Mike Reeves
2f3b92887b
Merge pull request #12714 from Security-Onion-Solutions/2.3.300
...
2.3.300
2024-04-01 11:26:43 -04:00
Mike Reeves
d15678f638
Update VERIFY_ISO.md
2024-04-01 11:25:29 -04:00
Mike Reeves
93c29bc1da
2.3.300
2024-04-01 11:22:31 -04:00
Mike Reeves
56263675f6
Merge pull request #12692 from Security-Onion-Solutions/2.3.300
...
2.3.300
2024-03-29 09:55:15 -04:00
Mike Reeves
1599e69851
2.3.300
2024-03-29 09:43:50 -04:00
weslambert
5ae7e27ace
Merge pull request #12677 from Security-Onion-Solutions/fix/strelka_yara_ignore
...
Ignore more rules
2024-03-27 16:17:34 -04:00
weslambert
945d2abeed
Ignore more rules
2024-03-27 16:13:30 -04:00
Doug Burks
68eb2d3ceb
Merge pull request #12614 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.300
2024-03-19 16:48:25 -04:00
Doug Burks
595f965183
Update soup for 2.3.300
2024-03-19 16:44:01 -04:00
Jason Ertel
834d18b77c
Merge pull request #12603 from Security-Onion-Solutions/jertel/ld
...
reschedule lock jobs
2024-03-18 09:41:21 -04:00
Jason Ertel
4849da1c11
Merge branch 'master' into jertel/ld
2024-03-18 09:31:17 -04:00
Jason Ertel
fbbddc2aaf
Merge pull request #12602 from Security-Onion-Solutions/jertel/lock
...
re-schedule lock jobs
2024-03-18 09:29:04 -04:00
Jason Ertel
4b24500b79
re-schedule lock jobs
2024-03-18 07:37:42 -04:00
Mike Reeves
f6a765addc
Merge pull request #12467 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update VERSION
2024-02-29 14:13:44 -05:00
Mike Reeves
8b56c0a744
Update VERSION
2024-02-29 14:12:35 -05:00
Mike Reeves
b31d38e734
Merge pull request #12463 from Security-Onion-Solutions/dev
...
2.3.290
2024-02-29 14:07:11 -05:00
Mike Reeves
b1db4137d0
Merge pull request #12462 from Security-Onion-Solutions/2.3.290
...
2.3.290
2024-02-29 09:15:41 -05:00
Mike Reeves
44ef164713
2.3.290
2024-02-29 09:08:37 -05:00
Jason Ertel
43f7dce297
Merge pull request #12407 from Security-Onion-Solutions/jertel/mergem
...
Jertel/mergem
2024-02-21 13:18:08 -05:00
Jason Ertel
4e4a4686f1
Merge branch 'master' into jertel/mergem
2024-02-21 13:14:29 -05:00
Jason Ertel
b5f44e48ab
Merge pull request #12403 from Security-Onion-Solutions/jertel/disctemplate
...
add message at top for clickable link
2024-02-21 12:42:04 -05:00
Jason Ertel
a44448519b
add message at top for clickable link
2024-02-21 10:53:50 -05:00
Jason Ertel
6245ee9a5b
Merge branch 'master' into jertel/disctemplate
2024-02-21 10:43:28 -05:00
Jason Ertel
49ca970076
add message at top for clickable link
2024-02-21 10:41:28 -05:00
Jason Ertel
f49fb7cbae
Merge pull request #12401 from Security-Onion-Solutions/jertel/disctemplate
...
template improvements
2024-02-21 10:39:03 -05:00
Jason Ertel
7692c9be53
template improvements
2024-02-21 10:36:07 -05:00
Jason Ertel
25ef12cdc5
Merge pull request #12395 from Security-Onion-Solutions/jertel/mergemaster
...
Jertel/mergemaster
2024-02-21 07:18:22 -05:00
Jason Ertel
2967adca90
Merge branch 'master' into jertel/mergemaster
2024-02-20 16:56:14 -05:00
Jason Ertel
d198458366
Merge pull request #12392 from Security-Onion-Solutions/jertel/glm_master
...
thread locking
2024-02-20 16:55:16 -05:00
Jason Ertel
9e98b409a5
thread locking
2024-02-20 16:00:41 -05:00
Doug Burks
ba8f729976
Merge pull request #12335 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.290
2024-02-09 11:18:59 -05:00
Doug Burks
5b67795c23
Update soup for 2.3.290
2024-02-09 11:12:43 -05:00
Jason Ertel
483bf60ae3
Merge pull request #12233 from Security-Onion-Solutions/jertel/23guidelines
...
Update 2-4.yml
2024-01-23 10:07:35 -05:00
Doug Burks
1a9350f60b
Update 2-4.yml
2024-01-23 10:05:59 -05:00
Doug Burks
f4afda0975
Merge pull request #12232 from Security-Onion-Solutions/dougburks-patch-1
...
Improve Github Discussions template for 2.4 category
2024-01-23 09:57:40 -05:00
Doug Burks
137372337c
Update 2-4.yml
2024-01-23 09:51:45 -05:00
Mike Reeves
1521532c60
Merge pull request #11880 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-11-28 15:33:48 -05:00
Mike Reeves
ada32967dc
Update VERSION
2023-11-28 15:30:49 -05:00
Mike Reeves
d5d2b5fbc7
Merge pull request #11879 from Security-Onion-Solutions/dev
...
2.3.280
2023-11-28 15:21:56 -05:00
Mike Reeves
84d6fcb752
Merge pull request #11878 from Security-Onion-Solutions/2.3.280
...
2.3.280
2023-11-28 15:00:34 -05:00
Mike Reeves
de9e9a2716
2.3.280
2023-11-28 14:58:25 -05:00
Josh Patterson
cec6cff19d
Merge pull request #11874 from Security-Onion-Solutions/23souphs
...
so-nginx watch managerssl to restart if changed
2023-11-27 12:48:06 -05:00
m0duspwnens
7311d6480c
so-nginx watch managerssl to restart if changed
2023-11-27 12:15:09 -05:00
Josh Patterson
f967c8e362
Merge pull request #11873 from Security-Onion-Solutions/23souphs
...
enable highstate after starting minion
2023-11-27 11:12:45 -05:00
m0duspwnens
cfad6414d2
enable highstate after starting minion
2023-11-27 11:10:39 -05:00
Josh Patterson
0fdaed9cf7
Merge pull request #11864 from Security-Onion-Solutions/import/suriinterface
...
suricata interface None if so-import
2023-11-22 10:42:43 -05:00
m0duspwnens
1dc88781f1
suricata interface None if so-import
2023-11-22 10:11:34 -05:00
Mike Reeves
0cfb8b0816
Merge pull request #11834 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update signing_policies.conf
2023-11-20 15:59:21 -05:00
Mike Reeves
c0968d3843
Update signing_policies.conf
2023-11-20 15:57:29 -05:00
Mike Reeves
3b133e87cd
Merge pull request #11831 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update signing_policies.conf
2023-11-20 15:19:42 -05:00
Mike Reeves
fee9b61ce9
Update soup
2023-11-20 15:14:25 -05:00
Mike Reeves
57612c69fe
Update signing_policies.conf
2023-11-20 15:11:50 -05:00
Mike Reeves
94accb0e8c
Update signing_policies.conf
2023-11-20 15:09:13 -05:00
Josh Patterson
3b8d1d470e
Merge pull request #11798 from Security-Onion-Solutions/m0duspwnens-patch-1
...
Update soup
2023-11-15 15:23:46 -05:00
Josh Patterson
c624a44b0e
Update soup
...
add quote
2023-11-15 15:19:54 -05:00
weslambert
bc509a0aa9
Merge pull request #11772 from Security-Onion-Solutions/upgrade/elastic_8_10_4
...
Elastic 8.10.4
2023-11-13 09:36:49 -05:00
Doug Burks
ee0ef3217f
Merge pull request #11771 from Security-Onion-Solutions/dougburks-patch-1
...
Add EOL warning to README.md
2023-11-13 09:18:50 -05:00
weslambert
18e319cbe3
Elastic 8.10.4
2023-11-13 09:17:33 -05:00
Doug Burks
3316e1261d
Add EOL warning to README.md
2023-11-13 09:16:25 -05:00
weslambert
b7cf44466c
Elastic 8.10.4
2023-11-13 09:16:23 -05:00
Mike Reeves
e321aa52a5
Merge pull request #11749 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update soup
2023-11-09 10:49:34 -05:00
Mike Reeves
07df045e79
Update soup
2023-11-09 10:38:53 -05:00
Mike Reeves
7b11ddb032
Update soup
2023-11-09 10:25:16 -05:00
Jorge Reyes
ac4428940e
Merge pull request #11561 from Security-Onion-Solutions/2.3/zeek6
...
Zeek 6 upgrade
2023-10-23 09:25:21 -04:00
reyesj2
a9457d5f53
Remove external community-id replaced with Zeek 6 built in community-id.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-17 16:02:16 -04:00
Jason Ertel
3672701dde
Merge pull request #11506 from Security-Onion-Solutions/jertel-patch-1
...
Update VERSION
2023-10-11 09:26:32 -04:00
Jason Ertel
07ed2cb3da
Update VERSION
2023-10-10 21:35:48 -04:00
Mike Reeves
3839e52401
Merge pull request #11374 from Security-Onion-Solutions/dev
...
2.3.270
2023-10-06 16:40:28 -04:00
Mike Reeves
b005a10a8e
Merge pull request #11373 from Security-Onion-Solutions/2.3.270
...
2.3.270
2023-09-22 12:59:04 -04:00
Mike Reeves
752ff5917f
2.3.270
2023-09-22 12:45:46 -04:00
Mike Reeves
815e5d53a6
Merge pull request #11367 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-09-21 09:40:58 -04:00
Mike Reeves
a967db8152
Update soup
2023-09-21 09:38:05 -04:00
Jason Ertel
7835cb6a7a
Merge pull request #11360 from Security-Onion-Solutions/jertel/vol
...
Jertel/vol
2023-09-20 08:29:43 -04:00
Jason Ertel
07b92eef9e
vol sprawl
2023-09-19 17:22:42 -04:00
Jason Ertel
8855619453
vol sprawl
2023-09-19 12:52:28 -04:00
Doug Burks
7763218b71
Merge pull request #11287 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.270
2023-09-11 09:08:21 -04:00
Doug Burks
29f12fac90
Update soup for 2.3.270
2023-09-11 09:05:19 -04:00
Doug Burks
1a9f8f0bc2
Merge pull request #11228 from Security-Onion-Solutions/master
...
Merge master to dev for updated 2.4 discussion template
2023-08-31 10:19:45 -04:00
Doug Burks
3e5f354d8b
Merge pull request #11227 from Security-Onion-Solutions/dougburks-patch-1
...
Update 2-4.yml discussion template with additional fields for CPU, RAM, and storage
2023-08-31 10:16:55 -04:00
Doug Burks
a1b76d2cd3
Update 2-4.yml
2023-08-31 10:12:47 -04:00
weslambert
43e402fad4
Merge pull request #11187 from Security-Onion-Solutions/fix/kibana_migration_version
...
Remove migration version
2023-08-28 11:48:58 -04:00
weslambert
170b408feb
Remove migration version
2023-08-28 11:26:35 -04:00
weslambert
e55725cca4
Merge pull request #11183 from Security-Onion-Solutions/feature/elastic_8_8_2
...
Elastic 8.8.2
2023-08-28 09:49:34 -04:00
weslambert
2b9f6b26d8
Elastic 8.8.2
2023-08-28 09:42:23 -04:00
weslambert
f10b67599e
Elastic 8.8.2
2023-08-28 09:41:36 -04:00
Doug Burks
ea03613df3
Merge pull request #11103 from Security-Onion-Solutions/master
...
Merge 2.4 discussion template to dev
2023-08-18 16:21:45 -04:00
Doug Burks
8ffb6b9e1c
Merge pull request #11102 from Security-Onion-Solutions/dougburks-patch-1
...
Create template for Github Discussions in the 2.4 Category
2023-08-18 16:19:04 -04:00
Doug Burks
ffadd4aa42
Create 2-4.yml
2023-08-18 16:13:31 -04:00
Mike Reeves
78ccea12b1
Merge pull request #10919 from Security-Onion-Solutions/master
...
Soup
2023-08-02 12:27:08 -04:00
Doug Burks
8bef5a84f7
Merge pull request #10916 from Security-Onion-Solutions/supersoup
...
Supersoup
2023-08-02 11:58:58 -04:00
Mike Reeves
679775a7d0
Add supersoup mode
2023-08-02 11:21:28 -04:00
Mike Reeves
3f5f93059e
Add supersoup mode
2023-08-02 11:20:23 -04:00
Mike Reeves
d2ae8f81e1
Add supersoup mode
2023-08-02 10:49:51 -04:00
Mike Reeves
fcc369d4b9
Add supersoup mode
2023-08-02 10:46:54 -04:00
Mike Reeves
9bb28fd0b5
Add supersoup mode
2023-08-02 10:31:55 -04:00
Mike Reeves
93c5e6a9e8
Add supersoup mode
2023-08-02 09:49:14 -04:00
Mike Reeves
6a7e756a37
Add supersoup mode
2023-08-02 09:47:35 -04:00
Mike Reeves
f6b9dec2ae
Add supersoup mode
2023-08-02 09:45:29 -04:00
Mike Reeves
37386057d9
Merge pull request #10622 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-06-20 14:52:03 -04:00
Mike Reeves
800945c3b6
Update VERSION
2023-06-20 14:50:29 -04:00
Mike Reeves
b56c0c5e64
Merge pull request #10621 from Security-Onion-Solutions/dev
...
2.3.260
2023-06-20 14:36:16 -04:00
Mike Reeves
01b986cd50
Merge pull request #10620 from Security-Onion-Solutions/2.3.260
...
2.3.260
2023-06-20 09:37:56 -04:00
Mike Reeves
3e862151f3
2.3.260
2023-06-20 09:18:30 -04:00
Doug Burks
15b3982930
Merge pull request #10610 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.260
2023-06-16 13:10:42 -04:00
Doug Burks
3d687f0404
Update soup for 2.3.260
2023-06-16 12:55:52 -04:00
weslambert
e74c2fa1b0
Merge pull request #10605 from Security-Onion-Solutions/fix/analyzer_dependencies
...
Update dependencies
2023-06-16 07:51:50 -04:00
Wes
ffc91393e7
Update pulsedive dependencies
2023-06-15 22:14:41 +00:00
Wes
d0ab2db312
Update dependencies
2023-06-15 21:03:40 +00:00
weslambert
4906068c7f
Merge pull request #10495 from Security-Onion-Solutions/foxtrot
...
Update requests and whoisit
2023-06-05 10:53:49 -04:00
Wes
ef8eece53b
Update dependencies
2023-06-05 13:45:44 +00:00
weslambert
660a50c08d
Update whoisit to 2.7.0
2023-06-03 08:53:02 -04:00
Wes
5d326a3c32
Update dependencies
2023-06-01 16:26:04 +00:00
weslambert
2a907d3de3
Update version to 2.3.260
2023-06-01 12:04:35 -04:00
weslambert
33134b1814
Update requests and whist
2023-06-01 12:03:58 -04:00
weslambert
b0962da758
Update version to 2.3.0-foxtrot
2023-05-31 08:50:51 -04:00
weslambert
8148fd9e56
Merge pull request #10434 from Security-Onion-Solutions/foxtrot
...
Strelka 0.23.05.22 - Remove ScanRuby scanner
2023-05-26 12:45:03 -04:00
weslambert
1ee332b55b
Update version to 2.3.260
2023-05-26 08:31:11 -04:00
weslambert
873632ec4f
Remove ScanRuby scanner
2023-05-25 17:23:44 -04:00
weslambert
f8068d7975
Update version to 2.3.0-foxtrot
2023-05-25 16:14:29 -04:00
weslambert
a79ebea5c3
Update version value to 2.3.250-foxtrot
2023-05-25 15:29:07 -04:00
weslambert
2fdc3874ca
Update version to foxtrot
2023-05-25 14:35:52 -04:00
Mike Reeves
7f52c2015d
Merge pull request #10408 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-05-22 15:25:05 -04:00
Mike Reeves
548e1e6937
Update VERSION
2023-05-22 15:23:52 -04:00
Mike Reeves
c949101d0f
Merge pull request #10406 from Security-Onion-Solutions/dev
...
2.3.250
2023-05-22 15:14:23 -04:00
Mike Reeves
7c1f19b91f
Merge pull request #10405 from Security-Onion-Solutions/2.3.250
...
2.3.250
2023-05-22 11:39:40 -04:00
Mike Reeves
598d6b025e
2.3.250
2023-05-22 11:37:13 -04:00
Jason Ertel
4d0d0714a5
Merge pull request #10401 from Security-Onion-Solutions/jertel/fixwhoisit
...
use the same requests version that's already packaged with the analyzer
2023-05-20 08:45:29 -04:00
Jason Ertel
cb0c078955
use the same requests version that's already packaged with the analyzer
2023-05-19 23:56:39 -04:00
Jason Ertel
aa426244bf
Merge pull request #10394 from Security-Onion-Solutions/jertel/fixwhoisit
...
fix lib dependency issue with whoisit
2023-05-19 14:34:32 -04:00
Jason Ertel
97b2ae8d82
fix lib dependency issue with whoisit
2023-05-19 14:23:12 -04:00
Doug Burks
7047125759
Merge pull request #10386 from Security-Onion-Solutions/2.3/elastic-8.7.1
...
UPGRADE: Elastic 8.7.1 #10269
2023-05-18 15:27:10 -04:00
Doug Burks
43f73abd4d
Update so-kibana-config-load
2023-05-18 15:18:27 -04:00
Doug Burks
51a8684850
Update config_saved_objects.ndjson
2023-05-18 15:17:36 -04:00
Doug Burks
b3c5239787
Merge pull request #10333 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.250
2023-05-11 08:28:53 -04:00
Doug Burks
0f562279ee
Update soup for 2.3.250
2023-05-11 07:26:58 -04:00
weslambert
834f45c0f2
Merge pull request #10286 from Security-Onion-Solutions/fix/strelka_ignore_yara_rules
...
