Mike Reeves
94c7dabd9e
Merge pull request #12693 from Security-Onion-Solutions/dev
...
2.3.300
2024-04-01 11:37:59 -04:00
Mike Reeves
2f3b92887b
Merge pull request #12714 from Security-Onion-Solutions/2.3.300
...
2.3.300
2024-04-01 11:26:43 -04:00
Mike Reeves
d15678f638
Update VERIFY_ISO.md
2024-04-01 11:25:29 -04:00
Mike Reeves
93c29bc1da
2.3.300
2024-04-01 11:22:31 -04:00
Mike Reeves
56263675f6
Merge pull request #12692 from Security-Onion-Solutions/2.3.300
...
2.3.300
2024-03-29 09:55:15 -04:00
Mike Reeves
1599e69851
2.3.300
2024-03-29 09:43:50 -04:00
weslambert
5ae7e27ace
Merge pull request #12677 from Security-Onion-Solutions/fix/strelka_yara_ignore
...
Ignore more rules
2024-03-27 16:17:34 -04:00
weslambert
945d2abeed
Ignore more rules
2024-03-27 16:13:30 -04:00
Doug Burks
68eb2d3ceb
Merge pull request #12614 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.300
2024-03-19 16:48:25 -04:00
Doug Burks
595f965183
Update soup for 2.3.300
2024-03-19 16:44:01 -04:00
Jason Ertel
834d18b77c
Merge pull request #12603 from Security-Onion-Solutions/jertel/ld
...
reschedule lock jobs
2024-03-18 09:41:21 -04:00
Jason Ertel
4849da1c11
Merge branch 'master' into jertel/ld
2024-03-18 09:31:17 -04:00
Jason Ertel
fbbddc2aaf
Merge pull request #12602 from Security-Onion-Solutions/jertel/lock
...
re-schedule lock jobs
2024-03-18 09:29:04 -04:00
Jason Ertel
4b24500b79
re-schedule lock jobs
2024-03-18 07:37:42 -04:00
Mike Reeves
f6a765addc
Merge pull request #12467 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update VERSION
2024-02-29 14:13:44 -05:00
Mike Reeves
8b56c0a744
Update VERSION
2024-02-29 14:12:35 -05:00
Mike Reeves
b31d38e734
Merge pull request #12463 from Security-Onion-Solutions/dev
...
2.3.290
2024-02-29 14:07:11 -05:00
Mike Reeves
b1db4137d0
Merge pull request #12462 from Security-Onion-Solutions/2.3.290
...
2.3.290
2024-02-29 09:15:41 -05:00
Mike Reeves
44ef164713
2.3.290
2024-02-29 09:08:37 -05:00
Jason Ertel
43f7dce297
Merge pull request #12407 from Security-Onion-Solutions/jertel/mergem
...
Jertel/mergem
2024-02-21 13:18:08 -05:00
Jason Ertel
4e4a4686f1
Merge branch 'master' into jertel/mergem
2024-02-21 13:14:29 -05:00
Jason Ertel
b5f44e48ab
Merge pull request #12403 from Security-Onion-Solutions/jertel/disctemplate
...
add message at top for clickable link
2024-02-21 12:42:04 -05:00
Jason Ertel
a44448519b
add message at top for clickable link
2024-02-21 10:53:50 -05:00
Jason Ertel
6245ee9a5b
Merge branch 'master' into jertel/disctemplate
2024-02-21 10:43:28 -05:00
Jason Ertel
49ca970076
add message at top for clickable link
2024-02-21 10:41:28 -05:00
Jason Ertel
f49fb7cbae
Merge pull request #12401 from Security-Onion-Solutions/jertel/disctemplate
...
template improvements
2024-02-21 10:39:03 -05:00
Jason Ertel
7692c9be53
template improvements
2024-02-21 10:36:07 -05:00
Jason Ertel
25ef12cdc5
Merge pull request #12395 from Security-Onion-Solutions/jertel/mergemaster
...
Jertel/mergemaster
2024-02-21 07:18:22 -05:00
Jason Ertel
2967adca90
Merge branch 'master' into jertel/mergemaster
2024-02-20 16:56:14 -05:00
Jason Ertel
d198458366
Merge pull request #12392 from Security-Onion-Solutions/jertel/glm_master
...
thread locking
2024-02-20 16:55:16 -05:00
Jason Ertel
9e98b409a5
thread locking
2024-02-20 16:00:41 -05:00
Doug Burks
ba8f729976
Merge pull request #12335 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.290
2024-02-09 11:18:59 -05:00
Doug Burks
5b67795c23
Update soup for 2.3.290
2024-02-09 11:12:43 -05:00
Jason Ertel
483bf60ae3
Merge pull request #12233 from Security-Onion-Solutions/jertel/23guidelines
...
Update 2-4.yml
2024-01-23 10:07:35 -05:00
Doug Burks
1a9350f60b
Update 2-4.yml
2024-01-23 10:05:59 -05:00
Doug Burks
f4afda0975
Merge pull request #12232 from Security-Onion-Solutions/dougburks-patch-1
...
