Compare commits

...
Author SHA1 Message Date
Mike ReevesandGitHub 94c7dabd9e Merge pull request #12693 from Security-Onion-Solutions/dev
2.3.300
2024-04-01 11:37:59 -04:00
Mike ReevesandGitHub 2f3b92887b Merge pull request #12714 from Security-Onion-Solutions/2.3.300
2.3.300
2024-04-01 11:26:43 -04:00
Mike ReevesandGitHub d15678f638 Update VERIFY_ISO.md 2024-04-01 11:25:29 -04:00
Mike Reeves 93c29bc1da 2.3.300 2024-04-01 11:22:31 -04:00
Mike ReevesandGitHub 56263675f6 Merge pull request #12692 from Security-Onion-Solutions/2.3.300
2.3.300
2024-03-29 09:55:15 -04:00
Mike Reeves 1599e69851 2.3.300 2024-03-29 09:43:50 -04:00
weslambertandGitHub 5ae7e27ace Merge pull request #12677 from Security-Onion-Solutions/fix/strelka_yara_ignore
Ignore more rules
2024-03-27 16:17:34 -04:00
weslambertandGitHub 945d2abeed Ignore more rules 2024-03-27 16:13:30 -04:00
Doug BurksandGitHub 68eb2d3ceb Merge pull request #12614 from Security-Onion-Solutions/dougburks-patch-1
Update soup for 2.3.300
2024-03-19 16:48:25 -04:00
Doug BurksandGitHub 595f965183 Update soup for 2.3.300 2024-03-19 16:44:01 -04:00
Jason ErtelandGitHub 834d18b77c Merge pull request #12603 from Security-Onion-Solutions/jertel/ld
reschedule lock jobs
2024-03-18 09:41:21 -04:00
Jason Ertel 4849da1c11 Merge branch 'master' into jertel/ld 2024-03-18 09:31:17 -04:00
Jason ErtelandGitHub fbbddc2aaf Merge pull request #12602 from Security-Onion-Solutions/jertel/lock
re-schedule lock jobs
2024-03-18 09:29:04 -04:00
Jason Ertel 4b24500b79 re-schedule lock jobs 2024-03-18 07:37:42 -04:00
Mike ReevesandGitHub f6a765addc Merge pull request #12467 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update VERSION
2024-02-29 14:13:44 -05:00
Mike ReevesandGitHub 8b56c0a744 Update VERSION 2024-02-29 14:12:35 -05:00
Mike ReevesandGitHub b31d38e734 Merge pull request #12463 from Security-Onion-Solutions/dev
2.3.290
2024-02-29 14:07:11 -05:00
Mike ReevesandGitHub b1db4137d0 Merge pull request #12462 from Security-Onion-Solutions/2.3.290
2.3.290
2024-02-29 09:15:41 -05:00
Mike Reeves 44ef164713 2.3.290 2024-02-29 09:08:37 -05:00
Jason ErtelandGitHub 43f7dce297 Merge pull request #12407 from Security-Onion-Solutions/jertel/mergem
Jertel/mergem
2024-02-21 13:18:08 -05:00
Jason Ertel 4e4a4686f1 Merge branch 'master' into jertel/mergem 2024-02-21 13:14:29 -05:00
Jason ErtelandGitHub b5f44e48ab Merge pull request #12403 from Security-Onion-Solutions/jertel/disctemplate
add message at top for clickable link
2024-02-21 12:42:04 -05:00
Jason Ertel a44448519b add message at top for clickable link 2024-02-21 10:53:50 -05:00
Jason ErtelandGitHub 6245ee9a5b Merge branch 'master' into jertel/disctemplate 2024-02-21 10:43:28 -05:00
Jason Ertel 49ca970076 add message at top for clickable link 2024-02-21 10:41:28 -05:00
Jason ErtelandGitHub f49fb7cbae Merge pull request #12401 from Security-Onion-Solutions/jertel/disctemplate
template improvements
2024-02-21 10:39:03 -05:00
Jason Ertel 7692c9be53 template improvements 2024-02-21 10:36:07 -05:00
Jason ErtelandGitHub 25ef12cdc5 Merge pull request #12395 from Security-Onion-Solutions/jertel/mergemaster
Jertel/mergemaster
2024-02-21 07:18:22 -05:00
Jason Ertel 2967adca90 Merge branch 'master' into jertel/mergemaster 2024-02-20 16:56:14 -05:00
Jason ErtelandGitHub d198458366 Merge pull request #12392 from Security-Onion-Solutions/jertel/glm_master
thread locking
2024-02-20 16:55:16 -05:00
Jason Ertel 9e98b409a5 thread locking 2024-02-20 16:00:41 -05:00
Doug BurksandGitHub ba8f729976 Merge pull request #12335 from Security-Onion-Solutions/dougburks-patch-1
Update soup for 2.3.290
2024-02-09 11:18:59 -05:00
Doug BurksandGitHub 5b67795c23 Update soup for 2.3.290 2024-02-09 11:12:43 -05:00
Jason ErtelandGitHub 483bf60ae3 Merge pull request #12233 from Security-Onion-Solutions/jertel/23guidelines
Update 2-4.yml
2024-01-23 10:07:35 -05:00
Doug BurksandJason Ertel 1a9350f60b Update 2-4.yml 2024-01-23 10:05:59 -05:00
Doug BurksandGitHub f4afda0975 Merge pull request #12232 from Security-Onion-Solutions/dougburks-patch-1
Improve Github Discussions template for 2.4 category
2024-01-23 09:57:40 -05:00
Doug BurksandGitHub 137372337c Update 2-4.yml 2024-01-23 09:51:45 -05:00
Mike ReevesandGitHub 1521532c60 Merge pull request #11880 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update VERSION
2023-11-28 15:33:48 -05:00
Mike ReevesandGitHub ada32967dc Update VERSION 2023-11-28 15:30:49 -05:00
Mike ReevesandGitHub d5d2b5fbc7 Merge pull request #11879 from Security-Onion-Solutions/dev
2.3.280
2023-11-28 15:21:56 -05:00
Mike ReevesandGitHub 84d6fcb752 Merge pull request #11878 from Security-Onion-Solutions/2.3.280
2.3.280
2023-11-28 15:00:34 -05:00
Mike Reeves de9e9a2716 2.3.280 2023-11-28 14:58:25 -05:00
Josh PattersonandGitHub cec6cff19d Merge pull request #11874 from Security-Onion-Solutions/23souphs
so-nginx watch managerssl to restart if changed
2023-11-27 12:48:06 -05:00
m0duspwnens 7311d6480c so-nginx watch managerssl to restart if changed 2023-11-27 12:15:09 -05:00
Josh PattersonandGitHub f967c8e362 Merge pull request #11873 from Security-Onion-Solutions/23souphs
enable highstate after starting minion
2023-11-27 11:12:45 -05:00
m0duspwnens cfad6414d2 enable highstate after starting minion 2023-11-27 11:10:39 -05:00
Josh PattersonandGitHub 0fdaed9cf7 Merge pull request #11864 from Security-Onion-Solutions/import/suriinterface
suricata interface None if so-import
2023-11-22 10:42:43 -05:00
m0duspwnens 1dc88781f1 suricata interface None if so-import 2023-11-22 10:11:34 -05:00
Mike ReevesandGitHub 0cfb8b0816 Merge pull request #11834 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update signing_policies.conf
2023-11-20 15:59:21 -05:00
Mike ReevesandGitHub c0968d3843 Update signing_policies.conf 2023-11-20 15:57:29 -05:00
Mike ReevesandGitHub 3b133e87cd Merge pull request #11831 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update signing_policies.conf
2023-11-20 15:19:42 -05:00