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-08 11:58:11 -04:00
weslambert
d4cf9efeca
Merge pull request #10303 from Security-Onion-Solutions/fix/kibana_pivot_to_pcap_url
...
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 11:55:22 -04:00
Doug Burks
c620983b4a
Merge pull request #10299 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:47:49 -04:00
Wes
ed19c139ea
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 13:44:36 +00:00
Doug Burks
af85c6261b
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:41:26 -04:00
weslambert
e9f58269cd
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-04 16:13:59 -04:00
Jason Ertel
208c3d96e9
Merge pull request #10266 from Security-Onion-Solutions/jertel/aws
...
more detection improvements
2023-05-02 08:17:13 -04:00
Jason Ertel
1e888a5d9e
more detection improvements
2023-05-02 07:56:11 -04:00
Jason Ertel
f7ae8d449e
Merge pull request #10259 from Security-Onion-Solutions/jertel/simplifycd
...
simplify cloud detection
2023-05-01 11:33:26 -04:00
Jason Ertel
195274bb11
Merge branch 'dev' into jertel/simplifycd
2023-05-01 11:29:39 -04:00
Jason Ertel
a0ac1d2274
simplify cloud detection
2023-05-01 11:04:43 -04:00
Mike Reeves
3dd39c7f59
Merge pull request #10234 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2023-04-26 14:41:04 -04:00
Mike Reeves
ba846bbf35
Update VERSION
2023-04-26 14:39:31 -04:00
Mike Reeves
0baf8e9471
Merge pull request #10227 from Security-Onion-Solutions/dev
...
2.3.240
2023-04-26 14:31:56 -04:00
Mike Reeves
e30fec7af0
Merge pull request #10226 from Security-Onion-Solutions/2.3.240
...
2.3.240
2023-04-26 09:58:18 -04:00
Mike Reeves
884f5cd3a6
2.3.240
2023-04-26 09:55:19 -04:00
Jason Ertel
11babd2f1c
Merge pull request #10221 from Security-Onion-Solutions/jertel/imdsv2to
...
timeout more quickly on aws imdsv2 detection
2023-04-26 07:59:13 -04:00
Jason Ertel
b440ab5c02
timeout more quickly on aws imdsv2 detection
2023-04-26 07:57:23 -04:00
Jason Ertel
91d667c3ad
Merge pull request #10200 from Security-Onion-Solutions/jertel/imdsv2_23
...
Detect cloud install on forced imdsv2 instances
2023-04-25 09:46:39 -04:00
Jason Ertel
f04c01b28c
Merge pull request #10204 from Security-Onion-Solutions/jertel/2.3.240_soup
...
soup update for 2.3.240
2023-04-25 09:46:28 -04:00
Jason Ertel
71ab8ddf1d
soup update for 2.3.240
2023-04-25 09:42:14 -04:00
Jason Ertel
f1f79d55dc
Detect cloud install on forced imdsv2 instances
2023-04-24 16:26:23 -04:00
Mike Reeves
db1bd16758
Merge pull request #10142 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-04-17 10:56:59 -04:00
Mike Reeves
ef73834d58
Update VERSION
2023-04-17 10:55:38 -04:00
Mike Reeves
3891548d6d
Merge pull request #10141 from Security-Onion-Solutions/dev
...
2.3.230 Release
2023-04-17 10:47:32 -04:00
Mike Reeves
9d6ed8b9b2
Merge pull request #10140 from Security-Onion-Solutions/2.3.230
...
2.3.230
2023-04-17 10:26:59 -04:00
Mike Reeves
ef92815a08
2.3.230
2023-04-17 10:22:39 -04:00
Doug Burks
19b5cdcb0e
Merge pull request #10119 from Security-Onion-Solutions/2.3/fix-suricata-dns
...
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 11:00:13 -04:00
Doug Burks
272b345892
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 10:52:37 -04:00
Mike Reeves
7fad9d60ef
Merge pull request #10113 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2023-04-12 10:32:43 -04:00
Mike Reeves
46fc62b8dc
Update init.sls
2023-04-12 10:29:54 -04:00
Doug Burks
ca9a93a4b0
Merge pull request #9998 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.230
2023-03-24 12:38:39 -04:00
Doug Burks
aa2e18fca9
Update soup for 2.3.230
2023-03-24 12:31:51 -04:00
Mike Reeves
7e4ce7b81d
Merge pull request #9877 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2023-03-01 16:37:14 -05:00
Mike Reeves
e5c0058dd1
Update HOTFIX
2023-03-01 16:36:08 -05:00
Mike Reeves
07c5b541a3
Merge pull request #9876 from Security-Onion-Solutions/master
...
Master to Dev
2023-03-01 16:35:48 -05:00
Mike Reeves
b756b8ea32
Merge pull request #9873 from Security-Onion-Solutions/hotfix/2.3.220
...
Hotfix/2.3.220
2023-03-01 16:32:49 -05:00
Mike Reeves
5b46e57ae1
Merge pull request #9875 from Security-Onion-Solutions/hotfix23220
...
Hotfix for 2.3.220
2023-03-01 16:14:26 -05:00
Mike Reeves
924009afb8
Hotfix for 2.3.220
2023-03-01 16:11:38 -05:00
Mike Reeves
8f5bacc510
Merge pull request #9874 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2023-03-01 14:52:04 -05:00
Mike Reeves
d5e48a7eca
Update init.sls
2023-03-01 14:50:55 -05:00
Mike Reeves
6346a92f0f
Merge pull request #9872 from Security-Onion-Solutions/hotfix23220
...
Hotfix for 2.3.220
2023-03-01 14:20:47 -05:00
Mike Reeves
13a566a9a2
Hotfix for 2.3.220
2023-03-01 14:19:04 -05:00
Mike Reeves
063c6599d8
Hotfix for 2.3.220
2023-03-01 14:17:22 -05:00
weslambert
9fb315c99d
Merge pull request #9870 from Security-Onion-Solutions/fix/curator_configuration_update_8.0.x
...
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 10:19:32 -05:00
Wes
6e0891e586
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 15:16:52 +00:00
Mike Reeves
3a96d59899
Merge pull request #9869 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2023-03-01 10:10:47 -05:00
Mike Reeves
5fa945956e
Update HOTFIX
2023-03-01 10:09:19 -05:00
Mike Reeves
b0aab96cf5
Merge pull request #9858 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-02-27 09:40:39 -05:00
Mike Reeves
11def72790
Update VERSION
2023-02-27 09:39:52 -05:00
Mike Reeves
2ca2724a4c
Merge pull request #9857 from Security-Onion-Solutions/dev
...
2.3.220
2023-02-27 09:35:14 -05:00
Mike Reeves
884883a225
Merge pull request #9856 from Security-Onion-Solutions/2.3.220
...
2.3.220
2023-02-27 09:26:28 -05:00
Mike Reeves
5c8ba3af65
2.3.220
2023-02-27 09:23:33 -05:00
Josh Brower
4b5d314adf
Merge pull request #9833 from Security-Onion-Solutions/FleetDMConfigFix
...
Remove unsupported config option
2023-02-21 16:36:58 -05:00
Josh Brower
6e637f559c
Remove unsupported config option
2023-02-21 16:35:11 -05:00
Doug Burks
cc5304e9f7
Merge pull request #9806 from Security-Onion-Solutions/2.3/upgrade-elastic-8.6.2
...
2.3/upgrade elastic 8.6.2
2023-02-17 08:03:01 -05:00
Doug Burks
002403055d
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:04:57 -05:00
Doug Burks
b80b80e825
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:03:47 -05:00
Josh Brower
c539d53a02
Merge pull request #9791 from Security-Onion-Solutions/fleetsapassword
...
Fix edge case
2023-02-15 15:30:49 -05:00
Josh Brower
3a22978c2b
Fix password gen edge case
2023-02-15 15:25:35 -05:00
Doug Burks
5b1461e9a1
Merge pull request #9782 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.220
2023-02-14 08:44:09 -05:00
Doug Burks
69f889dbd9
Update soup for 2.3.220
2023-02-14 08:42:35 -05:00
Josh Brower
aefe1cceb8
Merge pull request #9758 from Security-Onion-Solutions/fleetupgrade
...
Fix link for FleetDM standalone nodes
2023-02-09 14:10:45 -05:00
Josh Brower
b7e97eceb3
Fix link for FleetDM standalone nodes
2023-02-09 14:08:48 -05:00
Josh Brower
450e02e874
Merge pull request #9749 from Security-Onion-Solutions/fleetdm-fix
...
FleetDM Upgrade Fix
2023-02-09 09:30:22 -05:00
Josh Brower
09bebf08d6
Fix FleetDM SOC Link
2023-02-09 09:10:50 -05:00
Josh Brower
4dd54cea6c
Use correct variable name
2023-02-08 16:58:47 -05:00
Josh Brower
e07f4bd0ed
Workaround for FleetDM PW Req
2023-02-08 13:03:33 -05:00
Mike Reeves
6adb586bb4
Merge pull request #9734 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-02-07 09:07:06 -05:00
Mike Reeves
2f99821736
Update VERSION
2023-02-07 09:05:16 -05:00
Mike Reeves
db27c22158
Merge pull request #9730 from Security-Onion-Solutions/dev
...
2.3.210
2023-02-07 08:58:36 -05:00
Mike Reeves
2ff284fc7f
Merge pull request #9729 from Security-Onion-Solutions/2.3.210
...
2.3.210
2023-02-06 16:36:06 -05:00
Mike Reeves
5d0a3ef205
2.3.210
2023-02-06 16:32:45 -05:00
Mike Reeves
ac9c10dd3a
2.3.210
2023-02-06 15:46:27 -05:00
weslambert
d4d67b545d
Merge pull request #9699 from Security-Onion-Solutions/fix/strelka_yara_exclusion
...
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:38:29 -05:00
weslambert
2dced35800
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:24:20 -05:00
Josh Patterson
c2a04a79c5
Merge pull request #9697 from Security-Onion-Solutions/23mysqlpy
...
23mysqlpy
2023-02-01 14:17:24 -05:00
m0duspwnens
d43346a084
hold python mysql
2023-02-01 14:11:27 -05:00
m0duspwnens
0c4a27d120
lock python36-mysql-1.3.12-2.el7 version
2023-02-01 12:33:19 -05:00
Doug Burks
b4530ffffe
Merge pull request #9681 from Security-Onion-Solutions/fix/suricata-dhcp-parsing-2.3
...
2.3: Improve Suricata DHCP parsing and dashboard
2023-01-31 10:18:49 -05:00
Doug Burks
d12aa0ed56
Move host.domain table to end of DHCP tables
2023-01-31 07:14:18 -05:00
Doug Burks
17bcf50ccb
update Suricata DHCP parser to set server.address
2023-01-30 15:57:47 -05:00
Doug Burks
48401f6a3f
Merge pull request #9675 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.210
2023-01-30 09:17:47 -05:00
Doug Burks
a96825f43e
Update soup for 2.3.210
2023-01-30 09:16:00 -05:00
Doug Burks
2d48ae7bca
Merge pull request #9656 from Security-Onion-Solutions/2.3/elastic-8.6.1
...
UPGRADE: Elastic 8.6.1 #9594 (2.3)
2023-01-26 16:24:33 -05:00
Doug Burks
0ff519ed2f
Update to Elastic 8.6.1
2023-01-26 16:09:13 -05:00
Doug Burks
127533492f
Update to Elastic 8.6.1
2023-01-26 16:08:15 -05:00
Mike Reeves
7d4b4a8bd4
Merge pull request #9585 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-01-17 09:40:46 -05:00
Mike Reeves
e9fa84d71b
Update VERSION
2023-01-17 09:39:35 -05:00
Mike Reeves
cd8cf4a1ac
Merge pull request #9578 from Security-Onion-Solutions/dev
...
2.3.200
2023-01-17 09:26:23 -05:00
Mike Reeves
9718e61a6a
Merge pull request #9576 from Security-Onion-Solutions/2.3.200
...
2.3.200
2023-01-13 16:12:20 -05:00
Mike Reeves
22ec638e85
2.3.200
2023-01-13 16:08:27 -05:00
Doug Burks
7b0c22f967
Merge pull request #9568 from Security-Onion-Solutions/fix/soup-thehive-errors
...
soup should continue even if thehive errors
2023-01-12 13:28:41 -05:00
Doug Burks
672cab858e
Continue even if thehive errors
2023-01-12 12:48:16 -05:00
Josh Brower
29312d595b
Merge pull request #9559 from Security-Onion-Solutions/idh-skins
...
Fix mispelling
2023-01-11 11:04:29 -05:00
Josh Brower
b54f2e8752
Fix mispelling
2023-01-11 10:59:50 -05:00
Josh Brower
1470e120ef
Merge pull request #9540 from Security-Onion-Solutions/idhskins
...
bug fix - idh skins
2023-01-09 15:49:04 -05:00
Josh Brower
2c747ec837
make sure dir is created
2023-01-09 13:46:10 -05:00
Josh Brower
8cb5cd5fee
Merge pull request #9214 from Security-Onion-Solutions/idhskins
...
Custom IDH HTTP Skins
2023-01-06 15:14:14 -05:00
Doug Burks
a4bae77973
Merge pull request #9271 from Njinx/dev
...
so-status runs some code before checking for root privileges
2023-01-04 16:05:34 -05:00
Doug Burks
96a568f57f
Merge pull request #9515 from Security-Onion-Solutions/fix/so-common-references-2.3
...
fix so-common references
2023-01-04 14:31:57 -05:00
doug
7dcdcc18a5
fix so-common references
2023-01-04 14:28:47 -05:00
Doug Burks
10fc8de9f9
Merge pull request #9513 from Security-Onion-Solutions/fix/jinja-whitespace-2.3
...
fix jinja whitespace 2.3
2023-01-04 13:56:17 -05:00
doug
3482df5ee1
fix jinja whitespace
2023-01-04 13:33:51 -05:00
Doug Burks
9ea3d6bb1f
Merge pull request #9512 from Security-Onion-Solutions/fix/copyright-year-2023
...
Update Copyright year
2023-01-04 12:50:30 -05:00
doug
a67a254edc
update Copyright year
2023-01-04 12:44:18 -05:00
Doug Burks
08a5a9ab31
Merge pull request #9510 from Security-Onion-Solutions/fix/sysmon-fields-2.3
...
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:58:04 -05:00
Doug Burks
e3d32c7871
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:38:18 -05:00
weslambert
20d6ce1ce9
Merge pull request #9501 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_rita_beacon
...
Update RITA beacon parsing
2023-01-03 11:13:55 -05:00
Wes
bd114eb1c4
Update RITA beacon parsing
2023-01-03 16:01:35 +00:00
Doug Burks
55c6fc422b
Merge pull request #9497 from Security-Onion-Solutions/fix/sysmon-parsing-2.3
...
FIX: Sysmon logs are missing event.category and event.dataset #8194
2023-01-03 08:56:16 -05:00
doug
5d060f9832
update Sysmon File dashboard
2022-12-31 14:10:02 -05:00
doug
edcbfd17f5
update sysmon parser
2022-12-30 16:20:06 -05:00
Doug Burks
ff4850d9ce
Merge pull request #9452 from Security-Onion-Solutions/feature/improve-dashboards-2.3
...
FEATURE: Improve SOC Dashboards #9450 2.3
2022-12-21 15:46:21 -05:00
Doug Burks
3e1a5b6329
Improve Strelka dashboard
2022-12-21 15:34:06 -05:00
Doug Burks
b1709f3ea3
Improve Firewall dashboard
2022-12-21 15:28:41 -05:00
Doug Burks
76a73ea35c
Improve Software dashboard
2022-12-21 15:25:19 -05:00
Doug Burks
991a6ec43c
Improve Intel dashboard
2022-12-21 15:19:54 -05:00
Doug Burks
e2c0607249
Improve FTP dashboard
2022-12-21 14:36:44 -05:00
Doug Burks
82c61e6bc9
improve NIDS Alerts dashboard
2022-12-21 14:32:05 -05:00
Doug Burks
37aa779095
Minor improvements
2022-12-21 13:14:38 -05:00
Doug Burks
9e631ad63d
Improve SOC dashboards
2022-12-21 13:04:12 -05:00
Jason Ertel
fe6a55b58e
Merge pull request #9393 from Security-Onion-Solutions/jertel/soup23200
...
Move Kratos DB to /nsm
2022-12-14 14:26:19 -05:00
Jason Ertel
87cebedc85
Backup the new Kratos location
2022-12-14 14:12:47 -05:00
Jason Ertel
e66c995b1f
remove apparently unused reactor reference
2022-12-14 13:50:20 -05:00
Jason Ertel
e8a8f65ddc
fix typo
2022-12-14 12:56:25 -05:00
Jason Ertel
a7a15117f0
Improve soup wording when the script itself needs updated
2022-12-14 12:03:47 -05:00
Jason Ertel
865ba4264b
Stop backing up kratos since it now lives in /nsm. Ensure kratos is removed when re-installing.
2022-12-14 10:57:24 -05:00
Jason Ertel
6985b0ab27
Move kratos DB to /nsm
2022-12-14 10:50:24 -05:00
Mike Reeves
6e4912f759
Merge pull request #9385 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Highlander Config for Kibana
2022-12-13 13:54:30 -05:00
Mike Reeves
b0d934daf7
Update config.map.jinja
2022-12-13 13:52:13 -05:00
Doug Burks
8e50868abd
Merge pull request #9383 from Security-Onion-Solutions/fix/import-hyperlink
...
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:36:22 -05:00
Doug Burks
aa08803f03
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:23:27 -05:00
Doug Burks
bb346d531d
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:22:53 -05:00
Doug Burks
6c057d0b0a
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 12:43:54 -05:00
Doug Burks
47e43e53d9
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 12:43:10 -05:00
weslambert
a8456a4d65
Merge pull request #9369 from Security-Onion-Solutions/fix/sensoroni_analyzers_configuration_check
...
