 13:52:13 -05:00
Doug Burks
8e50868abd
Merge pull request #9383 from Security-Onion-Solutions/fix/import-hyperlink
...
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:36:22 -05:00
Doug Burks
aa08803f03
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:23:27 -05:00
Doug Burks
bb346d531d
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:22:53 -05:00
Doug Burks
6c057d0b0a
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 12:43:54 -05:00
Doug Burks
47e43e53d9
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 12:43:10 -05:00
weslambert
a8456a4d65
Merge pull request #9369 from Security-Onion-Solutions/fix/sensoroni_analyzers_configuration_check
...
Fix localfile analyzer 'file_path' check and add new list value verification function for helpers
2022-12-13 11:47:10 -05:00
Wes
98a1fb96c2
Add test coverage for empty list value
2022-12-13 16:23:16 +00:00
Wes
874bbd2580
Remove extra whitespace
2022-12-13 16:02:46 +00:00
Wes
90dedbb841
Update tests to account for change in 'file_path' value verification
2022-12-13 15:58:35 +00:00
Wes
df5dd5fe28
Use new list verification function for 'file_path'
2022-12-13 15:57:43 +00:00
Wes
d5ab455485
Add new test for list value verification function
2022-12-13 15:56:58 +00:00
Wes
20b79b7ab0
Add new function to verify list value
2022-12-13 15:56:26 +00:00
Jason Ertel
56019f48ca
Merge pull request #9358 from Security-Onion-Solutions/jertel/es853
...
Upgrade ES to 8.5.3
2022-12-12 13:45:56 -05:00
Jason Ertel
d7dd2d2ef8
Upgrade ES to 8.5.3
2022-12-12 13:43:28 -05:00
weslambert
3d431eaba9
Merge pull request #9341 from Security-Onion-Solutions/fix/analyzers_localfile_file_path
...
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 16:49:29 -05:00
weslambert
f85fb5ecf9
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 16:35:24 -05:00
Jason Ertel
1716cb0297
Merge pull request #9333 from Security-Onion-Solutions/jertel/mergedev
...
Jertel/mergedev
2022-12-08 09:17:20 -05:00
Jason Ertel
0ec366f075
clear hotfix
2022-12-08 09:15:41 -05:00
Jason Ertel
e9b9e128c6
Merge branch 'master' into jertel/mergedev
2022-12-08 09:14:08 -05:00
Mike Reeves
ef15de130a
Merge pull request #9329 from Security-Onion-Solutions/hotfix/2.3.190
...
Hotfix/2.3.190
2022-12-08 09:08:18 -05:00
Mike Reeves
e975ee0a8e
Merge pull request #9328 from Security-Onion-Solutions/mike4
...
2.3.190 hotfix
2022-12-07 16:22:05 -05:00
Mike Reeves
da94ddca13
2.3.190 hotfix
2022-12-07 16:17:57 -05:00
Mike Reeves
6e94751c65
Merge pull request #9327 from Security-Onion-Solutions/jertel/surifilecheck
...
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:10:30 -05:00
Jason Ertel
d48d473f43
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:06:24 -05:00
Jason Ertel
cff5a83ad5
Merge pull request #9324 from Security-Onion-Solutions/jertel/surifilecheck
...
Use original style due to pgrep conflict with cron
2022-12-07 12:06:26 -05:00
Jason Ertel
225b7e359c
Use original style due to pgrep conflict with cron
2022-12-07 11:53:42 -05:00
Mike Reeves
9a616caf53
Merge pull request #9322 from Security-Onion-Solutions/mike
...
2.3.190 hotfix
2022-12-07 11:15:30 -05:00
Mike Reeves
0aab268801
2.3.190 hotfix
2022-12-07 11:12:13 -05:00
Mike Reeves
0bb7f5c5e3
Merge pull request #9320 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2022-12-07 09:21:17 -05:00
Mike Reeves
4aff1f0fdb
Update HOTFIX
2022-12-07 09:19:51 -05:00
Jason Ertel
35ca08ea88
Merge pull request #9315 from Security-Onion-Solutions/jertel/surifilecheck
...
Suricata support for filecheck; reduce cron noise
2022-12-07 08:17:19 -05:00
Jason Ertel
7b05627d5c
Suricata support for filecheck; reduce cron noise
2022-12-07 07:58:32 -05:00
Mike Reeves
e3c1b6dbba
Merge pull request #9306 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update init.sls
2022-12-06 13:38:35 -05:00
Mike Reeves
f0c3b876a9
Update init.sls
2022-12-06 13:35:03 -05:00
Mike Reeves
531423f49a
Update init.sls
2022-12-06 13:25:03 -05:00
Jason Ertel
dfad5a748c
Merge pull request #9303 from Security-Onion-Solutions/jertel/surifilecheck
...
Jertel/surifilecheck
2022-12-06 11:52:36 -05:00
Jason Ertel
819b39c0bb
Update hotfix
2022-12-06 11:41:00 -05:00
Jason Ertel
0dd2e51e83
Ensure Suricata move events get picked up
2022-12-06 11:39:58 -05:00
Mike Reeves
f7730741c2
Merge pull request #9297 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-12-05 16:12:55 -05:00
Mike Reeves
cb2d6b7876
Update VERSION
2022-12-05 16:07:12 -05:00
Mike Reeves
93ca7548f8
Merge pull request #9273 from Security-Onion-Solutions/dev
...
2.3.190
2022-12-05 15:17:47 -05:00
Mike Reeves
9cbbed1038
Merge pull request #9294 from Security-Onion-Solutions/2.3.190a
...
2.3.190
2022-12-05 13:03:23 -05:00
Mike Reeves
967fd30bb1
2.3.190
2022-12-05 13:00:55 -05:00
weslambert
6c8c8a2d8e
Merge pull request #9292 from Security-Onion-Solutions/fix/strelka_disable_yara_rules_causing_errors
...
Disable additional YARA rules that are causing compilation errors
2022-12-05 11:31:23 -05:00
weslambert
8bb3b22993
Disable additional YARA rules there are causing compilation errors
2022-12-05 11:30:22 -05:00
Jason Ertel
5b6182c003
Merge pull request #9289 from Security-Onion-Solutions/jertel/filechek
...
Update filecheck to support Suricata extracted files
2022-12-05 10:59:44 -05:00
Jason Ertel
69c5a9dd90
ensure tmp files are not processed
2022-12-05 10:31:09 -05:00
Jason Ertel
86c31c129a
add suricata to socore group
2022-12-05 10:27:42 -05:00
Jason Ertel
483a9d477f
undo filecheck location move
2022-12-05 10:15:15 -05:00
Jason Ertel
d7f60a0e58
only check files on inotify
2022-12-05 10:01:40 -05:00
Jason Ertel
f06443f3dd
add suricata to socore group
2022-12-05 09:57:24 -05:00
Jason Ertel
fe798138e3
add suricata to socore group
2022-12-05 09:50:35 -05:00
Jason Ertel
e9bb60dedb
fix filecheck for suricata deployments
2022-12-05 09:28:25 -05:00
Jason Ertel
992ced685f
fix filecheck for suricata deployments
2022-12-05 09:27:31 -05:00
Jason Ertel
592bbf4217
fix filecheck for suricata deployments
2022-12-05 09:21:08 -05:00
Mike Reeves
eacf6238d8
Merge pull request #9274 from Security-Onion-Solutions/2.3.190
...
2.3.190
2022-12-02 15:33:53 -05:00
Mike Reeves
0a7ada314d
2.3.190
2022-12-02 15:31:42 -05:00
Mike Reeves
c8edb43748
Merge pull request #9272 from Security-Onion-Solutions/2.3.190
...
2.3.190
2022-12-02 15:28:02 -05:00
Mike Reeves
f112663a76
2.3.190
2022-12-02 15:21:42 -05:00
Ben Allen
a1b2c28a42
Check privileges much earlier
2022-12-02 14:08:22 -05:00
weslambert
4311d5135b
Merge pull request #9269 from Security-Onion-Solutions/fix/zeek_scripts_bzar_remove_by_default
...
Don't load BZAR script(s) by default
2022-12-02 11:02:07 -05:00
weslambert
2b2d39c869
Don't load BZAR script(s) by default
2022-12-02 10:46:45 -05:00
Mike Reeves
fcc0534572
Merge pull request #9267 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2022-12-02 09:41:03 -05:00
Mike Reeves
a3f9859fdb
Update init.sls
2022-12-02 09:38:13 -05:00
Doug Burks
cf5d5e4fc2
Merge pull request #9257 from Security-Onion-Solutions/dougburks-patch-1
...
Disable ecat_arp_info by default in so-zeek-logs and so-whiptail
2022-12-01 07:31:47 -05:00
Doug Burks
7184b9cb25
disable ecat_arp_info by default in so-zeek-logs
2022-12-01 07:18:05 -05:00
Doug Burks
544d716c19
disable ecat_arp_info by default
2022-12-01 07:17:16 -05:00
weslambert
f1f611cede
Merge pull request #9256 from Security-Onion-Solutions/fix/ics_ingest_pipelines_bsap_node_status
...
Change 'bsap.node.status.byte' to 'bsap.node.status_byte'
2022-11-30 13:04:39 -05:00
weslambert
5988c12773
Change 'bsap.node.status.byte' to 'bsap.node.status_byte'
2022-11-30 13:01:30 -05:00
Mike Reeves
dc5f4ef942
Merge pull request #9253 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Use shutil in case there are multiple filesystems involved.
2022-11-30 11:04:30 -05:00
Doug Burks
91e15c233d
Merge pull request #9252 from Security-Onion-Solutions/dougburks-patch-1
...
update stun, tunnel, and wireguard dashboards in dashboards.queries.json
2022-11-30 11:03:56 -05:00
Mike Reeves
42cde0b6f0
Use shutil in case there are multiple filesystems involved.
2022-11-30 10:59:09 -05:00
Doug Burks
1279997ca9
update stun, tunnel, and wireguard dashboards in dashboards.queries.json
2022-11-30 10:59:00 -05:00
weslambert
93e0ec8696
Merge pull request #9249 from Security-Onion-Solutions/fix/ics_ingest_pipelines_additional_field_renames
...
More ICS Field Name Updates
2022-11-30 10:26:36 -05:00
Wes
8f0547beda
Change 'bsap.node.status_byte' to 'bsap.node_status_byte'.
2022-11-30 15:24:53 +00:00
Wes
6cb4c02200
More field updates
2022-11-30 15:22:02 +00:00
weslambert
8c54c44690
Merge pull request #9248 from Security-Onion-Solutions/fix/ics_ingest_pipelines_additional_field_renames
...
Additional ICS field renames and updates
2022-11-30 10:09:44 -05:00
Wes
5d72f8d55a
Additional field renames and updates
2022-11-30 15:01:41 +00:00
Mike Reeves
768225ff5a
Merge pull request #9242 from Security-Onion-Solutions/TOoSmOotH-patch-1
2022-11-29 23:42:15 -05:00
Mike Reeves
571ac4edec
Update soup
2022-11-29 18:36:47 -05:00
weslambert
86cfac4983
Merge pull request #9241 from Security-Onion-Solutions/fix/ics_pipelines_field_renames
...
ICS Pipelines - Various Field Renames
2022-11-29 17:23:34 -05:00
Wes
e00a80feb4
Use native link_id naming scheme for now
2022-11-29 22:05:37 +00:00
Wes
e8e39a7105
Various field renames
2022-11-29 21:32:05 +00:00
Wes
13ea44db95
Use native 'is_orig' since we are already using that field name for other logs
2022-11-29 21:21:41 +00:00
weslambert
7f4f1397e7
Merge pull request #9240 from Security-Onion-Solutions/fix/add_s7comm_upload_download_ingest_pipeline
...
Add Zeek s7comm upload download ingest pipeline
2022-11-29 15:00:26 -05:00
Wes
5db3e22363
Add s7comm_upload_download references in various places
2022-11-29 19:58:18 +00:00
Wes
6fe2857ba5
Add Zeek s7comm_upload_download ingest pipeline
2022-11-29 19:45:56 +00:00
weslambert
56b0bae089
Merge pull request #9238 from Security-Onion-Solutions/fix/opcua_encoding_mask_format
...
Fix OP CUA Encoding Mask Format and Ensure Connection State Is Populated Before Assessing Its Value
2022-11-29 14:16:03 -05:00
weslambert
f947e501cb
Add space per request
2022-11-29 14:14:37 -05:00
weslambert
ff8bbc399f
Add space per request
2022-11-29 14:14:08 -05:00
weslambert
80226a27cc
Add space per request
2022-11-29 14:13:41 -05:00
weslambert
266207cc18
Add space per request
2022-11-29 14:12:52 -05:00
weslambert
5255c120c5
Add space per request
2022-11-29 14:11:20 -05:00
Wes
d44f8e495b
Check if connection.state is populated before trying to assess its value
2022-11-29 19:00:47 +00:00
Wes
13a8cbdabb
Add convert processor for opcua.encoding_mask
2022-11-29 18:59:30 +00:00
Doug Burks
c3c505f8ff
Merge pull request #9237 from Security-Onion-Solutions/dougburks-patch-1
...
add ICS COTP dashboard to dashboards.queries.json
2022-11-29 13:40:24 -05:00
Doug Burks
7ea0aa87e4
add ICS COTP dashboard to dashboards.queries.json
2022-11-29 13:38:19 -05:00
weslambert
82317656b1
Merge pull request #9235 from Security-Onion-Solutions/fix/mobus_read_write_multiple_registers_pipeline_failure_resolution
...
Change 'write' to 'read' to correct name and avoid pipeline failure
2022-11-29 12:56:05 -05:00
weslambert
1cc5961c07
Change 'write' to 'read' to correct name and avoid pipeline failure
2022-11-29 12:54:55 -05:00
weslambert
220e998b45
Merge pull request #9234 from Security-Onion-Solutions/fix/add_dnp3_control_ingest_pipeline
...
Add 'zeek.dnp3_control' ingest pipeline
2022-11-29 12:29:44 -05:00
Wes
16cd1080be
Add dnp3_control reference in various places
2022-11-29 17:23:37 +00:00
Wes
5db643e53b
Add Zeek dnp3_control ingest pipeline
2022-11-29 17:18:24 +00:00
weslambert
745cdef538
Merge pull request #9232 from Security-Onion-Solutions/fix/filebeat_ics_tag_bsap
...
Add 'ics' tag for 'bsap'-prefixed events/logs
2022-11-29 11:37:18 -05:00
weslambert
aa767b8dc1
Add 'ics' tag for 'bsap'-prefixed events/logs
2022-11-29 11:27:41 -05:00
Doug Burks
45cdd16308
Merge pull request #9228 from Security-Onion-Solutions/fix/zeek-ics-eventfields
...
More Zeek ICS changes
2022-11-29 09:18:40 -05:00
doug
1bb76bb251
update zeek s7comm parsers
2022-11-29 07:50:21 -05:00
doug
4251331bd4
update zeek tds parsers and dashboard
2022-11-29 07:43:20 -05:00
doug
124d56f4b9
update zeek cip parsers
2022-11-29 07:36:30 -05:00
doug
02821b97ad
update bacnet parsers
2022-11-29 07:26:11 -05:00
doug
9a50832669
fix more typos
2022-11-29 07:16:30 -05:00
doug
cffbe757a6
fix bsap typos
2022-11-29 06:56:51 -05:00
Doug Burks
14ff5670f7
add bsap entries to hunt.eventfields.json
2022-11-29 06:48:20 -05:00
Doug Burks
92e238aa10
Merge pull request #9227 from Security-Onion-Solutions/fix/zeek-ics-parsers
...
Fix Zeek ICS parsers and add dashboards
2022-11-28 15:58:24 -05:00
doug
8462e66873
fix opcua_binary_browse_description
2022-11-28 13:50:24 -05:00
Doug Burks
2763b5846c
improve dashboard descriptions
2022-11-28 13:10:23 -05:00
Doug Burks
dd4c34397d
improve dashboard descriptions
2022-11-28 13:03:54 -05:00
Doug Burks
a796fa2ff7
make sure that ICS dashboards with sankey also have separate event.dataset table
2022-11-28 12:09:57 -05:00
Doug Burks
268253ce14
update ENIP dashboard
2022-11-28 12:05:35 -05:00
Doug Burks
6a2f886fcc
improve ecat dashboard
2022-11-28 12:01:35 -05:00
Doug Burks
63915b0486
consolidate DNP3 dashboards
2022-11-28 11:58:48 -05:00
Doug Burks
ce7b16a230
more ICS dashboards
2022-11-28 10:06:58 -05:00
Doug Burks
a4f5e7b2a6
add ECAT dashboard
2022-11-28 10:05:15 -05:00
Doug Burks
cfbbc3a1a3
add S7 dashboard
2022-11-28 10:02:33 -05:00
Doug Burks
11a7f051a6
organize dashboards
2022-11-28 09:57:54 -05:00
Doug Burks
cb06269b1a
update DNP3 and MODBUS dashboards
2022-11-28 09:40:42 -05:00
Mike Reeves
d026414bcf
Merge pull request #9226 from Security-Onion-Solutions/bgfix
...
Remove BG for filecheck
2022-11-28 09:12:45 -05:00
Mike Reeves
e15ca408e7
Remove BG for filecheck
2022-11-28 09:11:41 -05:00
Mike Reeves
0e2753393b
Remove BG for filecheck
2022-11-28 09:09:25 -05:00
Doug Burks
b06e9e8477
add new zeek opcua logs to so-zeek-logs
2022-11-26 18:44:28 -05:00
Doug Burks
45892400cb
add new zeek opcua logs to so-whiptail
2022-11-26 18:42:51 -05:00
Doug Burks
1f0c984b98
add new zeek opcua logs to so-functions
2022-11-26 18:41:12 -05:00
doug
6d814d3909
add more zeek opcua parsers
2022-11-26 17:43:58 -05:00
Doug Burks
9ea59355d5
fix opcua_binary_opensecure_channel in so-functions
2022-11-26 17:03:57 -05:00
Doug Burks
c1287a61af
add opcua_binary_opensecure_channel to so-functions
2022-11-26 17:02:04 -05:00
Doug Burks
e44c94c56b
add opcua_binary_opensecure_channel to so-whiptail
2022-11-26 17:01:11 -05:00
Doug Burks
ec0cf71c3f
add opcua_binary_opensecure_channel to so-zeek-logs
2022-11-26 17:00:32 -05:00
doug
73adc571de
add more zeek ics parsers
2022-11-26 10:36:49 -05:00
doug
62c1bb2c0c
disable ecat_arp_info since it records all arp traffic
2022-11-25 18:01:53 -05:00
Doug Burks
692ec05b2d
fix opcua_binary_activate_session in hunt.eventfields.json
2022-11-25 17:51:25 -05:00
Doug Burks
00078fd9e5
add opcua_binary_activate_session_diagnostic_info to hunt.eventfields.json
2022-11-25 17:47:41 -05:00
Doug Burks
13c8fb0004
add ecat_coe_info to hunt.eventfields.json
2022-11-25 17:45:28 -05:00
Doug Burks
920b16e494
add ecat_dev_info to hunt.eventfields.json
2022-11-25 17:42:59 -05:00
Doug Burks
d98c57510a
add opcua_binary_activate_session_locale_id to hunt.eventfields.json
2022-11-25 17:39:17 -05:00
Doug Burks
58aa730437
add opcua_binary_create_session_endpoints to hunt.eventfields.json
2022-11-25 17:37:10 -05:00
Doug Burks
f36da68009
add opcua_binary_create_subscription to hunt.eventfields.json
2022-11-25 17:35:02 -05:00
Doug Burks
0091675ab6
fix opcua_binary_get_endpoints_description in hunt.eventfields.json
2022-11-25 17:32:30 -05:00
Doug Burks
83d25a97d3
add opcua_binary_get_endpoints_description to hunt.eventfields.json
2022-11-25 16:01:40 -05:00
Doug Burks
e536568c8a
add opcua_binary_activate_session to hunt.eventfields.json
2022-11-25 15:59:17 -05:00
Doug Burks
a00eb9071f
add opcua_binary_get_endpoints to hunt.eventfields.json
2022-11-25 15:57:35 -05:00
Doug Burks
c39cd9a290
add opcua_binary_browse_result to hunt.eventfields.json
2022-11-25 15:55:59 -05:00
Doug Burks
cb5483d401
add opcua_binary_create_session to hunt.eventfields.json
2022-11-25 15:53:09 -05:00
Doug Burks
fab0d17314
add opcua_binary_browse_description to hunt.eventfields.json
2022-11-25 15:51:49 -05:00
Doug Burks
465e6c4605
add opcua_binary_create_session_user_token to hunt.eventfields.json
2022-11-25 15:48:11 -05:00
Doug Burks
a119d6a842
add opcua_binary_get_endpoints_user_token to hunt.eventfields.json
2022-11-25 15:46:35 -05:00
Doug Burks
be8ce43b74
add opcua_binary_browse to hunt.eventfields.json
2022-11-25 15:44:22 -05:00
Doug Burks
b2a33d4800
add opcua_binary_browse_response_references to hunt.eventfields.json
2022-11-25 15:41:48 -05:00
Doug Burks
78fac49e66
add opcua_binary_read to hunt.eventfields.json
2022-11-25 15:39:58 -05:00
Doug Burks
ca08989404
add cip_io to hunt.eventfields.json
2022-11-25 15:37:21 -05:00
Doug Burks
4ed757916e
add opcua_binary_status_code_detail to hunt.eventfields.json
2022-11-25 15:35:17 -05:00
Doug Burks
676c543178
add opcua_binary to hunt.eventfields.json
2022-11-25 15:33:13 -05:00
Doug Burks
aa2eab5738
fix zeek ics logs in so-functions
2022-11-25 09:53:11 -05:00
Doug Burks
fe21b8bc17
fix zeek ics logs in so-functions
2022-11-25 09:45:18 -05:00
Doug Burks
33a478ff59
fix zeek ics logs in so-zeek-logs
2022-11-25 09:40:48 -05:00
Doug Burks
62fee1f420
fix zeek ics logs in so-whiptail
2022-11-25 09:39:58 -05:00
Doug Burks
2ada4712bc
fix zeek ics logs in so-zeek-logs
2022-11-25 09:37:52 -05:00
Doug Burks
fad6c46e7c
fix zeek ics logs in so-zeek-logs
2022-11-25 09:35:00 -05:00
Doug Burks
6f27c1b21e
fix zeek logs in so-whiptail
2022-11-25 09:26:54 -05:00
Doug Burks
0afb20ffa8
fix ics entries in so-functions
2022-11-25 09:19:11 -05:00
Doug Burks
40688a6076
add Zeek software to so-functions
2022-11-25 07:36:41 -05:00
Doug Burks
9431bf1c2a
add Zeek software log to so-whiptail
2022-11-25 07:28:48 -05:00
Doug Burks
9f5e75b302
add software to so-zeek-logs
2022-11-25 07:27:50 -05:00
Doug Burks
3f62cddc3b
change . to _
2022-11-23 12:21:12 -05:00
Doug Burks
085420997c
move status_code before status_code.link_id
2022-11-23 12:11:04 -05:00
Doug Burks
723e145eeb
Merge pull request #9221 from Security-Onion-Solutions/dougburks-patch-1
...
fix descriptions
2022-11-23 11:43:12 -05:00
Doug Burks
0a1d0d35c8
fix description
2022-11-23 11:33:31 -05:00
Doug Burks
9ee96f2280
fix description
2022-11-23 11:32:09 -05:00
Doug Burks
3871268c19
Merge pull request #9220 from Security-Onion-Solutions/fix/zeek-opcua-parsing
...
fix zeek opcua pipelines
2022-11-23 11:17:47 -05:00
doug
bc620b7def
fix zeek opcua pipelines
2022-11-23 10:56:32 -05:00
Josh Brower
5950771003
Merge remote-tracking branch 'remotes/origin/dev' into idhskins
2022-11-22 18:04:38 -05:00
Josh Brower
7c8ce7899b
Initial support for custom IDH http skins
2022-11-22 17:57:51 -05:00
Doug Burks
08d5f494ab
Merge pull request #9208 from Security-Onion-Solutions/dougburks-patch-1
...