Mike ReevesandGitHub fee9b61ce9 Update soup 2023-11-20 15:14:25 -05:00
Mike ReevesandGitHub 57612c69fe Update signing_policies.conf 2023-11-20 15:11:50 -05:00
Mike ReevesandGitHub 94accb0e8c Update signing_policies.conf 2023-11-20 15:09:13 -05:00
Josh PattersonandGitHub 3b8d1d470e Merge pull request #11798 from Security-Onion-Solutions/m0duspwnens-patch-1
Update soup
2023-11-15 15:23:46 -05:00
Josh PattersonandGitHub c624a44b0e Update soup
add quote
2023-11-15 15:19:54 -05:00
weslambertandGitHub bc509a0aa9 Merge pull request #11772 from Security-Onion-Solutions/upgrade/elastic_8_10_4
Elastic 8.10.4
2023-11-13 09:36:49 -05:00
Doug BurksandGitHub ee0ef3217f Merge pull request #11771 from Security-Onion-Solutions/dougburks-patch-1
Add EOL warning to README.md
2023-11-13 09:18:50 -05:00
weslambertandGitHub 18e319cbe3 Elastic 8.10.4 2023-11-13 09:17:33 -05:00
Doug BurksandGitHub 3316e1261d Add EOL warning to README.md 2023-11-13 09:16:25 -05:00
weslambertandGitHub b7cf44466c Elastic 8.10.4 2023-11-13 09:16:23 -05:00
Mike ReevesandGitHub e321aa52a5 Merge pull request #11749 from Security-Onion-Solutions/TOoSmOotH-patch-6
Update soup
2023-11-09 10:49:34 -05:00
Mike ReevesandGitHub 07df045e79 Update soup 2023-11-09 10:38:53 -05:00
Mike ReevesandGitHub 7b11ddb032 Update soup 2023-11-09 10:25:16 -05:00
Jorge ReyesandGitHub ac4428940e Merge pull request #11561 from Security-Onion-Solutions/2.3/zeek6
Zeek 6 upgrade
2023-10-23 09:25:21 -04:00
reyesj2 a9457d5f53 Remove external community-id replaced with Zeek 6 built in community-id.
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com>
2023-10-17 16:02:16 -04:00
Jason ErtelandGitHub 3672701dde Merge pull request #11506 from Security-Onion-Solutions/jertel-patch-1
Update VERSION
2023-10-11 09:26:32 -04:00
Jason ErtelandGitHub 07ed2cb3da Update VERSION 2023-10-10 21:35:48 -04:00
Mike ReevesandGitHub 3839e52401 Merge pull request #11374 from Security-Onion-Solutions/dev
2.3.270
2023-10-06 16:40:28 -04:00
Mike ReevesandGitHub b005a10a8e Merge pull request #11373 from Security-Onion-Solutions/2.3.270
2.3.270
2023-09-22 12:59:04 -04:00
Mike Reeves 752ff5917f 2.3.270 2023-09-22 12:45:46 -04:00
Mike ReevesandGitHub 815e5d53a6 Merge pull request #11367 from Security-Onion-Solutions/TOoSmOotH-patch-2
Update soup
2023-09-21 09:40:58 -04:00
Mike ReevesandGitHub a967db8152 Update soup 2023-09-21 09:38:05 -04:00
Jason ErtelandGitHub 7835cb6a7a Merge pull request #11360 from Security-Onion-Solutions/jertel/vol
Jertel/vol
2023-09-20 08:29:43 -04:00
Jason Ertel 07b92eef9e vol sprawl 2023-09-19 17:22:42 -04:00
Jason Ertel 8855619453 vol sprawl 2023-09-19 12:52:28 -04:00
Doug BurksandGitHub 7763218b71 Merge pull request #11287 from Security-Onion-Solutions/dougburks-patch-1
Update soup for 2.3.270
2023-09-11 09:08:21 -04:00
Doug BurksandGitHub 29f12fac90 Update soup for 2.3.270 2023-09-11 09:05:19 -04:00
Doug BurksandGitHub 1a9f8f0bc2 Merge pull request #11228 from Security-Onion-Solutions/master
Merge master to dev for updated 2.4 discussion template
2023-08-31 10:19:45 -04:00
Doug BurksandGitHub 3e5f354d8b Merge pull request #11227 from Security-Onion-Solutions/dougburks-patch-1
Update 2-4.yml discussion template with additional fields for CPU, RAM, and storage
2023-08-31 10:16:55 -04:00
Doug BurksandGitHub a1b76d2cd3 Update 2-4.yml 2023-08-31 10:12:47 -04:00
weslambertandGitHub 43e402fad4 Merge pull request #11187 from Security-Onion-Solutions/fix/kibana_migration_version
Remove migration version
2023-08-28 11:48:58 -04:00
weslambertandGitHub 170b408feb Remove migration version 2023-08-28 11:26:35 -04:00
weslambertandGitHub e55725cca4 Merge pull request #11183 from Security-Onion-Solutions/feature/elastic_8_8_2
Elastic 8.8.2
2023-08-28 09:49:34 -04:00
weslambertandGitHub 2b9f6b26d8 Elastic 8.8.2 2023-08-28 09:42:23 -04:00
weslambertandGitHub f10b67599e Elastic 8.8.2 2023-08-28 09:41:36 -04:00
Doug BurksandGitHub ea03613df3 Merge pull request #11103 from Security-Onion-Solutions/master
Merge 2.4 discussion template to dev
2023-08-18 16:21:45 -04:00
Doug BurksandGitHub 8ffb6b9e1c Merge pull request #11102 from Security-Onion-Solutions/dougburks-patch-1
Create template for Github Discussions in the 2.4 Category
2023-08-18 16:19:04 -04:00
Doug BurksandGitHub ffadd4aa42 Create 2-4.yml 2023-08-18 16:13:31 -04:00
Mike ReevesandGitHub 78ccea12b1 Merge pull request #10919 from Security-Onion-Solutions/master
Soup
2023-08-02 12:27:08 -04:00
Doug BurksandGitHub 8bef5a84f7 Merge pull request #10916 from Security-Onion-Solutions/supersoup
Supersoup
2023-08-02 11:58:58 -04:00
Mike Reeves 679775a7d0 Add supersoup mode 2023-08-02 11:21:28 -04:00
Mike Reeves 3f5f93059e Add supersoup mode 2023-08-02 11:20:23 -04:00
Mike Reeves d2ae8f81e1 Add supersoup mode 2023-08-02 10:49:51 -04:00
Mike Reeves fcc369d4b9 Add supersoup mode 2023-08-02 10:46:54 -04:00
Mike Reeves 9bb28fd0b5 Add supersoup mode 2023-08-02 10:31:55 -04:00
Mike Reeves 93c5e6a9e8 Add supersoup mode 2023-08-02 09:49:14 -04:00
Mike Reeves 6a7e756a37 Add supersoup mode 2023-08-02 09:47:35 -04:00
Mike Reeves f6b9dec2ae Add supersoup mode 2023-08-02 09:45:29 -04:00
Mike ReevesandGitHub 37386057d9 Merge pull request #10622 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update VERSION
2023-06-20 14:52:03 -04:00
Mike ReevesandGitHub 800945c3b6 Update VERSION 2023-06-20 14:50:29 -04:00
Mike ReevesandGitHub b56c0c5e64 Merge pull request #10621 from Security-Onion-Solutions/dev
2.3.260
2023-06-20 14:36:16 -04:00
Mike ReevesandGitHub 01b986cd50 Merge pull request #10620 from Security-Onion-Solutions/2.3.260
2.3.260
2023-06-20 09:37:56 -04:00
Mike Reeves 3e862151f3 2.3.260 2023-06-20 09:18:30 -04:00
Doug BurksandGitHub 15b3982930 Merge pull request #10610 from Security-Onion-Solutions/dougburks-patch-1
Update soup for 2.3.260
2023-06-16 13:10:42 -04:00
Doug BurksandGitHub 3d687f0404 Update soup for 2.3.260 2023-06-16 12:55:52 -04:00
