Mike Reeves
5639440e3d
Update soup
2024-04-04 09:34:42 -04:00
Mike Reeves
f50ae02559
Update soup
2024-04-03 15:58:56 -04:00
Mike Reeves
94c7dabd9e
Merge pull request #12693 from Security-Onion-Solutions/dev
...
2.3.300
2024-04-01 11:37:59 -04:00
Mike Reeves
2f3b92887b
Merge pull request #12714 from Security-Onion-Solutions/2.3.300
...
2.3.300
2024-04-01 11:26:43 -04:00
Mike Reeves
d15678f638
Update VERIFY_ISO.md
2024-04-01 11:25:29 -04:00
Mike Reeves
93c29bc1da
2.3.300
2024-04-01 11:22:31 -04:00
Mike Reeves
56263675f6
Merge pull request #12692 from Security-Onion-Solutions/2.3.300
...
2.3.300
2024-03-29 09:55:15 -04:00
Mike Reeves
1599e69851
2.3.300
2024-03-29 09:43:50 -04:00
weslambert
5ae7e27ace
Merge pull request #12677 from Security-Onion-Solutions/fix/strelka_yara_ignore
...
Ignore more rules
2024-03-27 16:17:34 -04:00
weslambert
945d2abeed
Ignore more rules
2024-03-27 16:13:30 -04:00
Doug Burks
68eb2d3ceb
Merge pull request #12614 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.300
2024-03-19 16:48:25 -04:00
Doug Burks
595f965183
Update soup for 2.3.300
2024-03-19 16:44:01 -04:00
Jason Ertel
834d18b77c
Merge pull request #12603 from Security-Onion-Solutions/jertel/ld
...
reschedule lock jobs
2024-03-18 09:41:21 -04:00
Jason Ertel
4849da1c11
Merge branch 'master' into jertel/ld
2024-03-18 09:31:17 -04:00
Jason Ertel
fbbddc2aaf
Merge pull request #12602 from Security-Onion-Solutions/jertel/lock
...
re-schedule lock jobs
2024-03-18 09:29:04 -04:00
Jason Ertel
4b24500b79
re-schedule lock jobs
2024-03-18 07:37:42 -04:00
Mike Reeves
f6a765addc
Merge pull request #12467 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update VERSION
2024-02-29 14:13:44 -05:00
Mike Reeves
8b56c0a744
Update VERSION
2024-02-29 14:12:35 -05:00
Mike Reeves
b31d38e734
Merge pull request #12463 from Security-Onion-Solutions/dev
...
2.3.290
2024-02-29 14:07:11 -05:00
Mike Reeves
b1db4137d0
Merge pull request #12462 from Security-Onion-Solutions/2.3.290
...
2.3.290
2024-02-29 09:15:41 -05:00
Mike Reeves
44ef164713
2.3.290
2024-02-29 09:08:37 -05:00
Jason Ertel
43f7dce297
Merge pull request #12407 from Security-Onion-Solutions/jertel/mergem
...
Jertel/mergem
2024-02-21 13:18:08 -05:00
Jason Ertel
4e4a4686f1
Merge branch 'master' into jertel/mergem
2024-02-21 13:14:29 -05:00
Jason Ertel
b5f44e48ab
Merge pull request #12403 from Security-Onion-Solutions/jertel/disctemplate
...
add message at top for clickable link
2024-02-21 12:42:04 -05:00
Jason Ertel
a44448519b
add message at top for clickable link
2024-02-21 10:53:50 -05:00
Jason Ertel
6245ee9a5b
Merge branch 'master' into jertel/disctemplate
2024-02-21 10:43:28 -05:00
Jason Ertel
49ca970076
add message at top for clickable link
2024-02-21 10:41:28 -05:00
Jason Ertel
f49fb7cbae
Merge pull request #12401 from Security-Onion-Solutions/jertel/disctemplate
...
template improvements
2024-02-21 10:39:03 -05:00
Jason Ertel
7692c9be53
template improvements
2024-02-21 10:36:07 -05:00
Jason Ertel
25ef12cdc5
Merge pull request #12395 from Security-Onion-Solutions/jertel/mergemaster
...