Improve Github Discussions template for 2.4 category
2024-01-23 09:57:40 -05:00
Doug Burks
137372337c
Update 2-4.yml
2024-01-23 09:51:45 -05:00
Mike Reeves
1521532c60
Merge pull request #11880 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-11-28 15:33:48 -05:00
Mike Reeves
ada32967dc
Update VERSION
2023-11-28 15:30:49 -05:00
Mike Reeves
d5d2b5fbc7
Merge pull request #11879 from Security-Onion-Solutions/dev
...
2.3.280
2023-11-28 15:21:56 -05:00
Mike Reeves
84d6fcb752
Merge pull request #11878 from Security-Onion-Solutions/2.3.280
...
2.3.280
2023-11-28 15:00:34 -05:00
Mike Reeves
de9e9a2716
2.3.280
2023-11-28 14:58:25 -05:00
Josh Patterson
cec6cff19d
Merge pull request #11874 from Security-Onion-Solutions/23souphs
...
so-nginx watch managerssl to restart if changed
2023-11-27 12:48:06 -05:00
m0duspwnens
7311d6480c
so-nginx watch managerssl to restart if changed
2023-11-27 12:15:09 -05:00
Josh Patterson
f967c8e362
Merge pull request #11873 from Security-Onion-Solutions/23souphs
...
enable highstate after starting minion
2023-11-27 11:12:45 -05:00
m0duspwnens
cfad6414d2
enable highstate after starting minion
2023-11-27 11:10:39 -05:00
Josh Patterson
0fdaed9cf7
Merge pull request #11864 from Security-Onion-Solutions/import/suriinterface
...
suricata interface None if so-import
2023-11-22 10:42:43 -05:00
m0duspwnens
1dc88781f1
suricata interface None if so-import
2023-11-22 10:11:34 -05:00
Mike Reeves
0cfb8b0816
Merge pull request #11834 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update signing_policies.conf
2023-11-20 15:59:21 -05:00
Mike Reeves
c0968d3843
Update signing_policies.conf
2023-11-20 15:57:29 -05:00
Mike Reeves
3b133e87cd
Merge pull request #11831 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update signing_policies.conf
2023-11-20 15:19:42 -05:00
Mike Reeves
fee9b61ce9
Update soup
2023-11-20 15:14:25 -05:00
Mike Reeves
57612c69fe
Update signing_policies.conf
2023-11-20 15:11:50 -05:00
Mike Reeves
94accb0e8c
Update signing_policies.conf
2023-11-20 15:09:13 -05:00
Josh Patterson
3b8d1d470e
Merge pull request #11798 from Security-Onion-Solutions/m0duspwnens-patch-1
...
Update soup
2023-11-15 15:23:46 -05:00
Josh Patterson
c624a44b0e
Update soup
...
add quote
2023-11-15 15:19:54 -05:00
weslambert
bc509a0aa9
Merge pull request #11772 from Security-Onion-Solutions/upgrade/elastic_8_10_4
...
Elastic 8.10.4
2023-11-13 09:36:49 -05:00
Doug Burks
ee0ef3217f
Merge pull request #11771 from Security-Onion-Solutions/dougburks-patch-1
...
Add EOL warning to README.md
2023-11-13 09:18:50 -05:00
weslambert
18e319cbe3
Elastic 8.10.4
2023-11-13 09:17:33 -05:00
Doug Burks
3316e1261d
Add EOL warning to README.md
2023-11-13 09:16:25 -05:00
weslambert
b7cf44466c
Elastic 8.10.4
2023-11-13 09:16:23 -05:00
Mike Reeves
e321aa52a5
Merge pull request #11749 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update soup
2023-11-09 10:49:34 -05:00
Mike Reeves
07df045e79
Update soup
2023-11-09 10:38:53 -05:00
Mike Reeves
7b11ddb032
Update soup
2023-11-09 10:25:16 -05:00
Jorge Reyes
ac4428940e
Merge pull request #11561 from Security-Onion-Solutions/2.3/zeek6
...
Zeek 6 upgrade
2023-10-23 09:25:21 -04:00
reyesj2
a9457d5f53
Remove external community-id replaced with Zeek 6 built in community-id.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-17 16:02:16 -04:00
Jason Ertel
3672701dde
Merge pull request #11506 from Security-Onion-Solutions/jertel-patch-1
...
Update VERSION
2023-10-11 09:26:32 -04:00
Jason Ertel
07ed2cb3da
Update VERSION
2023-10-10 21:35:48 -04:00
Mike Reeves
3839e52401
Merge pull request #11374 from Security-Onion-Solutions/dev
...
2.3.270
2023-10-06 16:40:28 -04:00
Mike Reeves
b005a10a8e
Merge pull request #11373 from Security-Onion-Solutions/2.3.270
...
2.3.270
2023-09-22 12:59:04 -04:00
Mike Reeves
752ff5917f
2.3.270
2023-09-22 12:45:46 -04:00
Mike Reeves
815e5d53a6
Merge pull request #11367 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-09-21 09:40:58 -04:00
Mike Reeves
a967db8152
Update soup
2023-09-21 09:38:05 -04:00
Jason Ertel
7835cb6a7a
Merge pull request #11360 from Security-Onion-Solutions/jertel/vol
...