weslambertandGitHub e74c2fa1b0 Merge pull request #10605 from Security-Onion-Solutions/fix/analyzer_dependencies
Update dependencies
2023-06-16 07:51:50 -04:00
Wes ffc91393e7 Update pulsedive dependencies 2023-06-15 22:14:41 +00:00
Wes d0ab2db312 Update dependencies 2023-06-15 21:03:40 +00:00
weslambertandGitHub 4906068c7f Merge pull request #10495 from Security-Onion-Solutions/foxtrot
Update requests and whoisit
2023-06-05 10:53:49 -04:00
Wes ef8eece53b Update dependencies 2023-06-05 13:45:44 +00:00
weslambertandGitHub 660a50c08d Update whoisit to 2.7.0 2023-06-03 08:53:02 -04:00
Wes 5d326a3c32 Update dependencies 2023-06-01 16:26:04 +00:00
weslambertandGitHub 2a907d3de3 Update version to 2.3.260 2023-06-01 12:04:35 -04:00
weslambertandGitHub 33134b1814 Update requests and whist 2023-06-01 12:03:58 -04:00
weslambertandGitHub b0962da758 Update version to 2.3.0-foxtrot 2023-05-31 08:50:51 -04:00
weslambertandGitHub 8148fd9e56 Merge pull request #10434 from Security-Onion-Solutions/foxtrot
Strelka 0.23.05.22 - Remove ScanRuby scanner
2023-05-26 12:45:03 -04:00
weslambertandGitHub 1ee332b55b Update version to 2.3.260 2023-05-26 08:31:11 -04:00
weslambertandGitHub 873632ec4f Remove ScanRuby scanner 2023-05-25 17:23:44 -04:00
weslambertandGitHub f8068d7975 Update version to 2.3.0-foxtrot 2023-05-25 16:14:29 -04:00
weslambertandGitHub a79ebea5c3 Update version value to 2.3.250-foxtrot 2023-05-25 15:29:07 -04:00
weslambertandGitHub 2fdc3874ca Update version to foxtrot 2023-05-25 14:35:52 -04:00
Mike ReevesandGitHub 7f52c2015d Merge pull request #10408 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update VERSION
2023-05-22 15:25:05 -04:00
Mike ReevesandGitHub 548e1e6937 Update VERSION 2023-05-22 15:23:52 -04:00
Mike ReevesandGitHub c949101d0f Merge pull request #10406 from Security-Onion-Solutions/dev
2.3.250
2023-05-22 15:14:23 -04:00
Mike ReevesandGitHub 7c1f19b91f Merge pull request #10405 from Security-Onion-Solutions/2.3.250
2.3.250
2023-05-22 11:39:40 -04:00
Mike Reeves 598d6b025e 2.3.250 2023-05-22 11:37:13 -04:00
Jason ErtelandGitHub 4d0d0714a5 Merge pull request #10401 from Security-Onion-Solutions/jertel/fixwhoisit
use the same requests version that's already packaged with the analyzer
2023-05-20 08:45:29 -04:00
Jason Ertel cb0c078955 use the same requests version that's already packaged with the analyzer 2023-05-19 23:56:39 -04:00
Jason ErtelandGitHub aa426244bf Merge pull request #10394 from Security-Onion-Solutions/jertel/fixwhoisit
fix lib dependency issue with whoisit
2023-05-19 14:34:32 -04:00
Jason Ertel 97b2ae8d82 fix lib dependency issue with whoisit 2023-05-19 14:23:12 -04:00
Doug BurksandGitHub 7047125759 Merge pull request #10386 from Security-Onion-Solutions/2.3/elastic-8.7.1
UPGRADE: Elastic 8.7.1 #10269
2023-05-18 15:27:10 -04:00
Doug BurksandGitHub 43f73abd4d Update so-kibana-config-load 2023-05-18 15:18:27 -04:00
Doug BurksandGitHub 51a8684850 Update config_saved_objects.ndjson 2023-05-18 15:17:36 -04:00
Doug BurksandGitHub b3c5239787 Merge pull request #10333 from Security-Onion-Solutions/dougburks-patch-1
Update soup for 2.3.250
2023-05-11 08:28:53 -04:00
Doug BurksandGitHub 0f562279ee Update soup for 2.3.250 2023-05-11 07:26:58 -04:00
weslambertandGitHub 834f45c0f2 Merge pull request #10286 from Security-Onion-Solutions/fix/strelka_ignore_yara_rules
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-08 11:58:11 -04:00
weslambertandGitHub d4cf9efeca Merge pull request #10303 from Security-Onion-Solutions/fix/kibana_pivot_to_pcap_url
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 11:55:22 -04:00
Doug BurksandGitHub c620983b4a Merge pull request #10299 from Security-Onion-Solutions/dougburks-patch-1
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:47:49 -04:00
Wes ed19c139ea Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen 2023-05-08 13:44:36 +00:00
Doug BurksandGitHub af85c6261b FIX: Improve soup's local file modification logic #8972 2023-05-08 09:41:26 -04:00
weslambertandGitHub e9f58269cd Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation 2023-05-04 16:13:59 -04:00
Jason ErtelandGitHub 208c3d96e9 Merge pull request #10266 from Security-Onion-Solutions/jertel/aws
more detection improvements
2023-05-02 08:17:13 -04:00
Jason Ertel 1e888a5d9e more detection improvements 2023-05-02 07:56:11 -04:00
Jason ErtelandGitHub f7ae8d449e Merge pull request #10259 from Security-Onion-Solutions/jertel/simplifycd
simplify cloud detection
2023-05-01 11:33:26 -04:00
Jason ErtelandGitHub 195274bb11 Merge branch 'dev' into jertel/simplifycd 2023-05-01 11:29:39 -04:00
Jason Ertel a0ac1d2274 simplify cloud detection 2023-05-01 11:04:43 -04:00
Mike ReevesandGitHub 3dd39c7f59 Merge pull request #10234 from Security-Onion-Solutions/TOoSmOotH-patch-2
Update VERSION
2023-04-26 14:41:04 -04:00
Mike ReevesandGitHub ba846bbf35 Update VERSION 2023-04-26 14:39:31 -04:00
Mike ReevesandGitHub 0baf8e9471 Merge pull request #10227 from Security-Onion-Solutions/dev
2.3.240
2023-04-26 14:31:56 -04:00
Mike ReevesandGitHub e30fec7af0 Merge pull request #10226 from Security-Onion-Solutions/2.3.240
2.3.240
2023-04-26 09:58:18 -04:00
Mike Reeves 884f5cd3a6 2.3.240 2023-04-26 09:55:19 -04:00
Jason ErtelandGitHub 11babd2f1c Merge pull request #10221 from Security-Onion-Solutions/jertel/imdsv2to
timeout more quickly on aws imdsv2 detection
2023-04-26 07:59:13 -04:00
Jason Ertel b440ab5c02 timeout more quickly on aws imdsv2 detection 2023-04-26 07:57:23 -04:00
Jason ErtelandGitHub 91d667c3ad Merge pull request #10200 from Security-Onion-Solutions/jertel/imdsv2_23
Detect cloud install on forced imdsv2 instances
2023-04-25 09:46:39 -04:00
Jason ErtelandGitHub f04c01b28c Merge pull request #10204 from Security-Onion-Solutions/jertel/2.3.240_soup
soup update for 2.3.240
2023-04-25 09:46:28 -04:00
Jason Ertel 71ab8ddf1d soup update for 2.3.240 2023-04-25 09:42:14 -04:00
Jason Ertel f1f79d55dc Detect cloud install on forced imdsv2 instances 2023-04-24 16:26:23 -04:00