Jertel/mergemaster
2024-02-21 07:18:22 -05:00
Jason Ertel
2967adca90
Merge branch 'master' into jertel/mergemaster
2024-02-20 16:56:14 -05:00
Jason Ertel
d198458366
Merge pull request #12392 from Security-Onion-Solutions/jertel/glm_master
...
thread locking
2024-02-20 16:55:16 -05:00
Jason Ertel
9e98b409a5
thread locking
2024-02-20 16:00:41 -05:00
Doug Burks
ba8f729976
Merge pull request #12335 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.290
2024-02-09 11:18:59 -05:00
Doug Burks
5b67795c23
Update soup for 2.3.290
2024-02-09 11:12:43 -05:00
Jason Ertel
483bf60ae3
Merge pull request #12233 from Security-Onion-Solutions/jertel/23guidelines
...
Update 2-4.yml
2024-01-23 10:07:35 -05:00
Doug Burks
1a9350f60b
Update 2-4.yml
2024-01-23 10:05:59 -05:00
Doug Burks
f4afda0975
Merge pull request #12232 from Security-Onion-Solutions/dougburks-patch-1
...
Improve Github Discussions template for 2.4 category
2024-01-23 09:57:40 -05:00
Doug Burks
137372337c
Update 2-4.yml
2024-01-23 09:51:45 -05:00
Mike Reeves
1521532c60
Merge pull request #11880 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-11-28 15:33:48 -05:00
Mike Reeves
ada32967dc
Update VERSION
2023-11-28 15:30:49 -05:00
Mike Reeves
d5d2b5fbc7
Merge pull request #11879 from Security-Onion-Solutions/dev
...
2.3.280
2023-11-28 15:21:56 -05:00
Mike Reeves
84d6fcb752
Merge pull request #11878 from Security-Onion-Solutions/2.3.280
...
2.3.280
2023-11-28 15:00:34 -05:00
Mike Reeves
de9e9a2716
2.3.280
2023-11-28 14:58:25 -05:00
Josh Patterson
cec6cff19d
Merge pull request #11874 from Security-Onion-Solutions/23souphs
...
so-nginx watch managerssl to restart if changed
2023-11-27 12:48:06 -05:00
m0duspwnens
7311d6480c
so-nginx watch managerssl to restart if changed
2023-11-27 12:15:09 -05:00
Josh Patterson
f967c8e362
Merge pull request #11873 from Security-Onion-Solutions/23souphs
...
enable highstate after starting minion
2023-11-27 11:12:45 -05:00
m0duspwnens
cfad6414d2
enable highstate after starting minion
2023-11-27 11:10:39 -05:00
Josh Patterson
0fdaed9cf7
Merge pull request #11864 from Security-Onion-Solutions/import/suriinterface
...
suricata interface None if so-import
2023-11-22 10:42:43 -05:00
m0duspwnens
1dc88781f1
suricata interface None if so-import
2023-11-22 10:11:34 -05:00
Mike Reeves
0cfb8b0816
Merge pull request #11834 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update signing_policies.conf
2023-11-20 15:59:21 -05:00
Mike Reeves
c0968d3843
Update signing_policies.conf
2023-11-20 15:57:29 -05:00
Mike Reeves
3b133e87cd
Merge pull request #11831 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update signing_policies.conf
2023-11-20 15:19:42 -05:00
Mike Reeves
fee9b61ce9
Update soup
2023-11-20 15:14:25 -05:00
Mike Reeves
57612c69fe
Update signing_policies.conf
2023-11-20 15:11:50 -05:00
Mike Reeves
94accb0e8c
Update signing_policies.conf
2023-11-20 15:09:13 -05:00
Josh Patterson
3b8d1d470e
Merge pull request #11798 from Security-Onion-Solutions/m0duspwnens-patch-1
...