Jertel/vol
2023-09-20 08:29:43 -04:00
Jason Ertel
07b92eef9e
vol sprawl
2023-09-19 17:22:42 -04:00
Jason Ertel
8855619453
vol sprawl
2023-09-19 12:52:28 -04:00
Doug Burks
7763218b71
Merge pull request #11287 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.270
2023-09-11 09:08:21 -04:00
Doug Burks
29f12fac90
Update soup for 2.3.270
2023-09-11 09:05:19 -04:00
Doug Burks
1a9f8f0bc2
Merge pull request #11228 from Security-Onion-Solutions/master
...
Merge master to dev for updated 2.4 discussion template
2023-08-31 10:19:45 -04:00
Doug Burks
3e5f354d8b
Merge pull request #11227 from Security-Onion-Solutions/dougburks-patch-1
...
Update 2-4.yml discussion template with additional fields for CPU, RAM, and storage
2023-08-31 10:16:55 -04:00
Doug Burks
a1b76d2cd3
Update 2-4.yml
2023-08-31 10:12:47 -04:00
weslambert
43e402fad4
Merge pull request #11187 from Security-Onion-Solutions/fix/kibana_migration_version
...
Remove migration version
2023-08-28 11:48:58 -04:00
weslambert
170b408feb
Remove migration version
2023-08-28 11:26:35 -04:00
weslambert
e55725cca4
Merge pull request #11183 from Security-Onion-Solutions/feature/elastic_8_8_2
...
Elastic 8.8.2
2023-08-28 09:49:34 -04:00
weslambert
2b9f6b26d8
Elastic 8.8.2
2023-08-28 09:42:23 -04:00
weslambert
f10b67599e
Elastic 8.8.2
2023-08-28 09:41:36 -04:00
Doug Burks
ea03613df3
Merge pull request #11103 from Security-Onion-Solutions/master
...
Merge 2.4 discussion template to dev
2023-08-18 16:21:45 -04:00
Doug Burks
8ffb6b9e1c
Merge pull request #11102 from Security-Onion-Solutions/dougburks-patch-1
...
Create template for Github Discussions in the 2.4 Category
2023-08-18 16:19:04 -04:00
Doug Burks
ffadd4aa42
Create 2-4.yml
2023-08-18 16:13:31 -04:00
Mike Reeves
78ccea12b1
Merge pull request #10919 from Security-Onion-Solutions/master
...
Soup
2023-08-02 12:27:08 -04:00
Doug Burks
8bef5a84f7
Merge pull request #10916 from Security-Onion-Solutions/supersoup
...
Supersoup
2023-08-02 11:58:58 -04:00
Mike Reeves
679775a7d0
Add supersoup mode
2023-08-02 11:21:28 -04:00
Mike Reeves
3f5f93059e
Add supersoup mode
2023-08-02 11:20:23 -04:00
Mike Reeves
d2ae8f81e1
Add supersoup mode
2023-08-02 10:49:51 -04:00
Mike Reeves
fcc369d4b9
Add supersoup mode
2023-08-02 10:46:54 -04:00
Mike Reeves
9bb28fd0b5
Add supersoup mode
2023-08-02 10:31:55 -04:00
Mike Reeves
93c5e6a9e8
Add supersoup mode
2023-08-02 09:49:14 -04:00
Mike Reeves
6a7e756a37
Add supersoup mode
2023-08-02 09:47:35 -04:00
Mike Reeves
f6b9dec2ae
Add supersoup mode
2023-08-02 09:45:29 -04:00
Mike Reeves
37386057d9
Merge pull request #10622 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-06-20 14:52:03 -04:00
Mike Reeves
800945c3b6
Update VERSION
2023-06-20 14:50:29 -04:00
Mike Reeves
b56c0c5e64
Merge pull request #10621 from Security-Onion-Solutions/dev
...
2.3.260
2023-06-20 14:36:16 -04:00
Mike Reeves
01b986cd50
Merge pull request #10620 from Security-Onion-Solutions/2.3.260
...
2.3.260
2023-06-20 09:37:56 -04:00
Mike Reeves
3e862151f3
2.3.260
2023-06-20 09:18:30 -04:00
Doug Burks
15b3982930
Merge pull request #10610 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.260
2023-06-16 13:10:42 -04:00
Doug Burks
3d687f0404
Update soup for 2.3.260
2023-06-16 12:55:52 -04:00
weslambert
e74c2fa1b0
Merge pull request #10605 from Security-Onion-Solutions/fix/analyzer_dependencies
...
Update dependencies
2023-06-16 07:51:50 -04:00
Wes
ffc91393e7
Update pulsedive dependencies
2023-06-15 22:14:41 +00:00
Wes
d0ab2db312
Update dependencies
2023-06-15 21:03:40 +00:00
weslambert
4906068c7f
Merge pull request #10495 from Security-Onion-Solutions/foxtrot
...
Update requests and whoisit
2023-06-05 10:53:49 -04:00
Wes
ef8eece53b
Update dependencies
2023-06-05 13:45:44 +00:00
weslambert
660a50c08d
Update whoisit to 2.7.0
2023-06-03 08:53:02 -04:00
Wes
5d326a3c32
Update dependencies
2023-06-01 16:26:04 +00:00
weslambert
2a907d3de3
Update version to 2.3.260
2023-06-01 12:04:35 -04:00
weslambert
33134b1814
Update requests and whist
2023-06-01 12:03:58 -04:00
weslambert
b0962da758
Update version to 2.3.0-foxtrot
2023-05-31 08:50:51 -04:00
weslambert
8148fd9e56
Merge pull request #10434 from Security-Onion-Solutions/foxtrot
...