Mike ReevesandGitHub db1bd16758 Merge pull request #10142 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update VERSION
2023-04-17 10:56:59 -04:00
Mike ReevesandGitHub ef73834d58 Update VERSION 2023-04-17 10:55:38 -04:00
Mike ReevesandGitHub 3891548d6d Merge pull request #10141 from Security-Onion-Solutions/dev
2.3.230 Release
2023-04-17 10:47:32 -04:00
Mike ReevesandGitHub 9d6ed8b9b2 Merge pull request #10140 from Security-Onion-Solutions/2.3.230
2.3.230
2023-04-17 10:26:59 -04:00
Mike Reeves ef92815a08 2.3.230 2023-04-17 10:22:39 -04:00
Doug BurksandGitHub 19b5cdcb0e Merge pull request #10119 from Security-Onion-Solutions/2.3/fix-suricata-dns
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 11:00:13 -04:00
Doug Burks 272b345892 FIX: Suricata DNS A and CNAME parsing #10117 2023-04-13 10:52:37 -04:00
Mike ReevesandGitHub 7fad9d60ef Merge pull request #10113 from Security-Onion-Solutions/TOoSmOotH-patch-4
Update init.sls
2023-04-12 10:32:43 -04:00
Mike ReevesandGitHub 46fc62b8dc Update init.sls 2023-04-12 10:29:54 -04:00
Doug BurksandGitHub ca9a93a4b0 Merge pull request #9998 from Security-Onion-Solutions/dougburks-patch-1
Update soup for 2.3.230
2023-03-24 12:38:39 -04:00
Doug BurksandGitHub aa2e18fca9 Update soup for 2.3.230 2023-03-24 12:31:51 -04:00
Mike ReevesandGitHub 7e4ce7b81d Merge pull request #9877 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update HOTFIX
2023-03-01 16:37:14 -05:00
Mike ReevesandGitHub e5c0058dd1 Update HOTFIX 2023-03-01 16:36:08 -05:00
Mike ReevesandGitHub 07c5b541a3 Merge pull request #9876 from Security-Onion-Solutions/master
Master to Dev
2023-03-01 16:35:48 -05:00
Mike ReevesandGitHub b756b8ea32 Merge pull request #9873 from Security-Onion-Solutions/hotfix/2.3.220
Hotfix/2.3.220
2023-03-01 16:32:49 -05:00
Mike ReevesandGitHub 5b46e57ae1 Merge pull request #9875 from Security-Onion-Solutions/hotfix23220
Hotfix for 2.3.220
2023-03-01 16:14:26 -05:00
Mike Reeves 924009afb8 Hotfix for 2.3.220 2023-03-01 16:11:38 -05:00
Mike ReevesandGitHub 8f5bacc510 Merge pull request #9874 from Security-Onion-Solutions/TOoSmOotH-patch-3
Update init.sls
2023-03-01 14:52:04 -05:00
Mike ReevesandGitHub d5e48a7eca Update init.sls 2023-03-01 14:50:55 -05:00
Mike ReevesandGitHub 6346a92f0f Merge pull request #9872 from Security-Onion-Solutions/hotfix23220
Hotfix for 2.3.220
2023-03-01 14:20:47 -05:00
Mike Reeves 13a566a9a2 Hotfix for 2.3.220 2023-03-01 14:19:04 -05:00
Mike Reeves 063c6599d8 Hotfix for 2.3.220 2023-03-01 14:17:22 -05:00
weslambertandGitHub 9fb315c99d Merge pull request #9870 from Security-Onion-Solutions/fix/curator_configuration_update_8.0.x
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 10:19:32 -05:00
Wes 6e0891e586 Update Curator configuration to align with requirements for Curator 8.0.x 2023-03-01 15:16:52 +00:00
Mike ReevesandGitHub 3a96d59899 Merge pull request #9869 from Security-Onion-Solutions/TOoSmOotH-patch-2
Update HOTFIX
2023-03-01 10:10:47 -05:00
Mike ReevesandGitHub 5fa945956e Update HOTFIX 2023-03-01 10:09:19 -05:00
Mike ReevesandGitHub b0aab96cf5 Merge pull request #9858 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update VERSION
2023-02-27 09:40:39 -05:00
Mike ReevesandGitHub 11def72790 Update VERSION 2023-02-27 09:39:52 -05:00
Mike ReevesandGitHub 2ca2724a4c Merge pull request #9857 from Security-Onion-Solutions/dev
2.3.220
2023-02-27 09:35:14 -05:00
Mike ReevesandGitHub 884883a225 Merge pull request #9856 from Security-Onion-Solutions/2.3.220
2.3.220
2023-02-27 09:26:28 -05:00
Mike Reeves 5c8ba3af65 2.3.220 2023-02-27 09:23:33 -05:00
Josh BrowerandGitHub 4b5d314adf Merge pull request #9833 from Security-Onion-Solutions/FleetDMConfigFix
Remove unsupported config option
2023-02-21 16:36:58 -05:00
Josh Brower 6e637f559c Remove unsupported config option 2023-02-21 16:35:11 -05:00
Doug BurksandGitHub cc5304e9f7 Merge pull request #9806 from Security-Onion-Solutions/2.3/upgrade-elastic-8.6.2
2.3/upgrade elastic 8.6.2
2023-02-17 08:03:01 -05:00
Doug BurksandGitHub 002403055d UPGRADE: Elastic 8.6.2 #9804 2023-02-17 07:04:57 -05:00
Doug BurksandGitHub b80b80e825 UPGRADE: Elastic 8.6.2 #9804 2023-02-17 07:03:47 -05:00
Josh BrowerandGitHub c539d53a02 Merge pull request #9791 from Security-Onion-Solutions/fleetsapassword
Fix edge case
2023-02-15 15:30:49 -05:00
Josh Brower 3a22978c2b Fix password gen edge case 2023-02-15 15:25:35 -05:00
Doug BurksandGitHub 5b1461e9a1 Merge pull request #9782 from Security-Onion-Solutions/dougburks-patch-1
Update soup for 2.3.220
2023-02-14 08:44:09 -05:00
Doug BurksandGitHub 69f889dbd9 Update soup for 2.3.220 2023-02-14 08:42:35 -05:00
Josh BrowerandGitHub aefe1cceb8 Merge pull request #9758 from Security-Onion-Solutions/fleetupgrade
Fix link for FleetDM standalone nodes
2023-02-09 14:10:45 -05:00
Josh Brower b7e97eceb3 Fix link for FleetDM standalone nodes 2023-02-09 14:08:48 -05:00
Josh BrowerandGitHub 450e02e874 Merge pull request #9749 from Security-Onion-Solutions/fleetdm-fix
FleetDM Upgrade Fix
2023-02-09 09:30:22 -05:00
Josh Brower 09bebf08d6 Fix FleetDM SOC Link 2023-02-09 09:10:50 -05:00
Josh Brower 4dd54cea6c Use correct variable name 2023-02-08 16:58:47 -05:00
Josh Brower e07f4bd0ed Workaround for FleetDM PW Req 2023-02-08 13:03:33 -05:00
Mike ReevesandGitHub 6adb586bb4 Merge pull request #9734 from Security-Onion-Solutions/TOoSmOotH-patch-1
Update VERSION
2023-02-07 09:07:06 -05:00
Mike ReevesandGitHub 2f99821736 Update VERSION 2023-02-07 09:05:16 -05:00
166 changed files with 567 additions and 81 deletions
+190
View File
@@ -0,0 +1,190 @@
body:
- type: markdown
attributes:
value: |
⚠️ This category is solely for conversations related to Security Onion 2.4 ⚠️
If your organization needs more immediate, enterprise grade professional support, with one-on-one virtual meetings and screensharing, contact us via our website: https://securityonion.com/support
- type: dropdown
attributes:
label: Version
description: Which version of Security Onion 2.4.x are you asking about?