Fix localfile analyzer 'file_path' check and add new list value verification function for helpers
2022-12-13 11:47:10 -05:00
Wes
98a1fb96c2
Add test coverage for empty list value
2022-12-13 16:23:16 +00:00
Wes
874bbd2580
Remove extra whitespace
2022-12-13 16:02:46 +00:00
Wes
90dedbb841
Update tests to account for change in 'file_path' value verification
2022-12-13 15:58:35 +00:00
Wes
df5dd5fe28
Use new list verification function for 'file_path'
2022-12-13 15:57:43 +00:00
Wes
d5ab455485
Add new test for list value verification function
2022-12-13 15:56:58 +00:00
Wes
20b79b7ab0
Add new function to verify list value
2022-12-13 15:56:26 +00:00
Jason Ertel
56019f48ca
Merge pull request #9358 from Security-Onion-Solutions/jertel/es853
...
Upgrade ES to 8.5.3
2022-12-12 13:45:56 -05:00
Jason Ertel
d7dd2d2ef8
Upgrade ES to 8.5.3
2022-12-12 13:43:28 -05:00
weslambert
3d431eaba9
Merge pull request #9341 from Security-Onion-Solutions/fix/analyzers_localfile_file_path
...
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 16:49:29 -05:00
weslambert
f85fb5ecf9
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 16:35:24 -05:00
Jason Ertel
1716cb0297
Merge pull request #9333 from Security-Onion-Solutions/jertel/mergedev
...
Jertel/mergedev
2022-12-08 09:17:20 -05:00
Jason Ertel
0ec366f075
clear hotfix
2022-12-08 09:15:41 -05:00
Jason Ertel
e9b9e128c6
Merge branch 'master' into jertel/mergedev
2022-12-08 09:14:08 -05:00
Mike Reeves
ef15de130a
Merge pull request #9329 from Security-Onion-Solutions/hotfix/2.3.190
...
Hotfix/2.3.190
2022-12-08 09:08:18 -05:00
Mike Reeves
e975ee0a8e
Merge pull request #9328 from Security-Onion-Solutions/mike4
...
2.3.190 hotfix
2022-12-07 16:22:05 -05:00
Mike Reeves
da94ddca13
2.3.190 hotfix
2022-12-07 16:17:57 -05:00
Mike Reeves
6e94751c65
Merge pull request #9327 from Security-Onion-Solutions/jertel/surifilecheck
...
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:10:30 -05:00
Jason Ertel
d48d473f43
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:06:24 -05:00
Jason Ertel
cff5a83ad5
Merge pull request #9324 from Security-Onion-Solutions/jertel/surifilecheck
...
Use original style due to pgrep conflict with cron
2022-12-07 12:06:26 -05:00
Jason Ertel
225b7e359c
Use original style due to pgrep conflict with cron
2022-12-07 11:53:42 -05:00
Mike Reeves
9a616caf53
Merge pull request #9322 from Security-Onion-Solutions/mike
...
2.3.190 hotfix
2022-12-07 11:15:30 -05:00
Mike Reeves
0aab268801
2.3.190 hotfix
2022-12-07 11:12:13 -05:00
Mike Reeves
0bb7f5c5e3
Merge pull request #9320 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2022-12-07 09:21:17 -05:00
Mike Reeves
4aff1f0fdb
Update HOTFIX
2022-12-07 09:19:51 -05:00
Jason Ertel
35ca08ea88
Merge pull request #9315 from Security-Onion-Solutions/jertel/surifilecheck
...
Suricata support for filecheck; reduce cron noise
2022-12-07 08:17:19 -05:00
Jason Ertel
7b05627d5c
Suricata support for filecheck; reduce cron noise
2022-12-07 07:58:32 -05:00
Mike Reeves
e3c1b6dbba
Merge pull request #9306 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update init.sls
2022-12-06 13:38:35 -05:00
Mike Reeves
f0c3b876a9
Update init.sls
2022-12-06 13:35:03 -05:00
Mike Reeves
531423f49a
Update init.sls
2022-12-06 13:25:03 -05:00
Jason Ertel
dfad5a748c
Merge pull request #9303 from Security-Onion-Solutions/jertel/surifilecheck
...
Jertel/surifilecheck
2022-12-06 11:52:36 -05:00
Jason Ertel
819b39c0bb
Update hotfix
2022-12-06 11:41:00 -05:00
Jason Ertel
0dd2e51e83
Ensure Suricata move events get picked up
2022-12-06 11:39:58 -05:00
Mike Reeves
f7730741c2
Merge pull request #9297 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-12-05 16:12:55 -05:00
Mike Reeves
cb2d6b7876
Update VERSION
2022-12-05 16:07:12 -05:00
Mike Reeves
93ca7548f8
Merge pull request #9273 from Security-Onion-Solutions/dev
...
2.3.190
2022-12-05 15:17:47 -05:00
Mike Reeves
9cbbed1038
Merge pull request #9294 from Security-Onion-Solutions/2.3.190a
...
2.3.190
2022-12-05 13:03:23 -05:00
Mike Reeves
967fd30bb1
2.3.190
2022-12-05 13:00:55 -05:00
weslambert
6c8c8a2d8e
Merge pull request #9292 from Security-Onion-Solutions/fix/strelka_disable_yara_rules_causing_errors
...
Disable additional YARA rules that are causing compilation errors
2022-12-05 11:31:23 -05:00
weslambert
8bb3b22993
Disable additional YARA rules there are causing compilation errors
2022-12-05 11:30:22 -05:00
Jason Ertel
5b6182c003
Merge pull request #9289 from Security-Onion-Solutions/jertel/filechek
...
Update filecheck to support Suricata extracted files
2022-12-05 10:59:44 -05:00
Jason Ertel
69c5a9dd90
ensure tmp files are not processed
2022-12-05 10:31:09 -05:00
Jason Ertel
86c31c129a
add suricata to socore group
2022-12-05 10:27:42 -05:00
Jason Ertel
483a9d477f
undo filecheck location move
2022-12-05 10:15:15 -05:00
Jason Ertel
d7f60a0e58
only check files on inotify
2022-12-05 10:01:40 -05:00
Jason Ertel
f06443f3dd
add suricata to socore group
2022-12-05 09:57:24 -05:00
Jason Ertel
fe798138e3
add suricata to socore group
2022-12-05 09:50:35 -05:00
Jason Ertel
e9bb60dedb
fix filecheck for suricata deployments
2022-12-05 09:28:25 -05:00
Jason Ertel
992ced685f
fix filecheck for suricata deployments
2022-12-05 09:27:31 -05:00
Jason Ertel
592bbf4217
fix filecheck for suricata deployments
2022-12-05 09:21:08 -05:00
Mike Reeves
eacf6238d8
Merge pull request #9274 from Security-Onion-Solutions/2.3.190
...
2.3.190
2022-12-02 15:33:53 -05:00
Mike Reeves
0a7ada314d
2.3.190
2022-12-02 15:31:42 -05:00
Mike Reeves
c8edb43748
Merge pull request #9272 from Security-Onion-Solutions/2.3.190
...
2.3.190
2022-12-02 15:28:02 -05:00
Mike Reeves
f112663a76
2.3.190
2022-12-02 15:21:42 -05:00
Ben Allen
a1b2c28a42
Check privileges much earlier
2022-12-02 14:08:22 -05:00
weslambert
4311d5135b
Merge pull request #9269 from Security-Onion-Solutions/fix/zeek_scripts_bzar_remove_by_default
...
Don't load BZAR script(s) by default
2022-12-02 11:02:07 -05:00
weslambert
2b2d39c869
Don't load BZAR script(s) by default
2022-12-02 10:46:45 -05:00
Mike Reeves
fcc0534572
Merge pull request #9267 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2022-12-02 09:41:03 -05:00
Mike Reeves
a3f9859fdb
Update init.sls
2022-12-02 09:38:13 -05:00
Doug Burks
cf5d5e4fc2
Merge pull request #9257 from Security-Onion-Solutions/dougburks-patch-1
...
Disable ecat_arp_info by default in so-zeek-logs and so-whiptail
2022-12-01 07:31:47 -05:00
Doug Burks
7184b9cb25
disable ecat_arp_info by default in so-zeek-logs
2022-12-01 07:18:05 -05:00
Doug Burks
544d716c19
disable ecat_arp_info by default
2022-12-01 07:17:16 -05:00
weslambert
f1f611cede
Merge pull request #9256 from Security-Onion-Solutions/fix/ics_ingest_pipelines_bsap_node_status
...
Change 'bsap.node.status.byte' to 'bsap.node.status_byte'
2022-11-30 13:04:39 -05:00
weslambert
5988c12773
Change 'bsap.node.status.byte' to 'bsap.node.status_byte'
2022-11-30 13:01:30 -05:00
Mike Reeves
dc5f4ef942
Merge pull request #9253 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Use shutil in case there are multiple filesystems involved.
2022-11-30 11:04:30 -05:00
Doug Burks
91e15c233d
Merge pull request #9252 from Security-Onion-Solutions/dougburks-patch-1
...
update stun, tunnel, and wireguard dashboards in dashboards.queries.json
2022-11-30 11:03:56 -05:00
Mike Reeves
42cde0b6f0
Use shutil in case there are multiple filesystems involved.
2022-11-30 10:59:09 -05:00
Doug Burks
1279997ca9
update stun, tunnel, and wireguard dashboards in dashboards.queries.json
2022-11-30 10:59:00 -05:00
weslambert
93e0ec8696
Merge pull request #9249 from Security-Onion-Solutions/fix/ics_ingest_pipelines_additional_field_renames
...
More ICS Field Name Updates
2022-11-30 10:26:36 -05:00
Wes
8f0547beda
Change 'bsap.node.status_byte' to 'bsap.node_status_byte'.
2022-11-30 15:24:53 +00:00
Wes
6cb4c02200
More field updates
2022-11-30 15:22:02 +00:00
weslambert
8c54c44690
Merge pull request #9248 from Security-Onion-Solutions/fix/ics_ingest_pipelines_additional_field_renames
...
Additional ICS field renames and updates
2022-11-30 10:09:44 -05:00
Wes
5d72f8d55a
Additional field renames and updates
2022-11-30 15:01:41 +00:00
Mike Reeves
768225ff5a
Merge pull request #9242 from Security-Onion-Solutions/TOoSmOotH-patch-1
2022-11-29 23:42:15 -05:00
Mike Reeves
571ac4edec
Update soup
2022-11-29 18:36:47 -05:00
weslambert
86cfac4983
Merge pull request #9241 from Security-Onion-Solutions/fix/ics_pipelines_field_renames
...
ICS Pipelines - Various Field Renames
2022-11-29 17:23:34 -05:00
Wes
e00a80feb4
Use native link_id naming scheme for now
2022-11-29 22:05:37 +00:00
Wes
e8e39a7105
Various field renames
2022-11-29 21:32:05 +00:00
Wes
13ea44db95
Use native 'is_orig' since we are already using that field name for other logs
2022-11-29 21:21:41 +00:00
weslambert
7f4f1397e7
Merge pull request #9240 from Security-Onion-Solutions/fix/add_s7comm_upload_download_ingest_pipeline
...
Add Zeek s7comm upload download ingest pipeline
2022-11-29 15:00:26 -05:00
Wes
5db3e22363
Add s7comm_upload_download references in various places
2022-11-29 19:58:18 +00:00
Wes
6fe2857ba5
Add Zeek s7comm_upload_download ingest pipeline
2022-11-29 19:45:56 +00:00
weslambert
56b0bae089
Merge pull request #9238 from Security-Onion-Solutions/fix/opcua_encoding_mask_format
...
Fix OP CUA Encoding Mask Format and Ensure Connection State Is Populated Before Assessing Its Value
2022-11-29 14:16:03 -05:00
weslambert
f947e501cb
Add space per request
2022-11-29 14:14:37 -05:00
weslambert
ff8bbc399f
Add space per request
2022-11-29 14:14:08 -05:00
weslambert
80226a27cc
Add space per request
2022-11-29 14:13:41 -05:00
weslambert
266207cc18
Add space per request
2022-11-29 14:12:52 -05:00
weslambert
5255c120c5
Add space per request
2022-11-29 14:11:20 -05:00
Wes
d44f8e495b
Check if connection.state is populated before trying to assess its value
2022-11-29 19:00:47 +00:00
Wes
13a8cbdabb
Add convert processor for opcua.encoding_mask
2022-11-29 18:59:30 +00:00
Doug Burks
c3c505f8ff
Merge pull request #9237 from Security-Onion-Solutions/dougburks-patch-1
...
add ICS COTP dashboard to dashboards.queries.json
2022-11-29 13:40:24 -05:00
Doug Burks
7ea0aa87e4
add ICS COTP dashboard to dashboards.queries.json
2022-11-29 13:38:19 -05:00
weslambert
82317656b1
Merge pull request #9235 from Security-Onion-Solutions/fix/mobus_read_write_multiple_registers_pipeline_failure_resolution
...
Change 'write' to 'read' to correct name and avoid pipeline failure
2022-11-29 12:56:05 -05:00
weslambert
1cc5961c07
Change 'write' to 'read' to correct name and avoid pipeline failure
2022-11-29 12:54:55 -05:00
weslambert
220e998b45
Merge pull request #9234 from Security-Onion-Solutions/fix/add_dnp3_control_ingest_pipeline
...
Add 'zeek.dnp3_control' ingest pipeline
2022-11-29 12:29:44 -05:00
Wes
16cd1080be
Add dnp3_control reference in various places
2022-11-29 17:23:37 +00:00
Wes
5db643e53b
Add Zeek dnp3_control ingest pipeline
2022-11-29 17:18:24 +00:00
weslambert
745cdef538
Merge pull request #9232 from Security-Onion-Solutions/fix/filebeat_ics_tag_bsap
...
Add 'ics' tag for 'bsap'-prefixed events/logs
2022-11-29 11:37:18 -05:00
weslambert
aa767b8dc1
Add 'ics' tag for 'bsap'-prefixed events/logs
2022-11-29 11:27:41 -05:00
Doug Burks
45cdd16308
Merge pull request #9228 from Security-Onion-Solutions/fix/zeek-ics-eventfields
...
More Zeek ICS changes
2022-11-29 09:18:40 -05:00
doug
1bb76bb251
update zeek s7comm parsers
2022-11-29 07:50:21 -05:00
doug
4251331bd4
update zeek tds parsers and dashboard
2022-11-29 07:43:20 -05:00
doug
124d56f4b9
update zeek cip parsers
2022-11-29 07:36:30 -05:00
doug
02821b97ad
update bacnet parsers
2022-11-29 07:26:11 -05:00
doug
9a50832669
fix more typos
2022-11-29 07:16:30 -05:00
doug
cffbe757a6
fix bsap typos
2022-11-29 06:56:51 -05:00
Doug Burks
14ff5670f7
add bsap entries to hunt.eventfields.json
2022-11-29 06:48:20 -05:00
Doug Burks
92e238aa10
Merge pull request #9227 from Security-Onion-Solutions/fix/zeek-ics-parsers
...
Fix Zeek ICS parsers and add dashboards
2022-11-28 15:58:24 -05:00
doug
8462e66873
fix opcua_binary_browse_description
2022-11-28 13:50:24 -05:00
Doug Burks
2763b5846c
improve dashboard descriptions
2022-11-28 13:10:23 -05:00
Doug Burks
dd4c34397d
improve dashboard descriptions
2022-11-28 13:03:54 -05:00
Doug Burks
a796fa2ff7
make sure that ICS dashboards with sankey also have separate event.dataset table
2022-11-28 12:09:57 -05:00
Doug Burks
268253ce14
update ENIP dashboard
2022-11-28 12:05:35 -05:00
Doug Burks
6a2f886fcc
improve ecat dashboard
2022-11-28 12:01:35 -05:00
Doug Burks
63915b0486
consolidate DNP3 dashboards
2022-11-28 11:58:48 -05:00
Doug Burks
ce7b16a230
more ICS dashboards
2022-11-28 10:06:58 -05:00
Doug Burks
a4f5e7b2a6
add ECAT dashboard
2022-11-28 10:05:15 -05:00
Doug Burks
cfbbc3a1a3
add S7 dashboard
2022-11-28 10:02:33 -05:00
Doug Burks
11a7f051a6
organize dashboards
2022-11-28 09:57:54 -05:00
Doug Burks
cb06269b1a
update DNP3 and MODBUS dashboards
2022-11-28 09:40:42 -05:00
Mike Reeves
d026414bcf
Merge pull request #9226 from Security-Onion-Solutions/bgfix
...