Initial dashboards for stun, tds, wireguard, and ics
2022-11-22 16:04:12 -05:00
weslambert
13827f3be5
Merge pull request #9209 from Security-Onion-Solutions/fix/add_missing_opcua_activate_session_pipelines
...
Add Missing OPCUA Activate Session Pipelines
2022-11-22 16:01:33 -05:00
weslambert
3a64362887
Remove extra space used during testing
2022-11-22 15:47:16 -05:00
Wes
e77a60bcbf
Add missing OPCUA 'activate_session' pipelines
2022-11-22 20:44:48 +00:00
weslambert
e560edf493
Merge pull request #9206 from Security-Onion-Solutions/fix/ingest_typos
...
Fix spelling of 'wireguard.responses' field name
2022-11-22 15:35:55 -05:00
Doug Burks
7caf827b77
add ecat_aoe_info to hunt.eventfields.json
2022-11-22 13:33:06 -05:00
Doug Burks
f40ccb7eff
add bacnet_discovery to hunt.eventfields.json
2022-11-22 13:27:26 -05:00
Doug Burks
e0cd550820
update ecat_arp_info in hunt.eventfields.json
2022-11-22 13:23:45 -05:00
Doug Burks
4e5106c863
update ecat_arp_info in hunt.eventfields.json
2022-11-22 13:21:33 -05:00
Doug Burks
5a107c63b8
add source.mac and destination.mac to dashboards.queries.json
2022-11-22 13:16:47 -05:00
Doug Burks
8a9a13865c
add ecat_registers to hunt.eventfields.json
2022-11-22 13:12:24 -05:00
Doug Burks
9cd6273beb
update ecat_log_address in hunt.eventfields.json
2022-11-22 13:10:46 -05:00
Doug Burks
724b26228c
add ecat_log_address to hunt.eventfields.json
2022-11-22 13:09:27 -05:00
weslambert
3c054fd133
Fix spelling of 'wireguard.responses' field name
2022-11-22 13:02:43 -05:00
Doug Burks
24ee38369f
add cotp to hunt.eventfields.json
2022-11-22 12:49:33 -05:00
weslambert
0bbe642d20
Merge pull request #9203 from Security-Onion-Solutions/fix/ics_ingest_field_names
...
Fix ICS Ingest Field Names
2022-11-22 12:30:10 -05:00
weslambert
8e17c23659
Fix format/speliing for 'enip.status_code' field name
2022-11-22 12:05:03 -05:00
weslambert
92170941f0
Fix spelling for 'stun.class' field name
2022-11-22 12:04:07 -05:00
Doug Burks
10ac789fbf
add profinet_dce_rpc to hunt.eventfields.json
2022-11-22 11:08:24 -05:00
Doug Burks
db58a35562
add profinet to hunt.eventfields.json
2022-11-22 11:07:03 -05:00
Doug Burks
1ad7a0db59
add bacnet_property to hunt.eventfields.json
2022-11-22 11:05:26 -05:00
Doug Burks
af626fe3a1
add bacnet to hunt.eventfields.json
2022-11-22 11:03:45 -05:00
Doug Burks
073f5ed789
add dnp3_objects to hunt.eventfields.json
2022-11-22 11:02:21 -05:00
Doug Burks
bbcefea417
add s7comm_plus to hunt.eventfields.json
2022-11-22 10:58:42 -05:00
Doug Burks
73c282595d
update dnp3 in hunt.eventfields.json
2022-11-22 10:57:06 -05:00
Doug Burks
07a53db09a
add cip_identity to hunt.evenfields.json
2022-11-22 10:55:39 -05:00
Doug Burks
80e50fa7b4
add ecat_arp_info to hunt.eventfields.json
2022-11-22 10:53:48 -05:00
Doug Burks
84d333e915
add s7comm to hunt.eventfields.json
2022-11-22 10:51:06 -05:00
Doug Burks
ae582caa55
Add modbus_detailed to hunt.eventfields.json
2022-11-22 10:48:33 -05:00
Doug Burks
264ae2b9ac
add enip to hunt.eventfields.json
2022-11-22 10:45:20 -05:00
Doug Burks
b522c9eea4
reorder fields in hunt.eventfields.json
2022-11-22 10:43:01 -05:00
Doug Burks
51cc047933
add cip to hunt.eventfields.json
2022-11-22 10:40:22 -05:00
Doug Burks
2a805ac1a6
Add tds entries to hunt.eventfields.json
2022-11-22 10:29:55 -05:00
Doug Burks
595f615ed9
Add ICS dashboard
2022-11-22 10:22:55 -05:00
Doug Burks
aa7c39d312
Add dashboards for stun, tds, and wireguard
2022-11-22 10:08:39 -05:00
weslambert
2170d498c5
Merge pull request #9195 from Security-Onion-Solutions/fix/missing_ics_pipelines
...
Add COTP and TDS ingest pipelines
2022-11-22 08:44:02 -05:00
Wes
95a6f9aa7d
Add COTP and TDS ingest pipelines
2022-11-22 13:35:19 +00:00
weslambert
ba65b351a2
Merge pull request #9193 from Security-Onion-Solutions/fix/ics_tag_syntax_error
...
Fix syntax error for 'ics' tag logic
2022-11-22 07:32:40 -05:00
weslambert
4c09c8856b
Fix syntax error for 'ics' tag logic
2022-11-22 07:23:56 -05:00
weslambert
3afa8bd9da
Merge pull request #9188 from Security-Onion-Solutions/feature/filebeat_config_ics_event_tag
...
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 17:06:25 -05:00
weslambert
72eccd2649
Fix indentation
2022-11-21 17:01:16 -05:00
weslambert
310ea633b6
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 16:43:43 -05:00
Doug Burks
31b4d9cd70
Merge pull request #9187 from Security-Onion-Solutions/dougburks-patch-1
...
Remove descriptions from so-zeek-logs and so-whiptail
2022-11-21 14:13:04 -05:00
Doug Burks
0536d174fe
Fix opcua_binary reference in so-zeek-logs
2022-11-21 14:03:22 -05:00
Doug Burks
96d7429a1c
Remove descriptions from so-whiptail
2022-11-21 13:32:51 -05:00
Doug Burks
a54bb2bad4
Remove descriptions from so-zeek-logs
2022-11-21 13:23:53 -05:00
Doug Burks
d4abbd89ca
Merge pull request #9185 from Security-Onion-Solutions/dougburks-patch-1
...
Update so-functions to enable ICS/SCADA for EVAL and IMPORT
2022-11-21 12:33:06 -05:00
Peter Di Giorgio
bdfab6858d
Merge pull request #9184 from Security-Onion-Solutions/foxtrot
...
Shorten Zeek Log Descriptions for formatting
2022-11-21 11:20:15 -06:00
lock-wire
f80c8b89e4
Shorten Log Descriptions
2022-11-21 09:49:31 -07:00
Peter Di Giorgio
29384d33e1
Merge pull request #9183 from Security-Onion-Solutions/dev
...
Synch Foxtrot from dev
2022-11-21 10:06:44 -06:00
Doug Burks
aebedf9ac6
Update so-functions to enable ICS/SCADA for EVAL and IMPORT
2022-11-21 10:05:18 -05:00
Doug Burks
40ee529c7e
Merge pull request #9178 from Security-Onion-Solutions/dougburks-patch-1
...
Simplify version in README.md to just 2.3
2022-11-21 08:46:22 -05:00
Doug Burks
b9ee2f1e38
Simplify version in README.md to just 2.3
2022-11-21 08:38:27 -05:00
weslambert
089b403a3b
Merge pull request #9166 from Security-Onion-Solutions/foxtrot
...
Merge final protocol analyzers into dev
2022-11-18 08:41:43 -05:00
Peter Di Giorgio
a28e5de5f4
Correct trailing \
2022-11-18 06:29:57 -06:00
Peter Di Giorgio
2e30cefd91
Add remaining protocol parsers
...
- icsnpp-bsap
- icsnpp-s7comm
- zeek-plugin-tds
- zeek-plugin-profinet
- zeek-spicy-wireguard
- zeek-spicy-stun
2022-11-17 10:47:00 -06:00
Peter Di Giorgio
33bf0c6902
Merge pull request #9163 from Security-Onion-Solutions/dev
...
Update Foxtrot from Dev
2022-11-17 10:44:24 -06:00
Peter Di Giorgio
13b6b43324
Update init.sls
2022-11-17 10:42:21 -06:00
weslambert
78bc2a95e5
Add icsnpp-bsap to enabled plugins
2022-11-17 11:20:24 -05:00
weslambert
5bb0e6e8c0
Merge pull request #9160 from Security-Onion-Solutions/feature/additional_ics_scada_ingest_node_pipelines
...
Add additional ICS/SCADA ingest node pipelines
2022-11-17 11:18:15 -05:00
Wes
a278194037
Add additional ICS/SCADA ingest node pipelines
2022-11-17 16:16:33 +00:00
lock-wire
1b8e546045
Add s7comm,tds,stun,profinet,wireguard
2022-11-16 21:41:02 -06:00
weslambert
7319cb07e2
Merge pull request #9153 from Security-Onion-Solutions/fix/ics_scada_ingest_pipeline_updates_2_3
...
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 16:17:08 -05:00
Wes
35e131b888
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 21:09:30 +00:00
Jason Ertel
fd34eb3c26
Merge pull request #9150 from Security-Onion-Solutions/kilo
...
Increase retry count and pause to allow more time for Ubuntu updates
2022-11-16 07:53:04 -05:00
Jason Ertel
02b00d2c87
Increase retry count and pause to allow more time for Ubuntu updates
2022-11-16 07:50:08 -05:00
Mike Reeves
b0e08ed749
Merge pull request #9066 from security-companion/analyzers-patch1
...
fix descriptions in files related to analyzers
2022-11-12 11:32:09 -05:00
Mike Reeves
ec3a688e66
Merge pull request #9128 from Security-Onion-Solutions/dougburks-patch-1
...
Add trailing backslash to bacnet_property in so-functions
2022-11-12 10:33:00 -05:00
Doug Burks
4400c77f7e
Add trailing backslash to bacnet_property in so-functions
2022-11-12 09:13:20 -05:00
Peter Di Giorgio
d890f75cca
Correct typo
2022-11-11 13:59:20 -08:00
Doug Burks
91b6087350
Merge pull request #9126 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in zeek init.sls icsnpp-opcua-binary
2022-11-11 21:50:36 +00:00
Doug Burks
edcbcec10a
fix typo in zeek init.sls icsnpp-opcua-binary
2022-11-11 16:49:12 -05:00
Doug Burks
18ab90288a
Merge pull request #9124 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 21:33:52 +00:00
Doug Burks
9bf1c1e869
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 16:27:11 -05:00
Peter Di Giorgio
1e96a0b6a6
Merge pull request #9122 from Security-Onion-Solutions/foxtrot
...
Merge new protocol analyzers into dev
2022-11-11 12:53:57 -08:00
lock-wire
8dc08f66fd
Merge branch 'foxtrot' of https://github.com/Security-Onion-Solutions/securityonion into foxtrot
...
merge remote
2022-11-11 12:18:02 -08:00
lock-wire
73b1e5949b
Add ecat, enip, cip, and opcua
2022-11-11 12:15:54 -08:00
Doug Burks
2d6a4d7c28
Merge pull request #9098 from Security-Onion-Solutions/feature/local-docs
...
FEATURE: Improve local copy of docs in SOC #9097
2022-11-11 16:21:54 +00:00
Peter Di Giorgio
ae389ee487
Merge pull request #9121 from Security-Onion-Solutions/dev
...
Update foxtrot from dev
2022-11-11 07:25:26 -08:00
lock-wire
85d30520ce
Add BSAP protocol
2022-11-11 07:22:55 -08:00
Jason Ertel
934ce9ba64
Merge pull request #9114 from Security-Onion-Solutions/kilo
...
merge master to dev
2022-11-10 16:50:33 -05:00
Jason Ertel
595a95fdf5
merge conflicts
2022-11-10 16:47:52 -05:00
Mike Reeves
fc649a565c
Merge pull request #9107 from Security-Onion-Solutions/patch/2.3.182
...
Patch/2.3.182
2022-11-10 16:30:17 -05:00
Mike Reeves
113b38056b
2.3.182
2022-11-10 15:12:47 -05:00
Mike Reeves
559276534d
2.3.182
2022-11-10 15:06:00 -05:00
Mike Reeves
4acd9f8816
Update soup
2022-11-09 10:10:52 -05:00
security-companion
7ee4eb6101
fix descriptions in files related to analyzers
2022-11-08 22:32:28 +01:00
doug
84b2fc9c17
FEATURE: Improve local copy of docs in SOC #9097
2022-11-08 16:26:09 -05:00
Mike Reeves
a7417a7242
Update soup
2022-11-08 14:48:48 -05:00
Mike Reeves
d18ff69ec9
Update VERSION
2022-11-08 14:45:53 -05:00
Peter Di Giorgio
5532577fdd
Merge pull request #9071 from Security-Onion-Solutions/dev
...
Merge Dev into Foxtrot
2022-11-04 08:01:29 -07:00
Peter Di Giorgio
5ebf470a86
Update zeek.bacnet_discovery
2022-11-03 22:27:04 -07:00
Peter Di Giorgio
4b39ccec6d
Update zeek.bacnet_property
2022-11-03 15:30:20 -07:00
Mike Reeves
18cd7a83c6
Merge pull request #9059 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update init.sls
2022-11-02 13:01:38 -04:00
Mike Reeves
c5bfe6ffdb
Update init.sls
2022-11-02 12:59:46 -04:00
Mike Reeves
4ac365e670
Update init.sls
2022-11-02 12:59:17 -04:00
Mike Reeves
ff1a903895
Update init.sls
2022-11-02 12:58:31 -04:00
Doug Burks
65f8b1ebe3
Merge pull request #9057 from Security-Onion-Solutions/dougburks-patch-1
...
Create README.txt in setup/automation/
2022-11-02 14:24:29 +00:00
Jason Ertel
c23e8e5a7b
Update README.txt
2022-11-02 10:23:19 -04:00
Doug Burks
aa4a9a093f
Create README.txt
2022-11-02 10:20:57 -04:00
Mike Reeves
0af813d7fe
Merge pull request #9056 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2022-11-02 10:17:43 -04:00
Mike Reeves
388486ec08
Update init.sls
2022-11-02 10:06:13 -04:00
Mike Reeves
b1b0a7df30
Merge pull request #9044 from Security-Onion-Solutions/watchdogfix
...
watchdog fix
2022-11-01 13:24:05 -04:00
Mike Reeves
f74aee6a03
Update init.sls
2022-11-01 13:21:12 -04:00
Mike Reeves
4c6e66428c
Merge pull request #9037 from Security-Onion-Solutions/soup190
...
Add soup and perms updates
2022-11-01 09:13:26 -04:00
Mike Reeves
16d8e9e5a0
Fix soup and perms updates
2022-11-01 09:05:26 -04:00
Mike Reeves
ee1f55361e
Add soup and perms updates
2022-10-31 16:33:38 -04:00
Mike Reeves
cb33464668
Merge pull request #9033 from Security-Onion-Solutions/strelkafix
...
Add Filechecks
2022-10-31 15:49:40 -04:00
Mike Reeves
06ddae13b5
Update filecheck
2022-10-31 15:41:57 -04:00
Mike Reeves
16d3dead04
Update sensor-rotate.conf
2022-10-31 15:33:10 -04:00
Mike Reeves
f7043f3f62
Update init.sls
2022-10-31 15:25:38 -04:00
Mike Reeves
bf41f2984a
Update init.sls
2022-10-31 14:58:55 -04:00
Mike Reeves
86ca3602f3
Update init.sls
2022-10-31 14:44:01 -04:00
Mike Reeves
416c28fded
Update init.sls
2022-10-31 14:42:23 -04:00
Mike Reeves
297373877a
Update init.sls
2022-10-31 14:36:40 -04:00
Mike Reeves
db9b93a96c
Update init.sls
2022-10-31 14:35:02 -04:00
Mike Reeves
5635375d8d
Update init.sls
2022-10-31 14:30:11 -04:00
Mike Reeves
07e72e4013
Update filecheck
2022-10-31 13:47:49 -04:00
Mike Reeves
518d2aaa9c
Update filecheck.yaml
2022-10-31 13:45:00 -04:00
Mike Reeves
e93e2995b7
Update filecheck
2022-10-31 13:42:18 -04:00
Mike Reeves
d2eb61a830
Update filecheck.yaml
2022-10-31 13:41:45 -04:00
Mike Reeves
4c5a2c0610
Update filecheck
2022-10-31 13:36:42 -04:00
Mike Reeves
e9e7362005
Add Filechecks
2022-10-31 12:57:08 -04:00
Peter Di Giorgio
b97c822800
Add zeek.bacnet_discovery and zeek.bacnet_property
2022-10-27 15:40:52 -07:00
Peter Di Giorgio
71e3b2d1fb
Create zeek.bacnet
2022-10-27 15:40:07 -07:00
Peter Di Giorgio
326ba710ce
Add logs for bacnet
...
bacnet
bacnet_discovery
bacnet_property
2022-10-27 15:38:32 -07:00
Peter Di Giorgio
1ea6feca37
Add icsnpp-bacnet
2022-10-27 15:31:38 -07:00
Peter Di Giorgio
c524442172
Merge pull request #9008 from Security-Onion-Solutions/master
...
Synch Foxtrot with 2.3.181 Release
2022-10-26 13:10:01 -07:00
weslambert
8e4d0db738
Merge pull request #9002 from Security-Onion-Solutions/fix/remove_ja3er_references
...
Remove JA3er references
2022-10-26 10:21:54 -04:00
weslambert
a170c194c8
Remove JA3er references
2022-10-26 10:18:10 -04:00
Peter Di Giorgio
2b51d72585
Rename zeek.read_write_multiple_registers to zeek.modbus_read_write_multiple_registers
2022-10-25 17:20:01 -07:00
weslambert
0d71006f40
Merge pull request #8997 from Security-Onion-Solutions/fix/sensoroni_analyzers_pyyaml_wheel_name
...
Fix PyYAML .whl file name and remove JA3er analyzer
2022-10-25 14:57:35 -04:00
Wes
a91e3b601c
Remove JA3er since it is no longer a valid service
2022-10-25 18:48:37 +00:00
Wes
4940421297
Add PyYAML .whl files back since they were 'deleted' in the previous commit
2022-10-25 18:47:51 +00:00
Wes
58b4a8fbab
Change PyYAML .whl file name to comply with Joliet's 240-character limit
2022-10-25 18:47:02 +00:00
Mike Reeves
bd7e12f682
Merge pull request #8952 from Njinx/dev
...
FEATURE: so-pcap-export can run without needing to be attached to a TTY
2022-10-25 14:38:48 -04:00
Mike Reeves
64e43f07b9
Merge pull request #8993 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update VERSION
2022-10-25 14:36:45 -04:00
Mike Reeves
2d84e2e977
Update VERSION
2022-10-25 14:35:52 -04:00
Mike Reeves
465a1a82d7
Merge pull request #8981 from Security-Onion-Solutions/dev
...
2.3.181
2022-10-25 14:30:50 -04:00
Peter Di Giorgio
61d36d584f
Add Modbus, DNP3, BZAR, and oui-logging
2022-10-25 07:10:52 -07:00
Peter Di Giorgio
2d343110cc
Add DNP3 and Modbus extensions to zeeklogs.sls
2022-10-25 07:09:11 -07:00
Peter Di Giorgio
4502e2c260
Remove logs for OT parsers
2022-10-24 23:16:18 -07:00
Peter Di Giorgio
beb67847f9
Remove modbus,bzar,dnp3,oui-logging
2022-10-24 23:14:32 -07:00
Peter Di Giorgio
9cdc29c482
Fix Syntax for zeeklogs pillar
2022-10-24 14:30:15 -07:00
weslambert
292f66138b
Merge pull request #8983 from Security-Onion-Solutions/revert-8982-fix/sensoroni_analyzers_pyyaml_wheel_name
...
Revert "Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold"
2022-10-24 16:49:19 -04:00
weslambert
0087768946
Revert "Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold"
2022-10-24 16:47:30 -04:00
Peter Di Giorgio
01d177366d
Fix Zeek Pillar
2022-10-24 12:00:43 -07:00
weslambert
712340a027
Merge pull request #8982 from Security-Onion-Solutions/fix/sensoroni_analyzers_pyyaml_wheel_name
...
Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold
2022-10-24 14:14:45 -04:00
Wes
1caac3f0b0
Add PyYAML .whl files back since they were 'deleted' in the previous commit.
2022-10-24 18:06:19 +00:00
Wes
54a5dd6cbd
Change name of PyYAML .whl file to remain under Joliet's 240-character limit/threshold
2022-10-24 18:05:15 +00:00
Mike Reeves
6570177b0c
Merge pull request #8979 from Security-Onion-Solutions/2.3.181
...
2.3.181
2022-10-24 11:39:08 -04:00
Mike Reeves
f7ed992f24
2.3.181
2022-10-24 11:33:31 -04:00
Mike Reeves
4a18f8d18a
2.3.181
2022-10-24 11:32:19 -04:00
Peter Di Giorgio
24cf481f4a
Merge pull request #8973 from lock-wire/patch-3
...
Add Modbus, DNP3, BZAR, and oui-logging
2022-10-21 18:06:13 -07:00
Peter Di Giorgio
cd4e0c1f8e
Add DNP3 and Modbus extensions to zeeklogs.sls
...
Add DNP3 and Modbus extenstions to zeeklogs to ensure filebeat.yml is configured properly to ship lots. Need to move these behind the OT flag.
2022-10-21 14:19:21 -07:00
Peter Di Giorgio
4a60310dc8
Add Modbus, DNP3, BZAR, and oui-logging
...
This is an initial proof of concept. Need to migrate these entries behind a flag.
2022-10-21 14:04:40 -07:00
weslambert
930620fce6
Merge pull request #8971 from lock-wire/patch-2
...