options:
-
- 2.4 Pre-release (Beta, Release Candidate)
- 2.4.10
- 2.4.20
- 2.4.30
- 2.4.40
- 2.4.50
- 2.4.60
- 2.4.70
- 2.4.80
- 2.4.90
- 2.4.100
- Other (please provide detail below)
validations:
required: true
- type: dropdown
attributes:
label: Installation Method
description: How did you install Security Onion?
options:
-
- Security Onion ISO image
- Network installation on Red Hat derivative like Oracle, Rocky, Alma, etc.
- Network installation on Ubuntu
- Network installation on Debian
- Other (please provide detail below)
validations:
required: true
- type: dropdown
attributes:
label: Description
description: >
Is this discussion about installation, configuration, upgrading, or other?
options:
-
- installation
- configuration
- upgrading
- other (please provide detail below)
validations:
required: true
- type: dropdown
attributes:
label: Installation Type
description: >
When you installed, did you choose Import, Eval, Standalone, Distributed, or something else?
options:
-
- Import
- Eval
- Standalone
- Distributed
- other (please provide detail below)
validations:
required: true
- type: dropdown
attributes:
label: Location
description: >
Is this deployment in the cloud, on-prem with Internet access, or airgap?
options:
-
- cloud
- on-prem with Internet access
- airgap
- other (please provide detail below)
validations:
required: true
- type: dropdown
attributes:
label: Hardware Specs
description: >
Does your hardware meet or exceed the minimum requirements for your installation type as shown at https://docs.securityonion.net/en/2.4/hardware.html?
options:
-
- Meets minimum requirements
- Exceeds minimum requirements
- Does not meet minimum requirements
- other (please provide detail below)
validations:
required: true
- type: input
attributes:
label: CPU
description: How many CPU cores do you have?
validations:
required: true
- type: input
attributes:
label: RAM
description: How much RAM do you have?
validations:
required: true
- type: input
attributes:
label: Storage for /
description: How much storage do you have for the / partition?
validations:
required: true
- type: input
attributes:
label: Storage for /nsm
description: How much storage do you have for the /nsm partition?
validations:
required: true
- type: dropdown
attributes:
label: Network Traffic Collection
description: >
Are you collecting network traffic from a tap or span port?
options:
-
- tap
- span port
- other (please provide detail below)
validations:
required: true
- type: dropdown
attributes:
label: Network Traffic Speeds
description: >
How much network traffic are you monitoring?
options:
-
- Less than 1Gbps
- 1Gbps to 10Gbps
- more than 10Gbps
validations:
required: true
- type: dropdown
attributes:
label: Status
description: >
Does SOC Grid show all services on all nodes as running OK?
options:
-
- Yes, all services on all nodes are running OK
- No, one or more services are failed (please provide detail below)
validations:
required: true
- type: dropdown
attributes:
label: Salt Status
description: >
Do you get any failures when you run "sudo salt-call state.highstate"?
options:
-
- Yes, there are salt failures (please provide detail below)
- No, there are no failures
validations:
required: true
- type: dropdown
attributes:
label: Logs
description: >
Are there any additional clues in /opt/so/log/?
options:
-
- Yes, there are additional clues in /opt/so/log/ (please provide detail below)
- No, there are no additional clues
validations:
required: true
- type: textarea
attributes:
label: Detail
description: Please read our discussion guidelines at https://github.com/Security-Onion-Solutions/securityonion/discussions/1720 and then provide detailed information to help us help you.
placeholder: |-
STOP! Before typing, please read our discussion guidelines at https://github.com/Security-Onion-Solutions/securityonion/discussions/1720 in their entirety!
If your organization needs more immediate, enterprise grade professional support, with one-on-one virtual meetings and screensharing, contact us via our website: https://securityonion.com/support
validations:
required: true
- type: checkboxes
attributes:
label: Guidelines
options:
- label: I have read the discussion guidelines at https://github.com/Security-Onion-Solutions/securityonion/discussions/1720 and assert that I have followed the guidelines.
required: true
+32
View File
@@ -0,0 +1,32 @@
name: 'Close Threads'
on:
schedule:
- cron: '50 1 * * *'
workflow_dispatch:
permissions:
issues: write
pull-requests: write
discussions: write
concurrency:
group: lock-threads
jobs:
close-threads:
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: write
steps:
- uses: actions/stale@v5
with:
days-before-issue-stale: -1
days-before-issue-close: 60
stale-issue-message: "This issue is stale because it has been inactive for an extended period. Stale issues convey that the issue, while important to someone, is not critical enough for the author, or other community members to work on, sponsor, or otherwise shepherd the issue through to a resolution."
close-issue-message: "This issue was closed because it has been stale for an extended period. It will be automatically locked in 30 days, after which no further commenting will be available."
days-before-pr-stale: 45
days-before-pr-close: 60
stale-pr-message: "This PR is stale because it has been inactive for an extended period. The longer a PR remains stale the more out of date with the main branch it becomes."
close-pr-message: "This PR was closed because it has been stale for an extended period. It will be automatically locked in 30 days. If there is still a commitment to finishing this PR re-open it before it is locked."
+25
View File
@@ -0,0 +1,25 @@
name: 'Lock Threads'
on:
schedule:
- cron: '50 2 * * *'
workflow_dispatch:
permissions:
issues: write
pull-requests: write
discussions: write
concurrency:
group: lock-threads
jobs:
lock-threads:
runs-on: ubuntu-latest
steps:
- uses: jertel/lock-threads@main
with:
include-discussion-currently-open: true
discussion-inactive-days: 90
issue-inactive-days: 30
pr-inactive-days: 30
+1
View File
@@ -0,0 +1 @@
+14
View File
@@ -2,6 +2,20 @@
Security Onion 2.3 is here!