Strelka 0.23.05.22 - Remove ScanRuby scanner
2023-05-26 12:45:03 -04:00
weslambert
1ee332b55b
Update version to 2.3.260
2023-05-26 08:31:11 -04:00
weslambert
873632ec4f
Remove ScanRuby scanner
2023-05-25 17:23:44 -04:00
weslambert
f8068d7975
Update version to 2.3.0-foxtrot
2023-05-25 16:14:29 -04:00
weslambert
a79ebea5c3
Update version value to 2.3.250-foxtrot
2023-05-25 15:29:07 -04:00
weslambert
2fdc3874ca
Update version to foxtrot
2023-05-25 14:35:52 -04:00
Mike Reeves
7f52c2015d
Merge pull request #10408 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-05-22 15:25:05 -04:00
Mike Reeves
548e1e6937
Update VERSION
2023-05-22 15:23:52 -04:00
Mike Reeves
c949101d0f
Merge pull request #10406 from Security-Onion-Solutions/dev
...
2.3.250
2023-05-22 15:14:23 -04:00
Mike Reeves
7c1f19b91f
Merge pull request #10405 from Security-Onion-Solutions/2.3.250
...
2.3.250
2023-05-22 11:39:40 -04:00
Mike Reeves
598d6b025e
2.3.250
2023-05-22 11:37:13 -04:00
Jason Ertel
4d0d0714a5
Merge pull request #10401 from Security-Onion-Solutions/jertel/fixwhoisit
...
use the same requests version that's already packaged with the analyzer
2023-05-20 08:45:29 -04:00
Jason Ertel
cb0c078955
use the same requests version that's already packaged with the analyzer
2023-05-19 23:56:39 -04:00
Jason Ertel
aa426244bf
Merge pull request #10394 from Security-Onion-Solutions/jertel/fixwhoisit
...
fix lib dependency issue with whoisit
2023-05-19 14:34:32 -04:00
Jason Ertel
97b2ae8d82
fix lib dependency issue with whoisit
2023-05-19 14:23:12 -04:00
Doug Burks
7047125759
Merge pull request #10386 from Security-Onion-Solutions/2.3/elastic-8.7.1
...
UPGRADE: Elastic 8.7.1 #10269
2023-05-18 15:27:10 -04:00
Doug Burks
43f73abd4d
Update so-kibana-config-load
2023-05-18 15:18:27 -04:00
Doug Burks
51a8684850
Update config_saved_objects.ndjson
2023-05-18 15:17:36 -04:00
Doug Burks
b3c5239787
Merge pull request #10333 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.250
2023-05-11 08:28:53 -04:00
Doug Burks
0f562279ee
Update soup for 2.3.250
2023-05-11 07:26:58 -04:00
weslambert
834f45c0f2
Merge pull request #10286 from Security-Onion-Solutions/fix/strelka_ignore_yara_rules
...
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-08 11:58:11 -04:00
weslambert
d4cf9efeca
Merge pull request #10303 from Security-Onion-Solutions/fix/kibana_pivot_to_pcap_url
...
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 11:55:22 -04:00
Doug Burks
c620983b4a
Merge pull request #10299 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:47:49 -04:00
Wes
ed19c139ea
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 13:44:36 +00:00
Doug Burks
af85c6261b
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:41:26 -04:00
weslambert
e9f58269cd
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-04 16:13:59 -04:00
Jason Ertel
208c3d96e9
Merge pull request #10266 from Security-Onion-Solutions/jertel/aws
...
more detection improvements
2023-05-02 08:17:13 -04:00
Jason Ertel
1e888a5d9e
more detection improvements
2023-05-02 07:56:11 -04:00
Jason Ertel
f7ae8d449e
Merge pull request #10259 from Security-Onion-Solutions/jertel/simplifycd
...
simplify cloud detection
2023-05-01 11:33:26 -04:00
Jason Ertel
195274bb11
Merge branch 'dev' into jertel/simplifycd
2023-05-01 11:29:39 -04:00
Jason Ertel
a0ac1d2274
simplify cloud detection
2023-05-01 11:04:43 -04:00
Mike Reeves
3dd39c7f59
Merge pull request #10234 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2023-04-26 14:41:04 -04:00
Mike Reeves
ba846bbf35
Update VERSION
2023-04-26 14:39:31 -04:00
Mike Reeves
0baf8e9471
Merge pull request #10227 from Security-Onion-Solutions/dev
...
2.3.240
2023-04-26 14:31:56 -04:00
Mike Reeves
e30fec7af0
Merge pull request #10226 from Security-Onion-Solutions/2.3.240
...
2.3.240
2023-04-26 09:58:18 -04:00
Mike Reeves
884f5cd3a6
2.3.240
2023-04-26 09:55:19 -04:00
Jason Ertel
11babd2f1c
Merge pull request #10221 from Security-Onion-Solutions/jertel/imdsv2to
...
timeout more quickly on aws imdsv2 detection
2023-04-26 07:59:13 -04:00
Jason Ertel
b440ab5c02
timeout more quickly on aws imdsv2 detection
2023-04-26 07:57:23 -04:00
Jason Ertel
91d667c3ad
Merge pull request #10200 from Security-Onion-Solutions/jertel/imdsv2_23
...