Add Ingest pipeline for Modbus and DNP3 extensions
2022-10-21 16:28:52 -04:00
Peter Di Giorgio
7a60d0987c
Update zeek.conn to include client.oui
2022-10-21 13:02:01 -07:00
Peter Di Giorgio
9ac06057c1
Create zeek.read_write_multiple_registers
2022-10-21 13:00:12 -07:00
Peter Di Giorgio
e5c69c3236
Create zeek.modbus_mask_write_register
2022-10-21 12:58:36 -07:00
Peter Di Giorgio
39f050c6e4
Rename modbus_detailed to zeek.modbus_detailed
2022-10-21 12:56:59 -07:00
Peter Di Giorgio
4ee083759c
Rename dnp3_objects to zeek.dnp3_objects
2022-10-21 12:56:35 -07:00
Peter Di Giorgio
072bfd87b7
Create Ingest for Modbus Detailed
2022-10-21 12:53:30 -07:00
Peter Di Giorgio
b7aaaa80bb
Create Ingest for DNP3 Objects extension
2022-10-21 12:51:13 -07:00
Jason Ertel
b8884b6ac9
Merge pull request #8968 from Security-Onion-Solutions/181soup
...
update soup for 2.3.181
2022-10-21 12:00:58 -04:00
Jason Ertel
05e271af47
update soup for 2.3.181
2022-10-21 11:52:54 -04:00
Mike Reeves
58e80a9db8
Merge pull request #8964 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2022-10-21 10:45:44 -04:00
Mike Reeves
e16fc3605e
Update VERSION
2022-10-21 10:43:34 -04:00
Ben Allen
f13f05eb94
Run without needing to be attached to a TTY
2022-10-19 14:11:11 -04:00
weslambert
a54fc4cead
Merge pull request #8942 from Security-Onion-Solutions/master
...
Update Foxtrot to .180
2022-10-18 16:39:21 -04:00
Mike Reeves
2127ba90ee
Merge pull request #8925 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-10-17 10:51:02 -04:00
Mike Reeves
3373aef87d
Update VERSION
2022-10-17 10:50:14 -04:00
Mike Reeves
fa45e8ded7
Merge pull request #8924 from Security-Onion-Solutions/dev
...
2.3.180
2022-10-17 10:41:06 -04:00
Mike Reeves
6d0ead7b5b
Merge pull request #8923 from Security-Onion-Solutions/2.3.180
...
2.3.180
2022-10-17 09:47:06 -04:00
Mike Reeves
a2a6625f3b
2.3.180
2022-10-17 09:39:07 -04:00
Mike Reeves
3c2510acd7
Merge pull request #8920 from Security-Onion-Solutions/dev
...
Merge Dev into Foxtrot
2022-10-17 09:34:57 -04:00
Doug Burks
0d807d20f4
Merge pull request #8914 from Security-Onion-Solutions/dougburks-patch-1
...
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 13:03:51 +00:00
Doug Burks
f4042263a3
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 08:59:10 -04:00
Doug Burks
a930f8233d
Merge pull request #8899 from Security-Onion-Solutions/dougburks-patch-2
...
Update soup for 2.3.180
2022-10-11 17:14:55 +00:00
Doug Burks
7401008523
Update soup for 2.3.180
2022-10-11 12:58:37 -04:00
Doug Burks
5199ea483e
Merge pull request #8878 from Security-Onion-Solutions/feature/improve-sysmon-dashboards
...
FEATURE: Add new Sysmon dashboards #8870
2022-10-07 16:47:02 +00:00
doug
454a7a4799
FEATURE: Add new Sysmon dashboards #8870
2022-10-07 11:52:49 -04:00
Doug Burks
6fb7733d8c
Merge pull request #8875 from Security-Onion-Solutions/dougburks-patch-1
...
Increment SO to 2.3.180 and Elastic to 8.4.3
2022-10-07 11:13:13 +00:00
Doug Burks
ab17cbee31
Update Elastic to 8.4.3
2022-10-07 07:03:10 -04:00
Doug Burks
9991f0cf95
update Elastic to 8.4.3
2022-10-07 07:02:24 -04:00
Doug Burks
44d46b06a2
increment version to 2.3.180
2022-10-07 06:58:07 -04:00
Mike Reeves
ba7231f07d
Merge pull request #8841 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update VERSION
2022-10-03 08:46:19 -04:00
Mike Reeves
8dc11ea23a
Update VERSION
2022-10-03 08:43:39 -04:00
Mike Reeves
116a6a0acd
Merge pull request #8806 from Security-Onion-Solutions/dev
...
2.3.170
2022-10-01 08:13:09 -04:00
Mike Reeves
311b69dc4a
Merge pull request #8805 from Security-Onion-Solutions/2.3.170
...
2.3.170
2022-09-23 15:34:49 -04:00
Mike Reeves
fd59acce5d
2.3.170
2022-09-23 15:26:14 -04:00
Mike Reeves
956d3e4345
Merge pull request #8793 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2022-09-22 09:22:20 -04:00
Mike Reeves
b8355b3a03
Update soup
2022-09-22 09:10:12 -04:00
bryant-treacle
535b9f86db
Merge pull request #8633 from Security-Onion-Solutions/bryant-sysmon
...
Fix issues: 8591-8953
2022-09-19 11:53:34 -04:00
Mike Reeves
97c66a5404
Merge pull request #8639 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
dev to 170
2022-08-31 08:23:48 -04:00
Josh Brower
6553beec99
Merge pull request #8644 from Security-Onion-Solutions/upgrade/elastic-8.4.1
...
Upgrade/elastic 8.4.1
2022-08-30 16:37:56 -04:00
Josh Brower
e171dd52b8
Upgrade Elastic to 8.4.1
2022-08-30 16:11:40 -04:00
Josh Brower
27a837369d
Upgrade Elastic to 8.4.1
2022-08-30 16:09:57 -04:00
Mike Reeves
043b9f78e2
Merge pull request #8638 from Security-Onion-Solutions/master
...
Merge pull request #8627 from Security-Onion-Solutions/dev
2022-08-30 14:42:18 -04:00
Mike Reeves
2f260a785f
Update README.md
2022-08-30 14:41:41 -04:00
Mike Reeves
001b2dc6cc
Update VERSION
2022-08-30 14:39:41 -04:00
Mike Reeves
b13eedfbc2
Merge pull request #8627 from Security-Onion-Solutions/dev
...
2.3.160
2022-08-30 14:33:36 -04:00
Mike Reeves
dd70ef17b9
Merge pull request #8636 from Security-Onion-Solutions/fixitup
...
Merge pull request #8571 from Security-Onion-Solutions/dev
2022-08-30 14:31:35 -04:00
bryant-treacle
82dff3e9da
Fix issues: 8591-8953
2022-08-30 13:48:53 +00:00
Mike Reeves
d9cfd92b8f
Merge pull request #8626 from Security-Onion-Solutions/2.3.160
...
2.3.160
2022-08-29 15:00:08 -04:00
Mike Reeves
33cb771780
2.3.160
2022-08-29 14:56:43 -04:00
Mike Reeves
76cca8594d
Merge pull request #8623 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update soup
2022-08-29 09:50:06 -04:00
weslambert
5c9c95ba1f
Merge pull request #8622 from Security-Onion-Solutions/fix/strelka_yara_gen_webshells_ignore
...
Ignore gen_webshells.yar
2022-08-29 09:40:51 -04:00
Mike Reeves
e62bebeafe
Update soup
2022-08-29 09:39:41 -04:00
weslambert
8a0e92cc6f
Add 'gen_webshells.yar' and re-arrange to put ignored rules in alphabetical order
2022-08-29 09:37:29 -04:00
Mike Reeves
3f9259dd0a
Merge pull request #8621 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soup
2022-08-29 09:34:29 -04:00
Mike Reeves
30b9868de1
Update soup
2022-08-29 09:32:46 -04:00
Doug Burks
e88243c306
Merge pull request #8602 from Security-Onion-Solutions/dougburks-patch-1
...
increment to 2.3.160
2022-08-26 08:06:22 -04:00
Doug Burks
2128550df2
increment to 2.3.160
2022-08-26 07:50:08 -04:00
Jason Ertel
db67c0ed94
Merge pull request #8577 from Security-Onion-Solutions/kilo
...
Increment version to 2.3.160
2022-08-23 07:14:05 -04:00
Jason Ertel
2e32c0d236
Increment version to 2.3.160
2022-08-23 07:00:14 -04:00
Mike Reeves
4b1ad1910d
Merge pull request #8571 from Security-Onion-Solutions/dev
...
2.3.150
2022-08-22 15:22:43 -04:00
Mike Reeves
c337145b2c
Merge pull request #8570 from Security-Onion-Solutions/2.3.150
...
2.3.150
2022-08-22 14:35:29 -04:00
Mike Reeves
bd7b4c92bc
2.3.150
2022-08-22 14:31:36 -04:00
Mike Reeves
33ebed3468
2.3.150
2022-08-22 14:31:04 -04:00
weslambert
616bc40412
Merge pull request #8558 from Security-Onion-Solutions/fix/soup_local_mods_check_skip_prompt
...
Allow local modification acceptance prompt to be skipped when passing 'skip-prompt' as a parameter value to check_local_mods() function
2022-08-19 16:11:23 -04:00
weslambert
f00d9074ff
Allow local modification acceptance prompt to be skipped when passing 'skip-prompt' as a parameter value to check_local_mods() function
2022-08-19 16:07:14 -04:00
Mike Reeves
9a692288e2
Merge pull request #8557 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update rulecat.conf
2022-08-19 13:14:32 -04:00
Mike Reeves
fea2b481e3
Update rulecat.conf
2022-08-19 13:12:49 -04:00
weslambert
c17f0081ef
Merge pull request #8550 from Security-Onion-Solutions/fix/soup_elastalert_indices_check_delete_if_less_than_es_8
...
SOUP: Ensure Elastalert indices are not deleted for major Elasticsearch version 8 or greater
2022-08-18 09:45:00 -04:00
weslambert
fbf0803906
Update verbiage around major Elasticsearch version and not requiring Elastalert index maintenance
2022-08-18 09:16:22 -04:00
weslambert
5deda45b66
Update elastalert_indices_check() function to only delete Elastalert indices if major Elasticsearch version is less than 8
...
Update elastalert_indices_check() function to only delete Elastalert indices if major Elasticsearch version is less than 8. Also clean up the output to only emit one notification regarding index deletion, and additional verbiage around function operation.
2022-08-18 09:11:38 -04:00
Josh Patterson
3b8d8163b3
Merge pull request #8544 from Security-Onion-Solutions/issue/8369
...
remove pipeline time panel
2022-08-17 09:56:01 -04:00
m0duspwnens
2dfd41bd3c
remove pipeline time panel - https://github.com/Security-Onion-Solutions/securityonion/issues/8369
2022-08-17 09:17:27 -04:00
Mike Reeves
49eead1d55
Merge pull request #8543 from Security-Onion-Solutions/kilo
...
Merge master into dev
2022-08-17 09:03:49 -04:00
Jason Ertel
54cb3c3a5a
Merge branch 'master' into kilo
2022-08-17 08:58:32 -04:00
Mike Reeves
9f2b920454
Merge pull request #8535 from Security-Onion-Solutions/hotfix/2.3.140
...
Hotfix/2.3.140
2022-08-15 15:06:37 -04:00
Mike Reeves
604af45661
Merge pull request #8534 from Security-Onion-Solutions/2.3.140hotfix3
...
2.3.140 Hotfix
2022-08-15 13:09:14 -04:00
Mike Reeves
3f435c5c1a
2.3.140 Hotfix
2022-08-15 13:03:25 -04:00
Mike Reeves
7769af4541
Merge pull request #8531 from Security-Onion-Solutions/dougburks-patch-1
2022-08-12 15:05:04 -04:00
Mike Reeves
9903be8120
Merge pull request #8532 from Security-Onion-Solutions/2.3.140-20220815
2022-08-12 15:04:00 -04:00
Doug Burks
991a601a3d
FIX: so-curator-closed-delete-delete needs to reference new Elasticsearch directory #8529
2022-08-12 13:21:06 -04:00
Doug Burks
86519d43dc
Update HOTFIX
2022-08-12 13:20:15 -04:00
Doug Burks
179f669acf
FIX: so-curator-closed-delete-delete needs to reference new Elasticsearch directory #8529
2022-08-12 13:10:47 -04:00
Doug Burks
a02f878dcc
Merge pull request #8517 from Security-Onion-Solutions/fix/cases-tlp-2.0
...
Fix/cases tlp 2.0
2022-08-11 15:55:21 -04:00
Doug Burks
32c29b28eb
revert to lower case #8469
2022-08-11 15:33:30 -04:00
Doug Burks
7bf2603414
revert to lower case #8469
2022-08-11 15:32:49 -04:00
Doug Burks
4003876465
FIX: Fix TLP options in Cases to align with TLP 2.0 #8469
2022-08-11 08:49:54 -04:00
Doug Burks
4c677961c4
FIX: Fix TLP options in Cases to align with TLP 2.0 #8469
2022-08-11 08:49:25 -04:00
weslambert
e950d865d8
Merge pull request #8485 from Security-Onion-Solutions/foxtrot
...
Improve local file modification check in SOUP
2022-08-08 10:06:13 -04:00
weslambert
fd7a118664
Invoke check_local_mods() function earlier so we don't have to wait for Docker image downloads or OS updates before checking and potentially exiting SOUP
2022-08-08 08:58:19 -04:00
weslambert
d7906945df
Add extra set of brackets for comparison of integers
2022-08-08 08:24:38 -04:00
weslambert
cb384ae024
Ensure check_local_mods() runs at the beginning of SOUP, in addition to the end, and also that it prompts (forces) the user to accept/review local modifications.
2022-08-05 11:25:33 -04:00
weslambert
7caead2387
Merge pull request #8476 from Security-Onion-Solutions/dev
...
Merge dev into foxtrot
2022-08-05 11:11:51 -04:00
Josh Patterson
4827c9e0d4
Merge pull request #8475 from Security-Onion-Solutions/issue/8441
...
add SYSTEMD_UNIT_FILE back to map file
2022-08-05 10:55:44 -04:00
m0duspwnens
3b62fc63c9
add SYSTEMD_UNIT_FILE back to map file
2022-08-05 10:53:07 -04:00
Josh Patterson
ad32c2b1a5
Merge pull request #8472 from Security-Onion-Solutions/issue/8441
...
ensure ExecStartPre is removed from default salt-minion service file
2022-08-04 16:36:16 -04:00
m0duspwnens
f02f431dab
ensure ExecStartPre is removed from default salt-minion service file
2022-08-04 16:34:06 -04:00
Josh Patterson
812964e4d8
Merge pull request #8460 from Security-Onion-Solutions/issue/8441
...
ensure parent dirs are created
2022-08-03 17:01:50 -04:00
m0duspwnens
99805cc326
ensure parent dirs are created
2022-08-03 16:54:22 -04:00
Josh Patterson
8d2b3f3dfe
Merge pull request #8457 from Security-Onion-Solutions/issue/8441
...
fix the requisite
2022-08-03 15:17:44 -04:00
m0duspwnens
15f7fd8920
fix the requisite
2022-08-03 15:16:12 -04:00
Josh Patterson
50460bf91e
Merge pull request #8456 from Security-Onion-Solutions/issue/8441
...
manage salt-minion start delay with systemd drop-in file
2022-08-03 13:44:09 -04:00
weslambert
ee654f767a
Merge pull request #8453 from Security-Onion-Solutions/fix/elasticsearch_geoip_local
...
Configure Elasticsearch to use local GeoLite2 databases by default
2022-08-03 09:40:23 -04:00
weslambert
8c694a7ca3
Disable ingest.geoip.downloader by default
2022-08-03 09:21:40 -04:00
weslambert
9ac640fa67
Remove airgap-specific logic for ingest.geoip.downloader
2022-08-03 09:21:03 -04:00
m0duspwnens
db8d9fff2c
manage salt-minion start delay with systemd drop-in file - https://github.com/Security-Onion-Solutions/securityonion/issues/8441
2022-08-02 16:22:26 -04:00
weslambert
811063268f
Merge pull request #8447 from Security-Onion-Solutions/feature/kibana_version_8_3_3
...
Update Kibana version to 8.3.3
2022-08-02 15:27:22 -04:00
weslambert
f2b10a5a86
Update Kibana version to 8.3.3
2022-08-02 11:32:01 -04:00
weslambert
c69cac0e5f
Update Kibana version to 8.3.3
2022-08-02 11:31:35 -04:00
weslambert
fed4433088
Merge pull request #8446 from Security-Onion-Solutions/fix/airgap_elasticsearch_geoip
...
Update Elasticsearch defaults file and config.map.jinja to allow for local GeoIP database use when airgap is enabled
2022-08-02 11:20:35 -04:00
Wes Lambert
839cfcaefa
Update Elasticsearch defaults file and config.map.jinja to allow for local GeoIP database use when airgap is enabled
2022-08-02 14:32:17 +00:00
weslambert
3123407ef0
Update Elastic version to 8.3.3
2022-08-01 10:41:39 -04:00
weslambert
d24125c9e6
Update Elastic version to 8.3.3
2022-08-01 10:40:57 -04:00
weslambert
64dc278c95
Merge pull request #8432 from Security-Onion-Solutions/dev
...
Merge dev into foxtrot
2022-08-01 10:12:35 -04:00
Doug Burks
626a824cd6
Merge pull request #8409 from Security-Onion-Solutions/dougburks-patch-1
...
increment version
2022-07-29 16:31:32 -04:00
Doug Burks
10ba3b4b5a
increment version
2022-07-29 16:30:12 -04:00
Doug Burks
1d059fc96e
Merge pull request #8408 from Security-Onion-Solutions/fix/dashboards-pivot-pcap
...
FIX: Display PCAP menu action on Dashboards page #8343
2022-07-29 16:29:32 -04:00
Doug Burks
4c1585f8d8
FIX: Display PCAP menu action on Dashboards page #8343
2022-07-29 14:50:10 -04:00
Josh Patterson
e235957c00
Merge pull request #8405 from Security-Onion-Solutions/issue/8404
...
https://github.com/Security-Onion-Solutions/securityonion/issues/8404
2022-07-29 10:07:52 -04:00
m0duspwnens
2cc665bac6
https://github.com/Security-Onion-Solutions/securityonion/issues/8404
2022-07-29 09:55:20 -04:00
Jason Ertel
d6e118dcd3
Merge pull request #8403 from Security-Onion-Solutions/kilo
...
Increment version
2022-07-29 08:28:14 -04:00
Jason Ertel
1d2534b2a1
Increment version
2022-07-29 08:24:57 -04:00
Doug Burks
484aa7b207
Merge pull request #8336 from Security-Onion-Solutions/hotfix/2.3.140
...
Hotfix/2.3.140
2022-07-19 16:13:47 -04:00
Mike Reeves
6986448239
Merge pull request #8333 from Security-Onion-Solutions/2.3.140hotfix
...
2.3.140 Hotfix
2022-07-19 14:47:50 -04:00
Mike Reeves
f1d74dcd67
Merge pull request #8334 from Security-Onion-Solutions/2.3.140hotfix
...
2.3.140 Hotfix
2022-07-19 14:47:29 -04:00
Mike Reeves
dd48d66c1c
2.3.140 Hotfix
2022-07-19 14:39:44 -04:00
Mike Reeves
440f4e75c1
Merge pull request #8332 from Security-Onion-Solutions/dev
...
Merge Hotfix
2022-07-19 13:30:20 -04:00
weslambert
c795a70e9c
Merge pull request #8329 from Security-Onion-Solutions/fix/elastalert_stop_check_enabled
...
Check to ensure Elastalert is enabled and suppress missing container error output
2022-07-19 13:27:35 -04:00
weslambert
340dbe8547
Check to see if Elastalert is enabled before trying to run 'so-elastalert-stop'. Also suppress error output for when so-elastalert container is not present.
2022-07-19 13:25:09 -04:00
Mike Reeves
52a5e743e9
Merge pull request #8327 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-07-19 11:17:13 -04:00
Wes Lambert
5ceff52796
Move Elastalert indices check to function and call from beginning of soup and during pre-upgrade to 2.3.140
2022-07-19 14:54:39 +00:00
Wes Lambert
f3a0ab0b2d
Perform Elastalert index check twice
2022-07-19 14:48:19 +00:00
Wes Lambert
4a7c994b66
Revise Elastalert index check deletion logic
2022-07-19 14:31:45 +00:00
Mike Reeves
07b8785f3d
Update soup
2022-07-19 10:23:10 -04:00
Mike Reeves
9a1092ab01
Update HOTFIX
2022-07-19 10:21:36 -04:00
Mike Reeves
fbcbfaf7c3
Merge pull request #8310 from Security-Onion-Solutions/dev
...
2.3.140
2022-07-18 11:23:54 -04:00
Mike Reeves
497110d6cd
Merge pull request #8320 from Security-Onion-Solutions/2.3.140-2
...
2.3.140
2022-07-18 10:57:53 -04:00
Mike Reeves
3711eb52b8
2.3.140
2022-07-18 10:54:50 -04:00
weslambert
8099b1688b
Merge pull request #8319 from Security-Onion-Solutions/fix/elasticsearch_query_missing_query_path
...
Fix missing query path for so-elasticsearch-query
2022-07-18 09:47:16 -04:00
weslambert
2914007393
Add forward slash to fix issue with missing query path
2022-07-18 09:07:34 -04:00
weslambert
f5e10430ed
Add forward slash to fix issue with missing query path
2022-07-18 09:07:13 -04:00
Mike Reeves
b5a78d4577
Merge pull request #8309 from Security-Onion-Solutions/2.3.140
...
2.3.140
2022-07-15 13:36:31 -04:00
Mike Reeves
0a14dad849
Update VERIFY_ISO.md
2022-07-15 13:31:51 -04:00
Mike Reeves
3430df6a20
2.3.140
2022-07-15 13:26:25 -04:00
Mike Reeves
881915f871
Merge pull request #8306 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update defaults.yaml
2022-07-14 16:20:29 -04:00
Mike Reeves
cf8c6a6e94
Update defaults.yaml
2022-07-14 15:17:27 -04:00
weslambert
52ebbf8ff3
Merge pull request #8304 from Security-Onion-Solutions/fix/kibana_space_defaults_web_response_url
...
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:08:02 -04:00
weslambert
2443e8b97e
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:04:56 -04:00
weslambert
4241eb4b29
Merge pull request #8298 from Security-Onion-Solutions/fix/kibana_space_defaults_shebang
...
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:50:21 -04:00
weslambert
0fd4f34b5b
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:48:39 -04:00
Josh Patterson
37df49d4f3
Merge pull request #8296 from Security-Onion-Solutions/elastalert_esversion_check
...
use onlyif requisite instead
2022-07-13 15:22:40 -04:00
m0duspwnens
7d7cf42d9a
use onlyif requisite instead
2022-07-13 15:21:34 -04:00
Doug Burks
de0a7d3bcd
Merge pull request #8293 from Security-Onion-Solutions/dougburks-patch-1
...
change hyperlink for Elastic 8 issues
2022-07-13 12:41:50 -04:00
Doug Burks
c67a58a5b1
change hyperlink for Elastic 8 issues
2022-07-13 12:40:03 -04:00
Josh Patterson
e79ca4bb9b
Merge pull request #8291 from Security-Onion-Solutions/elastalert_esversion_check
...
do not start elastalert if elasticsearch is not v8
2022-07-13 11:24:12 -04:00
m0duspwnens
086cf3996d
do not start elastalert if elasticsearch is not v8
2022-07-13 11:21:27 -04:00
Doug Burks
7ae5d49a4a
Merge pull request #8290 from Security-Onion-Solutions/dougburks-patch-1
...
increment version to 2.3.140
2022-07-13 09:33:37 -04:00
Doug Burks
34d3c6a882
increment version to 2.3.140
2022-07-13 09:32:28 -04:00
weslambert
4a5664db7b
Merge pull request #8289 from Security-Onion-Solutions/fix/soup_unsupported_indices_check
...