## End Of Life Warning
Security Onion 2.3 reaches End Of Life (EOL) on April 6, 2024:
https://blog.securityonion.net/2023/10/6-month-eol-notice-for-security-onion-23.html
For new installations, please see the 2.4 branch of this repo:
https://github.com/Security-Onion-Solutions/securityonion/tree/2.4/main
If you have an existing 2.3 installation and would like to migrate to 2.4, please see:
https://docs.securityonion.net/en/2.4/appendix.html
## Screenshots
Alerts
+11 -11
View File
@@ -1,18 +1,18 @@
### 2.3.210-20230202 ISO image built on 2023/02/02
### 2.3.300-20240401 ISO image built on 2024/04/01
### Download and Verify
2.3.210-20230202 ISO image:
https://download.securityonion.net/file/securityonion/securityonion-2.3.210-20230202.iso
2.3.300-20240401 ISO image:
https://download.securityonion.net/file/securityonion/securityonion-2.3.300-20240401.iso
MD5: ED38C36DBE40509FC5E87D82B07141C0
SHA1: EDEBDBE75FF34DAD87E141CA8F8614295ED23FB5
SHA256: 30068D4B910E83B63287EAB98E49497A584BAE07854367716813E5D610D3E5E3
MD5: 5CBDA8012D773C5EC362D21C4EA3B7FB
SHA1: 7A34FAA0E11F09F529FF38EC3239211CD87CB1A7
SHA256: 123066DAFBF6F2AA0E1924296CFEFE1213002D7760E8797AB74F1FC1D683C6D7
Signature for ISO image:
https://github.com/Security-Onion-Solutions/securityonion/raw/master/sigs/securityonion-2.3.210-20230202.iso.sig
https://github.com/Security-Onion-Solutions/securityonion/raw/master/sigs/securityonion-2.3.300-20240401.iso.sig
Signing key:
https://raw.githubusercontent.com/Security-Onion-Solutions/securityonion/master/KEYS
@@ -26,22 +26,22 @@ wget https://raw.githubusercontent.com/Security-Onion-Solutions/securityonion/ma
Download the signature file for the ISO:
```
wget https://github.com/Security-Onion-Solutions/securityonion/raw/master/sigs/securityonion-2.3.210-20230202.iso.sig
wget https://github.com/Security-Onion-Solutions/securityonion/raw/master/sigs/securityonion-2.3.300-20240401.iso.sig
```
Download the ISO image:
```
wget https://download.securityonion.net/file/securityonion/securityonion-2.3.210-20230202.iso
wget https://download.securityonion.net/file/securityonion/securityonion-2.3.300-20240401.iso
```
Verify the downloaded ISO image using the signature file:
```
gpg --verify securityonion-2.3.210-20230202.iso.sig securityonion-2.3.210-20230202.iso
gpg --verify securityonion-2.3.300-20240401.iso.sig securityonion-2.3.300-20240401.iso
```
The output should show "Good signature" and the Primary key fingerprint should match what's shown below:
```
gpg: Signature made Thu 02 Feb 2023 08:31:18 PM EST using RSA key ID FE507013
gpg: Signature made Wed 27 Mar 2024 05:09:33 PM EDT using RSA key ID FE507013
gpg: Good signature from "Security Onion Solutions, LLC <info@securityonionsolutions.com>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
+1 -1
View File
@@ -1 +1 @@
2.3.210
2.3.300
+3 -1
View File
@@ -15,6 +15,7 @@ zeek:
SpoolDir: /nsm/zeek/spool
CfgDir: /opt/zeek/etc
CompressLogs: 1
ZeekPort: 27760
local:
'@load':
- misc/loaded-scripts
@@ -41,12 +42,13 @@ zeek:
- frameworks/files/hash-all-files
- frameworks/files/detect-MHR
- policy/frameworks/notice/extend-email/hostnames
- policy/frameworks/notice/community-id
- policy/protocols/conn/community-id-logging
- ja3
- hassh
- intel
- cve-2020-0601
- securityonion/bpfconf
- securityonion/communityid
- securityonion/file-extraction
- oui-logging
- icsnpp-modbus
+1 -1
View File
@@ -37,7 +37,7 @@ x509_signing_policies:
- ST: Utah
- L: Salt Lake City
- basicConstraints: "critical CA:false"
- keyUsage: "critical keyEncipherment"
- keyUsage: "critical keyEncipherment, digitalSignature"
- subjectKeyIdentifier: hash
- authorityKeyIdentifier: keyid,issuer:always
- extendedKeyUsage: serverAuth
+6 -1
View File
@@ -53,8 +53,10 @@ if [[ $? -ne 0 ]]; then
exit 2
fi
TEMPPW=$FLEET_SA_PW!
# Create New User
CREATE_OUTPUT=$(docker exec so-fleet fleetctl user create --email $USER_EMAIL --name $USER_EMAIL --password $USER_PASS --global-role admin 2>&1)
CREATE_OUTPUT=$(docker exec so-fleet fleetctl user create --email $USER_EMAIL --name $USER_EMAIL --password $TEMPPW --global-role admin 2>&1)
if [[ $? -eq 0 ]]; then
echo "Successfully added user to Fleet"
@@ -64,6 +66,9 @@ else
exit 2
fi
# Reset New User Password to user supplied password
echo "$USER_PASS" | so-fleet-user-update "$USER_EMAIL"
# Disable forced password reset
MYSQL_OUTPUT=$(docker exec so-mysql mysql -u root --password=$MYSQL_PW fleet -e \
"UPDATE users SET admin_forced_password_reset = 0 WHERE email = '$USER_EMAIL'" 2>&1)
+144 -3
View File
@@ -17,9 +17,30 @@
. /usr/sbin/so-common
INSTALLEDVERSION=$(cat /etc/soversion)
if [[ $INSTALLEDVERSION == "2.4.4" ]]; then
echo "Initiating supersoup mode"
mkdir -p /tmp/supersoup
cd /tmp/supersoup
echo "Updating soup..."
wget https://raw.githubusercontent.com/Security-Onion-Solutions/securityonion/2.4/main/salt/manager/tools/sbin/soup
cp soup /opt/so/saltstack/default/salt/manager/tools/sbin
echo "Updating soup..."
salt-call state.apply manager
echo "Please run soup a second time."
exit 0
fi
if [ "$INSTALLEDVERSION" = '2.4.3' ] || [ "$INSTALLEDVERSION" = '2.4.2' ] || [ "$INSTALLEDVERSION" = '2.4.1' ] || [ "$INSTALLEDVERSION" = '2.4.0' ]; then
echo "soup is not supported on $INSTALLEDVERSION. Please install the latest 2.4 release."