Detect cloud install on forced imdsv2 instances
2023-04-25 09:46:39 -04:00
Jason Ertel
f04c01b28c
Merge pull request #10204 from Security-Onion-Solutions/jertel/2.3.240_soup
...
soup update for 2.3.240
2023-04-25 09:46:28 -04:00
Jason Ertel
71ab8ddf1d
soup update for 2.3.240
2023-04-25 09:42:14 -04:00
Jason Ertel
f1f79d55dc
Detect cloud install on forced imdsv2 instances
2023-04-24 16:26:23 -04:00
Mike Reeves
db1bd16758
Merge pull request #10142 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-04-17 10:56:59 -04:00
Mike Reeves
ef73834d58
Update VERSION
2023-04-17 10:55:38 -04:00
Mike Reeves
3891548d6d
Merge pull request #10141 from Security-Onion-Solutions/dev
...
2.3.230 Release
2023-04-17 10:47:32 -04:00
Mike Reeves
9d6ed8b9b2
Merge pull request #10140 from Security-Onion-Solutions/2.3.230
...
2.3.230
2023-04-17 10:26:59 -04:00
Mike Reeves
ef92815a08
2.3.230
2023-04-17 10:22:39 -04:00
Doug Burks
19b5cdcb0e
Merge pull request #10119 from Security-Onion-Solutions/2.3/fix-suricata-dns
...
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 11:00:13 -04:00
Doug Burks
272b345892
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 10:52:37 -04:00
Mike Reeves
7fad9d60ef
Merge pull request #10113 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2023-04-12 10:32:43 -04:00
Mike Reeves
46fc62b8dc
Update init.sls
2023-04-12 10:29:54 -04:00
Doug Burks
ca9a93a4b0
Merge pull request #9998 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.230
2023-03-24 12:38:39 -04:00
Doug Burks
aa2e18fca9
Update soup for 2.3.230
2023-03-24 12:31:51 -04:00
Mike Reeves
7e4ce7b81d
Merge pull request #9877 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2023-03-01 16:37:14 -05:00
Mike Reeves
e5c0058dd1
Update HOTFIX
2023-03-01 16:36:08 -05:00
Mike Reeves
07c5b541a3
Merge pull request #9876 from Security-Onion-Solutions/master
...
Master to Dev
2023-03-01 16:35:48 -05:00
Mike Reeves
b756b8ea32
Merge pull request #9873 from Security-Onion-Solutions/hotfix/2.3.220
...
Hotfix/2.3.220
2023-03-01 16:32:49 -05:00
Mike Reeves
5b46e57ae1
Merge pull request #9875 from Security-Onion-Solutions/hotfix23220
...
Hotfix for 2.3.220
2023-03-01 16:14:26 -05:00
Mike Reeves
924009afb8
Hotfix for 2.3.220
2023-03-01 16:11:38 -05:00
Mike Reeves
8f5bacc510
Merge pull request #9874 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2023-03-01 14:52:04 -05:00
Mike Reeves
d5e48a7eca
Update init.sls
2023-03-01 14:50:55 -05:00
Mike Reeves
6346a92f0f
Merge pull request #9872 from Security-Onion-Solutions/hotfix23220
...
Hotfix for 2.3.220
2023-03-01 14:20:47 -05:00
Mike Reeves
13a566a9a2
Hotfix for 2.3.220
2023-03-01 14:19:04 -05:00
Mike Reeves
063c6599d8
Hotfix for 2.3.220
2023-03-01 14:17:22 -05:00
weslambert
9fb315c99d
Merge pull request #9870 from Security-Onion-Solutions/fix/curator_configuration_update_8.0.x
...
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 10:19:32 -05:00
Wes
6e0891e586
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 15:16:52 +00:00
Mike Reeves
3a96d59899
Merge pull request #9869 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2023-03-01 10:10:47 -05:00
Mike Reeves
5fa945956e
Update HOTFIX
2023-03-01 10:09:19 -05:00
Mike Reeves
b0aab96cf5
Merge pull request #9858 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-02-27 09:40:39 -05:00
Mike Reeves
11def72790
Update VERSION
2023-02-27 09:39:52 -05:00
Mike Reeves
2ca2724a4c
Merge pull request #9857 from Security-Onion-Solutions/dev
...
2.3.220
2023-02-27 09:35:14 -05:00
Mike Reeves
884883a225
Merge pull request #9856 from Security-Onion-Solutions/2.3.220
...
2.3.220
2023-02-27 09:26:28 -05:00
Mike Reeves
5c8ba3af65
2.3.220
2023-02-27 09:23:33 -05:00
Josh Brower
4b5d314adf
Merge pull request #9833 from Security-Onion-Solutions/FleetDMConfigFix
...
Remove unsupported config option
2023-02-21 16:36:58 -05:00
Josh Brower
6e637f559c
Remove unsupported config option
2023-02-21 16:35:11 -05:00
Doug Burks
cc5304e9f7
Merge pull request #9806 from Security-Onion-Solutions/2.3/upgrade-elastic-8.6.2
...