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:15:22 -04:00
weslambert
513c7ae56c
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:13:28 -04:00
weslambert
fa894cf83b
Merge pull request #8288 from Security-Onion-Solutions/fix/soup_elastalert_indices_deletion_check
...
Ensure Elastalert indices are deleted before continuing with SOUP
2022-07-13 08:44:04 -04:00
weslambert
8e92060c29
Ensure Elastalert indices are deleted before continuing with SOUP -- if they are not, generate a failure condition
2022-07-13 08:38:55 -04:00
weslambert
d7eb8b9bcb
Merge pull request #8281 from Security-Onion-Solutions/fix/soup_elasticsearch8_index_compatibility
...
SOUP - Check for indices created by Elasticsearch 6
2022-07-12 16:20:47 -04:00
weslambert
d0a0ca8458
Update exit code for ES checks
2022-07-12 16:15:44 -04:00
Josh Patterson
57b79421d8
Merge pull request #8280 from Security-Onion-Solutions/fix_filebeat
...
move port bindings back under port bindings
2022-07-12 16:12:49 -04:00
weslambert
4502182b53
Typo - Ensure Elasticsearch version 6 indices are checked
2022-07-12 15:35:46 -04:00
weslambert
0fc6f7b022
Add check for Elasticsearch 6 indices
2022-07-12 15:34:24 -04:00
m0duspwnens
ec451c19f8
move port bindings back under port bindings
2022-07-12 15:17:25 -04:00
weslambert
e9a22d0aff
Merge pull request #8275 from Security-Onion-Solutions/fix/filebeat_es_output_additions
...
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
2022-07-11 19:03:07 -04:00
weslambert
11d3ed36b7
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
...
Add outputs for Elasticsearch and Kibana for Eval/Import Mode, since Logstash is not used in Eval Mode or Import Mode. Otherwise, logs from these inputs end up in a filebeat-prefixed index.
2022-07-11 17:22:09 -04:00
weslambert
d828bbfe47
Merge pull request #8273 from Security-Onion-Solutions/fix/kibana_space_defaults_cases
...
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:39:30 -04:00
weslambert
bd32394560
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:38:05 -04:00
weslambert
6f4f050a96
Merge pull request #8272 from Security-Onion-Solutions/fix/soup_kibana_space_defaults
...
Run so-kibana-space-defaults when upgrading to 2.3.140
2022-07-11 14:47:11 -04:00
weslambert
f77edaa5c9
Run so-kibana-space-defaults to re-establish the default enabled features since Fleet feature name changed
2022-07-11 14:41:23 -04:00
Jason Ertel
15124b6ad7
Merge pull request #8271 from Security-Onion-Solutions/kilo
...
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:47:28 -04:00
Jason Ertel
077053afbd
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:43:41 -04:00
weslambert
dd1d5b1a83
Merge pull request #8270 from Security-Onion-Solutions/fix/curator_actions_delete_kratos
...
Add delete and warm action for Kratos indices in applicable Curator delete/warm scripts
2022-07-11 11:39:43 -04:00
weslambert
e82b6fcdec
Typo - Change 'delete' to 'warm'
2022-07-11 11:34:53 -04:00
weslambert
8c8ac41b36
Add action for Kratos indices
2022-07-11 11:32:03 -04:00
weslambert
b611dda143
Add delete action for Kratos indices
2022-07-11 11:31:22 -04:00
weslambert
3f5b98d14d
Merge pull request #8269 from Security-Onion-Solutions/fix/curator_actions_kratos
...
Add Curator actions and adjust Curator close scripts to account for so-kibana and so-kratos indices
2022-07-11 11:21:20 -04:00
Wes Lambert
0b6219d95f
Adjust Curator close scripts to include Kibana and Kratos indices
2022-07-11 14:51:33 +00:00
Wes Lambert
2f729e24d9
Add Curator action files for Kratos indices
2022-07-11 14:34:10 +00:00
weslambert
992b6e14de
Merge pull request #8268 from Security-Onion-Solutions/fix/kibana_disable_fleetv2
...
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:09:12 -04:00
weslambert
09a1d8c549
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:06:24 -04:00
Jason Ertel
f28c6d590a
Merge pull request #8263 from Security-Onion-Solutions/kilo
...
Remove Jinja from yaml files before parsing
2022-07-08 20:32:22 -04:00
Jason Ertel
4f8bb6049b
Future proof the jinja check to ensure the script does not silently overwrite jinja templates
2022-07-08 17:30:00 -04:00
Jason Ertel
a8e6b26406
Remove Jinja from yaml files before parsing
2022-07-08 17:07:24 -04:00
weslambert
2903bdbc7e
Merge pull request #8260 from Security-Onion-Solutions/fix/kratos_dedicated_index_and_filestream_id_additions
...
Add dedicated index for Kratos and IDs for all filestream inputs
2022-07-08 12:04:40 -04:00
Wes Lambert
5c90fce3a1
Add Kratos Logstash output to search pipeline for Logstash
2022-07-08 15:58:00 +00:00
Wes Lambert
26698cfd07
Add Logstash output for dedicated Kratos index
2022-07-08 15:55:55 +00:00
Wes Lambert
764e8688b1
Modify Kratos input to use dedicated index and add filestream ID for all applicable inputs
2022-07-08 15:53:55 +00:00
Wes Lambert
b06c16f750
Add ingest node pipeline for Kratos
2022-07-08 15:53:00 +00:00
weslambert
42cfab4544
Merge pull request #8256 from Security-Onion-Solutions/fix/kibana_restart_after_role_sync
...
Restart Kibana in case it times out before being able to read role update
2022-07-07 17:44:47 -04:00
weslambert
4bbc901860
Restart Kibana in case it times out before being able to read in new role configuration
2022-07-07 17:19:02 -04:00
weslambert
a343f8ced0
Merge pull request #8255 from Security-Onion-Solutions/fix/so_kibana_user_role
...
Force so-user to sync roles to ensure so_kibana role change
2022-07-07 16:19:30 -04:00
weslambert
85be2f4f99
Force so-user to sync roles to ensure so_kibana role change from superuser to kibana_system
2022-07-07 15:55:44 -04:00
weslambert
8b3fa0c4c6
Merge pull request #8252 from Security-Onion-Solutions/feature/elastic_8_3_2
...
Update to Elastic 8.3.2
2022-07-07 11:14:14 -04:00
weslambert
ede845ce00
Update to Kibana 8.3.2
2022-07-07 11:05:44 -04:00
weslambert
42c96553c5
Update to Kibana 8.3.2
2022-07-07 11:04:43 -04:00
Mike Reeves
41d5cdd78c
Merge pull request #8246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2022-07-06 16:39:38 -04:00
Mike Reeves
c819d3a558
Update soup
2022-07-06 16:36:57 -04:00
Mike Reeves
c00d33632a
Update soup
2022-07-06 16:23:02 -04:00
Mike Reeves
a1ee793607
Merge pull request #8242 from Security-Onion-Solutions/fixsoup
...
Move soup order
2022-07-06 09:18:16 -04:00
Mike Reeves
1589107b97
Move soup order
2022-07-06 08:59:21 -04:00
Mike Reeves
31688ee898
Merge pull request #8238 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Make soup enforce versions
2022-07-05 16:56:14 -04:00
Mike Reeves
f1d188a46d
Update soup
2022-07-05 16:50:20 -04:00
Mike Reeves
5f0c3aa7ae
Update soup
2022-07-05 16:49:20 -04:00
weslambert
2b73cd1156
Merge pull request #8236 from Security-Onion-Solutions/fix/localfile_analyzer
...
Strip quotes and ensure file_path is typed as a list (localfile analyzer)
2022-07-05 16:28:56 -04:00
Mike Reeves
c6fac28804
Update soup
2022-07-05 16:26:44 -04:00
Jason Ertel
9d43b7ec89
Rollback string manipulation in favor of fixed unit tests
2022-07-05 16:21:27 -04:00
Jason Ertel
f6266b19cc
Fix unit test issues
2022-07-05 16:20:24 -04:00
Mike Reeves
df0a774ffd
Make soup enforce versions
2022-07-05 16:17:32 -04:00
weslambert
77ee30f31a
Merge pull request #8237 from Security-Onion-Solutions/feature/elastic_8_3_1
...
Bump Elastic to 8.3.1
2022-07-05 14:50:24 -04:00
weslambert
2938464501
Update to Kibana 8.3.1
2022-07-05 14:46:02 -04:00
weslambert
79e88c9ca3
Update to Kibana 8.3.1
2022-07-05 14:45:30 -04:00
Wes Lambert
e96206d065
Strip quotes and ensure file_path is typed as a list
2022-07-05 14:25:54 +00:00
Josh Brower
7fa9ca8fc6
Merge pull request #8233 from Security-Onion-Solutions/fix/remove-sudo-bpf
...
Remove unneeded sudo
2022-07-05 09:23:48 -04:00
Josh Brower
a1d1779126
Remove unneeded sudo
2022-07-05 09:21:05 -04:00
Josh Patterson
fb365739ae
Merge pull request #8225 from Security-Onion-Solutions/salltupdate
...
bootstrap-salt can now update to minor version with -r
2022-07-01 08:53:59 -04:00
m0duspwnens
5f898ae569
change to egrep
2022-07-01 08:47:46 -04:00
m0duspwnens
f0ff0d51f7
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 16:59:54 -04:00
m0duspwnens
7524ea2c05
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 15:10:13 -04:00
Mike Reeves
6bb979e2b6
Merge pull request #8219 from Security-Onion-Solutions/salty
...
Salty
2022-06-30 13:34:03 -04:00
Mike Reeves
8b3d5e808e
Fix repo location
2022-06-30 13:30:56 -04:00
Mike Reeves
e86b7bff84
Fix repo location
2022-06-30 13:29:21 -04:00
Josh Patterson
69ce3613ff
Merge pull request #8217 from Security-Onion-Solutions/salltupdate
...
point to salt3004.2
2022-06-30 11:29:35 -04:00
m0duspwnens
0ebd957308
point to salt3004.2
2022-06-30 11:26:03 -04:00
Josh Patterson
c3979f5a32
Merge pull request #8207 from Security-Onion-Solutions/salltupdate
...
Saltupdate 3004.2
2022-06-28 11:20:53 -04:00
m0duspwnens
8fccd4598a
update saltstack.list for 3004.2
2022-06-27 16:23:01 -04:00
weslambert
3552dfac03
Merge pull request #8199 from Security-Onion-Solutions/fix/filebeat_filestream_elastic8
...
Change type from 'log' to 'filestream' to ensure compatibility with E…
2022-06-27 14:58:54 -04:00
Josh Patterson
fba5592f62
Update minion.defaults.yaml
2022-06-27 12:10:18 -04:00
Josh Patterson
05e84699d1
Update master.defaults.yaml
2022-06-27 12:09:39 -04:00
Mike Reeves
f36c8da1fe
Update so-functions
2022-06-27 12:04:33 -04:00
Mike Reeves
080daee1d8
Update so-functions
2022-06-27 11:43:01 -04:00
Mike Reeves
909e876509
Update ubuntu.sls
2022-06-27 11:41:49 -04:00
Jason Ertel
ac68fa822b
Merge pull request #8200 from Security-Onion-Solutions/contrib
...
Add gh action for contrib check
2022-06-27 11:25:10 -04:00
Jason Ertel
675ace21f5
Add gh action for contrib check
2022-06-27 11:11:15 -04:00
weslambert
85f790b28a
Change type from 'log' to 'filestream' to ensure compatibility with Elastic 8
2022-06-27 10:39:58 -04:00
weslambert
d0818e83c9
Merge pull request #8197 from Security-Onion-Solutions/fix/localfile_analyzer_csv_path
...
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:36:59 -04:00
weslambert
568b43d0af
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:10:13 -04:00
Jason Ertel
2e123b7a4f
Merge pull request #8175 from Security-Onion-Solutions/kilo
...
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 08:16:39 -04:00
Jason Ertel
ba6f716e4a
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 06:09:04 -04:00
weslambert
10bcc43e85
Merge pull request #8167 from Security-Onion-Solutions/feature/update_es_8_2_3
...
Update to Elastic 8.2.3
2022-06-21 16:11:39 -04:00
weslambert
af687fb2b5
Update config_saved_objects.ndjson
2022-06-21 16:06:28 -04:00
weslambert
776cc30a8e
Update to ES 8.2.3
2022-06-21 16:06:01 -04:00
Doug Burks
00cf0b38d0
Merge pull request #8165 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve default dashboards #8136
2022-06-21 12:57:46 -04:00
Doug Burks
94c637449d
FIX: Improve default dashboards #8136
2022-06-21 12:53:06 -04:00
Josh Brower
0a203add3b
Merge pull request #8145 from Security-Onion-Solutions/defensivedepth-patch-1
...
pin v1.6.0
2022-06-17 13:14:58 -04:00
Josh Brower
b8ee896f8a
pin v1.6.0
2022-06-17 12:38:54 -04:00
Josh Brower
238e671f34
Merge pull request #8129 from Security-Onion-Solutions/fix/curator-cron
...
Change curator to daily for true cluster
2022-06-15 11:40:53 -04:00
Josh Brower
072cb3cca2
Change curator to daily for true cluster
2022-06-15 11:38:38 -04:00
weslambert
44595cb333
Merge pull request #8123 from Security-Onion-Solutions/foxtrot
...
Merge foxtrot into dev
2022-06-14 15:44:13 -04:00
weslambert
959cec1845
Delete Elastalert indices before upgrading to Elastic 8
2022-06-14 11:40:11 -04:00
Doug Burks
286909af4b
Merge pull request #8113 from Security-Onion-Solutions/fix/pfsense-category
...
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:08:00 -04:00
doug
025993407e
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:03:44 -04:00
weslambert
151a42734c
Update Elastic version to 8.2.2
2022-06-08 15:07:45 -04:00
weslambert
11e3576e0d
Update Elastic version to 8.2.2
2022-06-08 15:07:07 -04:00
weslambert
adeccd0e7f
Merge pull request #8097 from Security-Onion-Solutions/dev
...
Merge latest dev into foxtrot
2022-06-08 15:01:09 -04:00
weslambert
aadf391e5a
Temporarily downgrade version for merge
2022-06-08 14:59:01 -04:00
weslambert
47f74fa5c6
Temporarily downgrade version for merge
2022-06-08 14:58:05 -04:00
Jason Ertel
e405750d26
Merge pull request #8095 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.140
2022-06-08 09:07:56 -04:00
Jason Ertel
e36c33485d
Bump version to 2.3.140
2022-06-08 09:04:57 -04:00
Mike Reeves
65165e52f4
Merge pull request #8086 from Security-Onion-Solutions/dev
...
2.3.130
2022-06-07 15:51:12 -04:00
Mike Reeves
2cceae54df
Merge pull request #8087 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 13:44:38 -04:00
Mike Reeves
8912e241aa
2.3.130
2022-06-07 13:41:51 -04:00
Mike Reeves
7357f157ec
Merge pull request #8085 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 12:04:47 -04:00
Mike Reeves
37881bd4b6
2.3.130
2022-06-07 11:34:10 -04:00
Josh Brower
2574f0e23d
Merge pull request #8081 from Security-Onion-Solutions/fix/fleetdm-websockets
...
Allow websockets for fleetdm
2022-06-06 19:15:02 -04:00
Josh Brower
c9d9804c3a
Allow websockets for fleetdm
2022-06-06 17:26:24 -04:00
Doug Burks
73baa1d2f0
Merge pull request #8073 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md to include links to Dashboards and Cases
2022-06-04 08:53:54 -04:00
Doug Burks
dce415297c
improve readability in motd.md
2022-06-04 06:59:09 -04:00
Doug Burks
de126647f8
Update motd.md to include links to Dashboards and Cases
2022-06-04 06:55:08 -04:00
Doug Burks
c34f456151
Merge pull request #8069 from Security-Onion-Solutions/dougburks-patch-1
...
add bar and pie examples to overview dashboard in dashboards.queries.…
2022-06-03 15:04:16 -04:00
Doug Burks
83bff5ee87
add bar and pie examples to overview dashboard in dashboards.queries.json
2022-06-03 15:02:40 -04:00
Doug Burks
918f431728
Merge pull request #8065 from Security-Onion-Solutions/dougburks-patch-1
...
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:13:39 -04:00
Doug Burks
4a886338c8
fix description field for default dashboard in dashboards.queries.json
2022-06-03 11:10:01 -04:00
Doug Burks
7da1802eae
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:03:48 -04:00
Mike Reeves
ff92b524c2
Merge pull request #8062 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2022-06-02 11:51:42 -04:00
Mike Reeves
395eaa39b4
Update soup
2022-06-02 11:45:37 -04:00
Mike Reeves
2867a32931
Merge pull request #8061 from Security-Onion-Solutions/soup130
...
soup for 130
2022-06-02 10:42:17 -04:00
Mike Reeves
fce43cf390
soup for 130
2022-06-02 10:33:18 -04:00
Josh Patterson
e5c9b91529
Merge pull request #8054 from Security-Onion-Solutions/dmz_receiver
...
Dmz receiver
2022-06-01 15:31:42 -04:00
m0duspwnens
e5b74bcb78
remove podman state
2022-06-01 15:26:25 -04:00
Doug Burks
91f8d3e5e9
Merge pull request #8050 from Security-Onion-Solutions/fix/elastalert-query
...
FIX: Elastalert query in Hunt #8049
2022-05-31 16:54:34 -04:00
Doug Burks
269b16bbfd
https://github.com/Security-Onion-Solutions/securityonion/issues/8049
2022-05-31 16:51:05 -04:00
Doug Burks
cd382a1b25
FIX: Elastalert query in Hunt #8049
2022-05-31 16:50:32 -04:00
Doug Burks
e1c9b0d108
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:52 -04:00
Doug Burks
9a98667e85
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:11 -04:00
weslambert
494ce0756d
Merge pull request #8045 from Security-Onion-Solutions/fix/mhr_naming
...
Fix naming for Malware Hash Registry analyzer
2022-05-31 07:52:48 -04:00
Wes Lambert
7f30a364ee
Make sure everything is added back after renaming mhr to malwarehashregistry
2022-05-31 11:44:35 +00:00
Wes Lambert
c82aa89497
Fix Malware Hash Registry naming so it's more descriptive in SOC
2022-05-31 11:41:48 +00:00
Josh Brower
025677a1e6
Merge pull request #8034 from Security-Onion-Solutions/feature/sigmafp
...
Feature/SigmaCustomFilters
2022-05-31 07:25:44 -04:00
Josh Brower
a5361fb745
Change Target_log name
2022-05-28 18:07:05 -04:00
Mike Reeves
30d7801ae1
Merge pull request #8033 from Security-Onion-Solutions/kilo
2022-05-28 11:38:35 -04:00
Jason Ertel
210bc556db
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:29:04 -04:00
Jason Ertel
e87e672b9e
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:28:20 -04:00
Jason Ertel
a70da41f20
Merge pull request #8032 from Security-Onion-Solutions/kilo
...
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:34:40 -04:00
Jason Ertel
8bb02763dc
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:28:10 -04:00
weslambert
a59ada695b
Merge pull request #8031 from Security-Onion-Solutions/fix/screenshots
...
Fix/screenshots
2022-05-27 17:05:51 -04:00
doug
b93a108386
update Cases screenshot in README
2022-05-27 16:33:08 -04:00
doug
6089f3906d
update screenshots and README
2022-05-27 16:32:00 -04:00
Josh Brower
94ee45ac63
Merge pull request #8029 from Security-Onion-Solutions/upgrade/navigator
...
Upgrade Navigator to 4.6.4
2022-05-27 14:46:59 -04:00
Josh Brower
43cb78a6a8
Upgrade Navigator
2022-05-27 14:21:11 -04:00
Josh Patterson
76bb1fbbcc
Merge pull request #8014 from Security-Onion-Solutions/issue/7918
...
manage suricata classifications.config
2022-05-26 13:13:03 -04:00
m0duspwnens
53d6e1d30d
simplfy
2022-05-26 11:51:17 -04:00
m0duspwnens
1bfde852f5
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:43:31 -04:00
m0duspwnens
53883e4ade
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:40:33 -04:00
weslambert
1a0ac4d253
Merge pull request #8007 from Security-Onion-Solutions/fix/filestream-id
...
Add filestream input ID for RITA logs
2022-05-25 10:11:36 -04:00
weslambert
44622350ea
Add ID for RITA filestream inputs
2022-05-25 10:09:01 -04:00
weslambert
99864f4787
Merge pull request #8001 from Security-Onion-Solutions/feature/analyzer_readme
...
Add configuration requirements for various analyzers
2022-05-25 09:33:07 -04:00
Doug Burks
6bd02c0b99
Merge pull request #8003 from Security-Onion-Solutions/feature/elastic-7.17.4
...
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:24:13 -04:00
Doug Burks
1d0bb21908
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:30 -04:00
Doug Burks
bde06e7ec5
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:01 -04:00
Wes Lambert
b93512eb01
Adjust verbiage around pillar configuration
2022-05-24 12:36:32 +00:00
Wes Lambert
92dee14ee8
Add configuration requirements for various analyzers
2022-05-24 12:29:14 +00:00
weslambert
3e6dfcfaca
Merge pull request #7996 from Security-Onion-Solutions/weslambert-patch-2
...
Create Virustotal README
2022-05-23 11:43:43 -04:00
weslambert
a6f1bf3aef
Create Virustotal README
2022-05-23 11:39:44 -04:00
Jason Ertel
88f17f037e
Merge pull request #7982 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.9.0-alpha.3
2022-05-19 13:28:58 -04:00
Jason Ertel
c20859f8c3
Upgrade to Kratos 0.9.0-alpha.3
2022-05-18 17:05:21 -04:00
Jason Ertel
c95bafd521
Merge pull request #7969 from Security-Onion-Solutions/fix/helpers-analyzers
...
Only import yaml module when config is loaded
2022-05-18 07:15:32 -04:00
Wes Lambert
429ccb2dcc
Only import yaml module when config is loaded
2022-05-18 02:07:39 +00:00
weslambert
94ca3ddbda
Merge pull request #7961 from Security-Onion-Solutions/weslambert-patch-1
...
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 13:33:24 -04:00
weslambert
d3206a048f
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 12:49:16 -04:00
weslambert
ff855eb8f7
Merge pull request #7958 from Security-Onion-Solutions/feature/mhr_analyzer
...
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 12:42:01 -04:00
Wes Lambert
8af1f19ac3
Another no_results change
2022-05-17 16:12:43 +00:00
Wes Lambert
e4a7e3cba6
Change 'No results found.' to 'no_results'
2022-05-17 16:11:58 +00:00
weslambert
2688083ff1
Merge pull request #7959 from Security-Onion-Solutions/feature/whoislookup-analyzer
...