Remove BG for filecheck
2022-11-28 09:12:45 -05:00
Mike Reeves
e15ca408e7
Remove BG for filecheck
2022-11-28 09:11:41 -05:00
Mike Reeves
0e2753393b
Remove BG for filecheck
2022-11-28 09:09:25 -05:00
Doug Burks
b06e9e8477
add new zeek opcua logs to so-zeek-logs
2022-11-26 18:44:28 -05:00
Doug Burks
45892400cb
add new zeek opcua logs to so-whiptail
2022-11-26 18:42:51 -05:00
Doug Burks
1f0c984b98
add new zeek opcua logs to so-functions
2022-11-26 18:41:12 -05:00
doug
6d814d3909
add more zeek opcua parsers
2022-11-26 17:43:58 -05:00
Doug Burks
9ea59355d5
fix opcua_binary_opensecure_channel in so-functions
2022-11-26 17:03:57 -05:00
Doug Burks
c1287a61af
add opcua_binary_opensecure_channel to so-functions
2022-11-26 17:02:04 -05:00
Doug Burks
e44c94c56b
add opcua_binary_opensecure_channel to so-whiptail
2022-11-26 17:01:11 -05:00
Doug Burks
ec0cf71c3f
add opcua_binary_opensecure_channel to so-zeek-logs
2022-11-26 17:00:32 -05:00
doug
73adc571de
add more zeek ics parsers
2022-11-26 10:36:49 -05:00
doug
62c1bb2c0c
disable ecat_arp_info since it records all arp traffic
2022-11-25 18:01:53 -05:00
Doug Burks
692ec05b2d
fix opcua_binary_activate_session in hunt.eventfields.json
2022-11-25 17:51:25 -05:00
Doug Burks
00078fd9e5
add opcua_binary_activate_session_diagnostic_info to hunt.eventfields.json
2022-11-25 17:47:41 -05:00
Doug Burks
13c8fb0004
add ecat_coe_info to hunt.eventfields.json
2022-11-25 17:45:28 -05:00
Doug Burks
920b16e494
add ecat_dev_info to hunt.eventfields.json
2022-11-25 17:42:59 -05:00
Doug Burks
d98c57510a
add opcua_binary_activate_session_locale_id to hunt.eventfields.json
2022-11-25 17:39:17 -05:00
Doug Burks
58aa730437
add opcua_binary_create_session_endpoints to hunt.eventfields.json
2022-11-25 17:37:10 -05:00
Doug Burks
f36da68009
add opcua_binary_create_subscription to hunt.eventfields.json
2022-11-25 17:35:02 -05:00
Doug Burks
0091675ab6
fix opcua_binary_get_endpoints_description in hunt.eventfields.json
2022-11-25 17:32:30 -05:00
Doug Burks
83d25a97d3
add opcua_binary_get_endpoints_description to hunt.eventfields.json
2022-11-25 16:01:40 -05:00
Doug Burks
e536568c8a
add opcua_binary_activate_session to hunt.eventfields.json
2022-11-25 15:59:17 -05:00
Doug Burks
a00eb9071f
add opcua_binary_get_endpoints to hunt.eventfields.json
2022-11-25 15:57:35 -05:00
Doug Burks
c39cd9a290
add opcua_binary_browse_result to hunt.eventfields.json
2022-11-25 15:55:59 -05:00
Doug Burks
cb5483d401
add opcua_binary_create_session to hunt.eventfields.json
2022-11-25 15:53:09 -05:00
Doug Burks
fab0d17314
add opcua_binary_browse_description to hunt.eventfields.json
2022-11-25 15:51:49 -05:00
Doug Burks
465e6c4605
add opcua_binary_create_session_user_token to hunt.eventfields.json
2022-11-25 15:48:11 -05:00
Doug Burks
a119d6a842
add opcua_binary_get_endpoints_user_token to hunt.eventfields.json
2022-11-25 15:46:35 -05:00
Doug Burks
be8ce43b74
add opcua_binary_browse to hunt.eventfields.json
2022-11-25 15:44:22 -05:00
Doug Burks
b2a33d4800
add opcua_binary_browse_response_references to hunt.eventfields.json
2022-11-25 15:41:48 -05:00
Doug Burks
78fac49e66
add opcua_binary_read to hunt.eventfields.json
2022-11-25 15:39:58 -05:00
Doug Burks
ca08989404
add cip_io to hunt.eventfields.json
2022-11-25 15:37:21 -05:00
Doug Burks
4ed757916e
add opcua_binary_status_code_detail to hunt.eventfields.json
2022-11-25 15:35:17 -05:00
Doug Burks
676c543178
add opcua_binary to hunt.eventfields.json
2022-11-25 15:33:13 -05:00
Doug Burks
aa2eab5738
fix zeek ics logs in so-functions
2022-11-25 09:53:11 -05:00
Doug Burks
fe21b8bc17
fix zeek ics logs in so-functions
2022-11-25 09:45:18 -05:00
Doug Burks
33a478ff59
fix zeek ics logs in so-zeek-logs
2022-11-25 09:40:48 -05:00
Doug Burks
62fee1f420
fix zeek ics logs in so-whiptail
2022-11-25 09:39:58 -05:00
Doug Burks
2ada4712bc
fix zeek ics logs in so-zeek-logs
2022-11-25 09:37:52 -05:00
Doug Burks
fad6c46e7c
fix zeek ics logs in so-zeek-logs
2022-11-25 09:35:00 -05:00
Doug Burks
6f27c1b21e
fix zeek logs in so-whiptail
2022-11-25 09:26:54 -05:00
Doug Burks
0afb20ffa8
fix ics entries in so-functions
2022-11-25 09:19:11 -05:00
Doug Burks
40688a6076
add Zeek software to so-functions
2022-11-25 07:36:41 -05:00
Doug Burks
9431bf1c2a
add Zeek software log to so-whiptail
2022-11-25 07:28:48 -05:00
Doug Burks
9f5e75b302
add software to so-zeek-logs
2022-11-25 07:27:50 -05:00
Doug Burks
3f62cddc3b
change . to _
2022-11-23 12:21:12 -05:00
Doug Burks
085420997c
move status_code before status_code.link_id
2022-11-23 12:11:04 -05:00
Doug Burks
723e145eeb
Merge pull request #9221 from Security-Onion-Solutions/dougburks-patch-1
...
fix descriptions
2022-11-23 11:43:12 -05:00
Doug Burks
0a1d0d35c8
fix description
2022-11-23 11:33:31 -05:00
Doug Burks
9ee96f2280
fix description
2022-11-23 11:32:09 -05:00
Doug Burks
3871268c19
Merge pull request #9220 from Security-Onion-Solutions/fix/zeek-opcua-parsing
...
fix zeek opcua pipelines
2022-11-23 11:17:47 -05:00
doug
bc620b7def
fix zeek opcua pipelines
2022-11-23 10:56:32 -05:00
Josh Brower
5950771003
Merge remote-tracking branch 'remotes/origin/dev' into idhskins
2022-11-22 18:04:38 -05:00
Josh Brower
7c8ce7899b
Initial support for custom IDH http skins
2022-11-22 17:57:51 -05:00
Doug Burks
08d5f494ab
Merge pull request #9208 from Security-Onion-Solutions/dougburks-patch-1
...
Initial dashboards for stun, tds, wireguard, and ics
2022-11-22 16:04:12 -05:00
weslambert
13827f3be5
Merge pull request #9209 from Security-Onion-Solutions/fix/add_missing_opcua_activate_session_pipelines
...
Add Missing OPCUA Activate Session Pipelines
2022-11-22 16:01:33 -05:00
weslambert
3a64362887
Remove extra space used during testing
2022-11-22 15:47:16 -05:00
Wes
e77a60bcbf
Add missing OPCUA 'activate_session' pipelines
2022-11-22 20:44:48 +00:00
weslambert
e560edf493
Merge pull request #9206 from Security-Onion-Solutions/fix/ingest_typos
...
Fix spelling of 'wireguard.responses' field name
2022-11-22 15:35:55 -05:00
Doug Burks
7caf827b77
add ecat_aoe_info to hunt.eventfields.json
2022-11-22 13:33:06 -05:00
Doug Burks
f40ccb7eff
add bacnet_discovery to hunt.eventfields.json
2022-11-22 13:27:26 -05:00
Doug Burks
e0cd550820
update ecat_arp_info in hunt.eventfields.json
2022-11-22 13:23:45 -05:00
Doug Burks
4e5106c863
update ecat_arp_info in hunt.eventfields.json
2022-11-22 13:21:33 -05:00
Doug Burks
5a107c63b8
add source.mac and destination.mac to dashboards.queries.json
2022-11-22 13:16:47 -05:00
Doug Burks
8a9a13865c
add ecat_registers to hunt.eventfields.json
2022-11-22 13:12:24 -05:00
Doug Burks
9cd6273beb
update ecat_log_address in hunt.eventfields.json
2022-11-22 13:10:46 -05:00
Doug Burks
724b26228c
add ecat_log_address to hunt.eventfields.json
2022-11-22 13:09:27 -05:00
weslambert
3c054fd133
Fix spelling of 'wireguard.responses' field name
2022-11-22 13:02:43 -05:00
Doug Burks
24ee38369f
add cotp to hunt.eventfields.json
2022-11-22 12:49:33 -05:00
weslambert
0bbe642d20
Merge pull request #9203 from Security-Onion-Solutions/fix/ics_ingest_field_names
...
Fix ICS Ingest Field Names
2022-11-22 12:30:10 -05:00
weslambert
8e17c23659
Fix format/speliing for 'enip.status_code' field name
2022-11-22 12:05:03 -05:00
weslambert
92170941f0
Fix spelling for 'stun.class' field name
2022-11-22 12:04:07 -05:00
Doug Burks
10ac789fbf
add profinet_dce_rpc to hunt.eventfields.json
2022-11-22 11:08:24 -05:00
Doug Burks
db58a35562
add profinet to hunt.eventfields.json
2022-11-22 11:07:03 -05:00
Doug Burks
1ad7a0db59
add bacnet_property to hunt.eventfields.json
2022-11-22 11:05:26 -05:00
Doug Burks
af626fe3a1
add bacnet to hunt.eventfields.json
2022-11-22 11:03:45 -05:00
Doug Burks
073f5ed789
add dnp3_objects to hunt.eventfields.json
2022-11-22 11:02:21 -05:00
Doug Burks
bbcefea417
add s7comm_plus to hunt.eventfields.json
2022-11-22 10:58:42 -05:00
Doug Burks
73c282595d
update dnp3 in hunt.eventfields.json
2022-11-22 10:57:06 -05:00
Doug Burks
07a53db09a
add cip_identity to hunt.evenfields.json
2022-11-22 10:55:39 -05:00
Doug Burks
80e50fa7b4
add ecat_arp_info to hunt.eventfields.json
2022-11-22 10:53:48 -05:00
Doug Burks
84d333e915
add s7comm to hunt.eventfields.json
2022-11-22 10:51:06 -05:00
Doug Burks
ae582caa55
Add modbus_detailed to hunt.eventfields.json
2022-11-22 10:48:33 -05:00
Doug Burks
264ae2b9ac
add enip to hunt.eventfields.json
2022-11-22 10:45:20 -05:00
Doug Burks
b522c9eea4
reorder fields in hunt.eventfields.json
2022-11-22 10:43:01 -05:00
Doug Burks
51cc047933
add cip to hunt.eventfields.json
2022-11-22 10:40:22 -05:00
Doug Burks
2a805ac1a6
Add tds entries to hunt.eventfields.json
2022-11-22 10:29:55 -05:00
Doug Burks
595f615ed9
Add ICS dashboard
2022-11-22 10:22:55 -05:00
Doug Burks
aa7c39d312
Add dashboards for stun, tds, and wireguard
2022-11-22 10:08:39 -05:00
weslambert
2170d498c5
Merge pull request #9195 from Security-Onion-Solutions/fix/missing_ics_pipelines
...
Add COTP and TDS ingest pipelines
2022-11-22 08:44:02 -05:00
Wes
95a6f9aa7d
Add COTP and TDS ingest pipelines
2022-11-22 13:35:19 +00:00
weslambert
ba65b351a2
Merge pull request #9193 from Security-Onion-Solutions/fix/ics_tag_syntax_error
...
Fix syntax error for 'ics' tag logic
2022-11-22 07:32:40 -05:00
weslambert
4c09c8856b
Fix syntax error for 'ics' tag logic
2022-11-22 07:23:56 -05:00
weslambert
3afa8bd9da
Merge pull request #9188 from Security-Onion-Solutions/feature/filebeat_config_ics_event_tag
...
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 17:06:25 -05:00
weslambert
72eccd2649
Fix indentation
2022-11-21 17:01:16 -05:00
weslambert
310ea633b6
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 16:43:43 -05:00
Doug Burks
31b4d9cd70
Merge pull request #9187 from Security-Onion-Solutions/dougburks-patch-1
...
Remove descriptions from so-zeek-logs and so-whiptail
2022-11-21 14:13:04 -05:00
Doug Burks
0536d174fe
Fix opcua_binary reference in so-zeek-logs
2022-11-21 14:03:22 -05:00
Doug Burks
96d7429a1c
Remove descriptions from so-whiptail
2022-11-21 13:32:51 -05:00
Doug Burks
a54bb2bad4
Remove descriptions from so-zeek-logs
2022-11-21 13:23:53 -05:00
Doug Burks
d4abbd89ca
Merge pull request #9185 from Security-Onion-Solutions/dougburks-patch-1
...
Update so-functions to enable ICS/SCADA for EVAL and IMPORT
2022-11-21 12:33:06 -05:00
Peter Di Giorgio
bdfab6858d
Merge pull request #9184 from Security-Onion-Solutions/foxtrot
...
Shorten Zeek Log Descriptions for formatting
2022-11-21 11:20:15 -06:00
lock-wire
f80c8b89e4
Shorten Log Descriptions
2022-11-21 09:49:31 -07:00
Peter Di Giorgio
29384d33e1
Merge pull request #9183 from Security-Onion-Solutions/dev
...
Synch Foxtrot from dev
2022-11-21 10:06:44 -06:00
Doug Burks
aebedf9ac6
Update so-functions to enable ICS/SCADA for EVAL and IMPORT
2022-11-21 10:05:18 -05:00
Doug Burks
40ee529c7e
Merge pull request #9178 from Security-Onion-Solutions/dougburks-patch-1
...
Simplify version in README.md to just 2.3
2022-11-21 08:46:22 -05:00
Doug Burks
b9ee2f1e38
Simplify version in README.md to just 2.3
2022-11-21 08:38:27 -05:00
weslambert
089b403a3b
Merge pull request #9166 from Security-Onion-Solutions/foxtrot
...
Merge final protocol analyzers into dev
2022-11-18 08:41:43 -05:00
Peter Di Giorgio
a28e5de5f4
Correct trailing \
2022-11-18 06:29:57 -06:00
Peter Di Giorgio
2e30cefd91
Add remaining protocol parsers
...
- icsnpp-bsap
- icsnpp-s7comm
- zeek-plugin-tds
- zeek-plugin-profinet
- zeek-spicy-wireguard
- zeek-spicy-stun
2022-11-17 10:47:00 -06:00
Peter Di Giorgio
33bf0c6902
Merge pull request #9163 from Security-Onion-Solutions/dev
...
Update Foxtrot from Dev
2022-11-17 10:44:24 -06:00
Peter Di Giorgio
13b6b43324
Update init.sls
2022-11-17 10:42:21 -06:00
weslambert
78bc2a95e5
Add icsnpp-bsap to enabled plugins
2022-11-17 11:20:24 -05:00
weslambert
5bb0e6e8c0
Merge pull request #9160 from Security-Onion-Solutions/feature/additional_ics_scada_ingest_node_pipelines
...
Add additional ICS/SCADA ingest node pipelines
2022-11-17 11:18:15 -05:00
Wes
a278194037
Add additional ICS/SCADA ingest node pipelines
2022-11-17 16:16:33 +00:00
lock-wire
1b8e546045
Add s7comm,tds,stun,profinet,wireguard
2022-11-16 21:41:02 -06:00
weslambert
7319cb07e2
Merge pull request #9153 from Security-Onion-Solutions/fix/ics_scada_ingest_pipeline_updates_2_3
...
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 16:17:08 -05:00
Wes
35e131b888
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 21:09:30 +00:00
Jason Ertel
fd34eb3c26
Merge pull request #9150 from Security-Onion-Solutions/kilo
...
Increase retry count and pause to allow more time for Ubuntu updates
2022-11-16 07:53:04 -05:00
Jason Ertel
02b00d2c87
Increase retry count and pause to allow more time for Ubuntu updates
2022-11-16 07:50:08 -05:00
Mike Reeves
b0e08ed749
Merge pull request #9066 from security-companion/analyzers-patch1
...
fix descriptions in files related to analyzers
2022-11-12 11:32:09 -05:00
Mike Reeves
ec3a688e66
Merge pull request #9128 from Security-Onion-Solutions/dougburks-patch-1
...
Add trailing backslash to bacnet_property in so-functions
2022-11-12 10:33:00 -05:00
Doug Burks
4400c77f7e
Add trailing backslash to bacnet_property in so-functions
2022-11-12 09:13:20 -05:00
Peter Di Giorgio
d890f75cca
Correct typo
2022-11-11 13:59:20 -08:00
Doug Burks
91b6087350
Merge pull request #9126 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in zeek init.sls icsnpp-opcua-binary
2022-11-11 21:50:36 +00:00
Doug Burks
edcbcec10a
fix typo in zeek init.sls icsnpp-opcua-binary
2022-11-11 16:49:12 -05:00
Doug Burks
18ab90288a
Merge pull request #9124 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 21:33:52 +00:00
Doug Burks
9bf1c1e869
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 16:27:11 -05:00
Peter Di Giorgio
1e96a0b6a6
Merge pull request #9122 from Security-Onion-Solutions/foxtrot
...
Merge new protocol analyzers into dev
2022-11-11 12:53:57 -08:00
lock-wire
8dc08f66fd
Merge branch 'foxtrot' of https://github.com/Security-Onion-Solutions/securityonion into foxtrot
...
merge remote
2022-11-11 12:18:02 -08:00
lock-wire
73b1e5949b
Add ecat, enip, cip, and opcua
2022-11-11 12:15:54 -08:00
Doug Burks
2d6a4d7c28
Merge pull request #9098 from Security-Onion-Solutions/feature/local-docs
...
FEATURE: Improve local copy of docs in SOC #9097
2022-11-11 16:21:54 +00:00
Peter Di Giorgio
ae389ee487
Merge pull request #9121 from Security-Onion-Solutions/dev
...
Update foxtrot from dev
2022-11-11 07:25:26 -08:00
lock-wire
85d30520ce
Add BSAP protocol
2022-11-11 07:22:55 -08:00
Jason Ertel
934ce9ba64
Merge pull request #9114 from Security-Onion-Solutions/kilo
...
merge master to dev
2022-11-10 16:50:33 -05:00
Jason Ertel
595a95fdf5
merge conflicts
2022-11-10 16:47:52 -05:00
Mike Reeves
fc649a565c
Merge pull request #9107 from Security-Onion-Solutions/patch/2.3.182
...
Patch/2.3.182
2022-11-10 16:30:17 -05:00
Mike Reeves
113b38056b
2.3.182
2022-11-10 15:12:47 -05:00
Mike Reeves
559276534d
2.3.182
2022-11-10 15:06:00 -05:00
Mike Reeves
4acd9f8816
Update soup
2022-11-09 10:10:52 -05:00
security-companion
7ee4eb6101
fix descriptions in files related to analyzers
2022-11-08 22:32:28 +01:00
doug
84b2fc9c17
FEATURE: Improve local copy of docs in SOC #9097
2022-11-08 16:26:09 -05:00
Mike Reeves
a7417a7242
Update soup
2022-11-08 14:48:48 -05:00
Mike Reeves
d18ff69ec9
Update VERSION
2022-11-08 14:45:53 -05:00
Peter Di Giorgio
5532577fdd
Merge pull request #9071 from Security-Onion-Solutions/dev
...