2.3/upgrade elastic 8.6.2
2023-02-17 08:03:01 -05:00
Doug Burks
002403055d
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:04:57 -05:00
Doug Burks
b80b80e825
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:03:47 -05:00
Josh Brower
c539d53a02
Merge pull request #9791 from Security-Onion-Solutions/fleetsapassword
...
Fix edge case
2023-02-15 15:30:49 -05:00
Josh Brower
3a22978c2b
Fix password gen edge case
2023-02-15 15:25:35 -05:00
Doug Burks
5b1461e9a1
Merge pull request #9782 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.220
2023-02-14 08:44:09 -05:00
Doug Burks
69f889dbd9
Update soup for 2.3.220
2023-02-14 08:42:35 -05:00
Josh Brower
aefe1cceb8
Merge pull request #9758 from Security-Onion-Solutions/fleetupgrade
...
Fix link for FleetDM standalone nodes
2023-02-09 14:10:45 -05:00
Josh Brower
b7e97eceb3
Fix link for FleetDM standalone nodes
2023-02-09 14:08:48 -05:00
Josh Brower
450e02e874
Merge pull request #9749 from Security-Onion-Solutions/fleetdm-fix
...
FleetDM Upgrade Fix
2023-02-09 09:30:22 -05:00
Josh Brower
09bebf08d6
Fix FleetDM SOC Link
2023-02-09 09:10:50 -05:00
Josh Brower
4dd54cea6c
Use correct variable name
2023-02-08 16:58:47 -05:00
Josh Brower
e07f4bd0ed
Workaround for FleetDM PW Req
2023-02-08 13:03:33 -05:00
Mike Reeves
6adb586bb4
Merge pull request #9734 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-02-07 09:07:06 -05:00
Mike Reeves
2f99821736
Update VERSION
2023-02-07 09:05:16 -05:00
Mike Reeves
db27c22158
Merge pull request #9730 from Security-Onion-Solutions/dev
...
2.3.210
2023-02-07 08:58:36 -05:00
Mike Reeves
2ff284fc7f
Merge pull request #9729 from Security-Onion-Solutions/2.3.210
...
2.3.210
2023-02-06 16:36:06 -05:00
Mike Reeves
5d0a3ef205
2.3.210
2023-02-06 16:32:45 -05:00
Mike Reeves
ac9c10dd3a
2.3.210
2023-02-06 15:46:27 -05:00
weslambert
d4d67b545d
Merge pull request #9699 from Security-Onion-Solutions/fix/strelka_yara_exclusion
...
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:38:29 -05:00
weslambert
2dced35800
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:24:20 -05:00
Josh Patterson
c2a04a79c5
Merge pull request #9697 from Security-Onion-Solutions/23mysqlpy
...
23mysqlpy
2023-02-01 14:17:24 -05:00
m0duspwnens
d43346a084
hold python mysql
2023-02-01 14:11:27 -05:00
m0duspwnens
0c4a27d120
lock python36-mysql-1.3.12-2.el7 version
2023-02-01 12:33:19 -05:00
Doug Burks
b4530ffffe
Merge pull request #9681 from Security-Onion-Solutions/fix/suricata-dhcp-parsing-2.3
...
2.3: Improve Suricata DHCP parsing and dashboard
2023-01-31 10:18:49 -05:00
Doug Burks
d12aa0ed56
Move host.domain table to end of DHCP tables
2023-01-31 07:14:18 -05:00
Doug Burks
17bcf50ccb
update Suricata DHCP parser to set server.address
2023-01-30 15:57:47 -05:00
Doug Burks
48401f6a3f
Merge pull request #9675 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.210
2023-01-30 09:17:47 -05:00
Doug Burks
a96825f43e
Update soup for 2.3.210
2023-01-30 09:16:00 -05:00
Doug Burks
2d48ae7bca
Merge pull request #9656 from Security-Onion-Solutions/2.3/elastic-8.6.1
...
UPGRADE: Elastic 8.6.1 #9594 (2.3)
2023-01-26 16:24:33 -05:00
Doug Burks
0ff519ed2f
Update to Elastic 8.6.1
2023-01-26 16:09:13 -05:00
Doug Burks
127533492f
Update to Elastic 8.6.1
2023-01-26 16:08:15 -05:00
Mike Reeves
7d4b4a8bd4
Merge pull request #9585 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-01-17 09:40:46 -05:00
Mike Reeves
e9fa84d71b
Update VERSION
2023-01-17 09:39:35 -05:00
Mike Reeves
cd8cf4a1ac
Merge pull request #9578 from Security-Onion-Solutions/dev
...
2.3.200
2023-01-17 09:26:23 -05:00
Mike Reeves
9718e61a6a
Merge pull request #9576 from Security-Onion-Solutions/2.3.200
...
2.3.200
2023-01-13 16:12:20 -05:00
Mike Reeves
22ec638e85
2.3.200
2023-01-13 16:08:27 -05:00
Doug Burks
7b0c22f967
Merge pull request #9568 from Security-Onion-Solutions/fix/soup-thehive-errors
...
soup should continue even if thehive errors
2023-01-12 13:28:41 -05:00
Doug Burks
672cab858e
Continue even if thehive errors
2023-01-12 12:48:16 -05:00
Josh Brower
29312d595b
Merge pull request #9559 from Security-Onion-Solutions/idh-skins
...