exit 1
fi
UPDATE_DIR=/tmp/sogh/securityonion
DEFAULT_SALT_DIR=/opt/so/saltstack/default
INSTALLEDVERSION=$(cat /etc/soversion)
POSTVERSION=$INSTALLEDVERSION
INSTALLEDSALTVERSION=$(salt --versions-report | grep Salt: | awk '{print $2}')
BATCHSIZE=5
@@ -212,7 +233,7 @@ check_local_mods() {
if [[ -f $default_file ]]; then
file_diff=$(diff "$default_file" "$local_file" )
if [[ ! " ${local_ignore_arr[*]} " =~ " ${local_file} " ]]; then
if [[ $(echo "$file_diff" | grep -c "^<") -gt 0 ]]; then
if [[ $(echo "$file_diff" | grep -Ec "^[<>]") -gt 0 ]]; then
local_mod_arr+=( "$local_file" )
fi
fi
@@ -553,6 +574,16 @@ preupgrade_changes() {
[[ "$INSTALLEDVERSION" == 2.3.182 ]] && up_to_2.3.190
[[ "$INSTALLEDVERSION" == 2.3.190 ]] && up_to_2.3.200
[[ "$INSTALLEDVERSION" == 2.3.200 ]] && up_to_2.3.210
[[ "$INSTALLEDVERSION" == 2.3.210 ]] && up_to_2.3.220
[[ "$INSTALLEDVERSION" == 2.3.220 ]] && up_to_2.3.230
[[ "$INSTALLEDVERSION" == 2.3.230 ]] && up_to_2.3.240
[[ "$INSTALLEDVERSION" == 2.3.240 ]] && up_to_2.3.250
[[ "$INSTALLEDVERSION" == 2.3.250 ]] && up_to_2.3.260
[[ "$INSTALLEDVERSION" == 2.3.260 ]] && up_to_2.3.270
[[ "$INSTALLEDVERSION" == 2.3.270 ]] && up_to_2.3.280
[[ "$INSTALLEDVERSION" == 2.3.280 ]] && up_to_2.3.290
[[ "$INSTALLEDVERSION" == 2.3.290 ]] && up_to_2.3.300
true
}
@@ -578,6 +609,15 @@ postupgrade_changes() {
[[ "$POSTVERSION" == 2.3.182 ]] && post_to_2.3.190
[[ "$POSTVERSION" == 2.3.190 ]] && post_to_2.3.200
[[ "$POSTVERSION" == 2.3.200 ]] && post_to_2.3.210
[[ "$POSTVERSION" == 2.3.210 ]] && post_to_2.3.220
[[ "$POSTVERSION" == 2.3.220 ]] && post_to_2.3.230
[[ "$POSTVERSION" == 2.3.230 ]] && post_to_2.3.240
[[ "$POSTVERSION" == 2.3.240 ]] && post_to_2.3.250
[[ "$POSTVERSION" == 2.3.250 ]] && post_to_2.3.260
[[ "$POSTVERSION" == 2.3.260 ]] && post_to_2.3.270
[[ "$POSTVERSION" == 2.3.270 ]] && post_to_2.3.280
[[ "$POSTVERSION" == 2.3.280 ]] && post_to_2.3.290
[[ "$POSTVERSION" == 2.3.290 ]] && post_to_2.3.300
true
}
@@ -706,6 +746,58 @@ post_to_2.3.210() {
POSTVERSION=2.3.210
}
post_to_2.3.220() {
echo "Nothing to do for .220"
POSTVERSION=2.3.220
}
post_to_2.3.230() {
echo "Nothing to do for .230"
POSTVERSION=2.3.230
}
post_to_2.3.240() {
echo "Nothing to do for .240"
POSTVERSION=2.3.240
}
post_to_2.3.250() {
echo "Nothing to do for .250"
POSTVERSION=2.3.250
}
post_to_2.3.260() {
echo "Nothing to do for .260"
POSTVERSION=2.3.260
}
post_to_2.3.270() {
echo "Pruning unused docker volumes on all nodes - This process will run in the background."
salt --async \* cmd.run "docker volume prune -f"
POSTVERSION=2.3.270
}
post_to_2.3.280() {
salt-call state.apply ca queue=True
stop_salt_minion
mv /etc/pki/managerssl.crt /etc/pki/managerssl.crt.old
mv /etc/pki/managerssl.key /etc/pki/managerssl.key.old
systemctl_func "start" "salt-minion"
enable_highstate
POSTVERSION=2.3.280
}
post_to_2.3.290() {
echo "Nothing to do for .290"
POSTVERSION=2.3.290
}
post_to_2.3.300() {
echo "Nothing to do for .300"
POSTVERSION=2.3.300
}
stop_salt_master() {
# kill all salt jobs across the grid because the hang indefinitely if they are queued and salt-master restarts
set +e
@@ -1041,6 +1133,51 @@ up_to_2.3.210() {
INSTALLEDVERSION=2.3.210
}
up_to_2.3.220() {
echo "Upgrading to 2.3.220"
INSTALLEDVERSION=2.3.220
}
up_to_2.3.230() {
echo "Upgrading to 2.3.230"
INSTALLEDVERSION=2.3.230
}
up_to_2.3.240() {
echo "Upgrading to 2.3.240"
INSTALLEDVERSION=2.3.240
}
up_to_2.3.250() {
echo "Upgrading to 2.3.250"
INSTALLEDVERSION=2.3.250
}
up_to_2.3.260() {
echo "Upgrading to 2.3.260"
INSTALLEDVERSION=2.3.260
}
up_to_2.3.270() {
echo "Upgrading to 2.3.270"
INSTALLEDVERSION=2.3.270
}
up_to_2.3.280() {
echo "Upgrading to 2.3.280"
INSTALLEDVERSION=2.3.280
}
up_to_2.3.290() {
echo "Upgrading to 2.3.290"
INSTALLEDVERSION=2.3.290
}
up_to_2.3.300() {
echo "Upgrading to 2.3.300"
INSTALLEDVERSION=2.3.300
}
verify_upgradespace() {
CURRENTSPACE=$(df -BG / | grep -v Avail | awk '{print $4}' | sed 's/.$//')