Merge Dev into Foxtrot
2022-11-04 08:01:29 -07:00
Peter Di Giorgio
5ebf470a86
Update zeek.bacnet_discovery
2022-11-03 22:27:04 -07:00
Peter Di Giorgio
4b39ccec6d
Update zeek.bacnet_property
2022-11-03 15:30:20 -07:00
Mike Reeves
18cd7a83c6
Merge pull request #9059 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update init.sls
2022-11-02 13:01:38 -04:00
Mike Reeves
c5bfe6ffdb
Update init.sls
2022-11-02 12:59:46 -04:00
Mike Reeves
4ac365e670
Update init.sls
2022-11-02 12:59:17 -04:00
Mike Reeves
ff1a903895
Update init.sls
2022-11-02 12:58:31 -04:00
Doug Burks
65f8b1ebe3
Merge pull request #9057 from Security-Onion-Solutions/dougburks-patch-1
...
Create README.txt in setup/automation/
2022-11-02 14:24:29 +00:00
Jason Ertel
c23e8e5a7b
Update README.txt
2022-11-02 10:23:19 -04:00
Doug Burks
aa4a9a093f
Create README.txt
2022-11-02 10:20:57 -04:00
Mike Reeves
0af813d7fe
Merge pull request #9056 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2022-11-02 10:17:43 -04:00
Mike Reeves
388486ec08
Update init.sls
2022-11-02 10:06:13 -04:00
Mike Reeves
b1b0a7df30
Merge pull request #9044 from Security-Onion-Solutions/watchdogfix
...
watchdog fix
2022-11-01 13:24:05 -04:00
Mike Reeves
f74aee6a03
Update init.sls
2022-11-01 13:21:12 -04:00
Mike Reeves
4c6e66428c
Merge pull request #9037 from Security-Onion-Solutions/soup190
...
Add soup and perms updates
2022-11-01 09:13:26 -04:00
Mike Reeves
16d8e9e5a0
Fix soup and perms updates
2022-11-01 09:05:26 -04:00
Mike Reeves
ee1f55361e
Add soup and perms updates
2022-10-31 16:33:38 -04:00
Mike Reeves
cb33464668
Merge pull request #9033 from Security-Onion-Solutions/strelkafix
...
Add Filechecks
2022-10-31 15:49:40 -04:00
Mike Reeves
06ddae13b5
Update filecheck
2022-10-31 15:41:57 -04:00
Mike Reeves
16d3dead04
Update sensor-rotate.conf
2022-10-31 15:33:10 -04:00
Mike Reeves
f7043f3f62
Update init.sls
2022-10-31 15:25:38 -04:00
Mike Reeves
bf41f2984a
Update init.sls
2022-10-31 14:58:55 -04:00
Mike Reeves
86ca3602f3
Update init.sls
2022-10-31 14:44:01 -04:00
Mike Reeves
416c28fded
Update init.sls
2022-10-31 14:42:23 -04:00
Mike Reeves
297373877a
Update init.sls
2022-10-31 14:36:40 -04:00
Mike Reeves
db9b93a96c
Update init.sls
2022-10-31 14:35:02 -04:00
Mike Reeves
5635375d8d
Update init.sls
2022-10-31 14:30:11 -04:00
Mike Reeves
07e72e4013
Update filecheck
2022-10-31 13:47:49 -04:00
Mike Reeves
518d2aaa9c
Update filecheck.yaml
2022-10-31 13:45:00 -04:00
Mike Reeves
e93e2995b7
Update filecheck
2022-10-31 13:42:18 -04:00
Mike Reeves
d2eb61a830
Update filecheck.yaml
2022-10-31 13:41:45 -04:00
Mike Reeves
4c5a2c0610
Update filecheck
2022-10-31 13:36:42 -04:00
Mike Reeves
e9e7362005
Add Filechecks
2022-10-31 12:57:08 -04:00
Peter Di Giorgio
b97c822800
Add zeek.bacnet_discovery and zeek.bacnet_property
2022-10-27 15:40:52 -07:00
Peter Di Giorgio
71e3b2d1fb
Create zeek.bacnet
2022-10-27 15:40:07 -07:00
Peter Di Giorgio
326ba710ce
Add logs for bacnet
...
bacnet
bacnet_discovery
bacnet_property
2022-10-27 15:38:32 -07:00
Peter Di Giorgio
1ea6feca37
Add icsnpp-bacnet
2022-10-27 15:31:38 -07:00
Peter Di Giorgio
c524442172
Merge pull request #9008 from Security-Onion-Solutions/master
...
Synch Foxtrot with 2.3.181 Release
2022-10-26 13:10:01 -07:00
weslambert
8e4d0db738
Merge pull request #9002 from Security-Onion-Solutions/fix/remove_ja3er_references
...
Remove JA3er references
2022-10-26 10:21:54 -04:00
weslambert
a170c194c8
Remove JA3er references
2022-10-26 10:18:10 -04:00
Peter Di Giorgio
2b51d72585
Rename zeek.read_write_multiple_registers to zeek.modbus_read_write_multiple_registers
2022-10-25 17:20:01 -07:00
weslambert
0d71006f40
Merge pull request #8997 from Security-Onion-Solutions/fix/sensoroni_analyzers_pyyaml_wheel_name
...
Fix PyYAML .whl file name and remove JA3er analyzer
2022-10-25 14:57:35 -04:00
Wes
a91e3b601c
Remove JA3er since it is no longer a valid service
2022-10-25 18:48:37 +00:00
Wes
4940421297
Add PyYAML .whl files back since they were 'deleted' in the previous commit
2022-10-25 18:47:51 +00:00
Wes
58b4a8fbab
Change PyYAML .whl file name to comply with Joliet's 240-character limit
2022-10-25 18:47:02 +00:00
Mike Reeves
bd7e12f682
Merge pull request #8952 from Njinx/dev
...
FEATURE: so-pcap-export can run without needing to be attached to a TTY
2022-10-25 14:38:48 -04:00
Mike Reeves
64e43f07b9
Merge pull request #8993 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update VERSION
2022-10-25 14:36:45 -04:00
Mike Reeves
2d84e2e977
Update VERSION
2022-10-25 14:35:52 -04:00
Mike Reeves
465a1a82d7
Merge pull request #8981 from Security-Onion-Solutions/dev
...
2.3.181
2022-10-25 14:30:50 -04:00
Peter Di Giorgio
61d36d584f
Add Modbus, DNP3, BZAR, and oui-logging
2022-10-25 07:10:52 -07:00
Peter Di Giorgio
2d343110cc
Add DNP3 and Modbus extensions to zeeklogs.sls
2022-10-25 07:09:11 -07:00
Peter Di Giorgio
4502e2c260
Remove logs for OT parsers
2022-10-24 23:16:18 -07:00
Peter Di Giorgio
beb67847f9
Remove modbus,bzar,dnp3,oui-logging
2022-10-24 23:14:32 -07:00
Peter Di Giorgio
9cdc29c482
Fix Syntax for zeeklogs pillar
2022-10-24 14:30:15 -07:00
weslambert
292f66138b
Merge pull request #8983 from Security-Onion-Solutions/revert-8982-fix/sensoroni_analyzers_pyyaml_wheel_name
...
Revert "Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold"
2022-10-24 16:49:19 -04:00
weslambert
0087768946
Revert "Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold"
2022-10-24 16:47:30 -04:00
Peter Di Giorgio
01d177366d
Fix Zeek Pillar
2022-10-24 12:00:43 -07:00
weslambert
712340a027
Merge pull request #8982 from Security-Onion-Solutions/fix/sensoroni_analyzers_pyyaml_wheel_name
...
Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold
2022-10-24 14:14:45 -04:00
Wes
1caac3f0b0
Add PyYAML .whl files back since they were 'deleted' in the previous commit.
2022-10-24 18:06:19 +00:00
Wes
54a5dd6cbd
Change name of PyYAML .whl file to remain under Joliet's 240-character limit/threshold
2022-10-24 18:05:15 +00:00
Mike Reeves
6570177b0c
Merge pull request #8979 from Security-Onion-Solutions/2.3.181
...
2.3.181
2022-10-24 11:39:08 -04:00
Mike Reeves
f7ed992f24
2.3.181
2022-10-24 11:33:31 -04:00
Mike Reeves
4a18f8d18a
2.3.181
2022-10-24 11:32:19 -04:00
Peter Di Giorgio
24cf481f4a
Merge pull request #8973 from lock-wire/patch-3
...
Add Modbus, DNP3, BZAR, and oui-logging
2022-10-21 18:06:13 -07:00
Peter Di Giorgio
cd4e0c1f8e
Add DNP3 and Modbus extensions to zeeklogs.sls
...
Add DNP3 and Modbus extenstions to zeeklogs to ensure filebeat.yml is configured properly to ship lots. Need to move these behind the OT flag.
2022-10-21 14:19:21 -07:00
Peter Di Giorgio
4a60310dc8
Add Modbus, DNP3, BZAR, and oui-logging
...
This is an initial proof of concept. Need to migrate these entries behind a flag.
2022-10-21 14:04:40 -07:00
weslambert
930620fce6
Merge pull request #8971 from lock-wire/patch-2
...
Add Ingest pipeline for Modbus and DNP3 extensions
2022-10-21 16:28:52 -04:00
Peter Di Giorgio
7a60d0987c
Update zeek.conn to include client.oui
2022-10-21 13:02:01 -07:00
Peter Di Giorgio
9ac06057c1
Create zeek.read_write_multiple_registers
2022-10-21 13:00:12 -07:00
Peter Di Giorgio
e5c69c3236
Create zeek.modbus_mask_write_register
2022-10-21 12:58:36 -07:00
Peter Di Giorgio
39f050c6e4
Rename modbus_detailed to zeek.modbus_detailed
2022-10-21 12:56:59 -07:00
Peter Di Giorgio
4ee083759c
Rename dnp3_objects to zeek.dnp3_objects
2022-10-21 12:56:35 -07:00
Peter Di Giorgio
072bfd87b7
Create Ingest for Modbus Detailed
2022-10-21 12:53:30 -07:00
Peter Di Giorgio
b7aaaa80bb
Create Ingest for DNP3 Objects extension
2022-10-21 12:51:13 -07:00
Jason Ertel
b8884b6ac9
Merge pull request #8968 from Security-Onion-Solutions/181soup
...
update soup for 2.3.181
2022-10-21 12:00:58 -04:00
Jason Ertel
05e271af47
update soup for 2.3.181
2022-10-21 11:52:54 -04:00
Mike Reeves
58e80a9db8
Merge pull request #8964 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2022-10-21 10:45:44 -04:00
Mike Reeves
e16fc3605e
Update VERSION
2022-10-21 10:43:34 -04:00
Ben Allen
f13f05eb94
Run without needing to be attached to a TTY
2022-10-19 14:11:11 -04:00
weslambert
a54fc4cead
Merge pull request #8942 from Security-Onion-Solutions/master
...
Update Foxtrot to .180
2022-10-18 16:39:21 -04:00
Mike Reeves
2127ba90ee
Merge pull request #8925 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-10-17 10:51:02 -04:00
Mike Reeves
3373aef87d
Update VERSION
2022-10-17 10:50:14 -04:00
Mike Reeves
fa45e8ded7
Merge pull request #8924 from Security-Onion-Solutions/dev
...
2.3.180
2022-10-17 10:41:06 -04:00
Mike Reeves
6d0ead7b5b
Merge pull request #8923 from Security-Onion-Solutions/2.3.180
...
2.3.180
2022-10-17 09:47:06 -04:00
Mike Reeves
a2a6625f3b
2.3.180
2022-10-17 09:39:07 -04:00
Mike Reeves
3c2510acd7
Merge pull request #8920 from Security-Onion-Solutions/dev
...
Merge Dev into Foxtrot
2022-10-17 09:34:57 -04:00
Doug Burks
0d807d20f4
Merge pull request #8914 from Security-Onion-Solutions/dougburks-patch-1
...
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 13:03:51 +00:00
Doug Burks
f4042263a3
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 08:59:10 -04:00
Doug Burks
a930f8233d
Merge pull request #8899 from Security-Onion-Solutions/dougburks-patch-2
...
Update soup for 2.3.180
2022-10-11 17:14:55 +00:00
Doug Burks
7401008523
Update soup for 2.3.180
2022-10-11 12:58:37 -04:00
Doug Burks
5199ea483e
Merge pull request #8878 from Security-Onion-Solutions/feature/improve-sysmon-dashboards
...
FEATURE: Add new Sysmon dashboards #8870
2022-10-07 16:47:02 +00:00
doug
454a7a4799
FEATURE: Add new Sysmon dashboards #8870
2022-10-07 11:52:49 -04:00
Doug Burks
6fb7733d8c
Merge pull request #8875 from Security-Onion-Solutions/dougburks-patch-1
...
Increment SO to 2.3.180 and Elastic to 8.4.3
2022-10-07 11:13:13 +00:00
Doug Burks
ab17cbee31
Update Elastic to 8.4.3
2022-10-07 07:03:10 -04:00
Doug Burks
9991f0cf95
update Elastic to 8.4.3
2022-10-07 07:02:24 -04:00
Doug Burks
44d46b06a2
increment version to 2.3.180
2022-10-07 06:58:07 -04:00
Mike Reeves
ba7231f07d
Merge pull request #8841 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update VERSION
2022-10-03 08:46:19 -04:00
Mike Reeves
8dc11ea23a
Update VERSION
2022-10-03 08:43:39 -04:00
Mike Reeves
116a6a0acd
Merge pull request #8806 from Security-Onion-Solutions/dev
...
2.3.170
2022-10-01 08:13:09 -04:00
Mike Reeves
311b69dc4a
Merge pull request #8805 from Security-Onion-Solutions/2.3.170
...
2.3.170
2022-09-23 15:34:49 -04:00
Mike Reeves
fd59acce5d
2.3.170
2022-09-23 15:26:14 -04:00
Mike Reeves
956d3e4345
Merge pull request #8793 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2022-09-22 09:22:20 -04:00
Mike Reeves
b8355b3a03
Update soup
2022-09-22 09:10:12 -04:00
bryant-treacle
535b9f86db
Merge pull request #8633 from Security-Onion-Solutions/bryant-sysmon
...
Fix issues: 8591-8953
2022-09-19 11:53:34 -04:00
Mike Reeves
97c66a5404
Merge pull request #8639 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
dev to 170
2022-08-31 08:23:48 -04:00
Josh Brower
6553beec99
Merge pull request #8644 from Security-Onion-Solutions/upgrade/elastic-8.4.1
...
Upgrade/elastic 8.4.1
2022-08-30 16:37:56 -04:00
Josh Brower
e171dd52b8
Upgrade Elastic to 8.4.1
2022-08-30 16:11:40 -04:00
Josh Brower
27a837369d
Upgrade Elastic to 8.4.1
2022-08-30 16:09:57 -04:00
Mike Reeves
043b9f78e2
Merge pull request #8638 from Security-Onion-Solutions/master
...
Merge pull request #8627 from Security-Onion-Solutions/dev
2022-08-30 14:42:18 -04:00
Mike Reeves
2f260a785f
Update README.md
2022-08-30 14:41:41 -04:00
Mike Reeves
001b2dc6cc
Update VERSION
2022-08-30 14:39:41 -04:00
Mike Reeves
b13eedfbc2
Merge pull request #8627 from Security-Onion-Solutions/dev
...
2.3.160
2022-08-30 14:33:36 -04:00
Mike Reeves
dd70ef17b9
Merge pull request #8636 from Security-Onion-Solutions/fixitup
...
Merge pull request #8571 from Security-Onion-Solutions/dev
2022-08-30 14:31:35 -04:00
bryant-treacle
82dff3e9da
Fix issues: 8591-8953
2022-08-30 13:48:53 +00:00
Mike Reeves
d9cfd92b8f
Merge pull request #8626 from Security-Onion-Solutions/2.3.160
...
2.3.160
2022-08-29 15:00:08 -04:00
Mike Reeves
33cb771780
2.3.160
2022-08-29 14:56:43 -04:00
Mike Reeves
76cca8594d
Merge pull request #8623 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update soup
2022-08-29 09:50:06 -04:00
weslambert
5c9c95ba1f
Merge pull request #8622 from Security-Onion-Solutions/fix/strelka_yara_gen_webshells_ignore
...
Ignore gen_webshells.yar
2022-08-29 09:40:51 -04:00
Mike Reeves
e62bebeafe
Update soup
2022-08-29 09:39:41 -04:00
weslambert
8a0e92cc6f
Add 'gen_webshells.yar' and re-arrange to put ignored rules in alphabetical order
2022-08-29 09:37:29 -04:00
Mike Reeves
3f9259dd0a
Merge pull request #8621 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soup
2022-08-29 09:34:29 -04:00
Mike Reeves
30b9868de1
Update soup
2022-08-29 09:32:46 -04:00
Doug Burks
e88243c306
Merge pull request #8602 from Security-Onion-Solutions/dougburks-patch-1
...
increment to 2.3.160
2022-08-26 08:06:22 -04:00
Doug Burks
2128550df2
increment to 2.3.160
2022-08-26 07:50:08 -04:00
Jason Ertel
db67c0ed94
Merge pull request #8577 from Security-Onion-Solutions/kilo
...
Increment version to 2.3.160
2022-08-23 07:14:05 -04:00
Jason Ertel
2e32c0d236
Increment version to 2.3.160
2022-08-23 07:00:14 -04:00
Mike Reeves
4b1ad1910d
Merge pull request #8571 from Security-Onion-Solutions/dev
...
2.3.150
2022-08-22 15:22:43 -04:00
Mike Reeves
c337145b2c
Merge pull request #8570 from Security-Onion-Solutions/2.3.150
...