Add Whoislookup RDAP-based analyzer
2022-05-17 12:09:06 -04:00
Wes Lambert
766e9748c5
Add Whoislookup RDAP-based analyzer
2022-05-17 15:52:12 +00:00
weslambert
3761b491c0
Remove whitespace
2022-05-17 10:50:33 -04:00
Wes Lambert
e8fc3ccdf4
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 14:44:53 +00:00
Doug Burks
eb9597217c
Merge pull request #7949 from Security-Onion-Solutions/fix/dashboards-hunt-queries
...
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:47:06 -04:00
doug
5cbb50a781
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:33:48 -04:00
Jason Ertel
685789de33
Merge pull request #7936 from Security-Onion-Solutions/kilo
...
Improved unit test coverage of new analyzers; Utilize localized summa…
2022-05-12 16:47:18 -04:00
Jason Ertel
b45b6b198b
Improved unit test coverage of new analyzers; Utilize localized summaries; Require 100% code coverage on analyzers
2022-05-12 16:32:47 -04:00
weslambert
6c506bbab0
Merge pull request #7935 from Security-Onion-Solutions/fix/pulsedive
...
Fix Pulsedive analyzer logic
2022-05-12 15:20:15 -04:00
Wes Lambert
3dc266cfa9
Add test for when indicator is not found
2022-05-12 19:02:41 +00:00
Wes Lambert
a233c08830
Update logic to handle indicators that are not present in database.
2022-05-12 19:02:02 +00:00
Doug Burks
58b049257d
Merge pull request #7932 from Security-Onion-Solutions/dougburks-patch-1
...
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:24:18 -04:00
Doug Burks
6ed3f42449
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:23:00 -04:00
m0duspwnens
d8abc0a195
if in dmz_nodes dont add to filebeta
2022-05-11 11:51:18 -04:00
m0duspwnens
a641346c02
prevent nodes with logstash:dmz:true from being added to logstash:nodes pillar
2022-05-10 17:28:19 -04:00
Jason Ertel
60b55acd6f
Merge pull request #7926 from Security-Onion-Solutions/kilo
...
Add support for analyzers in airgapped environments
2022-05-10 17:12:18 -04:00
Jason Ertel
35e47c8c3e
Add support for analyzers in airgapped environments
2022-05-10 16:51:00 -04:00
weslambert
7f797a11f8
Merge pull request #7924 from Security-Onion-Solutions/analyzer-docs
...
Update analyzer docs with information about analyzers that require au…
2022-05-10 09:40:50 -04:00
Jason Ertel
91a7f25d3a
Corrected brand name capitalization
2022-05-10 09:39:19 -04:00
weslambert
34d57c386b
Update analyzer docs with information about analyzers that require authentication
2022-05-10 09:32:18 -04:00
weslambert
000e813fbb
Merge pull request #7921 from Security-Onion-Solutions/fix/analyzer-packages
...
Update analyzer packages to those downloaded by Alpine and add additional build script option
2022-05-09 16:43:31 -04:00
Wes Lambert
555ca2e277
Update analyzer build/testing script to download necessary Python packages
2022-05-09 20:06:39 +00:00
Wes Lambert
32adba6141
Update analyzer packages with those built from native (Alpine) Docker image
2022-05-09 20:04:41 +00:00
Jason Ertel
e19635e44a
Merge pull request #7920 from Security-Onion-Solutions/kilo
...
Disable MRU queries on dashboards
2022-05-09 15:08:55 -04:00
Jason Ertel
31c04aabdd
Disable MRU queries on dashboards
2022-05-09 15:06:43 -04:00
Jason Ertel
dc209a37cd
Merge pull request #7916 from Security-Onion-Solutions/kilo
...
Disable actions on dashboards group-by tables
2022-05-09 11:52:22 -04:00
Jason Ertel
3f35dc54d2
Disable actions on dashboards group-by tables
2022-05-09 11:44:39 -04:00
Josh Brower
8e368bdebe
Merge in upstream dev
2022-05-06 20:01:07 -04:00
Jason Ertel
0e64a9e5c3
Merge pull request #7912 from Security-Onion-Solutions/kilo
...
Add dashboard ref to soc.json
2022-05-06 15:18:05 -04:00
Jason Ertel
0786191fc9
Add dashboard ref to soc.json
2022-05-06 15:16:27 -04:00
Jason Ertel
60763c38db
Merge pull request #7911 from Security-Onion-Solutions/kilo
...
Analyzers + Dashboards
2022-05-06 13:50:54 -04:00
weslambert
9800f59ed7
Add Urlscan to observable support matrix
2022-05-06 13:11:43 -04:00
Wes Lambert
ccac71f649
Fix formatting/whitespace
2022-05-06 17:08:40 +00:00
Wes Lambert
1990ba0cf0
Fix formatting/whitespace
2022-05-06 17:08:33 +00:00
Wes Lambert
8ff5778569
Add Urlscan analyzer and tests
2022-05-06 17:01:06 +00:00
Jason Ertel
bee4cf4c52
Fix typo in analyzer desc
2022-05-06 09:20:03 -04:00
Jason Ertel
105c95909c
Dashboard queries
2022-05-04 19:32:06 -04:00
Jason Ertel
890bcd58f9
Merge branch 'dev' into kilo
2022-05-04 19:25:08 -04:00
weslambert
a96c665d04
Change test name for EmailRep
2022-05-03 14:13:25 -04:00
weslambert
f3a91d9fcd
Add EmailRep analyzer to observable support matrix
2022-05-03 10:10:57 -04:00
Wes Lambert
5a9acb3857
Add EmailRep analyzer and tests
2022-05-03 14:06:32 +00:00
Wes Lambert
8b5666b238
Ensure API key is used
2022-05-03 12:48:06 +00:00
weslambert
efb229cfcb
Update to match configuration in analyzer dir
2022-05-02 16:35:21 -04:00
weslambert
2fcb2b081d
Update allowed complexity to 12
2022-05-02 16:14:43 -04:00
weslambert
25f17a5efd
Update allowed complexity to 11
2022-04-29 09:42:57 -04:00
weslambert
66b4fe9f58
Add additional information around URI and User Agent
2022-04-28 17:14:36 -04:00
Wes Lambert
c001708707
Add Pulsedive analyzer and tests
2022-04-28 20:56:03 +00:00
weslambert
4edd729596
Add initial supported observable matrix/table
2022-04-27 08:58:34 -04:00
Wes Lambert
76f183b112
Add Greynoise analyzer and tests
2022-04-26 17:25:35 +00:00
Wes Lambert
bd63753d80
Update analyzer name/description
2022-04-25 19:27:10 +00:00
Wes Lambert
15fcaa7030
Add localfile analyzer and tests
2022-04-25 19:23:35 +00:00
Jason Ertel
71a86b0a3c
Merge pull request #7856 from Security-Onion-Solutions/bumpver
...
Bump version
2022-04-25 13:01:19 -04:00
Jason Ertel
e2145720bd
Bump version
2022-04-25 12:10:29 -04:00
Mike Reeves
b4aa59c619
Merge pull request #7853 from Security-Onion-Solutions/dev
...
2.3.120
2022-04-25 11:33:05 -04:00
Mike Reeves
6975153cf4
Merge pull request #7852 from Security-Onion-Solutions/2.3.120
...
2.3.120
2022-04-25 08:59:52 -04:00
Mike Reeves
0935f51667
2.3.120
2022-04-25 08:57:35 -04:00
Mike Reeves
f92d65737b
2.3.120
2022-04-25 08:53:04 -04:00
Josh Patterson
8f5967911b
Merge pull request #7847 from Security-Onion-Solutions/m0duspwnens-patch-1
...
add eval
2022-04-22 16:06:01 -04:00
Josh Patterson
80eb31368a
add eval
2022-04-22 16:04:29 -04:00
Jason Ertel
d8fdf2b701
Merge branch 'dev' into kilo
2022-04-22 15:11:24 -04:00
Jason Ertel
459d388614
Only override nameservers if the first nameserver given is non empty
2022-04-22 15:08:56 -04:00
Wes Lambert
fbf6e64e67
Add initial OTX analyzer and tests
2022-04-22 17:13:40 +00:00
weslambert
677db7c563
Merge pull request #7841 from Security-Onion-Solutions/weslambert-patch-2
...
Update shard count for Zeek in setup
2022-04-21 17:27:57 -04:00
weslambert
1bb216954c
Merge pull request #7840 from Security-Onion-Solutions/weslambert-patch-1
...
Update shards for Zeek
2022-04-21 17:26:57 -04:00
weslambert
c81988ab00
Update shard count for Zeek in setup
2022-04-21 17:26:30 -04:00
weslambert
542db5b7f5
Update defaults.yaml
2022-04-21 17:24:24 -04:00
Wes Lambert
b2db32a2c7
Add function/test for non-existent VT api_key
2022-04-21 17:33:24 +00:00
Wes Lambert
9287d6adf7
Reduce size of test output for test
2022-04-21 16:56:22 +00:00
Wes Lambert
c8e189f35a
Add source-packages for JA3er
2022-04-21 16:46:45 +00:00
Wes Lambert
5afcc8de4f
Add JA3er analyzer and associated test
2022-04-21 16:42:46 +00:00
weslambert
d7eed52fae
Change -f to -r
2022-04-21 09:46:44 -04:00
Doug Burks
2910b56ea1
Merge pull request #7835 from Security-Onion-Solutions/elastic-7.17.3
...
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 09:02:51 -04:00
Doug Burks
e608285341
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:57:08 -04:00
Doug Burks
04856540dc
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:54:09 -04:00
Doug Burks
feb7eeeb8e
UPGRADE: Elastic 7.17.3 #7807
2022-04-21 08:47:40 -04:00
Doug Burks
44f4b1da7f
Merge pull request #7832 from Security-Onion-Solutions/fix/prevent-multiple-instances
...
FIX: Prevent multiple instances of so-sensor-clean and so-playbook-sync #6622
2022-04-20 17:00:09 -04:00
Doug Burks
1edb443c5d
so-playbook-sync pgrep should be more strict to avoid multiple matches on Ubuntu
2022-04-20 16:48:26 -04:00
Doug Burks
8fc03afdc0
so-sensor-clean pgrep should be more strict to avoid matching multiples on Ubuntu
2022-04-20 16:47:18 -04:00
Mike Reeves
fe09b5b0d1
Merge pull request #7831 from Security-Onion-Solutions/awlocal
...
Remove setup from auto starting if you choose to not enter the grid
2022-04-20 14:42:58 -04:00
Mike Reeves
c3952e94c8
Remove setup from auto starting if you choose to not enter the grid
2022-04-20 14:36:38 -04:00
Doug Burks
3aac644da5
Merge pull request #7830 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve Zeek file extraction #7829
2022-04-20 14:13:13 -04:00
Doug Burks
15ef0968d9
FIX: Improve Zeek file extraction #7829
2022-04-20 14:01:46 -04:00
Jason Ertel
aeb70dad8f
Doc updates
2022-04-19 14:31:21 -04:00
Jason Ertel
4129cef9fb
Add new spamhaus analyzer
2022-04-19 12:12:52 -04:00
Josh Patterson
40d9335573
Merge pull request #7822 from Security-Onion-Solutions/workstation_state
...
add securityonion-strelka-oneshot and securityonion-strelka-fileshot to workstation
2022-04-19 09:21:35 -04:00
m0duspwnens
807f6adf1e
add securityonion-strelka-oneshot and securityonion-strelka-fileshot to workstation
2022-04-19 09:19:09 -04:00
Doug Burks
6339ee3bf3
Merge pull request #7818 from Security-Onion-Solutions/dougburks-patch-1
...
Slight change to IDH verbiage in so-whiptail
2022-04-18 16:35:22 -04:00
Doug Burks
5d62ece03b
Slight change to IDH verbiage in so-whiptail
2022-04-18 16:33:54 -04:00
Doug Burks
6905ca276a
Merge pull request #7816 from Security-Onion-Solutions/dougburks-patch-1
...
remove old comments from so-whiptail
2022-04-18 11:30:43 -04:00
Doug Burks
3682754399
remove old comments from so-whiptail
2022-04-18 11:29:46 -04:00
Jason Ertel
0cb73d8f6a
Merge branch 'dev' into kilo
2022-04-18 11:04:32 -04:00
Mike Reeves
186258687e
Merge pull request #7815 from Security-Onion-Solutions/awlocal
...
Fix Analyst Install Loop
2022-04-18 11:04:10 -04:00
Mike Reeves
012ff3e1bc
Fix Analyst Install Loop
2022-04-18 11:02:19 -04:00
Josh Brower
891a197a6a
Merge pull request #7814 from Security-Onion-Solutions/defensivedepth-patch-2
...
Fix ES/LS Log Pruning
2022-04-18 10:45:27 -04:00
Josh Brower
b35b505f0a
Fix pattern matching
2022-04-18 10:39:04 -04:00
Josh Brower
2b39570b08
Fix matching logic
2022-04-18 10:37:38 -04:00
Jason Ertel
159122b52c
Merge branch 'dev' into kilo
2022-04-18 10:11:37 -04:00
Doug Burks
3fb7399000
Merge pull request #7813 from Security-Onion-Solutions/dougburks-patch-1
...
Remove distributed verbiage from other node option in so-whiptail
2022-04-18 08:24:52 -04:00
Doug Burks
400879c079
Remove distributed verbiage from other node option in so-whiptail
2022-04-18 07:53:57 -04:00
Doug Burks
62f3f13bbc
Merge pull request #7803 from Security-Onion-Solutions/dougburks-patch-1
...
move thehive removal from up_to_2.3.120 to post_to_2.3.120
2022-04-15 15:48:12 -04:00
Doug Burks
0eda9a3bd7
move thehive removal from up_to_2.3.120 to post_to_2.3.120
2022-04-15 15:45:01 -04:00
Doug Burks
ee00678362
Merge pull request #7802 from Security-Onion-Solutions/dougburks-patch-1
...
Replace old saltstack repo in so-preflight
2022-04-15 13:17:14 -04:00
Doug Burks
ce192c2526
Update so-preflight
2022-04-15 13:11:15 -04:00
Josh Brower
d60d31f723
Merge pull request #7801 from Security-Onion-Solutions/defensivedepth-patch-1
...
Remove thehive entries from so-status
2022-04-15 12:25:21 -04:00
Josh Brower
bd19da1878
Remove thehive entries from so-status
2022-04-15 12:21:56 -04:00
Doug Burks
f461d01961
Merge pull request #7800 from Security-Onion-Solutions/dougburks-patch-1
...
Improve grammar in so-whiptail
2022-04-15 10:52:29 -04:00
Doug Burks
a69d361d1b
Improve grammar in so-whiptail
2022-04-15 10:45:34 -04:00
Josh Brower
19cba9dca9
Merge pull request #7798 from Security-Onion-Solutions/awlocal
...
Make analyst iso install init management interface
2022-04-15 07:26:53 -04:00
Mike Reeves
5081a81a6c
Make analyst iso install init management interface
2022-04-14 20:00:58 -04:00
Josh Patterson
ba61057433
Merge pull request #7796 from Security-Onion-Solutions/fix_analyst_setup
...
Fix analyst setup
2022-04-14 16:12:53 -04:00
m0duspwnens
b8a80f76cf
change words
2022-04-14 16:09:39 -04:00
Josh Patterson
be2573bb7d
Merge pull request #7794 from Security-Onion-Solutions/soup_salt_influx
...
remove influxdb module patched state files when salt is upgraded
2022-04-14 16:08:10 -04:00
m0duspwnens
36aef87a3c
remove cd before running so-setup analyst
2022-04-14 16:03:43 -04:00
m0duspwnens
02c19da3c4
remove influxdb module patched state files when salt is upgraded
2022-04-14 15:00:14 -04:00
Josh Patterson
2d094a3bfc
Merge pull request #7784 from Security-Onion-Solutions/workstation_script
...
modify so-analyst-install to work with new states and install on managers
2022-04-13 14:37:24 -04:00
m0duspwnens
371fda09db
fix copy paste fail
2022-04-13 14:28:05 -04:00
m0duspwnens
149375115e
warn about required reboot and prompt if reboot desired at completion of install
2022-04-13 14:26:14 -04:00
m0duspwnens
4728bea633
fix typo
2022-04-13 14:03:09 -04:00
m0duspwnens
3ee09db752
added warning about installing and ensure can only install workstation on centos
2022-04-13 13:39:48 -04:00
m0duspwnens
6477e6c5a2
added warning about installing and ensure can only install workstation on centos
2022-04-13 13:39:39 -04:00
m0duspwnens
2389d3fac9
modify so-analyst-install to work with new states and install on managers
2022-04-13 12:32:05 -04:00
Mike Reeves
ecc29b586d
Merge pull request #7772 from Security-Onion-Solutions/awlocal
2022-04-12 15:45:56 -04:00
Mike Reeves
2977604d96
Merge branch 'awlocal' of https://github.com/Security-Onion-Solutions/securityonion into awlocal
2022-04-12 15:39:45 -04:00
Mike Reeves
5253cb5d25
Remove keys at the end of an install
2022-04-12 15:33:17 -04:00
Josh Brower
1cb5a791ca
Add idh req_storage elif
2022-04-12 14:29:07 -04:00
Mike Reeves
8408628b03
Stop thehive on soup
2022-04-12 13:54:08 -04:00
Mike Reeves
02f4cd9926
Replace salt code on a saltstack update
2022-04-12 12:15:22 -04:00
Mike Reeves
c1824e9f17
Replace salt code on a saltstack update
2022-04-12 11:55:45 -04:00
Mike Reeves
081d7e3a09
Replace salt code on a saltstack update
2022-04-12 11:20:26 -04:00
Mike Reeves
a7221ba2b4
Remove summary for thins the workstation doesnt care about
2022-04-12 11:06:12 -04:00
Mike Reeves
aa90a016d7
Change disk requirements for IDH
2022-04-12 10:44:45 -04:00
Josh Patterson
dbddff7be7
Merge pull request #7766 from Security-Onion-Solutions/issue/7763
...
Issue/7763
2022-04-11 16:44:04 -04:00
Josh Brower
f1574de827
Merge pull request #7765 from Security-Onion-Solutions/fix/compress-clean-elastic-logs
...
Compress + Clean ES & Logstash App Logs
2022-04-11 16:43:03 -04:00
Josh Brower
886d69fb38
Compress + Clean ES & Logstash App Logs
2022-04-11 16:09:24 -04:00
m0duspwnens
d68b6e7c9a
only start if exit code != 0
2022-04-11 16:03:00 -04:00
m0duspwnens
d102ca298d
move messages about starting services on soup failure before exit message
2022-04-11 16:01:36 -04:00
m0duspwnens
9914148441
more verbose
2022-04-11 15:51:11 -04:00
m0duspwnens
464772d7d3
start salt-master and salt-minion service is soup fails and exits
2022-04-11 15:43:09 -04:00
Mike Reeves
13f6957ae8
Merge pull request #7764 from Security-Onion-Solutions/awlocal
2022-04-11 15:40:06 -04:00
m0duspwnens
2a18059ad9
use quotes
2022-04-11 15:37:07 -04:00
m0duspwnens
01510c184a
set_os and set_cron_service_name sooner
2022-04-11 15:36:02 -04:00
Mike Reeves
eb2d759bf8
Add more whiptail menus
2022-04-11 15:14:29 -04:00
Mike Reeves
5ed7361e3a
Add more whiptail menus
2022-04-11 15:14:06 -04:00
m0duspwnens
6ed8694008
dont need to pass -t
2022-04-11 15:11:57 -04:00
m0duspwnens
79dc2374e0
check that salt-master is running before requiring manager
2022-04-11 15:09:00 -04:00
m0duspwnens
a2180a6721
ensure salt-master service is running before proceeding with soup
2022-04-11 15:01:41 -04:00
Mike Reeves
f9633e7287
Add more whiptail menus
2022-04-11 14:51:17 -04:00
Mike Reeves
0b2745b342
Sending things to the screen
2022-04-11 11:49:24 -04:00
Mike Reeves
ea34b69795
Sending things to the screen
2022-04-11 11:46:42 -04:00
Mike Reeves
97e691c321
Sending things to the screen
2022-04-11 11:43:13 -04:00
Mike Reeves
a3bf904e2d
Import GPG
2022-04-11 11:32:08 -04:00
Mike Reeves
9ed49ef318
Import GPG
2022-04-11 11:29:56 -04:00
Mike Reeves
f7760394a1
Import GPG
2022-04-11 11:25:54 -04:00
Mike Reeves
d9416f3828
Salt local install of Analyst Workstation
2022-04-11 11:04:25 -04:00
Jason Ertel
2d025e944c
Add yaml since helpers module uses it
2022-04-09 17:48:21 -04:00
Jason Ertel
202ca34c6f
Remove obsolete source/site pkg dirs
2022-04-09 14:36:21 -04:00
Jason Ertel
f9568626f2
Merge branch 'dev' into kilo
2022-04-09 09:02:55 -04:00
Jason Ertel
224e30c0ee
Change localized table layout
2022-04-08 17:31:15 -04:00
Jason Ertel
ebcfbaa06d
Analyzer improvements
2022-04-08 16:57:40 -04:00
Josh Patterson
365866c9cc
Merge pull request #7750 from Security-Onion-Solutions/issue_7730
...
ensure bash is used for influx query
2022-04-08 15:26:24 -04:00
m0duspwnens
59d5be682a
ensure bash is used for influx query
2022-04-08 15:01:38 -04:00
Mike Reeves
7805311ea2
Merge pull request #7748 from Security-Onion-Solutions/bravo
...
Bravo
2022-04-08 14:48:54 -04:00
Josh Patterson
8757ca0dfb
Merge pull request #7749 from Security-Onion-Solutions/issue/7113
...
ensure we can grab management ip and display whiptail if we cant
2022-04-08 12:10:54 -04:00
m0duspwnens
3e8c687d61
ensure we can grab management ip and display whiptail if we cant
2022-04-08 12:05:38 -04:00
Jason Ertel
13c9af5a5a
Clearing hotfix
2022-04-08 10:23:44 -04:00
Mike Reeves
a5313b330f
Merge master into dev
2022-04-08 09:07:46 -04:00
Mike Reeves
0bc3d5d757
Merge pull request #7741 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110 20220407
2022-04-07 16:30:50 -04:00
Mike Reeves
6d88a5b541
Merge pull request #7740 from Security-Onion-Solutions/hfix0407
...
2.3.110 hotfix 0407
2022-04-07 16:11:58 -04:00
Mike Reeves
6a28e752f0
2.3.110 hotfix 0407
2022-04-07 16:03:13 -04:00
Josh Brower
ae8d300567
Merge pull request #7738 from Security-Onion-Solutions/feature/idh-allow-multiple-int
...
Include firewall state
2022-04-07 14:52:31 -04:00
Mike Reeves
2ad3f63cb5
Merge pull request #7739 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2022-04-07 14:46:20 -04:00
Mike Reeves
93e04850c4
Update HOTFIX
2022-04-07 14:40:54 -04:00
Josh Brower
36b2d78dfe
Include firewall state
2022-04-07 14:02:21 -04:00
Jason Ertel
44e318e046
Provide CLI feedback for missing input
2022-04-07 10:16:44 -04:00
Josh Patterson
09e7b5a8bf
Merge pull request #7733 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-07 09:05:51 -04:00
m0duspwnens
8fbd16f75d
ensure salt.list is absent
2022-04-07 09:03:51 -04:00
m0duspwnens
722b200e16
add retry to apt_update incase running in background
2022-04-07 08:58:07 -04:00
m0duspwnens
b2a98af18b
proper formatting
2022-04-07 08:55:30 -04:00
m0duspwnens
be3769fd7c
run apt-get update if saltstack.list changes
2022-04-07 08:53:44 -04:00
m0duspwnens
08ac696f14
remove saltstack repo created by bootstrap-salt for ubuntu
2022-04-06 17:38:06 -04:00
Josh Brower
86771e1fe6
Merge pull request #7732 from Security-Onion-Solutions/feature/idh-allow-multiple-int
...