if [ "$CURRENTSPACE" -lt "10" ]; then
@@ -1624,8 +1761,12 @@ if [[ -z $UNATTENDED ]]; then
SOUP - Security Onion UPdater
**WARNING** Security Onion 2.3 reaches End Of Life (EOL) on April 6, 2024.
Please make plans to migrate to Security Onion 2.4:
https://blog.securityonion.net/2023/10/6-month-eol-notice-for-security-onion-23.html
Please review the following for more information about the update process and recent updates:
https://docs.securityonion.net/soup
https://docs.securityonion.net/en/2.3/soup.html
https://blog.securityonion.net
EOF
+17 -14
View File
@@ -14,22 +14,25 @@
---
# Remember, leave a key empty if there is no value. None will be a string,
# not a Python "NoneType"
client:
hosts:
- {{elasticsearch}}
port: 9200
elasticsearch:
client:
hosts:
- https://{{elasticsearch}}:9200
cloud_id:
ca_certs:
client_cert:
client_key:
verify_certs: False
request_timeout: 30
other_settings:
api_key:
id:
api_key:
master_only: False
{%- if salt['pillar.get']('elasticsearch:auth:enabled') is sameas true %}
username: "{{ ES_USER }}"
password: "{{ ES_PASS }}"
username: "{{ ES_USER }}"
password: "{{ ES_PASS }}"
{%- endif %}
url_prefix:
use_ssl: True
certificate:
client_cert:
client_key:
ssl_no_validate: True
timeout: 30
master_only: False
logging:
loglevel: INFO
+2
View File
@@ -139,6 +139,8 @@ so-curator:
- file: actionconfs
- file: curconf
- file: curlogdir
- watch:
- file: curconf
{% else %}
- force: True
{% endif %}
+16 -16
View File
@@ -1,21 +1,21 @@
{
"description" : "suricata.dns",
"processors" : [
{ "rename": { "field": "message2.proto", "target_field": "network.transport", "ignore_missing": true } },
{ "rename": { "field": "message2.app_proto", "target_field": "network.protocol", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.type", "target_field": "dns.query.type", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.tx_id", "target_field": "dns.id", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.version", "target_field": "dns.version", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.rrname", "target_field": "dns.query.name", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.rrtype", "target_field": "dns.query.type_name", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.flags", "target_field": "dns.flags", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.qr", "target_field": "dns.qr", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.rd", "target_field": "dns.recursion.desired", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.ra", "target_field": "dns.recursion.available", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.rcode", "target_field": "dns.response.code_name", "ignore_missing": true } },
{ "rename": { "field": "message2.grouped.A", "target_field": "dns.answers.data", "ignore_missing": true } },
{ "rename": { "field": "message2.grouped.CNAME", "target_field": "dns.answers.name", "ignore_missing": true } },
{ "pipeline": { "if": "ctx.dns.query?.name != null && ctx.dns.query.name.contains('.')", "name": "dns.tld" } },
{ "pipeline": { "name": "common" } }
{ "rename": { "field": "message2.proto", "target_field": "network.transport", "ignore_missing": true } },
{ "rename": { "field": "message2.app_proto", "target_field": "network.protocol", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.type", "target_field": "dns.query.type", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.tx_id", "target_field": "dns.id", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.version", "target_field": "dns.version", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.rrname", "target_field": "dns.query.name", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.rrtype", "target_field": "dns.query.type_name", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.flags", "target_field": "dns.flags", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.qr", "target_field": "dns.qr", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.rd", "target_field": "dns.recursion.desired", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.ra", "target_field": "dns.recursion.available", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.rcode", "target_field": "dns.response.code_name", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.grouped.A", "target_field": "dns.answers.data", "ignore_missing": true } },
{ "rename": { "field": "message2.dns.grouped.CNAME", "target_field": "dns.answers.name", "ignore_missing": true } },
{ "pipeline": { "if": "ctx.dns.query?.name != null && ctx.dns.query.name.contains('.')", "name": "dns.tld" } },
{ "pipeline": { "name": "common" } }
]
}
@@ -26,9 +26,6 @@ spec:
distributed_tls_write_endpoint: /api/v1/osquery/distributed/write
enable_windows_events_publisher: true
enable_windows_events_subscriber: true
logger_plugin: tls
logger_tls_endpoint: /api/v1/osquery/log
logger_tls_period: 10
pack_delimiter: _
host_settings:
enable_software_inventory: false
+1 -1
View File
@@ -59,7 +59,7 @@ update() {
IFS=$'\r\n' GLOBIGNORE='*' command eval 'LINES=($(cat $1))'
for i in "${LINES[@]}"; do
RESPONSE=$({{ ELASTICCURL }} -X PUT "localhost:5601/api/saved_objects/config/8.6.1" -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d " $i ")
RESPONSE=$({{ ELASTICCURL }} -X PUT "localhost:5601/api/saved_objects/config/8.10.4" -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d " $i ")
echo $RESPONSE; if [[ "$RESPONSE" != *"\"success\":true"* ]] && [[ "$RESPONSE" != *"updated_at"* ]] ; then RETURN_CODE=1;fi
done
@@ -1 +1 @@
{"attributes": {"buildNum": 39457,"defaultIndex": "2289a0c0-6970-11ea-a0cd-ffa0f6a1bc29","defaultRoute": "/app/dashboards#/view/a8411b30-6d03-11ea-b301-3d6c35840645","discover:sampleSize": 100,"theme:darkMode": true,"timepicker:timeDefaults": "{\n \"from\": \"now-24h\",\n \"to\": \"now\"\n}"},"coreMigrationVersion": "8.6.1","id": "8.6.1","migrationVersion": {"config": "7.13.0"},"references": [],"type": "config","updated_at": "2021-10-10T10:10:10.105Z","version": "WzI5NzUsMl0="}
{"attributes": {"buildNum": 39457,"defaultIndex": "2289a0c0-6970-11ea-a0cd-ffa0f6a1bc29","defaultRoute": "/app/dashboards#/view/a8411b30-6d03-11ea-b301-3d6c35840645","discover:sampleSize": 100,"theme:darkMode": true,"timepicker:timeDefaults": "{\n \"from\": \"now-24h\",\n \"to\": \"now\"\n}"},"coreMigrationVersion": "8.10.4","id": "8.10.4","references": [],"type": "config","updated_at": "2021-10-10T10:10:10.105Z","version": "WzI5NzUsMl0="}
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -319,7 +319,7 @@ http {
{%- if fleet_node %}
location /fleet/ {
return 307 https://{{ fleet_ip }}/fleet;
return 307 https://{{ fleet_ip }}/fleet/dashboard;
}
{%- else %}
+4
View File
@@ -118,6 +118,10 @@ so-nginx:
- watch:
- file: nginxconf
- file: nginxconfdir
{% if grains.role in ['so-manager', 'so-managersearch', 'so-eval', 'so-standalone', 'so-import', 'so-fleet'] %}
- x509: managerssl_key
- x509: managerssl_crt
{% endif %}
- require:
- file: nginxconf
{% if grains.role in ['so-manager', 'so-managersearch', 'so-eval', 'so-standalone', 'so-import', 'so-fleet'] %}
+9
View File
@@ -84,6 +84,14 @@ playbook_password_none:
{% else %}
playbookfilesdir:
file.directory:
- name: /opt/so/conf/playbook/redmine-files
- dir_mode: 775
- user: 939
- group: 939
- makedirs: True
so-playbook:
docker_container.running:
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-playbook:{{ VERSION }}
@@ -91,6 +99,7 @@ so-playbook:
- name: so-playbook
- binds:
- /opt/so/log/playbook:/playbook/log:rw
- /opt/so/conf/playbook/redmine-files:/usr/src/redmine/files:rw
- environment:
- REDMINE_DB_MYSQL={{ MANAGERIP }}
- REDMINE_DB_DATABASE=playbook
+8
View File
@@ -52,6 +52,13 @@ redisconf:
- group: 939
- template: jinja
redisdatadir:
file.directory:
- name: /nsm/redis/data
- user: 939
- group: 939
- makedirs: True
so-redis:
docker_container.running:
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-redis:{{ VERSION }}
@@ -64,6 +71,7 @@ so-redis:
- /opt/so/log/redis:/var/log/redis:rw
- /opt/so/conf/redis/etc/redis.conf:/usr/local/etc/redis/redis.conf:ro
- /opt/so/conf/redis/working:/redis:rw
- /nsm/redis/data:/data:rw
- /etc/pki/redis.crt:/certs/redis.crt:ro
- /etc/pki/redis.key:/certs/redis.key:ro
{% if grains['role'] in ['so-manager', 'so-helix', 'so-managersearch', 'so-standalone', 'so-import'] %}
@@ -1,2 +1,2 @@
requests>=2.27.1
requests>=2.31.0
pyyaml>=6.0
@@ -1,2 +1,2 @@
requests>=2.27.1
requests>=2.31.0
pyyaml>=6.0
@@ -1,2 +1,2 @@
requests>=2.27.1
requests>=2.31.0
pyyaml>=6.0
@@ -1,2 +1,2 @@
requests>=2.27.1
requests>=2.31.0
python-whois>=0.7.3
@@ -1,2 +1,2 @@
requests>=2.27.1
requests>=2.31.0
pyyaml>=6.0
@@ -1,2 +1,2 @@
requests>=2.27.1
requests>=2.31.0
pyyaml>=6.0

Some files were not shown because too many files have changed in this diff Show More