2.3.150
2022-08-22 14:35:29 -04:00
Mike Reeves
bd7b4c92bc
2.3.150
2022-08-22 14:31:36 -04:00
Mike Reeves
33ebed3468
2.3.150
2022-08-22 14:31:04 -04:00
weslambert
616bc40412
Merge pull request #8558 from Security-Onion-Solutions/fix/soup_local_mods_check_skip_prompt
...
Allow local modification acceptance prompt to be skipped when passing 'skip-prompt' as a parameter value to check_local_mods() function
2022-08-19 16:11:23 -04:00
weslambert
f00d9074ff
Allow local modification acceptance prompt to be skipped when passing 'skip-prompt' as a parameter value to check_local_mods() function
2022-08-19 16:07:14 -04:00
Mike Reeves
9a692288e2
Merge pull request #8557 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update rulecat.conf
2022-08-19 13:14:32 -04:00
Mike Reeves
fea2b481e3
Update rulecat.conf
2022-08-19 13:12:49 -04:00
weslambert
c17f0081ef
Merge pull request #8550 from Security-Onion-Solutions/fix/soup_elastalert_indices_check_delete_if_less_than_es_8
...
SOUP: Ensure Elastalert indices are not deleted for major Elasticsearch version 8 or greater
2022-08-18 09:45:00 -04:00
weslambert
fbf0803906
Update verbiage around major Elasticsearch version and not requiring Elastalert index maintenance
2022-08-18 09:16:22 -04:00
weslambert
5deda45b66
Update elastalert_indices_check() function to only delete Elastalert indices if major Elasticsearch version is less than 8
...
Update elastalert_indices_check() function to only delete Elastalert indices if major Elasticsearch version is less than 8. Also clean up the output to only emit one notification regarding index deletion, and additional verbiage around function operation.
2022-08-18 09:11:38 -04:00
Josh Patterson
3b8d8163b3
Merge pull request #8544 from Security-Onion-Solutions/issue/8369
...
remove pipeline time panel
2022-08-17 09:56:01 -04:00
m0duspwnens
2dfd41bd3c
remove pipeline time panel - https://github.com/Security-Onion-Solutions/securityonion/issues/8369
2022-08-17 09:17:27 -04:00
Mike Reeves
49eead1d55
Merge pull request #8543 from Security-Onion-Solutions/kilo
...
Merge master into dev
2022-08-17 09:03:49 -04:00
Jason Ertel
54cb3c3a5a
Merge branch 'master' into kilo
2022-08-17 08:58:32 -04:00
Mike Reeves
9f2b920454
Merge pull request #8535 from Security-Onion-Solutions/hotfix/2.3.140
...
Hotfix/2.3.140
2022-08-15 15:06:37 -04:00
Mike Reeves
604af45661
Merge pull request #8534 from Security-Onion-Solutions/2.3.140hotfix3
...
2.3.140 Hotfix
2022-08-15 13:09:14 -04:00
Mike Reeves
3f435c5c1a
2.3.140 Hotfix
2022-08-15 13:03:25 -04:00
Mike Reeves
7769af4541
Merge pull request #8531 from Security-Onion-Solutions/dougburks-patch-1
2022-08-12 15:05:04 -04:00
Mike Reeves
9903be8120
Merge pull request #8532 from Security-Onion-Solutions/2.3.140-20220815
2022-08-12 15:04:00 -04:00
Doug Burks
991a601a3d
FIX: so-curator-closed-delete-delete needs to reference new Elasticsearch directory #8529
2022-08-12 13:21:06 -04:00
Doug Burks
86519d43dc
Update HOTFIX
2022-08-12 13:20:15 -04:00
Doug Burks
179f669acf
FIX: so-curator-closed-delete-delete needs to reference new Elasticsearch directory #8529
2022-08-12 13:10:47 -04:00
Doug Burks
a02f878dcc
Merge pull request #8517 from Security-Onion-Solutions/fix/cases-tlp-2.0
...
Fix/cases tlp 2.0
2022-08-11 15:55:21 -04:00
Doug Burks
32c29b28eb
revert to lower case #8469
2022-08-11 15:33:30 -04:00
Doug Burks
7bf2603414
revert to lower case #8469
2022-08-11 15:32:49 -04:00
Doug Burks
4003876465
FIX: Fix TLP options in Cases to align with TLP 2.0 #8469
2022-08-11 08:49:54 -04:00
Doug Burks
4c677961c4
FIX: Fix TLP options in Cases to align with TLP 2.0 #8469
2022-08-11 08:49:25 -04:00
weslambert
e950d865d8
Merge pull request #8485 from Security-Onion-Solutions/foxtrot
...
Improve local file modification check in SOUP
2022-08-08 10:06:13 -04:00
weslambert
fd7a118664
Invoke check_local_mods() function earlier so we don't have to wait for Docker image downloads or OS updates before checking and potentially exiting SOUP
2022-08-08 08:58:19 -04:00
weslambert
d7906945df
Add extra set of brackets for comparison of integers
2022-08-08 08:24:38 -04:00
weslambert
cb384ae024
Ensure check_local_mods() runs at the beginning of SOUP, in addition to the end, and also that it prompts (forces) the user to accept/review local modifications.
2022-08-05 11:25:33 -04:00
weslambert
7caead2387
Merge pull request #8476 from Security-Onion-Solutions/dev
...
Merge dev into foxtrot
2022-08-05 11:11:51 -04:00
Josh Patterson
4827c9e0d4
Merge pull request #8475 from Security-Onion-Solutions/issue/8441
...
add SYSTEMD_UNIT_FILE back to map file
2022-08-05 10:55:44 -04:00
m0duspwnens
3b62fc63c9
add SYSTEMD_UNIT_FILE back to map file
2022-08-05 10:53:07 -04:00
Josh Patterson
ad32c2b1a5
Merge pull request #8472 from Security-Onion-Solutions/issue/8441
...
ensure ExecStartPre is removed from default salt-minion service file
2022-08-04 16:36:16 -04:00
m0duspwnens
f02f431dab
ensure ExecStartPre is removed from default salt-minion service file
2022-08-04 16:34:06 -04:00
Josh Patterson
812964e4d8
Merge pull request #8460 from Security-Onion-Solutions/issue/8441
...
ensure parent dirs are created
2022-08-03 17:01:50 -04:00
m0duspwnens
99805cc326
ensure parent dirs are created
2022-08-03 16:54:22 -04:00
Josh Patterson
8d2b3f3dfe
Merge pull request #8457 from Security-Onion-Solutions/issue/8441
...
fix the requisite
2022-08-03 15:17:44 -04:00
m0duspwnens
15f7fd8920
fix the requisite
2022-08-03 15:16:12 -04:00
Josh Patterson
50460bf91e
Merge pull request #8456 from Security-Onion-Solutions/issue/8441
...
manage salt-minion start delay with systemd drop-in file
2022-08-03 13:44:09 -04:00
weslambert
ee654f767a
Merge pull request #8453 from Security-Onion-Solutions/fix/elasticsearch_geoip_local
...
Configure Elasticsearch to use local GeoLite2 databases by default
2022-08-03 09:40:23 -04:00
weslambert
8c694a7ca3
Disable ingest.geoip.downloader by default
2022-08-03 09:21:40 -04:00
weslambert
9ac640fa67
Remove airgap-specific logic for ingest.geoip.downloader
2022-08-03 09:21:03 -04:00
m0duspwnens
db8d9fff2c
manage salt-minion start delay with systemd drop-in file - https://github.com/Security-Onion-Solutions/securityonion/issues/8441
2022-08-02 16:22:26 -04:00
weslambert
811063268f
Merge pull request #8447 from Security-Onion-Solutions/feature/kibana_version_8_3_3
...
Update Kibana version to 8.3.3
2022-08-02 15:27:22 -04:00
weslambert
f2b10a5a86
Update Kibana version to 8.3.3
2022-08-02 11:32:01 -04:00
weslambert
c69cac0e5f
Update Kibana version to 8.3.3
2022-08-02 11:31:35 -04:00
weslambert
fed4433088
Merge pull request #8446 from Security-Onion-Solutions/fix/airgap_elasticsearch_geoip
...
Update Elasticsearch defaults file and config.map.jinja to allow for local GeoIP database use when airgap is enabled
2022-08-02 11:20:35 -04:00
Wes Lambert
839cfcaefa
Update Elasticsearch defaults file and config.map.jinja to allow for local GeoIP database use when airgap is enabled
2022-08-02 14:32:17 +00:00
weslambert
3123407ef0
Update Elastic version to 8.3.3
2022-08-01 10:41:39 -04:00
weslambert
d24125c9e6
Update Elastic version to 8.3.3
2022-08-01 10:40:57 -04:00
weslambert
64dc278c95
Merge pull request #8432 from Security-Onion-Solutions/dev
...
Merge dev into foxtrot
2022-08-01 10:12:35 -04:00
Doug Burks
626a824cd6
Merge pull request #8409 from Security-Onion-Solutions/dougburks-patch-1
...
increment version
2022-07-29 16:31:32 -04:00
Doug Burks
10ba3b4b5a
increment version
2022-07-29 16:30:12 -04:00
Doug Burks
1d059fc96e
Merge pull request #8408 from Security-Onion-Solutions/fix/dashboards-pivot-pcap
...
FIX: Display PCAP menu action on Dashboards page #8343
2022-07-29 16:29:32 -04:00
Doug Burks
4c1585f8d8
FIX: Display PCAP menu action on Dashboards page #8343
2022-07-29 14:50:10 -04:00
Josh Patterson
e235957c00
Merge pull request #8405 from Security-Onion-Solutions/issue/8404
...
https://github.com/Security-Onion-Solutions/securityonion/issues/8404
2022-07-29 10:07:52 -04:00
m0duspwnens
2cc665bac6
https://github.com/Security-Onion-Solutions/securityonion/issues/8404
2022-07-29 09:55:20 -04:00
Jason Ertel
d6e118dcd3
Merge pull request #8403 from Security-Onion-Solutions/kilo
...
Increment version
2022-07-29 08:28:14 -04:00
Jason Ertel
1d2534b2a1
Increment version
2022-07-29 08:24:57 -04:00
Doug Burks
484aa7b207
Merge pull request #8336 from Security-Onion-Solutions/hotfix/2.3.140
...
Hotfix/2.3.140
2022-07-19 16:13:47 -04:00
Mike Reeves
6986448239
Merge pull request #8333 from Security-Onion-Solutions/2.3.140hotfix
...
2.3.140 Hotfix
2022-07-19 14:47:50 -04:00
Mike Reeves
f1d74dcd67
Merge pull request #8334 from Security-Onion-Solutions/2.3.140hotfix
...
2.3.140 Hotfix
2022-07-19 14:47:29 -04:00
Mike Reeves
dd48d66c1c
2.3.140 Hotfix
2022-07-19 14:39:44 -04:00
Mike Reeves
440f4e75c1
Merge pull request #8332 from Security-Onion-Solutions/dev
...
Merge Hotfix
2022-07-19 13:30:20 -04:00
weslambert
c795a70e9c
Merge pull request #8329 from Security-Onion-Solutions/fix/elastalert_stop_check_enabled
...
Check to ensure Elastalert is enabled and suppress missing container error output
2022-07-19 13:27:35 -04:00
weslambert
340dbe8547
Check to see if Elastalert is enabled before trying to run 'so-elastalert-stop'. Also suppress error output for when so-elastalert container is not present.
2022-07-19 13:25:09 -04:00
Mike Reeves
52a5e743e9
Merge pull request #8327 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-07-19 11:17:13 -04:00
Wes Lambert
5ceff52796
Move Elastalert indices check to function and call from beginning of soup and during pre-upgrade to 2.3.140
2022-07-19 14:54:39 +00:00
Wes Lambert
f3a0ab0b2d
Perform Elastalert index check twice
2022-07-19 14:48:19 +00:00
Wes Lambert
4a7c994b66
Revise Elastalert index check deletion logic
2022-07-19 14:31:45 +00:00
Mike Reeves
07b8785f3d
Update soup
2022-07-19 10:23:10 -04:00
Mike Reeves
9a1092ab01
Update HOTFIX
2022-07-19 10:21:36 -04:00
Mike Reeves
fbcbfaf7c3
Merge pull request #8310 from Security-Onion-Solutions/dev
...
2.3.140
2022-07-18 11:23:54 -04:00
Mike Reeves
497110d6cd
Merge pull request #8320 from Security-Onion-Solutions/2.3.140-2
...
2.3.140
2022-07-18 10:57:53 -04:00
Mike Reeves
3711eb52b8
2.3.140
2022-07-18 10:54:50 -04:00
weslambert
8099b1688b
Merge pull request #8319 from Security-Onion-Solutions/fix/elasticsearch_query_missing_query_path
...
Fix missing query path for so-elasticsearch-query
2022-07-18 09:47:16 -04:00
weslambert
2914007393
Add forward slash to fix issue with missing query path
2022-07-18 09:07:34 -04:00
weslambert
f5e10430ed
Add forward slash to fix issue with missing query path
2022-07-18 09:07:13 -04:00
Mike Reeves
b5a78d4577
Merge pull request #8309 from Security-Onion-Solutions/2.3.140
...
2.3.140
2022-07-15 13:36:31 -04:00
Mike Reeves
0a14dad849
Update VERIFY_ISO.md
2022-07-15 13:31:51 -04:00
Mike Reeves
3430df6a20
2.3.140
2022-07-15 13:26:25 -04:00
Mike Reeves
881915f871
Merge pull request #8306 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update defaults.yaml
2022-07-14 16:20:29 -04:00
Mike Reeves
cf8c6a6e94
Update defaults.yaml
2022-07-14 15:17:27 -04:00
weslambert
52ebbf8ff3
Merge pull request #8304 from Security-Onion-Solutions/fix/kibana_space_defaults_web_response_url
...
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:08:02 -04:00
weslambert
2443e8b97e
Change web_response to evaluate the response from the Spaces API and the default space query
2022-07-14 12:04:56 -04:00
weslambert
4241eb4b29
Merge pull request #8298 from Security-Onion-Solutions/fix/kibana_space_defaults_shebang
...
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:50:21 -04:00
weslambert
0fd4f34b5b
Add shebang so that so-kibana-space-defaults will work correctly on Ubuntu
2022-07-13 16:48:39 -04:00
Josh Patterson
37df49d4f3
Merge pull request #8296 from Security-Onion-Solutions/elastalert_esversion_check
...
use onlyif requisite instead
2022-07-13 15:22:40 -04:00
m0duspwnens
7d7cf42d9a
use onlyif requisite instead
2022-07-13 15:21:34 -04:00
Doug Burks
de0a7d3bcd
Merge pull request #8293 from Security-Onion-Solutions/dougburks-patch-1
...
change hyperlink for Elastic 8 issues
2022-07-13 12:41:50 -04:00
Doug Burks
c67a58a5b1
change hyperlink for Elastic 8 issues
2022-07-13 12:40:03 -04:00
Josh Patterson
e79ca4bb9b
Merge pull request #8291 from Security-Onion-Solutions/elastalert_esversion_check
...
do not start elastalert if elasticsearch is not v8
2022-07-13 11:24:12 -04:00
m0duspwnens
086cf3996d
do not start elastalert if elasticsearch is not v8
2022-07-13 11:21:27 -04:00
Doug Burks
7ae5d49a4a
Merge pull request #8290 from Security-Onion-Solutions/dougburks-patch-1
...
increment version to 2.3.140
2022-07-13 09:33:37 -04:00
Doug Burks
34d3c6a882
increment version to 2.3.140
2022-07-13 09:32:28 -04:00
weslambert
4a5664db7b
Merge pull request #8289 from Security-Onion-Solutions/fix/soup_unsupported_indices_check
...
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:15:22 -04:00
weslambert
513c7ae56c
Add missing 'fi' to if/then for unsupported indices check
2022-07-13 09:13:28 -04:00
weslambert
fa894cf83b
Merge pull request #8288 from Security-Onion-Solutions/fix/soup_elastalert_indices_deletion_check
...
Ensure Elastalert indices are deleted before continuing with SOUP
2022-07-13 08:44:04 -04:00
weslambert
8e92060c29
Ensure Elastalert indices are deleted before continuing with SOUP -- if they are not, generate a failure condition
2022-07-13 08:38:55 -04:00
weslambert
d7eb8b9bcb
Merge pull request #8281 from Security-Onion-Solutions/fix/soup_elasticsearch8_index_compatibility
...
SOUP - Check for indices created by Elasticsearch 6
2022-07-12 16:20:47 -04:00
weslambert
d0a0ca8458
Update exit code for ES checks
2022-07-12 16:15:44 -04:00
Josh Patterson
57b79421d8
Merge pull request #8280 from Security-Onion-Solutions/fix_filebeat
...
move port bindings back under port bindings
2022-07-12 16:12:49 -04:00
weslambert
4502182b53
Typo - Ensure Elasticsearch version 6 indices are checked
2022-07-12 15:35:46 -04:00
weslambert
0fc6f7b022
Add check for Elasticsearch 6 indices
2022-07-12 15:34:24 -04:00
m0duspwnens
ec451c19f8
move port bindings back under port bindings
2022-07-12 15:17:25 -04:00
weslambert
e9a22d0aff
Merge pull request #8275 from Security-Onion-Solutions/fix/filebeat_es_output_additions
...
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
2022-07-11 19:03:07 -04:00
weslambert
11d3ed36b7
Specify outputs for Elasticsearch and Kibana for Eval and Import Mode
...
Add outputs for Elasticsearch and Kibana for Eval/Import Mode, since Logstash is not used in Eval Mode or Import Mode. Otherwise, logs from these inputs end up in a filebeat-prefixed index.
2022-07-11 17:22:09 -04:00
weslambert
d828bbfe47
Merge pull request #8273 from Security-Onion-Solutions/fix/kibana_space_defaults_cases
...
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:39:30 -04:00
weslambert
bd32394560
Add securitySolutionCases feature to ensure Cases are disabled by default
2022-07-11 16:38:05 -04:00
weslambert
6f4f050a96
Merge pull request #8272 from Security-Onion-Solutions/fix/soup_kibana_space_defaults
...