Fix mispelling
2023-01-11 11:04:29 -05:00
Josh Brower
b54f2e8752
Fix mispelling
2023-01-11 10:59:50 -05:00
Josh Brower
1470e120ef
Merge pull request #9540 from Security-Onion-Solutions/idhskins
...
bug fix - idh skins
2023-01-09 15:49:04 -05:00
Josh Brower
2c747ec837
make sure dir is created
2023-01-09 13:46:10 -05:00
Josh Brower
8cb5cd5fee
Merge pull request #9214 from Security-Onion-Solutions/idhskins
...
Custom IDH HTTP Skins
2023-01-06 15:14:14 -05:00
Doug Burks
a4bae77973
Merge pull request #9271 from Njinx/dev
...
so-status runs some code before checking for root privileges
2023-01-04 16:05:34 -05:00
Doug Burks
96a568f57f
Merge pull request #9515 from Security-Onion-Solutions/fix/so-common-references-2.3
...
fix so-common references
2023-01-04 14:31:57 -05:00
doug
7dcdcc18a5
fix so-common references
2023-01-04 14:28:47 -05:00
Doug Burks
10fc8de9f9
Merge pull request #9513 from Security-Onion-Solutions/fix/jinja-whitespace-2.3
...
fix jinja whitespace 2.3
2023-01-04 13:56:17 -05:00
doug
3482df5ee1
fix jinja whitespace
2023-01-04 13:33:51 -05:00
Doug Burks
9ea3d6bb1f
Merge pull request #9512 from Security-Onion-Solutions/fix/copyright-year-2023
...
Update Copyright year
2023-01-04 12:50:30 -05:00
doug
a67a254edc
update Copyright year
2023-01-04 12:44:18 -05:00
Doug Burks
08a5a9ab31
Merge pull request #9510 from Security-Onion-Solutions/fix/sysmon-fields-2.3
...
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:58:04 -05:00
Doug Burks
e3d32c7871
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:38:18 -05:00
weslambert
20d6ce1ce9
Merge pull request #9501 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_rita_beacon
...
Update RITA beacon parsing
2023-01-03 11:13:55 -05:00
Wes
bd114eb1c4
Update RITA beacon parsing
2023-01-03 16:01:35 +00:00
Doug Burks
55c6fc422b
Merge pull request #9497 from Security-Onion-Solutions/fix/sysmon-parsing-2.3
...
FIX: Sysmon logs are missing event.category and event.dataset #8194
2023-01-03 08:56:16 -05:00
doug
5d060f9832
update Sysmon File dashboard
2022-12-31 14:10:02 -05:00
doug
edcbfd17f5
update sysmon parser
2022-12-30 16:20:06 -05:00
Doug Burks
ff4850d9ce
Merge pull request #9452 from Security-Onion-Solutions/feature/improve-dashboards-2.3
...
FEATURE: Improve SOC Dashboards #9450 2.3
2022-12-21 15:46:21 -05:00
Doug Burks
3e1a5b6329
Improve Strelka dashboard
2022-12-21 15:34:06 -05:00
Doug Burks
b1709f3ea3
Improve Firewall dashboard
2022-12-21 15:28:41 -05:00
Doug Burks
76a73ea35c
Improve Software dashboard
2022-12-21 15:25:19 -05:00
Doug Burks
991a6ec43c
Improve Intel dashboard
2022-12-21 15:19:54 -05:00
Doug Burks
e2c0607249
Improve FTP dashboard
2022-12-21 14:36:44 -05:00
Doug Burks
82c61e6bc9
improve NIDS Alerts dashboard
2022-12-21 14:32:05 -05:00
Doug Burks
37aa779095
Minor improvements
2022-12-21 13:14:38 -05:00
Doug Burks
9e631ad63d
Improve SOC dashboards
2022-12-21 13:04:12 -05:00
Jason Ertel
fe6a55b58e
Merge pull request #9393 from Security-Onion-Solutions/jertel/soup23200
...
Move Kratos DB to /nsm
2022-12-14 14:26:19 -05:00
Jason Ertel
87cebedc85
Backup the new Kratos location
2022-12-14 14:12:47 -05:00
Jason Ertel
e66c995b1f
remove apparently unused reactor reference
2022-12-14 13:50:20 -05:00
Jason Ertel
e8a8f65ddc
fix typo
2022-12-14 12:56:25 -05:00
Jason Ertel
a7a15117f0
Improve soup wording when the script itself needs updated
2022-12-14 12:03:47 -05:00
Jason Ertel
865ba4264b
Stop backing up kratos since it now lives in /nsm. Ensure kratos is removed when re-installing.
2022-12-14 10:57:24 -05:00
Jason Ertel
6985b0ab27
Move kratos DB to /nsm
2022-12-14 10:50:24 -05:00
Mike Reeves
6e4912f759
Merge pull request #9385 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Highlander Config for Kibana
2022-12-13 13:54:30 -05:00
Mike Reeves
b0d934daf7
Update config.map.jinja
2022-12-13 13:52:13 -05:00
Doug Burks
8e50868abd
Merge pull request #9383 from Security-Onion-Solutions/fix/import-hyperlink
...
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:36:22 -05:00
Doug Burks
aa08803f03
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:23:27 -05:00
Doug Burks
bb346d531d
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:22:53 -05:00
Doug Burks
6c057d0b0a
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 12:43:54 -05:00
Doug Burks
47e43e53d9
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 12:43:10 -05:00
weslambert
a8456a4d65
Merge pull request #9369 from Security-Onion-Solutions/fix/sensoroni_analyzers_configuration_check
...