Feature/idh allow multiple int
2022-04-06 17:21:30 -04:00
Josh Brower
f5e539a05c
Initial support for restricting IDH services on MGT IP
2022-04-06 17:16:38 -04:00
Josh Patterson
0c1ac729e1
Merge pull request #7731 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update the centos repo for airgap prior to applying hotfix
2022-04-06 17:00:09 -04:00
m0duspwnens
833106775f
update the centos repo for airgap prior to applying hotfix or standard soup run
2022-04-06 16:53:55 -04:00
Mike Reeves
fbd417b09e
Merge pull request #7720 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-05 20:29:17 -04:00
Mike Reeves
4224d1f258
Merge pull request #7719 from Security-Onion-Solutions/hfix0405
...
2.3.110 hotfix 0405
2022-04-05 19:17:42 -04:00
Mike Reeves
79175b57fa
2.3.110 hotfix 0405
2022-04-05 19:15:20 -04:00
Josh Patterson
5717382340
Merge pull request #7717 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
use -r for bootstrap-salt for ubuntu
2022-04-05 17:37:22 -04:00
m0duspwnens
cf68aeb36e
use -r for bootstrap-salt for ubuntu
2022-04-05 17:35:03 -04:00
Josh Patterson
882eb83fee
Merge pull request #7716 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
point to so repo
2022-04-05 17:30:10 -04:00
m0duspwnens
89c7f5b356
point to so repo
2022-04-05 17:28:47 -04:00
Mike Reeves
bed9a20025
Merge pull request #7714 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
proper salt format
2022-04-05 15:45:36 -04:00
m0duspwnens
89518b5939
proper salt format
2022-04-05 15:44:06 -04:00
Mike Reeves
07b14d7fa7
Merge pull request #7713 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
update update_repo function
2022-04-05 15:42:45 -04:00
m0duspwnens
1248ba8924
update update_repo function
2022-04-05 15:40:39 -04:00
Josh Patterson
cbbe3b9248
Merge pull request #7712 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
add deb to saltstack.list
2022-04-05 14:45:46 -04:00
m0duspwnens
b467cde9ad
add deb to saltstack.list
2022-04-05 14:42:36 -04:00
Josh Patterson
6d6f328cad
Merge pull request #7711 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
manage repo conf for ubuntu
2022-04-05 13:50:32 -04:00
m0duspwnens
020871ef61
update hotfix version
2022-04-05 13:49:28 -04:00
m0duspwnens
e08b13629a
manage repo conf for ubuntu
2022-04-05 13:41:26 -04:00
Jason Ertel
d8defdd7b0
Improve unit test stability
2022-04-05 07:36:25 -04:00
Jason Ertel
d2fa80e48a
Update status codes to match SOC
2022-04-05 07:20:23 -04:00
Doug Burks
1e187f0c44
Merge pull request #7703 from Security-Onion-Solutions/hotfix/2.3.110
...
Hotfix/2.3.110
2022-04-04 23:37:28 -04:00
Josh Brower
7906c053b1
Initial support for restricting IDH services on MGT IP
2022-04-04 16:46:05 -04:00
Mike Reeves
f5073243f9
Merge pull request #7702 from Security-Onion-Solutions/hfix0401
...
2.3.110 hotfix 0401
2022-04-04 16:13:08 -04:00
Mike Reeves
0c7a07f5c0
Merge pull request #7667 from Security-Onion-Solutions/analystsetup
...
Analyst Setup
2022-04-04 16:09:13 -04:00
Mike Reeves
04370a04ce
2.3.110 hotfix 0401
2022-04-04 16:06:20 -04:00
Jason Ertel
04eef0d31f
Merge branch 'dev' into kilo
2022-04-04 15:59:09 -04:00
Jason Ertel
7df6833568
Add unit tests for Urlhaus; remove placeholder whois analyzer
2022-04-04 15:58:53 -04:00
Josh Patterson
809bc1858c
Merge pull request #7700 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
salt 3004.1 hotfix
2022-04-04 13:32:34 -04:00
m0duspwnens
f9563b2dc4
patch influxdb modules
2022-04-04 12:57:36 -04:00
m0duspwnens
b7aff4f4df
remove influxdb state files
2022-04-04 12:28:23 -04:00
m0duspwnens
1e955e0d38
enable highstate before highstate run for hotfix
2022-04-04 11:28:03 -04:00
m0duspwnens
127420b472
hotfix function for 2.3.10 hotfix 1
2022-04-04 10:39:44 -04:00
Wes Lambert
07cf3469a0
Remove pyyaml for requirements file
2022-04-04 11:40:02 +00:00
Wes Lambert
39101cafd1
Add UrlHaus analyzer and helpers script
2022-04-01 21:11:57 +00:00
Mike Reeves
5387caf6f4
fix formatting
2022-04-01 16:50:55 -04:00
Mike Reeves
07783713e6
fix formatting
2022-04-01 16:22:40 -04:00
Mike Reeves
5974279ed7
fix formatting
2022-04-01 16:17:22 -04:00
Mike Reeves
277c7d9d33
fix formatting
2022-04-01 16:05:37 -04:00
Mike Reeves
d20a07bb5f
fix formatting
2022-04-01 16:00:44 -04:00
Josh Patterson
7f4c2687cf
Merge pull request #7691 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
remove influx patch state files
2022-04-01 15:58:03 -04:00
m0duspwnens
48e40513ff
remove influx patch state files
2022-04-01 15:53:48 -04:00
Mike Reeves
a449a91f38
fix formatting
2022-04-01 15:52:38 -04:00
Mike Reeves
76f43380d9
fix so salt master gets installed
2022-04-01 14:29:24 -04:00
Mike Reeves
7c39559787
fix so salt master gets installed
2022-04-01 14:19:17 -04:00
Jason Ertel
cedb23f4bc
Merge pull request #7689 from Security-Onion-Solutions/esup
...
Upgrade to ES 7.17.2
2022-04-01 13:57:04 -04:00
Jason Ertel
6e7b2ccedc
Upgrade to ES 7.17.2
2022-04-01 13:50:57 -04:00
Mike Reeves
8e9386fcd4
fix the yum commands
2022-04-01 13:17:13 -04:00
Mike Reeves
97fc652a97
fix the yum commands
2022-04-01 11:54:55 -04:00
Mike Reeves
2782c9b464
Update salt versions
2022-04-01 11:26:58 -04:00
Josh Patterson
c429423dae
Merge pull request #7683 from Security-Onion-Solutions/m0duspwnens-salt-3004.1
...
Update to salt 3004.1
2022-04-01 11:19:31 -04:00
m0duspwnens
45dd7d4758
salt 3004.1 in setup
2022-04-01 11:17:38 -04:00
Josh Patterson
b5ce8756e9
Merge pull request #7686 from Security-Onion-Solutions/workstation_state
...
dont run workstation.trusted-ca if not connected to grid
2022-04-01 11:06:53 -04:00
m0duspwnens
e14463c0ab
dont run workstation.trusted-ca if not connected to grid
2022-04-01 11:05:34 -04:00
Mike Reeves
d524f3833b
Let the patch pillar do its work
2022-04-01 10:09:55 -04:00
Josh Patterson
f71fcdaed7
salt 3004.1
2022-04-01 09:55:55 -04:00
Josh Patterson
d95391505f
Update minion.defaults.yaml
2022-04-01 09:55:03 -04:00
Mike Reeves
0b80dad2c0
Merge pull request #7682 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-04-01 09:53:57 -04:00
Mike Reeves
02a96c409e
Update HOTFIX
2022-04-01 09:52:57 -04:00
Mike Reeves
cb2044cee9
Fix the analyst pillar
2022-04-01 09:29:29 -04:00
Mike Reeves
64e480714a
Fix the analyst pillar
2022-04-01 09:10:38 -04:00
Jason Ertel
2dc370c8b6
Add source packages to salt state
2022-03-31 18:56:38 -04:00
Jason Ertel
57dc848792
Support analyzer deps
2022-03-31 16:48:13 -04:00
Jason Ertel
9947ba6e43
Support CentOS paths
2022-03-31 16:47:56 -04:00
Jason Ertel
48fbc2290f
Add dep support for analyzers
2022-03-31 13:59:35 -04:00
Mike Reeves
edc6a461ec
Fix analyst pillar
2022-03-31 13:57:37 -04:00
Mike Reeves
63eb15aa6d
Run anayst Pillar
2022-03-31 13:35:30 -04:00
Mike Reeves
5264526ff1
Fix salt master declaration
2022-03-31 12:05:59 -04:00
Mike Reeves
c9eb188a79
Only run specific states during install for AW
2022-03-31 12:01:55 -04:00
Mike Reeves
ad833965a0
Fix extra space
2022-03-31 11:12:10 -04:00
Mike Reeves
179aa5e29c
Add firewall rules for Analyst workstation
2022-03-31 10:49:38 -04:00
Josh Patterson
86b311c468
Merge pull request #7675 from Security-Onion-Solutions/issue/7203
...
different systemd unit files for ubuntu and centos
2022-03-31 10:18:10 -04:00
m0duspwnens
fc60f64ddb
different systemd unit files for ubuntu and centos
2022-03-31 10:11:43 -04:00
Jason Ertel
1aba4da2bb
Correct analyzer path
2022-03-30 21:01:07 -04:00
Mike Reeves
a049e458c6
Add workstation to the salt config
2022-03-30 14:03:52 -04:00
Jason Ertel
45f511caab
Remove extra comma
2022-03-30 13:21:35 -04:00
Mike Reeves
f43a6757e0
Add analyst install network stack
2022-03-30 11:16:00 -04:00
Mike Reeves
c3d3806f65
Add analyst install network stack
2022-03-30 11:14:35 -04:00
Mike Reeves
dceb46888f
Add analyst install network stack
2022-03-30 11:06:59 -04:00
Jason Ertel
e667bb1e59
merge
2022-03-30 10:57:40 -04:00
Mike Reeves
816d0b1075
Don't prompt for install type since we know its analyst
2022-03-29 17:35:13 -04:00
Mike Reeves
c4a4e9737b
Set standalone to load Xwindows
2022-03-29 17:31:53 -04:00
Josh Patterson
1cb48fc6a8
Merge pull request #7668 from Security-Onion-Solutions/issue/7203
...
run salt_minion_service state last to prevent salt-minion from restarting during state run
2022-03-29 17:30:32 -04:00
Mike Reeves
45161b2a39
Set standalone to load Xwindows
2022-03-29 17:28:32 -04:00
Mike Reeves
67582be575
Set standalone to load Xwindows
2022-03-29 17:23:38 -04:00
Mike Reeves
86e32f3e6c
Set standalone to load Xwindows
2022-03-29 17:13:47 -04:00
Mike Reeves
053ec81285
Set standalone to load Xwindows
2022-03-29 17:12:25 -04:00
Mike Reeves
853235ca9b
Set standalone to load Xwindows
2022-03-29 17:11:19 -04:00
Mike Reeves
afb918d79c
Set standalone to load Xwindows
2022-03-29 17:08:03 -04:00
m0duspwnens
7a4d93f09b
run salt_minion_service state last to prevent salt-minion from restarting during state run
2022-03-29 15:44:05 -04:00
Jason Ertel
b2a96fab7e
merge
2022-03-29 14:07:20 -04:00
Jason Ertel
d2bf6d5618
Add build script to help pre-validate analyzers before pushing
2022-03-29 14:04:23 -04:00
Jason Ertel
484ef4bc31
Ensure generated python files are not pushed to version control
2022-03-29 13:51:12 -04:00
Jason Ertel
cb491630ae
Analyzer CI
2022-03-29 13:40:56 -04:00
Jason Ertel
0a8d24a225
Add automated CI for analyzers
2022-03-29 13:10:04 -04:00
Mike Reeves
3ace55dfe5
Add initial analyst install code
2022-03-29 12:49:30 -04:00
Mike Reeves
102d2507cb
Add initial analyst install code
2022-03-29 12:48:52 -04:00
Mike Reeves
0d23688aa0
Add initial analyst install code
2022-03-29 12:46:45 -04:00
Mike Reeves
80af497f95
Add initial analyst install code
2022-03-29 12:43:20 -04:00
Mike Reeves
990470a765
Add initial analyst install option to so-setup
2022-03-29 10:41:45 -04:00
Josh Patterson
f5095b273d
Merge pull request #7665 from Security-Onion-Solutions/workstation_state
...
Workstation state
2022-03-29 10:27:07 -04:00
m0duspwnens
e3f3af52e1
fix spacing
2022-03-29 10:19:29 -04:00
m0duspwnens
2f489895ef
top match and remove_gui state
2022-03-29 10:17:21 -04:00
weslambert
7f7eaf173b
Merge pull request #7663 from Security-Onion-Solutions/fix/strelka_fw
...
Add strelka_frontend to heavynode, sensor, and standalone role FW por…
2022-03-28 16:14:25 -04:00
weslambert
6004dde54a
Add strelka_frontend to heavynode, sensor, and standalone role FW portgroups
2022-03-28 16:05:07 -04:00
Jason Ertel
c23b87965f
Merge branch 'dev' into kilo
2022-03-28 15:53:33 -04:00
Jason Ertel
deb9b0e5ef
Add analyze feature
2022-03-28 15:53:24 -04:00
m0duspwnens
0ddfaf8d74
changes for workstation
2022-03-28 15:34:15 -04:00
weslambert
fb7160cba5
Merge pull request #7644 from Security-Onion-Solutions/fix/syslog_pr_adjustment
...
Update with changes from Abe's PR and other fixes
2022-03-25 13:59:20 -04:00
weslambert
e6599cd10e
Update with changes from Abe's PR and other fixes
2022-03-25 13:57:44 -04:00
weslambert
c02d7fab50
Merge pull request #7636 from Security-Onion-Solutions/feature/rita
...
Parsing of RITA Logs
2022-03-24 13:05:22 -04:00
weslambert
fbc86f43ec
Add exclude filter for logs for when there are no results from analysis
2022-03-24 13:03:03 -04:00
weslambert
4c93217aac
Merge pull request #7635 from Security-Onion-Solutions/fix/process_mappings_keyword
...
Additional .keyword shims for process mappings
2022-03-24 12:53:16 -04:00
Wes Lambert
fe1b72655b
Additional .keyword shims for process mappings
2022-03-24 16:45:06 +00:00
m0duspwnens
293de159db
fix package names
2022-03-24 11:33:16 -04:00
m0duspwnens
7cfc52da8a
fix include
2022-03-24 10:02:25 -04:00
m0duspwnens
a0841ee7a7
workstation state
2022-03-24 09:57:58 -04:00
weslambert
5160a55dcf
Merge pull request #7629 from Security-Onion-Solutions/fix/roles_load_check_cluster_health
...
Check ES cluster health before trying to load roles
2022-03-23 11:07:24 -04:00
weslambert
1f2bca599f
Check cluster health before trying to load roles for ES
2022-03-23 11:00:26 -04:00
Wes Lambert
8a56c88773
Adjust log file paths
2022-03-22 17:51:17 +00:00
Wes Lambert
57f01c70ec
Remove extra forward slash in log path
2022-03-22 17:45:23 +00:00
Wes Lambert
2487d468ab
Add RITA Elasticsearch ingest pipeline config
2022-03-22 17:38:22 +00:00
Wes Lambert
f613d8ad86
Add RITA Logstash config
2022-03-22 17:36:18 +00:00
weslambert
bb9d6673ec
Fix casing
2022-03-21 12:38:50 -04:00
weslambert
9afa949623
Don't rotate Filebeat log on startup
2022-03-21 12:38:12 -04:00
weslambert
b2c26807a3
Add xpack.reporting.kibanaServer.hostname to defaults file
2022-03-21 09:30:25 -04:00
Wes Lambert
faeaa948c8
Remove extra Salt logic and clean up output format of resultant script
2022-03-19 04:31:48 +00:00
Wes Lambert
1a6ef0cc6b
Re-enable FB module load
2022-03-19 03:55:40 +00:00
Wes Lambert
a18b38de4d
Update so-filebeat-module-setup to use new load style to avoid having to explicitly enabled filesets
2022-03-19 03:54:41 +00:00
Wes Lambert
2e7d314650
Remove Cyberark module
2022-03-19 03:43:55 +00:00
Wes Lambert
c97847f0e2
Remove Threat Intel Recored Future fileset
2022-03-19 03:43:34 +00:00
Wes Lambert
59a2ac38f5
Disable FB module load for now
2022-03-18 22:12:09 +00:00
Wes Lambert
543bf9a7a7
Update Kibana version to 8
2022-03-18 22:07:21 +00:00
Wes Lambert
d111c08fb3
Update Curator commands with new Filebeat module variables
2022-03-18 21:45:33 +00:00
Doug Burks
a3f8a10eb9
Merge pull request #7608 from Security-Onion-Solutions/fix/telegraf-non-root
...
FIX: Run telegraf as non-root #7468
2022-03-18 15:17:28 -04:00
weslambert
a9ea99daa8
Switch from so_elastic user to so_kibana user for Elastic 8
2022-03-18 15:09:50 -04:00
weslambert
cb0d4acd57
Remove X-Pack ML entry for Elastic 8
2022-03-18 14:46:28 -04:00
Doug Burks
eda7a8d7ea
FIX: Update telegraf influxdbsize.sh to collect influxdb size from influxdb_size.log #7468
2022-03-18 13:15:43 -04:00
Doug Burks
f7dc5588ae
FIX: Update common init.sls to create cron job to write influxdb size for telegraf #7468
2022-03-18 13:13:46 -04:00
Doug Burks
c13994994b
FIX: Update telegraf init.sls to run telegraf as non-root #7468
2022-03-18 13:11:56 -04:00
weslambert
e0374be4aa
Update version from 7.16.2 to 8.1.0 for Kibana config
2022-03-18 11:57:33 -04:00
weslambert
6f294cc0c2
Change Kibana user role from superuser to kibana_system for Elastic 8
2022-03-18 11:54:08 -04:00
weslambert
5ec5b9a2ee
Remove older module config files
2022-03-18 10:14:13 -04:00
weslambert
c659a443b0
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:25:10 -04:00
weslambert
99430fddeb
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:24:39 -04:00
weslambert
7128b04636
Remove indices.query.bool.max_clause_count because it is dynamically allocated in Elastic 8
2022-03-17 21:20:41 -04:00
weslambert
712a92aa39
Switch from log input to filestream input
2022-03-17 21:18:03 -04:00
Wes Lambert
6e2aaa0098
Clean up original map file
2022-03-17 21:08:57 +00:00
Wes Lambert
09892a815b
Add back bind mounts and remove THIRDPARTY
2022-03-17 21:06:07 +00:00
Wes Lambert
a60ef33930
Reorganize FB module management
2022-03-17 21:01:03 +00:00
Josh Patterson
949365c636
Merge pull request #7602 from Security-Onion-Solutions/issue/7601
...
prevent so-setup iso from running on ubuntu
2022-03-17 11:37:53 -04:00
m0duspwnens
a896348743
prevent so-setup iso from running on ubuntu - https://github.com/Security-Onion-Solutions/securityonion/issues/7601
2022-03-17 11:31:16 -04:00
Josh Brower
5b9c82a434
Merge pull request #7494 from Security-Onion-Solutions/fix/fleetdm-custom-hostname
...
Force regen of ssl cert
2022-03-16 15:17:05 -04:00
Doug Burks
50477071b8
Merge pull request #7588 from Security-Onion-Solutions/fix/prevent-multiple-instances
...
FIX: Prevent multiple instances of so-sensor-clean and so-playbook-sync #6622
2022-03-16 13:54:00 -04:00
Doug Burks
e65f2a5513
FIX: Prevent multiple instances of so-sensor-clean #6622
2022-03-16 13:28:39 -04:00
Doug Burks
e56f90d83c
FIX: Prevent multiple instances of so-playbook-sync #6622
2022-03-16 13:27:37 -04:00
weslambert
aaded58131
Merge pull request #7565 from Security-Onion-Solutions/fix/es_template_fix
...
Custom ES template fixes
2022-03-15 11:09:46 -04:00
Doug Burks
9bf0265cea
Merge pull request #7566 from Security-Onion-Solutions/feature/hunt-soc-auth
...
FEATURE: Add new Hunt query for SOC logins #7327
2022-03-15 10:58:40 -04:00
Mike Reeves
e01c1398d5
Merge pull request #7564 from Security-Onion-Solutions/removethehive
...
Removethehive
2022-03-15 10:56:08 -04:00
Wes Lambert
42d6c3a956
Replace Elastic connection check using ELASTICCURL with so-elasticsearch-query
2022-03-15 14:55:04 +00:00
Doug Burks
eec44a6b02
Add a SOC Auth query to hunt.queries.json
2022-03-15 10:38:46 -04:00
Doug Burks
d1e1887e36
Add support for Kratos audit logs in hunt.eventfields.json
2022-03-15 10:37:58 -04:00
Wes Lambert
5f56c7a261
Replace ELASTICCURL with so-elasticsearch-query
2022-03-15 14:32:00 +00:00
weslambert
d46620ea2a
Merge pull request #7561 from Security-Onion-Solutions/es_template_map_fix
...
Custom ES Template Fixes
2022-03-15 10:01:42 -04:00
Jason Ertel
408f9d6695
Update .gitleaks.toml
2022-03-15 09:53:27 -04:00
Jason Ertel
b810f14428
Update .gitleaks.toml
2022-03-15 09:53:11 -04:00
Jason Ertel
cec9cba40e
Create .gitleaks.toml
2022-03-15 09:47:57 -04:00
Jason Ertel
8ebeeb497f
add configuration to override leak detector defaults
2022-03-15 09:43:09 -04:00
Mike Reeves
9c80ff4f65
Remove hive from more files
2022-03-15 09:37:58 -04:00
Mike Reeves
81f0aa58b8
Remove hive from more files
2022-03-15 08:28:03 -04:00
Doug Burks
63cef4daff
Merge pull request #7557 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: surilogcompress cron job not running
2022-03-15 07:41:05 -04:00
Doug Burks
db4f138a78
FIX: surilogcompress cron job not running
...
The suricata user was originally created with `/opt/so/conf/suricata` as its home directory. I think at some point we changed permissions on `/opt/so/conf` and at that point the `surilogcompress` cron job stopped working. Changing the home directory to `/nsm/suricata` works on all of my PROD systems (including Ubuntu and CentOS).
For more information, please see:
https://github.com/Security-Onion-Solutions/securityonion/issues/7133
2022-03-15 07:10:02 -04:00
Mike Reeves
b5b60af16f
Remove hive from so-user
2022-03-14 15:06:07 -04:00
Mike Reeves
b83fec6fd2
More hive remova
2022-03-14 14:51:39 -04:00
Mike Reeves
ff30f572d7
Remove thehive from image common
2022-03-14 10:40:41 -04:00
Mike Reeves
95195c07fc
Disable hive in automation files
2022-03-14 10:36:23 -04:00
Jason Ertel
16f673d956
Merge pull request #7541 from Security-Onion-Solutions/kilo
...