Run so-kibana-space-defaults when upgrading to 2.3.140
2022-07-11 14:47:11 -04:00
weslambert
f77edaa5c9
Run so-kibana-space-defaults to re-establish the default enabled features since Fleet feature name changed
2022-07-11 14:41:23 -04:00
Jason Ertel
15124b6ad7
Merge pull request #8271 from Security-Onion-Solutions/kilo
...
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:47:28 -04:00
Jason Ertel
077053afbd
Add content-type header to PUT request, now required in Kratos 0.10.1
2022-07-11 13:43:41 -04:00
weslambert
dd1d5b1a83
Merge pull request #8270 from Security-Onion-Solutions/fix/curator_actions_delete_kratos
...
Add delete and warm action for Kratos indices in applicable Curator delete/warm scripts
2022-07-11 11:39:43 -04:00
weslambert
e82b6fcdec
Typo - Change 'delete' to 'warm'
2022-07-11 11:34:53 -04:00
weslambert
8c8ac41b36
Add action for Kratos indices
2022-07-11 11:32:03 -04:00
weslambert
b611dda143
Add delete action for Kratos indices
2022-07-11 11:31:22 -04:00
weslambert
3f5b98d14d
Merge pull request #8269 from Security-Onion-Solutions/fix/curator_actions_kratos
...
Add Curator actions and adjust Curator close scripts to account for so-kibana and so-kratos indices
2022-07-11 11:21:20 -04:00
Wes Lambert
0b6219d95f
Adjust Curator close scripts to include Kibana and Kratos indices
2022-07-11 14:51:33 +00:00
Wes Lambert
2f729e24d9
Add Curator action files for Kratos indices
2022-07-11 14:34:10 +00:00
weslambert
992b6e14de
Merge pull request #8268 from Security-Onion-Solutions/fix/kibana_disable_fleetv2
...
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:09:12 -04:00
weslambert
09a1d8c549
Disable fleetv2 because it is now used to control Fleet visibility and 'fleet' is now used for 'Integrations'
2022-07-11 10:06:24 -04:00
Jason Ertel
f28c6d590a
Merge pull request #8263 from Security-Onion-Solutions/kilo
...
Remove Jinja from yaml files before parsing
2022-07-08 20:32:22 -04:00
Jason Ertel
4f8bb6049b
Future proof the jinja check to ensure the script does not silently overwrite jinja templates
2022-07-08 17:30:00 -04:00
Jason Ertel
a8e6b26406
Remove Jinja from yaml files before parsing
2022-07-08 17:07:24 -04:00
weslambert
2903bdbc7e
Merge pull request #8260 from Security-Onion-Solutions/fix/kratos_dedicated_index_and_filestream_id_additions
...
Add dedicated index for Kratos and IDs for all filestream inputs
2022-07-08 12:04:40 -04:00
Wes Lambert
5c90fce3a1
Add Kratos Logstash output to search pipeline for Logstash
2022-07-08 15:58:00 +00:00
Wes Lambert
26698cfd07
Add Logstash output for dedicated Kratos index
2022-07-08 15:55:55 +00:00
Wes Lambert
764e8688b1
Modify Kratos input to use dedicated index and add filestream ID for all applicable inputs
2022-07-08 15:53:55 +00:00
Wes Lambert
b06c16f750
Add ingest node pipeline for Kratos
2022-07-08 15:53:00 +00:00
weslambert
42cfab4544
Merge pull request #8256 from Security-Onion-Solutions/fix/kibana_restart_after_role_sync
...
Restart Kibana in case it times out before being able to read role update
2022-07-07 17:44:47 -04:00
weslambert
4bbc901860
Restart Kibana in case it times out before being able to read in new role configuration
2022-07-07 17:19:02 -04:00
weslambert
a343f8ced0
Merge pull request #8255 from Security-Onion-Solutions/fix/so_kibana_user_role
...
Force so-user to sync roles to ensure so_kibana role change
2022-07-07 16:19:30 -04:00
weslambert
85be2f4f99
Force so-user to sync roles to ensure so_kibana role change from superuser to kibana_system
2022-07-07 15:55:44 -04:00
weslambert
8b3fa0c4c6
Merge pull request #8252 from Security-Onion-Solutions/feature/elastic_8_3_2
...
Update to Elastic 8.3.2
2022-07-07 11:14:14 -04:00
weslambert
ede845ce00
Update to Kibana 8.3.2
2022-07-07 11:05:44 -04:00
weslambert
42c96553c5
Update to Kibana 8.3.2
2022-07-07 11:04:43 -04:00
Mike Reeves
41d5cdd78c
Merge pull request #8246 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2022-07-06 16:39:38 -04:00
Mike Reeves
c819d3a558
Update soup
2022-07-06 16:36:57 -04:00
Mike Reeves
c00d33632a
Update soup
2022-07-06 16:23:02 -04:00
Mike Reeves
a1ee793607
Merge pull request #8242 from Security-Onion-Solutions/fixsoup
...
Move soup order
2022-07-06 09:18:16 -04:00
Mike Reeves
1589107b97
Move soup order
2022-07-06 08:59:21 -04:00
Mike Reeves
31688ee898
Merge pull request #8238 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Make soup enforce versions
2022-07-05 16:56:14 -04:00
Mike Reeves
f1d188a46d
Update soup
2022-07-05 16:50:20 -04:00
Mike Reeves
5f0c3aa7ae
Update soup
2022-07-05 16:49:20 -04:00
weslambert
2b73cd1156
Merge pull request #8236 from Security-Onion-Solutions/fix/localfile_analyzer
...
Strip quotes and ensure file_path is typed as a list (localfile analyzer)
2022-07-05 16:28:56 -04:00
Mike Reeves
c6fac28804
Update soup
2022-07-05 16:26:44 -04:00
Jason Ertel
9d43b7ec89
Rollback string manipulation in favor of fixed unit tests
2022-07-05 16:21:27 -04:00
Jason Ertel
f6266b19cc
Fix unit test issues
2022-07-05 16:20:24 -04:00
Mike Reeves
df0a774ffd
Make soup enforce versions
2022-07-05 16:17:32 -04:00
weslambert
77ee30f31a
Merge pull request #8237 from Security-Onion-Solutions/feature/elastic_8_3_1
...
Bump Elastic to 8.3.1
2022-07-05 14:50:24 -04:00
weslambert
2938464501
Update to Kibana 8.3.1
2022-07-05 14:46:02 -04:00
weslambert
79e88c9ca3
Update to Kibana 8.3.1
2022-07-05 14:45:30 -04:00
Wes Lambert
e96206d065
Strip quotes and ensure file_path is typed as a list
2022-07-05 14:25:54 +00:00
Josh Brower
7fa9ca8fc6
Merge pull request #8233 from Security-Onion-Solutions/fix/remove-sudo-bpf
...
Remove unneeded sudo
2022-07-05 09:23:48 -04:00
Josh Brower
a1d1779126
Remove unneeded sudo
2022-07-05 09:21:05 -04:00
Josh Patterson
fb365739ae
Merge pull request #8225 from Security-Onion-Solutions/salltupdate
...
bootstrap-salt can now update to minor version with -r
2022-07-01 08:53:59 -04:00
m0duspwnens
5f898ae569
change to egrep
2022-07-01 08:47:46 -04:00
m0duspwnens
f0ff0d51f7
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 16:59:54 -04:00
m0duspwnens
7524ea2c05
allow bootstrap-salt to install specific verion even if -r is used
2022-06-30 15:10:13 -04:00
Mike Reeves
6bb979e2b6
Merge pull request #8219 from Security-Onion-Solutions/salty
...
Salty
2022-06-30 13:34:03 -04:00
Mike Reeves
8b3d5e808e
Fix repo location
2022-06-30 13:30:56 -04:00
Mike Reeves
e86b7bff84
Fix repo location
2022-06-30 13:29:21 -04:00
Josh Patterson
69ce3613ff
Merge pull request #8217 from Security-Onion-Solutions/salltupdate
...
point to salt3004.2
2022-06-30 11:29:35 -04:00
m0duspwnens
0ebd957308
point to salt3004.2
2022-06-30 11:26:03 -04:00
Josh Patterson
c3979f5a32
Merge pull request #8207 from Security-Onion-Solutions/salltupdate
...
Saltupdate 3004.2
2022-06-28 11:20:53 -04:00
m0duspwnens
8fccd4598a
update saltstack.list for 3004.2
2022-06-27 16:23:01 -04:00
weslambert
3552dfac03
Merge pull request #8199 from Security-Onion-Solutions/fix/filebeat_filestream_elastic8
...
Change type from 'log' to 'filestream' to ensure compatibility with E…
2022-06-27 14:58:54 -04:00
Josh Patterson
fba5592f62
Update minion.defaults.yaml
2022-06-27 12:10:18 -04:00
Josh Patterson
05e84699d1
Update master.defaults.yaml
2022-06-27 12:09:39 -04:00
Mike Reeves
f36c8da1fe
Update so-functions
2022-06-27 12:04:33 -04:00
Mike Reeves
080daee1d8
Update so-functions
2022-06-27 11:43:01 -04:00
Mike Reeves
909e876509
Update ubuntu.sls
2022-06-27 11:41:49 -04:00
Jason Ertel
ac68fa822b
Merge pull request #8200 from Security-Onion-Solutions/contrib
...
Add gh action for contrib check
2022-06-27 11:25:10 -04:00
Jason Ertel
675ace21f5
Add gh action for contrib check
2022-06-27 11:11:15 -04:00
weslambert
85f790b28a
Change type from 'log' to 'filestream' to ensure compatibility with Elastic 8
2022-06-27 10:39:58 -04:00
weslambert
d0818e83c9
Merge pull request #8197 from Security-Onion-Solutions/fix/localfile_analyzer_csv_path
...
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:36:59 -04:00
weslambert
568b43d0af
Ensure file_path uses jinja to derive the value(s) from the pillar
2022-06-27 10:10:13 -04:00
Jason Ertel
2e123b7a4f
Merge pull request #8175 from Security-Onion-Solutions/kilo
...
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 08:16:39 -04:00
Jason Ertel
ba6f716e4a
Avoid failing setup due to retrying while waiting for lock file
2022-06-23 06:09:04 -04:00
weslambert
10bcc43e85
Merge pull request #8167 from Security-Onion-Solutions/feature/update_es_8_2_3
...
Update to Elastic 8.2.3
2022-06-21 16:11:39 -04:00
weslambert
af687fb2b5
Update config_saved_objects.ndjson
2022-06-21 16:06:28 -04:00
weslambert
776cc30a8e
Update to ES 8.2.3
2022-06-21 16:06:01 -04:00
Doug Burks
00cf0b38d0
Merge pull request #8165 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve default dashboards #8136
2022-06-21 12:57:46 -04:00
Doug Burks
94c637449d
FIX: Improve default dashboards #8136
2022-06-21 12:53:06 -04:00
Josh Brower
0a203add3b
Merge pull request #8145 from Security-Onion-Solutions/defensivedepth-patch-1
...
pin v1.6.0
2022-06-17 13:14:58 -04:00
Josh Brower
b8ee896f8a
pin v1.6.0
2022-06-17 12:38:54 -04:00
Josh Brower
238e671f34
Merge pull request #8129 from Security-Onion-Solutions/fix/curator-cron
...
Change curator to daily for true cluster
2022-06-15 11:40:53 -04:00
Josh Brower
072cb3cca2
Change curator to daily for true cluster
2022-06-15 11:38:38 -04:00
weslambert
44595cb333
Merge pull request #8123 from Security-Onion-Solutions/foxtrot
...
Merge foxtrot into dev
2022-06-14 15:44:13 -04:00
weslambert
959cec1845
Delete Elastalert indices before upgrading to Elastic 8
2022-06-14 11:40:11 -04:00
Doug Burks
286909af4b
Merge pull request #8113 from Security-Onion-Solutions/fix/pfsense-category
...
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:08:00 -04:00
doug
025993407e
FIX: Add event.category field to pfsense firewall logs #8112
2022-06-13 08:03:44 -04:00
weslambert
151a42734c
Update Elastic version to 8.2.2
2022-06-08 15:07:45 -04:00
weslambert
11e3576e0d
Update Elastic version to 8.2.2
2022-06-08 15:07:07 -04:00
weslambert
adeccd0e7f
Merge pull request #8097 from Security-Onion-Solutions/dev
...
Merge latest dev into foxtrot
2022-06-08 15:01:09 -04:00
weslambert
aadf391e5a
Temporarily downgrade version for merge
2022-06-08 14:59:01 -04:00
weslambert
47f74fa5c6
Temporarily downgrade version for merge
2022-06-08 14:58:05 -04:00
Jason Ertel
e405750d26
Merge pull request #8095 from Security-Onion-Solutions/kilo
...
Bump version to 2.3.140
2022-06-08 09:07:56 -04:00
Jason Ertel
e36c33485d
Bump version to 2.3.140
2022-06-08 09:04:57 -04:00
Mike Reeves
65165e52f4
Merge pull request #8086 from Security-Onion-Solutions/dev
...
2.3.130
2022-06-07 15:51:12 -04:00
Mike Reeves
2cceae54df
Merge pull request #8087 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 13:44:38 -04:00
Mike Reeves
8912e241aa
2.3.130
2022-06-07 13:41:51 -04:00
Mike Reeves
7357f157ec
Merge pull request #8085 from Security-Onion-Solutions/2.3.130
...
2.3.130
2022-06-07 12:04:47 -04:00
Mike Reeves
37881bd4b6
2.3.130
2022-06-07 11:34:10 -04:00
Josh Brower
2574f0e23d
Merge pull request #8081 from Security-Onion-Solutions/fix/fleetdm-websockets
...
Allow websockets for fleetdm
2022-06-06 19:15:02 -04:00
Josh Brower
c9d9804c3a
Allow websockets for fleetdm
2022-06-06 17:26:24 -04:00
Doug Burks
73baa1d2f0
Merge pull request #8073 from Security-Onion-Solutions/dougburks-patch-1
...
Update motd.md to include links to Dashboards and Cases
2022-06-04 08:53:54 -04:00
Doug Burks
dce415297c
improve readability in motd.md
2022-06-04 06:59:09 -04:00
Doug Burks
de126647f8
Update motd.md to include links to Dashboards and Cases
2022-06-04 06:55:08 -04:00
Doug Burks
c34f456151
Merge pull request #8069 from Security-Onion-Solutions/dougburks-patch-1
...
add bar and pie examples to overview dashboard in dashboards.queries.…
2022-06-03 15:04:16 -04:00
Doug Burks
83bff5ee87
add bar and pie examples to overview dashboard in dashboards.queries.json
2022-06-03 15:02:40 -04:00
Doug Burks
918f431728
Merge pull request #8065 from Security-Onion-Solutions/dougburks-patch-1
...
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:13:39 -04:00
Doug Burks
4a886338c8
fix description field for default dashboard in dashboards.queries.json
2022-06-03 11:10:01 -04:00
Doug Burks
7da1802eae
Add sankey diagram to default dashboard in dashboards.queries.json
2022-06-03 11:03:48 -04:00
Mike Reeves
ff92b524c2
Merge pull request #8062 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update soup
2022-06-02 11:51:42 -04:00
Mike Reeves
395eaa39b4
Update soup
2022-06-02 11:45:37 -04:00
Mike Reeves
2867a32931
Merge pull request #8061 from Security-Onion-Solutions/soup130
...
soup for 130
2022-06-02 10:42:17 -04:00
Mike Reeves
fce43cf390
soup for 130
2022-06-02 10:33:18 -04:00
Josh Patterson
e5c9b91529
Merge pull request #8054 from Security-Onion-Solutions/dmz_receiver
...
Dmz receiver
2022-06-01 15:31:42 -04:00
m0duspwnens
e5b74bcb78
remove podman state
2022-06-01 15:26:25 -04:00
Doug Burks
91f8d3e5e9
Merge pull request #8050 from Security-Onion-Solutions/fix/elastalert-query
...
FIX: Elastalert query in Hunt #8049
2022-05-31 16:54:34 -04:00
Doug Burks
269b16bbfd
https://github.com/Security-Onion-Solutions/securityonion/issues/8049
2022-05-31 16:51:05 -04:00
Doug Burks
cd382a1b25
FIX: Elastalert query in Hunt #8049
2022-05-31 16:50:32 -04:00
Doug Burks
e1c9b0d108
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:52 -04:00
Doug Burks
9a98667e85
FIX: Elastalert query in Hunt #8049
2022-05-31 16:47:11 -04:00
weslambert
494ce0756d
Merge pull request #8045 from Security-Onion-Solutions/fix/mhr_naming
...
Fix naming for Malware Hash Registry analyzer
2022-05-31 07:52:48 -04:00
Wes Lambert
7f30a364ee
Make sure everything is added back after renaming mhr to malwarehashregistry
2022-05-31 11:44:35 +00:00
Wes Lambert
c82aa89497
Fix Malware Hash Registry naming so it's more descriptive in SOC
2022-05-31 11:41:48 +00:00
Josh Brower
025677a1e6
Merge pull request #8034 from Security-Onion-Solutions/feature/sigmafp
...
Feature/SigmaCustomFilters
2022-05-31 07:25:44 -04:00
Josh Brower
a5361fb745
Change Target_log name
2022-05-28 18:07:05 -04:00
Mike Reeves
30d7801ae1
Merge pull request #8033 from Security-Onion-Solutions/kilo
2022-05-28 11:38:35 -04:00
Jason Ertel
210bc556db
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:29:04 -04:00
Jason Ertel
e87e672b9e
Add logscan and suricata variants for cloud tests to move from PM into the cloud and help alleviate disk contention
2022-05-28 10:28:20 -04:00
Jason Ertel
a70da41f20
Merge pull request #8032 from Security-Onion-Solutions/kilo
...
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:34:40 -04:00
Jason Ertel
8bb02763dc
Exclude pkg upgrade retry error logs from failing setup
2022-05-28 08:28:10 -04:00
weslambert
a59ada695b
Merge pull request #8031 from Security-Onion-Solutions/fix/screenshots
...