Fix localfile analyzer 'file_path' check and add new list value verification function for helpers
2022-12-13 11:47:10 -05:00
Wes
98a1fb96c2
Add test coverage for empty list value
2022-12-13 16:23:16 +00:00
Wes
874bbd2580
Remove extra whitespace
2022-12-13 16:02:46 +00:00
Wes
90dedbb841
Update tests to account for change in 'file_path' value verification
2022-12-13 15:58:35 +00:00
Wes
df5dd5fe28
Use new list verification function for 'file_path'
2022-12-13 15:57:43 +00:00
Wes
d5ab455485
Add new test for list value verification function
2022-12-13 15:56:58 +00:00
Wes
20b79b7ab0
Add new function to verify list value
2022-12-13 15:56:26 +00:00
Jason Ertel
56019f48ca
Merge pull request #9358 from Security-Onion-Solutions/jertel/es853
...
Upgrade ES to 8.5.3
2022-12-12 13:45:56 -05:00
Jason Ertel
d7dd2d2ef8
Upgrade ES to 8.5.3
2022-12-12 13:43:28 -05:00
weslambert
3d431eaba9
Merge pull request #9341 from Security-Onion-Solutions/fix/analyzers_localfile_file_path
...
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 16:49:29 -05:00
weslambert
f85fb5ecf9
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 16:35:24 -05:00
Jason Ertel
1716cb0297
Merge pull request #9333 from Security-Onion-Solutions/jertel/mergedev
...
Jertel/mergedev
2022-12-08 09:17:20 -05:00
Jason Ertel
0ec366f075
clear hotfix
2022-12-08 09:15:41 -05:00
Jason Ertel
e9b9e128c6
Merge branch 'master' into jertel/mergedev
2022-12-08 09:14:08 -05:00
Mike Reeves
ef15de130a
Merge pull request #9329 from Security-Onion-Solutions/hotfix/2.3.190
...
Hotfix/2.3.190
2022-12-08 09:08:18 -05:00
Mike Reeves
e975ee0a8e
Merge pull request #9328 from Security-Onion-Solutions/mike4
...
2.3.190 hotfix
2022-12-07 16:22:05 -05:00
Mike Reeves
da94ddca13
2.3.190 hotfix
2022-12-07 16:17:57 -05:00
Mike Reeves
6e94751c65
Merge pull request #9327 from Security-Onion-Solutions/jertel/surifilecheck
...
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:10:30 -05:00
Jason Ertel
d48d473f43
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:06:24 -05:00
Jason Ertel
cff5a83ad5
Merge pull request #9324 from Security-Onion-Solutions/jertel/surifilecheck
...
Use original style due to pgrep conflict with cron
2022-12-07 12:06:26 -05:00
Jason Ertel
225b7e359c
Use original style due to pgrep conflict with cron
2022-12-07 11:53:42 -05:00
Mike Reeves
9a616caf53
Merge pull request #9322 from Security-Onion-Solutions/mike
...
2.3.190 hotfix
2022-12-07 11:15:30 -05:00
Mike Reeves
0aab268801
2.3.190 hotfix
2022-12-07 11:12:13 -05:00
Mike Reeves
0bb7f5c5e3
Merge pull request #9320 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2022-12-07 09:21:17 -05:00
Mike Reeves
4aff1f0fdb
Update HOTFIX
2022-12-07 09:19:51 -05:00
Jason Ertel
35ca08ea88
Merge pull request #9315 from Security-Onion-Solutions/jertel/surifilecheck
...
Suricata support for filecheck; reduce cron noise
2022-12-07 08:17:19 -05:00
Jason Ertel
7b05627d5c
Suricata support for filecheck; reduce cron noise
2022-12-07 07:58:32 -05:00
Mike Reeves
e3c1b6dbba
Merge pull request #9306 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update init.sls
2022-12-06 13:38:35 -05:00
Mike Reeves
f0c3b876a9
Update init.sls
2022-12-06 13:35:03 -05:00
Mike Reeves
531423f49a
Update init.sls
2022-12-06 13:25:03 -05:00
Jason Ertel
dfad5a748c
Merge pull request #9303 from Security-Onion-Solutions/jertel/surifilecheck
...
Jertel/surifilecheck
2022-12-06 11:52:36 -05:00
Jason Ertel
819b39c0bb
Update hotfix
2022-12-06 11:41:00 -05:00
Jason Ertel
0dd2e51e83
Ensure Suricata move events get picked up
2022-12-06 11:39:58 -05:00
Mike Reeves
f7730741c2
Merge pull request #9297 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-12-05 16:12:55 -05:00
Mike Reeves
cb2d6b7876
Update VERSION
2022-12-05 16:07:12 -05:00
Ben Allen
a1b2c28a42
Check privileges much earlier
2022-12-02 14:08:22 -05:00
Josh Brower
5950771003
Merge remote-tracking branch 'remotes/origin/dev' into idhskins
2022-11-22 18:04:38 -05:00
Josh Brower
7c8ce7899b
Initial support for custom IDH http skins
2022-11-22 17:57:51 -05:00