Add assignee field to case list
2022-03-14 08:49:46 -04:00
Jason Ertel
5a28725def
Add assignee to case list
2022-03-14 08:45:28 -04:00
Wes Lambert
ba24f75893
Fix index typo
2022-03-11 18:11:16 +00:00
Wes Lambert
70ed20f691
Add new sls file for custom ES index templates
2022-03-11 18:07:23 +00:00
Wes Lambert
d12ff503c2
Chage role loading verbiage
2022-03-11 16:23:19 +00:00
Wes Lambert
dc258cf043
Load custom component templates in so-elasticsearch-templates-load
2022-03-11 16:22:55 +00:00
Wes Lambert
8e43a6e571
Don't generate index template if index_template definition is not present in pillar
2022-03-11 16:22:06 +00:00
m0duspwnens
e1e8a20e11
make sure values exist in data structure
2022-03-10 17:09:00 -05:00
Josh Brower
f0e44827a5
rm extra line
2022-03-10 08:48:46 -05:00
Josh Brower
814e16ba95
Force regen of ssl cert
2022-03-10 08:47:26 -05:00
Mike Reeves
7ca06df66f
Merge pull request #7484 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-03-09 14:50:52 -05:00
Mike Reeves
6f15acd2f9
Update VERSION
2022-03-09 14:50:14 -05:00
Mike Reeves
3725130128
Merge pull request #7481 from Security-Onion-Solutions/dev
...
2.3.110
2022-03-09 14:44:40 -05:00
Mike Reeves
2c66fa1883
Merge pull request #7482 from Security-Onion-Solutions/kilo
...
Merge master with .100 hotfix #3 into dev
2022-03-09 12:24:04 -05:00
Jason Ertel
61a3155dfa
merge from master
2022-03-09 12:22:24 -05:00
Mike Reeves
99f25deb80
Merge pull request #7480 from Security-Onion-Solutions/2.3.110rel
...
2.3.110
2022-03-09 12:16:31 -05:00
Mike Reeves
0cb628f565
2.3.110
2022-03-09 12:12:32 -05:00
weslambert
262e68cb75
Merge pull request #7469 from Security-Onion-Solutions/fix/kibana_config_load_template
...
Add .template extension to ensure we are loading the template and not the resultant file
2022-03-08 21:12:29 -05:00
weslambert
c83b63d0d8
Add .template extension to load template file
2022-03-08 20:53:16 -05:00
weslambert
8d9ddf5f1b
Add .template extension to load template
2022-03-08 20:52:13 -05:00
weslambert
8115da358f
Add .template extension to load template file
2022-03-08 20:51:50 -05:00
Doug Burks
06efef7b81
Merge pull request #7467 from Security-Onion-Solutions/dougburks-patch-1
...
Revert security_opt addition in telegraf init.sls
2022-03-08 18:51:52 -05:00
Doug Burks
b76c01ef53
Revert security_opt addition in telegraf init.sls
2022-03-08 18:27:15 -05:00
weslambert
5f3c29b7f8
Merge pull request #7466 from Security-Onion-Solutions/fix/process_name_keyword
...
Add process.name.keyword
2022-03-08 12:47:31 -05:00
weslambert
65f998d6f7
Remove process.name.keyword for future-proofing
2022-03-08 12:44:51 -05:00
weslambert
406267a892
Add process.name.keyword
2022-03-08 12:42:34 -05:00
weslambert
d9c3160fbf
Merge pull request #7465 from Security-Onion-Solutions/fix/kibana_saved_objects_load
...
Kibana dashboard/saved objects loading improvements
2022-03-08 12:22:55 -05:00
Wes Lambert
d392cb258c
Switch Kibana state to kibana.so_savedobjects_defaults in top file
2022-03-08 16:59:48 +00:00
Wes Lambert
86e228b200
Add .template extension for future-proofing config files
2022-03-08 16:58:37 +00:00
Wes Lambert
a6fd1023b4
Fix criteria for successful execution
2022-03-08 16:57:26 +00:00
Wes Lambert
3f31f7fd41
Add .template extension to fix script behavior and not modify watched file
2022-03-08 16:43:43 +00:00
Jason Ertel
f64da9632f
Merge pull request #7461 from Security-Onion-Solutions/kilo
...
Gracefully handle situations where another process is using the Kratos DB while so-user executes
2022-03-08 11:02:14 -05:00
Jason Ertel
0cec5879bb
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:55:26 -05:00
Jason Ertel
d8ca4976be
Merge branch 'dev' into kilo
2022-03-08 10:41:40 -05:00
Jason Ertel
914d81ca07
Revert "Gracefully handle situations when another process is using the Kratos DB"
...
This reverts commit f2865d8b7f .
2022-03-08 10:40:20 -05:00
Jason Ertel
f2865d8b7f
Gracefully handle situations when another process is using the Kratos DB
2022-03-08 10:38:05 -05:00
Wes Lambert
28554164cd
Remove drop file when securitySolution saved objects change
2022-03-08 14:39:23 +00:00
Wes Lambert
14dddd8649
Remove drop file when config saved objects change
2022-03-08 14:37:15 +00:00
Wes Lambert
c0f49f6fb0
Remove drop file when dashbaord saved objects change
2022-03-08 14:35:04 +00:00
Wes Lambert
d10d4acf9f
Modify Kibana config load script to drop file if successfully executed
2022-03-08 14:33:15 +00:00
Doug Burks
da8e885ede
Merge pull request #7451 from Security-Onion-Solutions/fix/docker-apparmor
...
Update init.sls to avoid telegraf apparmor issues
2022-03-07 17:06:42 -05:00
Doug Burks
104de2a3c9
Update init.sls to avoid telegraf apparmor issues
...
See #2560
2022-03-07 16:11:22 -05:00
Mike Reeves
fb59421f5b
Merge pull request #7446 from Security-Onion-Solutions/fixpipelineload
...
Only load pipelines on change
2022-03-07 15:17:32 -05:00
weslambert
e2bda255cc
Merge pull request #7447 from Security-Onion-Solutions/fix/es_templates_soup
...
Remove old Elasticsearch index templates during SOUP
2022-03-07 15:10:44 -05:00
Mike Reeves
4eb37fd5a9
Update init.sls
2022-03-07 15:09:36 -05:00
Wes Lambert
fa9be58b23
Specify index templates
2022-03-07 20:04:23 +00:00
Wes Lambert
647b316a96
Remove old ES index templates
...
Signed-off-by: Wes Lambert <wlambertts@gmail.com >
2022-03-07 20:02:45 +00:00
Mike Reeves
d33db6fb23
Only load pipelines on change
2022-03-07 14:25:46 -05:00
weslambert
eac120f4c2
Merge pull request #7444 from Security-Onion-Solutions/fix/dtc_client_override
...
Add DTC client mappings
2022-03-07 13:38:19 -05:00
Wes Lambert
c549b20221
Add DTC client mappings
2022-03-07 18:36:26 +00:00
Mike Reeves
e6132be4e6
Merge pull request #7443 from Security-Onion-Solutions/fixtemplates
...
Only load templates on change
2022-03-07 10:42:51 -05:00
Mike Reeves
c67604590d
Only load templates on change
2022-03-07 09:52:18 -05:00
weslambert
5600b55f05
Merge pull request #7427 from Security-Onion-Solutions/fix/syslog_kibana_viz
...
Replace syslog facility and severity with label fields in Kibana syslog dashboard
2022-03-07 08:14:35 -05:00
Doug Burks
a59779905f
Merge pull request #7437 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo
2022-03-07 08:05:07 -05:00
Doug Burks
848a5c6350
fix typo
2022-03-07 08:03:41 -05:00
Wes Lambert
33ba45472f
Replace syslog facility and severity with label fields
2022-03-04 21:40:41 +00:00
weslambert
ee4035f022
Merge pull request #7426 from Security-Onion-Solutions/fix/syslog_zeek
...
Change to label fields for syslog facility and severity
2022-03-04 16:31:45 -05:00
weslambert
f71ccadb8a
Change to label fields for Zeek syslog
2022-03-04 16:29:55 -05:00
weslambert
fc3273fa49
Change to label fields to comply with what's defined in Filebeat template
2022-03-04 16:29:01 -05:00
weslambert
3148fa0e06
Merge pull request #7422 from Security-Onion-Solutions/fix/syslog_dot_keyword
...
.keyword additions and increase max_clause_count
2022-03-04 15:32:29 -05:00
weslambert
254cf53c2f
Increase clause count to 3500
2022-03-04 10:36:37 -05:00
Wes Lambert
ffae22beef
Add DTC syslog mappings for .keyword and add refs to defaults.yml
2022-03-04 13:04:11 +00:00
weslambert
93c2f82345
Merge pull request #7413 from Security-Onion-Solutions/fix/add_keyword_subfield
...
Add .keyword subfield for more mappings
2022-03-03 10:42:38 -05:00
Wes Lambert
1f71816ad7
Add keyword subfield for DTC winlog mappings
2022-03-03 14:54:30 +00:00
Wes Lambert
1c086e36da
Add missing comma for file mappings
2022-03-03 13:49:54 +00:00
Wes Lambert
aa8d24b6cd
Add DTC destination, source, and winlog mapping references to templates in defaults file
2022-03-03 13:42:20 +00:00
Wes Lambert
85979cbce8
Add file, process, and winlog mapping changes
2022-03-03 13:37:27 +00:00
Wes Lambert
8f97f09c9c
Additional .keyword changes for host.hostname client.address, and event.action
2022-03-02 21:54:46 +00:00
Wes Lambert
3ee46e4c29
Add .keyword for destination/source geo.country_name
2022-03-02 21:50:03 +00:00
weslambert
a21060306c
Merge pull request #7404 from Security-Onion-Solutions/fix/field_limit_adjustment
...
Adjust field limit for now due to component template errors
2022-03-02 11:41:35 -05:00
Wes Lambert
c5b16fdf3b
Adjust field limit for now
2022-03-02 16:33:39 +00:00
weslambert
b80e82aaf6
Merge pull request #7396 from Security-Onion-Solutions/fix/dot_security
...
Revert back to usage of .security field
2022-03-02 10:42:29 -05:00
Josh Brower
2ba72791aa
Remove sigma regen cron
2022-03-02 10:31:15 -05:00
Wes Lambert
ab9b81ea39
Change match_only_text to text for mac in host mappings
2022-03-02 15:01:05 +00:00
Wes Lambert
ed620b93b7
Add custom analyzer definition to all SO/DTC mappings
2022-03-02 14:43:19 +00:00
Wes Lambert
27c8eaa630
Update all other mappings for .security where applicable
2022-03-02 14:39:23 +00:00
Wes Lambert
e925d435ff
Update event, file, and host mappings to include .security
2022-03-02 14:33:52 +00:00
Wes Lambert
496b161253
Update ECS mappings to include .security
2022-03-02 14:27:36 +00:00
Wes Lambert
aae2fd1fbb
Update DNS mappings to include .security
2022-03-02 14:27:15 +00:00
Wes Lambert
0b45cf7ae1
Update base mappings to include .security
2022-03-02 14:25:57 +00:00
Wes Lambert
d89af5f04f
Update agent mappings to include .security
2022-03-02 14:25:14 +00:00
Wes Lambert
2d2ec45029
Modify base ECS mappings to include .security where possible, as well as custom analyzer definition
2022-03-02 14:19:36 +00:00
weslambert
93386f4620
Merge pull request #7389 from Security-Onion-Solutions/fix/revert_text
...
Fix/revert text
2022-03-02 09:17:46 -05:00
Wes Lambert
5489b8559d
Revert "Switch from .security to match_only_text"
...
This reverts commit f7862af934 .
2022-03-01 18:44:00 +00:00
Wes Lambert
2a9caccc7c
Revert "Add additional .text subfield mappings"
...
This reverts commit 61dadc6249 .
2022-03-01 18:43:24 +00:00
Doug Burks
adf3dc0cf6
Merge pull request #7370 from Security-Onion-Solutions/fix/syslog
...
Revert syslog pipeline updates from Abe's PR for now
2022-03-01 11:13:13 -05:00
Wes Lambert
a290602a70
Revert syslog pipeline updates from Abe' PR for now
2022-03-01 15:31:07 +00:00
weslambert
4201ee45c6
Merge pull request #7369 from Security-Onion-Solutions/fix/ingest_timestamp
...
Rename ingest timestamp to event.ingested
2022-03-01 10:11:16 -05:00
Wes Lambert
038dc49098
Temporarily increase field limit before trimming efforts
2022-03-01 15:06:28 +00:00
Wes Lambert
dc07adca63
Rename ingest.timestamp to event.ingested
2022-03-01 15:05:08 +00:00
Josh Brower
39718561ce
Merge pull request #7366 from Security-Onion-Solutions/delta
...
Enable state tracking for sigma refresh
2022-03-01 05:53:14 -05:00
Josh Brower
e960d99901
Enable state tracking for sigma refresh
2022-02-28 21:18:41 -05:00
Josh Brower
09f1a5025d
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-28 21:18:07 -05:00
Josh Brower
41a58b791a
Enable state tracking for sigma refresh
2022-02-28 21:17:59 -05:00
Jason Ertel
73b2a36e89
Merge pull request #7365 from Security-Onion-Solutions/kilo
...
Upgrade to ES 7.17.1
2022-02-28 18:26:31 -05:00
Jason Ertel
f147bb33ed
Upgrade to ES 7.17.1
2022-02-28 18:18:09 -05:00
Josh Patterson
6b3b5e9a1f
Merge pull request #7363 from Security-Onion-Solutions/soup_singlenode_30
...
allow for check_log_size_limit to work without salt-master running
2022-02-28 17:13:42 -05:00
Josh Brower
f824717094
Merge pull request #7364 from Security-Onion-Solutions/delta
...
IDH Node verbiage
2022-02-28 17:09:08 -05:00
Josh Brower
0cee0d5dea
IDH Node verbiage
2022-02-28 16:47:24 -05:00
Josh Brower
d71bde0e38
Merge pull request #7362 from Security-Onion-Solutions/delta
...
Navigator - include attack json for airgap
2022-02-28 16:33:10 -05:00
Josh Brower
2075412ca2
Navigator - include attack json for airgap
2022-02-28 16:15:30 -05:00
m0duspwnens
a51f833f36
output only the value for log_size_limit
2022-02-28 16:13:43 -05:00
Jason Ertel
04a99a0adc
Merge pull request #7361 from Security-Onion-Solutions/kilo
...
Clear out hotfix file
2022-02-28 16:04:30 -05:00
Jason Ertel
166ac0d194
Clear out hotfix file
2022-02-28 16:01:42 -05:00
m0duspwnens
8d12e136f2
Merge remote-tracking branch 'remotes/origin/dev' into soup_singlenode_30
2022-02-28 15:43:37 -05:00
m0duspwnens
710059211d
remove debug echo, mkdir verbose
2022-02-28 14:54:39 -05:00
weslambert
a1c0ae4aab
Merge pull request #7356 from Security-Onion-Solutions/fix/es_config_load_order
...
Run template load first to prevent issues with pipeline changes that …
2022-02-28 14:50:22 -05:00
m0duspwnens
80e5198f9e
combine local and default pillars to get pillar values locally
2022-02-28 14:35:16 -05:00
m0duspwnens
dc24cb711d
need local to be --local
2022-02-28 13:50:08 -05:00
m0duspwnens
c5bf818049
debug messages and pass local to lookup_salt_value
2022-02-28 13:39:50 -05:00
weslambert
414b9dcd59
Run template load first to prevent issues with pipeline changes that generate new indices
2022-02-28 12:33:18 -05:00
m0duspwnens
cd981fa2ae
forgot then for if
2022-02-28 12:25:06 -05:00
m0duspwnens
278235b0ca
update so-common lookup_salt_value to accept local option. soup get minion id from grains with local option
2022-02-28 12:15:23 -05:00
weslambert
a9caef9596
Merge pull request #7338 from Security-Onion-Solutions/fix/endgame_template
...
Revert Endgame index name changes
2022-02-28 08:13:09 -05:00
Doug Burks
e0b3635318
Merge pull request #7339 from Security-Onion-Solutions/fix/zeek_dns-import
...
Avoid changing _index for imported logs
2022-02-27 05:09:00 -05:00
Doug Burks
32b71fdcac
Avoid changing _index for imported logs
2022-02-26 10:36:09 -05:00
Wes Lambert
bd1b21a5b6
Revert Endgame index name changes
2022-02-26 02:53:57 +00:00
weslambert
56cb8d62ab
Merge pull request #7337 from Security-Onion-Solutions/fix/pb_overrides
...
Fix formatting for PB overrides
2022-02-25 20:48:38 -05:00
weslambert
e942d81433
Ensure correct formatting for source override
2022-02-25 19:14:58 -05:00
weslambert
a511fd33e9
Ensure correct formatting for destination override
2022-02-25 19:14:21 -05:00
Doug Burks
74037e6f00
Merge pull request #7335 from Security-Onion-Solutions/fix/soup-postversion
...
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 15:27:31 -05:00
Josh Brower
25b0069353
Merge pull request #7334 from Security-Onion-Solutions/delta
...
IDH Setup - dont show ssh fix screen
2022-02-25 15:01:25 -05:00
Josh Brower
6a270eb8b3
IDH Setup - dont show ssh fix screen - fix
2022-02-25 14:58:30 -05:00
Josh Brower
ee39ec1882
IDH Setup - dont show ssh fix screen
2022-02-25 14:55:28 -05:00
Doug Burks
8df47e809d
make sure that each post_to_* function sets POSTVERSION at end
2022-02-25 14:30:59 -05:00
Mike Reeves
fa15a2e012
Merge pull request #7333 from Security-Onion-Solutions/endgamecurator
...
Fix endgame index name
2022-02-25 13:31:29 -05:00
Mike Reeves
15924ebe0f
Fix endgame index name
2022-02-25 13:29:29 -05:00
weslambert
c95f48e49a
Merge pull request #7330 from Security-Onion-Solutions/fix/pb-override
...
Override destination/source mappings with .keyword for Playbook
2022-02-25 13:07:31 -05:00
Wes Lambert
a8bdff89ae
Move files into SO component template directory
2022-02-25 18:00:16 +00:00
Wes Lambert
08097fe9ec
Add Playbook override mappings
2022-02-25 17:58:51 +00:00
Josh Brower
ce4c859f3a
Merge pull request #7328 from Security-Onion-Solutions/fix/soup-sigma-refresh
...
.110 Post processing - sigma refresh
2022-02-25 12:24:19 -05:00
Josh Patterson
9de9d92b2b
Merge pull request #7329 from Security-Onion-Solutions/delta
...
add extra hosts for filebeat on idh node
2022-02-25 12:23:37 -05:00
m0duspwnens
d76facb1bb
add extra hosts for idh node
2022-02-25 12:21:43 -05:00
Josh Brower
1abf27873d
.110 Post processing - sigma refresh
2022-02-25 12:19:59 -05:00
weslambert
a6ab09501e
Merge pull request #7326 from Security-Onion-Solutions/fix/additional_text_subfield_mappings
...
Add additional .text subfield mappings
2022-02-25 11:29:26 -05:00
Wes Lambert
61dadc6249
Add additional .text subfield mappings
2022-02-25 16:27:37 +00:00
Josh Brower
be80f0530c
Merge pull request #7321 from Security-Onion-Solutions/delta
...
IDH Improvements
2022-02-24 21:27:36 -05:00
Josh Brower
96ed3cb158
IDH - Setup Summary new lines
2022-02-24 20:59:47 -05:00
Josh Brower
4a597b9f0e
Merge remote-tracking branch 'remotes/origin/dev' into delta
2022-02-24 19:58:10 -05:00
Josh Brower
cf7325a546
IDH - Play tweaks, Setup summary, log rotate
2022-02-24 19:57:11 -05:00
Josh Patterson
8302c45059
Merge pull request #7320 from Security-Onion-Solutions/delta_ssh
...
default to false if local role doesnt exist
2022-02-24 18:06:19 -05:00
m0duspwnens
0970bbc983
default to false if local role doesnt exist
2022-02-24 17:55:50 -05:00
Josh Brower
e8e683c2e9
Merge pull request #7319 from Security-Onion-Solutions/delta
...
Add and Update IDH Plays
2022-02-24 15:48:38 -05:00
Josh Brower
fbc702375c
Add and Update IDH Plays
2022-02-24 15:06:04 -05:00
Josh Patterson
5c747fbb4c
Merge pull request #7318 from Security-Onion-Solutions/delta_ssh
...
change name of selinux policy state for idh node
2022-02-24 14:49:55 -05:00
m0duspwnens
8b61d4818d
change name of selinux policy state for idh node
2022-02-24 14:47:14 -05:00
weslambert
22b01dab1e
Merge pull request #7317 from Security-Onion-Solutions/fix/add_text_subfield_to_dtc_mappings
...
Add .text subfield mappings for DTC where fields are defined
2022-02-24 14:47:11 -05:00
Wes Lambert
0f8a39002f
Add .text subfield mappings for DTC where fields are defined
2022-02-24 19:39:52 +00:00
weslambert
5e29c71381
Merge pull request #7315 from Security-Onion-Solutions/fix/split_zeek_dns
...
Split Zeek DNS records into a separate index
2022-02-24 13:21:52 -05:00
weslambert
23fb62c0d6
Split Zeek DNS records into a separate index
2022-02-24 12:52:25 -05:00
weslambert
313487a887
Merge pull request #7313 from Security-Onion-Solutions/fix/kibana_dashboard_load
...
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:48:28 -05:00
weslambert
bc1794e437
Fix function name
2022-02-24 09:42:14 -05:00
Josh Patterson
d7aa413c46
Merge pull request #7314 from Security-Onion-Solutions/delta
...
default port 2222 for ssh idh node
2022-02-24 09:37:11 -05:00
weslambert
45ccfc5ad4
Add back post to .100 and call for .110
2022-02-24 09:35:43 -05:00
weslambert
582bf4c64c
Remove dashboard updates for .100 so we don't run twice
2022-02-24 09:25:59 -05:00
weslambert
7f08ecdcbe
Add function reference for .110 post changes
2022-02-24 09:25:15 -05:00
weslambert
a22e470038
Add Kibana dashboard updates for 2.3.110
2022-02-24 09:20:44 -05:00
weslambert
bc2c1b4ccc
Merge pull request #6935 from abesinger/issue/6912
...
Updated syslog pipeline, resolves #6912 .
2022-02-24 08:33:55 -05:00
Josh Brower
5779e40401
Merge pull request #7308 from Security-Onion-Solutions/defensivedepth-patch-1
...