Fix/screenshots
2022-05-27 17:05:51 -04:00
doug
b93a108386
update Cases screenshot in README
2022-05-27 16:33:08 -04:00
doug
6089f3906d
update screenshots and README
2022-05-27 16:32:00 -04:00
Josh Brower
94ee45ac63
Merge pull request #8029 from Security-Onion-Solutions/upgrade/navigator
...
Upgrade Navigator to 4.6.4
2022-05-27 14:46:59 -04:00
Josh Brower
43cb78a6a8
Upgrade Navigator
2022-05-27 14:21:11 -04:00
Josh Patterson
76bb1fbbcc
Merge pull request #8014 from Security-Onion-Solutions/issue/7918
...
manage suricata classifications.config
2022-05-26 13:13:03 -04:00
m0duspwnens
53d6e1d30d
simplfy
2022-05-26 11:51:17 -04:00
m0duspwnens
1bfde852f5
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:43:31 -04:00
m0duspwnens
53883e4ade
manage suricata classifications.config https://github.com/Security-Onion-Solutions/securityonion/issues/7918
2022-05-26 11:40:33 -04:00
weslambert
1a0ac4d253
Merge pull request #8007 from Security-Onion-Solutions/fix/filestream-id
...
Add filestream input ID for RITA logs
2022-05-25 10:11:36 -04:00
weslambert
44622350ea
Add ID for RITA filestream inputs
2022-05-25 10:09:01 -04:00
weslambert
99864f4787
Merge pull request #8001 from Security-Onion-Solutions/feature/analyzer_readme
...
Add configuration requirements for various analyzers
2022-05-25 09:33:07 -04:00
Doug Burks
6bd02c0b99
Merge pull request #8003 from Security-Onion-Solutions/feature/elastic-7.17.4
...
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:24:13 -04:00
Doug Burks
1d0bb21908
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:30 -04:00
Doug Burks
bde06e7ec5
UPGRADE: Elastic 7.17.4 #8002
2022-05-24 13:19:01 -04:00
Wes Lambert
b93512eb01
Adjust verbiage around pillar configuration
2022-05-24 12:36:32 +00:00
Wes Lambert
92dee14ee8
Add configuration requirements for various analyzers
2022-05-24 12:29:14 +00:00
weslambert
3e6dfcfaca
Merge pull request #7996 from Security-Onion-Solutions/weslambert-patch-2
...
Create Virustotal README
2022-05-23 11:43:43 -04:00
weslambert
a6f1bf3aef
Create Virustotal README
2022-05-23 11:39:44 -04:00
Jason Ertel
88f17f037e
Merge pull request #7982 from Security-Onion-Solutions/kilo
...
Upgrade to Kratos 0.9.0-alpha.3
2022-05-19 13:28:58 -04:00
Jason Ertel
c20859f8c3
Upgrade to Kratos 0.9.0-alpha.3
2022-05-18 17:05:21 -04:00
Jason Ertel
c95bafd521
Merge pull request #7969 from Security-Onion-Solutions/fix/helpers-analyzers
...
Only import yaml module when config is loaded
2022-05-18 07:15:32 -04:00
Wes Lambert
429ccb2dcc
Only import yaml module when config is loaded
2022-05-18 02:07:39 +00:00
weslambert
94ca3ddbda
Merge pull request #7961 from Security-Onion-Solutions/weslambert-patch-1
...
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 13:33:24 -04:00
weslambert
d3206a048f
Add information for MHR and WhoisLookup, and other minor updates
2022-05-17 12:49:16 -04:00
weslambert
ff855eb8f7
Merge pull request #7958 from Security-Onion-Solutions/feature/mhr_analyzer
...
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 12:42:01 -04:00
Wes Lambert
8af1f19ac3
Another no_results change
2022-05-17 16:12:43 +00:00
Wes Lambert
e4a7e3cba6
Change 'No results found.' to 'no_results'
2022-05-17 16:11:58 +00:00
weslambert
2688083ff1
Merge pull request #7959 from Security-Onion-Solutions/feature/whoislookup-analyzer
...
Add Whoislookup RDAP-based analyzer
2022-05-17 12:09:06 -04:00
Wes Lambert
766e9748c5
Add Whoislookup RDAP-based analyzer
2022-05-17 15:52:12 +00:00
weslambert
3761b491c0
Remove whitespace
2022-05-17 10:50:33 -04:00
Wes Lambert
e8fc3ccdf4
Add Team Cymru Malware Hash Registry Analyzer
2022-05-17 14:44:53 +00:00
Doug Burks
eb9597217c
Merge pull request #7949 from Security-Onion-Solutions/fix/dashboards-hunt-queries
...
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:47:06 -04:00
doug
5cbb50a781
update dashboards.queries.json and hunt.queries.json
2022-05-16 08:33:48 -04:00
Jason Ertel
685789de33
Merge pull request #7936 from Security-Onion-Solutions/kilo
...
Improved unit test coverage of new analyzers; Utilize localized summa…
2022-05-12 16:47:18 -04:00
Jason Ertel
b45b6b198b
Improved unit test coverage of new analyzers; Utilize localized summaries; Require 100% code coverage on analyzers
2022-05-12 16:32:47 -04:00
weslambert
6c506bbab0
Merge pull request #7935 from Security-Onion-Solutions/fix/pulsedive
...
Fix Pulsedive analyzer logic
2022-05-12 15:20:15 -04:00
Wes Lambert
3dc266cfa9
Add test for when indicator is not found
2022-05-12 19:02:41 +00:00
Wes Lambert
a233c08830
Update logic to handle indicators that are not present in database.
2022-05-12 19:02:02 +00:00
Doug Burks
58b049257d
Merge pull request #7932 from Security-Onion-Solutions/dougburks-patch-1
...
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:24:18 -04:00
Doug Burks
6ed3f42449
remove duplicate showSubtitle from hunt.queries.json
2022-05-12 09:23:00 -04:00
m0duspwnens
d8abc0a195
if in dmz_nodes dont add to filebeta
2022-05-11 11:51:18 -04:00
m0duspwnens
a641346c02
prevent nodes with logstash:dmz:true from being added to logstash:nodes pillar
2022-05-10 17:28:19 -04:00
Jason Ertel
60b55acd6f
Merge pull request #7926 from Security-Onion-Solutions/kilo
...
Add support for analyzers in airgapped environments
2022-05-10 17:12:18 -04:00
Jason Ertel
35e47c8c3e
Add support for analyzers in airgapped environments
2022-05-10 16:51:00 -04:00
weslambert
7f797a11f8
Merge pull request #7924 from Security-Onion-Solutions/analyzer-docs
...
Update analyzer docs with information about analyzers that require au…
2022-05-10 09:40:50 -04:00
Jason Ertel
91a7f25d3a
Corrected brand name capitalization
2022-05-10 09:39:19 -04:00
weslambert
34d57c386b
Update analyzer docs with information about analyzers that require authentication
2022-05-10 09:32:18 -04:00
weslambert
000e813fbb
Merge pull request #7921 from Security-Onion-Solutions/fix/analyzer-packages
...
Update analyzer packages to those downloaded by Alpine and add additional build script option
2022-05-09 16:43:31 -04:00
Wes Lambert
555ca2e277
Update analyzer build/testing script to download necessary Python packages
2022-05-09 20:06:39 +00:00
Wes Lambert
32adba6141
Update analyzer packages with those built from native (Alpine) Docker image
2022-05-09 20:04:41 +00:00
Jason Ertel
e19635e44a
Merge pull request #7920 from Security-Onion-Solutions/kilo
...
Disable MRU queries on dashboards
2022-05-09 15:08:55 -04:00
Jason Ertel
31c04aabdd
Disable MRU queries on dashboards
2022-05-09 15:06:43 -04:00
Jason Ertel
dc209a37cd
Merge pull request #7916 from Security-Onion-Solutions/kilo
...
Disable actions on dashboards group-by tables
2022-05-09 11:52:22 -04:00
Jason Ertel
3f35dc54d2
Disable actions on dashboards group-by tables
2022-05-09 11:44:39 -04:00
Josh Brower
8e368bdebe
Merge in upstream dev
2022-05-06 20:01:07 -04:00
Jason Ertel
0e64a9e5c3
Merge pull request #7912 from Security-Onion-Solutions/kilo
...
Add dashboard ref to soc.json
2022-05-06 15:18:05 -04:00
Jason Ertel
0786191fc9
Add dashboard ref to soc.json
2022-05-06 15:16:27 -04:00
Jason Ertel
60763c38db
Merge pull request #7911 from Security-Onion-Solutions/kilo
...
Analyzers + Dashboards
2022-05-06 13:50:54 -04:00
weslambert
9800f59ed7
Add Urlscan to observable support matrix
2022-05-06 13:11:43 -04:00
Wes Lambert
ccac71f649
Fix formatting/whitespace
2022-05-06 17:08:40 +00:00
Wes Lambert
1990ba0cf0
Fix formatting/whitespace
2022-05-06 17:08:33 +00:00
Wes Lambert
8ff5778569
Add Urlscan analyzer and tests
2022-05-06 17:01:06 +00:00
Jason Ertel
bee4cf4c52
Fix typo in analyzer desc
2022-05-06 09:20:03 -04:00
Jason Ertel
105c95909c
Dashboard queries
2022-05-04 19:32:06 -04:00
Jason Ertel
890bcd58f9
Merge branch 'dev' into kilo
2022-05-04 19:25:08 -04:00
weslambert
a96c665d04
Change test name for EmailRep
2022-05-03 14:13:25 -04:00
weslambert
f3a91d9fcd
Add EmailRep analyzer to observable support matrix
2022-05-03 10:10:57 -04:00
Wes Lambert
5a9acb3857
Add EmailRep analyzer and tests
2022-05-03 14:06:32 +00:00
Wes Lambert
8b5666b238
Ensure API key is used
2022-05-03 12:48:06 +00:00
weslambert
efb229cfcb
Update to match configuration in analyzer dir
2022-05-02 16:35:21 -04:00
weslambert
2fcb2b081d
Update allowed complexity to 12
2022-05-02 16:14:43 -04:00
weslambert
25f17a5efd
Update allowed complexity to 11
2022-04-29 09:42:57 -04:00
weslambert
66b4fe9f58
Add additional information around URI and User Agent
2022-04-28 17:14:36 -04:00
Wes Lambert
c001708707
Add Pulsedive analyzer and tests
2022-04-28 20:56:03 +00:00
weslambert
4edd729596
Add initial supported observable matrix/table
2022-04-27 08:58:34 -04:00
Wes Lambert
76f183b112
Add Greynoise analyzer and tests
2022-04-26 17:25:35 +00:00
Wes Lambert
bd63753d80
Update analyzer name/description
2022-04-25 19:27:10 +00:00
Wes Lambert
15fcaa7030
Add localfile analyzer and tests
2022-04-25 19:23:35 +00:00
Jason Ertel
71a86b0a3c
Merge pull request #7856 from Security-Onion-Solutions/bumpver
...
Bump version
2022-04-25 13:01:19 -04:00
Jason Ertel
e2145720bd
Bump version
2022-04-25 12:10:29 -04:00
Jason Ertel
d8fdf2b701
Merge branch 'dev' into kilo
2022-04-22 15:11:24 -04:00
Jason Ertel
459d388614
Only override nameservers if the first nameserver given is non empty
2022-04-22 15:08:56 -04:00
Wes Lambert
fbf6e64e67
Add initial OTX analyzer and tests
2022-04-22 17:13:40 +00:00
Wes Lambert
b2db32a2c7
Add function/test for non-existent VT api_key
2022-04-21 17:33:24 +00:00
Wes Lambert
9287d6adf7
Reduce size of test output for test
2022-04-21 16:56:22 +00:00
Wes Lambert
c8e189f35a
Add source-packages for JA3er
2022-04-21 16:46:45 +00:00
Wes Lambert
5afcc8de4f
Add JA3er analyzer and associated test
2022-04-21 16:42:46 +00:00
weslambert
d7eed52fae
Change -f to -r
2022-04-21 09:46:44 -04:00
Jason Ertel
aeb70dad8f
Doc updates
2022-04-19 14:31:21 -04:00
Jason Ertel
4129cef9fb
Add new spamhaus analyzer
2022-04-19 12:12:52 -04:00
Jason Ertel
0cb73d8f6a
Merge branch 'dev' into kilo
2022-04-18 11:04:32 -04:00
Jason Ertel
159122b52c
Merge branch 'dev' into kilo
2022-04-18 10:11:37 -04:00
Jason Ertel
2d025e944c
Add yaml since helpers module uses it
2022-04-09 17:48:21 -04:00
Jason Ertel
202ca34c6f
Remove obsolete source/site pkg dirs
2022-04-09 14:36:21 -04:00
Jason Ertel
f9568626f2
Merge branch 'dev' into kilo
2022-04-09 09:02:55 -04:00
Jason Ertel
224e30c0ee
Change localized table layout
2022-04-08 17:31:15 -04:00
Jason Ertel
ebcfbaa06d
Analyzer improvements
2022-04-08 16:57:40 -04:00
Jason Ertel
44e318e046
Provide CLI feedback for missing input
2022-04-07 10:16:44 -04:00
Jason Ertel
d8defdd7b0
Improve unit test stability
2022-04-05 07:36:25 -04:00
Jason Ertel
d2fa80e48a
Update status codes to match SOC
2022-04-05 07:20:23 -04:00
Jason Ertel
04eef0d31f
Merge branch 'dev' into kilo
2022-04-04 15:59:09 -04:00
Jason Ertel
7df6833568
Add unit tests for Urlhaus; remove placeholder whois analyzer
2022-04-04 15:58:53 -04:00
Wes Lambert
07cf3469a0
Remove pyyaml for requirements file
2022-04-04 11:40:02 +00:00
Wes Lambert
39101cafd1
Add UrlHaus analyzer and helpers script
2022-04-01 21:11:57 +00:00
Jason Ertel
2dc370c8b6
Add source packages to salt state
2022-03-31 18:56:38 -04:00
Jason Ertel
57dc848792
Support analyzer deps
2022-03-31 16:48:13 -04:00
Jason Ertel
9947ba6e43
Support CentOS paths
2022-03-31 16:47:56 -04:00
Jason Ertel
48fbc2290f
Add dep support for analyzers
2022-03-31 13:59:35 -04:00
Jason Ertel
1aba4da2bb
Correct analyzer path
2022-03-30 21:01:07 -04:00
Jason Ertel
45f511caab
Remove extra comma
2022-03-30 13:21:35 -04:00
Jason Ertel
e667bb1e59
merge
2022-03-30 10:57:40 -04:00
Jason Ertel
b2a96fab7e
merge
2022-03-29 14:07:20 -04:00
Jason Ertel
d2bf6d5618
Add build script to help pre-validate analyzers before pushing
2022-03-29 14:04:23 -04:00
Jason Ertel
484ef4bc31
Ensure generated python files are not pushed to version control
2022-03-29 13:51:12 -04:00
Jason Ertel
cb491630ae
Analyzer CI
2022-03-29 13:40:56 -04:00
Jason Ertel
0a8d24a225
Add automated CI for analyzers
2022-03-29 13:10:04 -04:00
Jason Ertel
c23b87965f
Merge branch 'dev' into kilo
2022-03-28 15:53:33 -04:00
Jason Ertel
deb9b0e5ef
Add analyze feature
2022-03-28 15:53:24 -04:00
weslambert
bb9d6673ec
Fix casing
2022-03-21 12:38:50 -04:00
weslambert
9afa949623
Don't rotate Filebeat log on startup
2022-03-21 12:38:12 -04:00
weslambert
b2c26807a3
Add xpack.reporting.kibanaServer.hostname to defaults file
2022-03-21 09:30:25 -04:00
Wes Lambert
faeaa948c8
Remove extra Salt logic and clean up output format of resultant script
2022-03-19 04:31:48 +00:00
Wes Lambert
1a6ef0cc6b
Re-enable FB module load
2022-03-19 03:55:40 +00:00
Wes Lambert
a18b38de4d
Update so-filebeat-module-setup to use new load style to avoid having to explicitly enabled filesets
2022-03-19 03:54:41 +00:00
Wes Lambert
2e7d314650
Remove Cyberark module
2022-03-19 03:43:55 +00:00
Wes Lambert
c97847f0e2
Remove Threat Intel Recored Future fileset
2022-03-19 03:43:34 +00:00
Wes Lambert
59a2ac38f5
Disable FB module load for now
2022-03-18 22:12:09 +00:00
Wes Lambert
543bf9a7a7
Update Kibana version to 8
2022-03-18 22:07:21 +00:00
Wes Lambert
d111c08fb3
Update Curator commands with new Filebeat module variables
2022-03-18 21:45:33 +00:00
weslambert
a9ea99daa8
Switch from so_elastic user to so_kibana user for Elastic 8
2022-03-18 15:09:50 -04:00
weslambert
cb0d4acd57
Remove X-Pack ML entry for Elastic 8
2022-03-18 14:46:28 -04:00
weslambert
e0374be4aa
Update version from 7.16.2 to 8.1.0 for Kibana config
2022-03-18 11:57:33 -04:00
weslambert
6f294cc0c2
Change Kibana user role from superuser to kibana_system for Elastic 8
2022-03-18 11:54:08 -04:00
weslambert
5ec5b9a2ee
Remove older module config files
2022-03-18 10:14:13 -04:00
weslambert
c659a443b0
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:25:10 -04:00
weslambert
99430fddeb
Update from search.remote to cluster.remote for Elastic 8
2022-03-17 21:24:39 -04:00
weslambert
7128b04636
Remove indices.query.bool.max_clause_count because it is dynamically allocated in Elastic 8
2022-03-17 21:20:41 -04:00
weslambert
712a92aa39
Switch from log input to filestream input
2022-03-17 21:18:03 -04:00
Wes Lambert
6e2aaa0098
Clean up original map file
2022-03-17 21:08:57 +00:00
Wes Lambert
09892a815b
Add back bind mounts and remove THIRDPARTY
2022-03-17 21:06:07 +00:00
Wes Lambert
a60ef33930
Reorganize FB module management
2022-03-17 21:01:03 +00:00