UC true
2022-02-24 07:48:39 -05:00
Josh Brower
585c275df6
UC true
2022-02-23 19:35:10 -05:00
Josh Brower
babc114d27
Merge branch 'delta' of https://github.com/Security-Onion-Solutions/securityonion into delta
2022-02-23 19:33:18 -05:00
Josh Brower
2bf20bd1f0
UC true
2022-02-23 19:33:10 -05:00
Josh Patterson
a9c6dc32ab
Merge pull request #7305 from Security-Onion-Solutions/delta_ssh
...
allow only manager to connect to ssh port for idh node
2022-02-23 15:17:31 -05:00
m0duspwnens
61ae61953f
allow only manager to connect to ssh port for idh node
2022-02-23 15:14:11 -05:00
weslambert
2aa811dcd2
Merge pull request #7300 from Security-Onion-Solutions/fix/new_es_template_config
...
Add IDH and Kratos index templates
2022-02-23 12:24:38 -05:00
weslambert
6a0ecb9e9c
Add IDH and Kratos index templates
2022-02-23 12:13:46 -05:00
Josh Brower
b7b2183c15
Merge pull request #7296 from Security-Onion-Solutions/delta
...
IDH - Import & Enables Plays
2022-02-23 10:52:37 -05:00
weslambert
00dbf54a5f
Merge pull request #7295 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update so-functions
2022-02-23 10:50:32 -05:00
Josh Brower
83aa261d88
IDH - Import & Enables Plays
2022-02-23 10:50:13 -05:00
Mike Reeves
c4cc3fa35f
Update so-functions
2022-02-23 10:47:37 -05:00
Josh Brower
0121eda536
Merge pull request #7282 from Security-Onion-Solutions/delta
...
Initial Support - IDH Node
2022-02-23 08:49:40 -05:00
Doug Burks
aadc2a844b
Merge pull request #7284 from Security-Onion-Solutions/fix/so-curator-closed-delete
...
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:40:23 -05:00
doug
1392fc37e8
FIX: curator should exclude so-case* indices #7270
2022-02-22 17:00:52 -05:00
weslambert
9f7612b599
Merge pull request #7283 from Security-Onion-Solutions/fix/match_only_text
...
Switch from .security to using match_only_text with .text
2022-02-22 15:41:29 -05:00
Wes Lambert
f7862af934
Switch from .security to match_only_text
2022-02-22 20:33:49 +00:00
Josh Brower
1d95aca4de
IDH - VNC default port
2022-02-22 14:16:45 -05:00
Josh Brower
99554d5db8
IDH - UDP vs TCP support
2022-02-22 14:10:05 -05:00
Josh Brower
df9fc807a3
IDH - restart scripts, filebeat fix
2022-02-22 08:05:53 -05:00
Josh Brower
3610b0cd30
merge in dev
2022-02-21 16:52:53 -05:00
Josh Brower
eea2b9ccfd
IDH - Play - ssh
2022-02-21 16:43:26 -05:00
Josh Brower
05be776f4b
IDH - so-status
2022-02-21 16:41:36 -05:00
Doug Burks
5b46d19b13
Merge pull request #7273 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:25:58 -05:00
Doug Burks
1abd824c5f
FIX: curator should exclude so-case* indices #7270
2022-02-21 09:00:05 -05:00
Josh Brower
2203e2fedd
IDH - Final setup fixes
2022-02-19 21:01:48 -05:00
Josh Brower
780cd38adf
IDH - setup tweaks
2022-02-19 12:28:45 -05:00
Mike Reeves
fc0e27a7ae
Merge pull request #7261 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update networks.cfg.jinja
2022-02-18 20:03:47 -05:00
Mike Reeves
0d1da5d1dc
Update networks.cfg.jinja
2022-02-18 20:02:50 -05:00
Josh Brower
bf477a1c19
IDH - Initial whiptail
2022-02-18 17:21:04 -05:00
weslambert
3124f2bd12
Merge pull request #7255 from Security-Onion-Solutions/fix/remove_old_templates
...
Remove old index templates
2022-02-18 15:23:07 -05:00
Jason Ertel
380f0ef93a
Merge pull request #7256 from Security-Onion-Solutions/kilo
...
Update password len requirements; clarify password update help
2022-02-18 15:19:08 -05:00
Jason Ertel
93e9548eaf
Require a minimum of 8 characters for passwords, to match Kratos min requirements
2022-02-18 15:14:48 -05:00
Wes Lambert
4d1533537b
Remove old index templates
2022-02-18 20:08:13 +00:00
Josh Brower
0362afb260
IDH - Finalize Firewall config
2022-02-18 13:23:48 -05:00
Josh Patterson
d14967dd45
Merge pull request #7251 from Security-Onion-Solutions/issue/7233
...
dont allow $ to be used for elasticsearch:auth or kibana:secrets
2022-02-18 13:22:22 -05:00
m0duspwnens
cb55af4c1c
dont allow $ to be used for elasticsearch:auth or kibana:secrets - https://github.com/Security-Onion-Solutions/securityonion/issues/7233
2022-02-18 13:13:56 -05:00
weslambert
87a5e64f12
Merge pull request #7249 from Security-Onion-Solutions/fix/component_index_association
...
Update component -> index association for file/scan mappings for Strelka
2022-02-18 12:19:41 -05:00
Josh Brower
8de5a054d4
Merge pull request #7248 from Security-Onion-Solutions/feature/kratos-log-ingest
...
Ingest Kratos logs
2022-02-18 11:56:20 -05:00
William Wernert
786b01c85a
Merge pull request #6496 from JamesMConroy/so-staus-tty
...
so-staus detects tty
2022-02-18 11:52:18 -05:00
Josh Brower
118277ebc5
Ingest Kratos logs
2022-02-18 11:49:02 -05:00
Mike Reeves
27299cbe1b
Merge pull request #7247 from christopherwoodall/patch-7
...
Update so-setup
2022-02-18 11:47:19 -05:00
Christopher Woodall
118266bf5f
Update so-setup
...
Patch so setup to ignore deprecation warnings.
2022-02-18 11:38:56 -05:00
Mike Reeves
5d949de146
Merge pull request #7246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update networks.cfg.jinja
2022-02-18 11:28:57 -05:00
Mike Reeves
6f4ee4123a
Update networks.cfg.jinja
2022-02-18 11:26:58 -05:00
Mike Reeves
e4148818d8
Merge pull request #7226 from Security-Onion-Solutions/zeekhn
...
Add Zeek Homenet in networks.cfg
2022-02-18 11:11:56 -05:00
Mike Reeves
becdc34677
Merge pull request #7227 from hacker0ni/patch-1
...
Allow downgrades in docker_install
2022-02-18 11:10:26 -05:00
Mike Reeves
95eab61615
Rename to the .jinja standard
2022-02-18 11:06:33 -05:00
Mike Reeves
9341669a15
Merge pull request #7244 from christopherwoodall/patch-6
...
Update config.map.jinja
2022-02-18 09:57:33 -05:00
Jason Ertel
fdc63b5816
Clarify so-user update usage/help
2022-02-18 09:41:09 -05:00
Christopher Woodall
eaff6a12de
Update config.map.jinja
...
Extend the array instead of appending.
2022-02-18 08:50:28 -05:00
weslambert
6ee3287d2d
Update component -> index association for file/scan mappings for Strelka
2022-02-18 08:12:34 -05:00
James Conroy
91c207cd38
Update salt/common/tools/sbin/so-status
...
Removed # {% raw %} from line 170
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:43 -06:00
James Conroy
b774e62dfa
Update salt/common/tools/sbin/so-status
...
Add salt raw directive
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-17 20:37:25 -06:00
Josh Brower
f995d0768f
IDH - Initial firewall support
2022-02-17 15:54:20 -05:00
Doug Burks
3b887c7b1a
Merge pull request #7239 from Security-Onion-Solutions/dougburks-patch-1
...
so-ip-update needs to queue the Kibana dashboard update
2022-02-17 15:54:10 -05:00
Doug Burks
b4b7938ce2
so-ip-update needs to queue the Kibana dashboard update in case a salt operation is already running
2022-02-17 15:47:33 -05:00
Doug Burks
e5d7c1c77a
Merge pull request #7238 from Security-Onion-Solutions/dougburks-patch-1-1
...
so-ip-update needs to update Kibana dashboards
2022-02-17 14:53:31 -05:00
Doug Burks
1a96162966
so-ip-update needs to update Kibana dashboards
2022-02-17 14:49:55 -05:00
hacker0ni
bc72b3da91
Allow downgrades in docker_install
...
When running the installer again on a new node, it tries to pull the docker packages but since the installer ran again before, the install command fails on Ubuntu 18.04 stating that the `--allow-downgrades` is not specified in the command. This change adds that to circumvent the issue.
2022-02-17 11:47:36 -05:00
Mike Reeves
3e194c9b4b
Walk the homenet for zeek
2022-02-17 11:33:22 -05:00
Josh Brower
6c124733b5
IDH - Enable default states
2022-02-17 10:50:26 -05:00
weslambert
6842099e11
Merge pull request #7224 from Security-Onion-Solutions/fix/zeek_viz
...
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 10:05:46 -05:00
Wes Lambert
5c1f61bda8
Switch from dns.answers to dns.answers.name for DTC
2022-02-17 15:03:46 +00:00
weslambert
53c7ad6041
Merge pull request #7223 from Security-Onion-Solutions/fix/shard_settings_setup
...
Ensure setup configures pillar correctly for index settings
2022-02-17 09:48:11 -05:00
Josh Brower
ef4df58510
IDH - Jinjafy hostname
2022-02-17 09:00:57 -05:00
weslambert
c0f9cb188b
Add missing colon
2022-02-17 07:58:05 -05:00
weslambert
d309c4fc0a
Update pillar structure for index_settings/shards
2022-02-17 07:10:29 -05:00
Jason Ertel
cb9712aa08
Merge pull request #7217 from Security-Onion-Solutions/kilo
...
MFA
2022-02-16 16:47:40 -05:00
weslambert
d084625ee0
Merge pull request #7218 from Security-Onion-Solutions/fix/composable_templates_soup
...
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:24:57 -05:00
weslambert
e71b606dd6
Add pillar update for ES index templates for 2.3.110
2022-02-16 16:22:06 -05:00
weslambert
f1f9322bee
Merge pull request #7216 from Security-Onion-Solutions/fix/es_template_netflow_mappings_indent
...
Fix indent for so-netflow component template references
2022-02-16 14:47:31 -05:00
weslambert
185ea2fd99
Fix indent for so-netflow component template references
2022-02-16 14:46:12 -05:00
Mike Reeves
89eb2d0a8b
Add netowrks.cfg to Zeek
2022-02-16 14:24:58 -05:00
Jason Ertel
2c4ba75c0c
Merge branch 'dev' into kilo
2022-02-15 17:05:24 -05:00
weslambert
9e222b1464
Merge pull request #7206 from Security-Onion-Solutions/feature/template-reorg
...
Re-organize Elasticsearch Index Templates
2022-02-15 16:50:14 -05:00
Josh Brower
3ccef12df7
IDH - Pillarize OpenCanary Config
2022-02-15 13:57:31 -05:00
Wes Lambert
4fa3749418
Remove bind or ES templates
2022-02-15 18:08:03 +00:00
Wes Lambert
786a189f65
Merge branch 'feature/template-reorg' of https://github.com/security-onion-solutions/securityonion into feature/template-reorg
2022-02-15 17:06:02 +00:00
Wes Lambert
de731fc05d
Remove default templates from ES template pillar since they are now managed in the defaults file.
2022-02-15 17:04:57 +00:00
Wes Lambert
3df58eadd1
Modify logic to include custom templates
2022-02-15 17:00:24 +00:00
weslambert
1a53ec4372
Fix malformed copy/paste
2022-02-15 11:14:10 -05:00
Wes Lambert
dce3b7a874
Update defaults file to include ES index templates
2022-02-15 15:53:07 +00:00
Jason Ertel
377fe1987d
Merge branch 'dev' into kilo
2022-02-15 07:49:26 -05:00
Jason Ertel
d97423e9f8
Enable MFA support
2022-02-15 07:49:12 -05:00
Wes Lambert
8e389bf6e5
Add ES template map file
2022-02-14 15:38:32 +00:00
Wes Lambert
ebce67060f
Initial template refactor
2022-02-14 15:20:33 +00:00
James Conroy
a43ac2aea2
Move the jinja endraw directive below is_tty
...
This will prevent jninja from interpreting the shell string length
expansion as the start of jninja comments
2022-02-12 12:25:24 -06:00
James Conroy
95b4f7b4ef
Update the PADDING_CONSTENT to 15
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3046e811f0
Use spaces to define centerd justification output
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
6a1e586b8c
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
01346cbb06
Changed color variables to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:24 -06:00
James Conroy
3adb6c1389
Renamed colors to attributes
...
Also correctly used tput to assign blue color
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dabae3888f
Renamed colors to attributes
...
As suggested by rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
c69e968790
Renamed Colors to Attributes
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
dfcabb5722
Seperate bold attribute from colors
...
As suggested by @rwwiv
Co-authored-by: William Wernert <william.wernert@gmail.com >
2022-02-12 12:25:23 -06:00
James Conroy
b9b3876069
Exit with an error code if the user isn't root
2022-02-12 12:25:23 -06:00
James Conroy
bfcfad2e7d
Check for tty in main
...
So that the value is set every time it is checked
2022-02-12 12:25:23 -06:00
James Conroy
163182c858
Don't set the padding constant if not in a tty
...
This will preserve the original width from before my changes
2022-02-12 12:25:23 -06:00
James Conroy
6b4549499d
Don't split lines after standalone tests
...
This is to make the formatting consistent with the rest of the scripts
2022-02-12 12:25:23 -06:00
James Conroy
68a5826d70
Always print a line of '-'
...
Even when not printing to a tty
This is behavior preferred by the team
2022-02-12 12:25:22 -06:00
James Conroy
daa73c8845
Removed MYNAME variable
...
Preferring to just use the value of $0 instead
2022-02-12 12:25:22 -06:00
James Conroy
7f694c17ed
Revert improvements to usage function
...
Made to make it more consistent with the rest of the scripts in
Security Onion
2022-02-12 12:25:22 -06:00
James Conroy
fd9a03a77f
Added Changes Suggested by Reviewer
...
Added a missing semi colon between a local variable's declaration and
assignment
Removed an unused return value
Made a TODO more descriptive
2022-02-12 12:25:22 -06:00
James Conroy
2993a20947
Moved line declaration out of tty conditional
...
This way it will always be set to ""
2022-02-12 12:25:22 -06:00
James Conroy
ac5527e1ab
Added Comments for future enhancements
2022-02-12 12:25:22 -06:00
James Conroy
715f9da6e2
Reworked tty detection and status printing
...
I was able to reduce the line count and make the script more reliable
2022-02-12 12:25:22 -06:00
James Conroy
caa06b026f
Refactored to reduce length and number of lines
2022-02-12 12:25:21 -06:00
James Conroy
a048de65ca
Print help message if not running as root
2022-02-12 12:25:21 -06:00
James Conroy
f807471a17
Only print color codes if we're printing to a tty
...
If we're not printing to a tty the escape sequences can only clutter the
screen.
Also removed a redundant function to print lines if not printing to a
tty. It was only called if docker wasn't running, not if the output
wasn't a tty.
2022-02-12 12:25:21 -06:00
James Conroy
81122d0693
Updated the useage function to use printf
...
Using a hear doc means we have to exactly specify the formatting. Useing
printf handles formatting for us
2022-02-12 12:25:21 -06:00
Josh Brower
1e5b9ef0bf
IDH - Enable Filebeat
2022-02-10 11:37:10 -05:00
Josh Brower
b66472eced
IDH - disable nginx
2022-02-09 14:56:56 -05:00
Josh Brower
f31fbbf1ed
IDH - states allowed
2022-02-09 13:57:18 -05:00
William Wernert
1fee5e6a60
Merge pull request #7162 from Security-Onion-Solutions/rwwiv-contributing-patch-1
...
Also merge CONTRIBUTING.md changes to dev
2022-02-09 11:59:00 -05:00
Josh Brower
30c40ed3d7
IDH Initial Support
2022-02-09 10:37:47 -05:00
Mike Reeves
d63fe73c90
Merge pull request #7157 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update to 7.17.0
2022-02-09 09:46:25 -05:00
Mike Reeves
51bd266717
Update to 7.17.0
2022-02-09 09:44:28 -05:00
weslambert
380fa7d0c8
Merge pull request #7153 from Security-Onion-Solutions/fix/dtc_event_mappings
...
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 16:36:49 -05:00
Wes Lambert
9b841fd872
Add 'event.created' and 'event.ingested' keyword mapping
2022-02-08 21:34:32 +00:00
weslambert
c216457a3e
Merge pull request #7147 from Security-Onion-Solutions/fix/ct_snyk
...
Add Snyk component template
2022-02-08 10:25:27 -05:00
Wes Lambert
c2c4e4df17
Add Snyk component template
2022-02-08 15:23:43 +00:00
weslambert
7be1549d41
Merge pull request #7146 from Security-Onion-Solutions/feature/additional_dtc_ct
...
Additional component templates
2022-02-08 10:12:31 -05:00
Josh Brower
ac8e06e79b
Initial support - IDH Node
2022-02-08 09:08:52 -05:00
Josh Brower
a3602c9eb9
Initial support - IDH Node
2022-02-08 08:24:15 -05:00
Wes Lambert
f9a50d33c3
Add new templates
2022-02-08 13:17:23 +00:00
Wes Lambert
2951e12c96
Remove snyk component template for now and fix folder structure
2022-02-08 13:16:59 +00:00
Wes Lambert
6d0ca6fcbb
Fix mangled key name/typo
2022-02-08 12:59:07 +00:00
Wes Lambert
2dd5db15b6
Add component and index template listing scripts
2022-02-08 03:40:42 +00:00
Wes Lambert
5090854d4d
Add additional component templates and index template references
2022-02-08 03:03:55 +00:00
Josh Brower
37b17b8821
Initial support - IDH Node
2022-02-07 19:27:51 -05:00
Josh Brower
f590bc43a6
Initial support - IDH Node
2022-02-07 19:09:27 -05:00
Josh Brower
7a9cb6d110
Initial support - IDH Node
2022-02-07 16:49:11 -05:00
weslambert
b41c5439c6
Merge pull request #7141 from Security-Onion-Solutions/fix/index_template_mapping_reference
...
Add mapping references for new component templates to index templates
2022-02-07 15:06:19 -05:00
Wes Lambert
1366e5288e
Add mappings references for new component templates to index templates
2022-02-07 19:54:23 +00:00
weslambert
f9196a8228
Merge pull request #7140 from Security-Onion-Solutions/feature/dtc_new_mappings
...
New DTC/Component Template Mappings
2022-02-07 14:47:07 -05:00
Wes Lambert
03bfb052ed
Add component templates for Elasticsearch, Kibana, Logstash, Netflow, Suricata, and Zeek
2022-02-07 19:42:24 +00:00
Josh Brower
9b1fac8417
Initial support - IDH Node
2022-02-07 14:36:40 -05:00
weslambert
c9b40d8569
Merge pull request #7136 from Security-Onion-Solutions/feature/so_es_indices_list_sort
...
Sort index listing alphabetically and add header
2022-02-07 09:34:58 -05:00
Wes Lambert
50215c550b
Sort index listing alphabetically and add header (@gebhard73)
2022-02-07 14:31:42 +00:00
Josh Patterson
ee17064585
Merge pull request #7122 from Security-Onion-Solutions/soup_docker_iso
...
Soup docker iso
2022-02-07 09:29:35 -05:00
Josh Patterson
e0c0eba24e
Update soup
2022-02-07 09:23:30 -05:00
Josh Patterson
7d09d1f7e2
Update soup
2022-02-07 09:22:43 -05:00
Mike Reeves
77fc9df448
Merge pull request #7134 from Security-Onion-Solutions/mastermerger
...
Mastermerger
2022-02-07 08:38:27 -05:00
Mike Reeves
abd121733f
Merge branch 'master' into mastermerger
2022-02-07 08:34:17 -05:00
m0duspwnens
7c31eb1288
mount iso at different point
2022-02-04 16:07:06 -05:00
m0duspwnens
780aace854
set AGDOCKER
2022-02-04 15:44:25 -05:00
m0duspwnens
eb0696b425
update dockers if -f used
2022-02-04 15:36:44 -05:00
m0duspwnens
267ef354c2
unmount iso after updating dockers
2022-02-04 15:09:35 -05:00
m0duspwnens
23fbf140ba
soup with dockers from iso
2022-02-04 15:06:42 -05:00
weslambert
d0b54a3a34
Merge pull request #7119 from Security-Onion-Solutions/feature/dtc_additional
...
Add additional scan and rule fileset mappings
2022-02-04 14:14:20 -05:00
Wes Lambert
317f6471d8
Add additional scan and rule filset mappings
2022-02-04 19:05:09 +00:00
weslambert
08c7181f1a
Merge pull request #7118 from Security-Onion-Solutions/fix/dtc_file_mappings
...
Fix/dtc file mappings
2022-02-04 13:22:11 -05:00
Wes Lambert
1ce8bb3523
Fix winlog mapping reference reversion
2022-02-04 18:14:01 +00:00
Wes Lambert
5e03b1a5de
Fix reference for file mappings in template
2022-02-04 18:11:03 +00:00
weslambert
898db542bf
Merge pull request #7117 from Security-Onion-Solutions/feature/winlog_dtc_mappings
...
Add winlog mappings
2022-02-04 12:16:16 -05:00
weslambert
66452b14ef
Merge pull request #7116 from Security-Onion-Solutions/fix/endgame_mappings
...
Fix EG template and mappings
2022-02-04 12:16:07 -05:00
Wes Lambert
69cb83cac9
Add winlog mappings
2022-02-04 17:08:26 +00:00
Wes Lambert
f3902cf77d
Fix EG template and mappings
2022-02-04 16:00:16 +00:00
weslambert
1af63edc6b
Merge pull request #7115 from Security-Onion-Solutions/feature/additional_dtc_mappings
...
Additional DTC mapping changes
2022-02-04 10:46:47 -05:00
Wes Lambert
a3031b2b5c
Additional DTC mapping changes
2022-02-04 15:38:51 +00:00
weslambert
1edc1dd842
Merge pull request #7096 from Security-Onion-Solutions/fix/dtc-ct-keyword-subfield
...
Add more DTC transition mappings
2022-02-03 12:35:34 -05:00
Wes Lambert
1ce386bb7f
Add more DTC transition mappings
2022-02-03 17:33:05 +00:00
weslambert
c7d23df000
Merge pull request #7076 from Security-Onion-Solutions/fix/zeek_dns_answers_name
...
Rename dns.answers to prevent field conflict
2022-02-03 12:22:26 -05:00
weslambert
c5b5c5858e
Rename to prevent field conflict
2022-02-02 14:31:46 -05:00
weslambert
5e9e0d971b
Merge pull request #7070 from Security-Onion-Solutions/feature/composable_templates
...
Initial composable template configuration and base mappings
2022-02-02 10:25:15 -05:00
Wes Lambert
9db1510b0e
Initial composable template configuration and base mappings
2022-02-02 02:08:31 +00:00
Jason Ertel
1bac031975
Merge pull request #7058 from Security-Onion-Solutions/kilo
...
Bump to 2.3.110
2022-02-01 15:04:48 -05:00
Jason Ertel
c5d6f09320
Bump to 2.3.110
2022-02-01 15:03:41 -05:00
abesinger
31d22e717d
Updated syslog pipeline, resolves #6912 . Also cleaned up formatting to make it more readable.
2022-01-19 18:45:26 -06:00