Update soup
2023-11-15 15:23:46 -05:00
Josh Patterson
c624a44b0e
Update soup
...
add quote
2023-11-15 15:19:54 -05:00
weslambert
bc509a0aa9
Merge pull request #11772 from Security-Onion-Solutions/upgrade/elastic_8_10_4
...
Elastic 8.10.4
2023-11-13 09:36:49 -05:00
Doug Burks
ee0ef3217f
Merge pull request #11771 from Security-Onion-Solutions/dougburks-patch-1
...
Add EOL warning to README.md
2023-11-13 09:18:50 -05:00
weslambert
18e319cbe3
Elastic 8.10.4
2023-11-13 09:17:33 -05:00
Doug Burks
3316e1261d
Add EOL warning to README.md
2023-11-13 09:16:25 -05:00
weslambert
b7cf44466c
Elastic 8.10.4
2023-11-13 09:16:23 -05:00
Mike Reeves
e321aa52a5
Merge pull request #11749 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update soup
2023-11-09 10:49:34 -05:00
Mike Reeves
07df045e79
Update soup
2023-11-09 10:38:53 -05:00
Mike Reeves
7b11ddb032
Update soup
2023-11-09 10:25:16 -05:00
Jorge Reyes
ac4428940e
Merge pull request #11561 from Security-Onion-Solutions/2.3/zeek6
...
Zeek 6 upgrade
2023-10-23 09:25:21 -04:00
reyesj2
a9457d5f53
Remove external community-id replaced with Zeek 6 built in community-id.
...
Signed-off-by: reyesj2 <94730068+reyesj2@users.noreply.github.com >
2023-10-17 16:02:16 -04:00
Jason Ertel
3672701dde
Merge pull request #11506 from Security-Onion-Solutions/jertel-patch-1
...
Update VERSION
2023-10-11 09:26:32 -04:00
Jason Ertel
07ed2cb3da
Update VERSION
2023-10-10 21:35:48 -04:00
Mike Reeves
3839e52401
Merge pull request #11374 from Security-Onion-Solutions/dev
...
2.3.270
2023-10-06 16:40:28 -04:00
Mike Reeves
b005a10a8e
Merge pull request #11373 from Security-Onion-Solutions/2.3.270
...
2.3.270
2023-09-22 12:59:04 -04:00
Mike Reeves
752ff5917f
2.3.270
2023-09-22 12:45:46 -04:00
Mike Reeves
815e5d53a6
Merge pull request #11367 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update soup
2023-09-21 09:40:58 -04:00
Mike Reeves
a967db8152
Update soup
2023-09-21 09:38:05 -04:00
Jason Ertel
7835cb6a7a
Merge pull request #11360 from Security-Onion-Solutions/jertel/vol
...
Jertel/vol
2023-09-20 08:29:43 -04:00
Jason Ertel
07b92eef9e
vol sprawl
2023-09-19 17:22:42 -04:00
Jason Ertel
8855619453
vol sprawl
2023-09-19 12:52:28 -04:00
Doug Burks
7763218b71
Merge pull request #11287 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.270
2023-09-11 09:08:21 -04:00
Doug Burks
29f12fac90
Update soup for 2.3.270
2023-09-11 09:05:19 -04:00
Doug Burks
1a9f8f0bc2
Merge pull request #11228 from Security-Onion-Solutions/master
...
Merge master to dev for updated 2.4 discussion template
2023-08-31 10:19:45 -04:00
Doug Burks
3e5f354d8b
Merge pull request #11227 from Security-Onion-Solutions/dougburks-patch-1
...
Update 2-4.yml discussion template with additional fields for CPU, RAM, and storage
2023-08-31 10:16:55 -04:00
Doug Burks
a1b76d2cd3
Update 2-4.yml
2023-08-31 10:12:47 -04:00
weslambert
43e402fad4
Merge pull request #11187 from Security-Onion-Solutions/fix/kibana_migration_version
...
Remove migration version
2023-08-28 11:48:58 -04:00
weslambert
170b408feb
Remove migration version
2023-08-28 11:26:35 -04:00
weslambert
e55725cca4
Merge pull request #11183 from Security-Onion-Solutions/feature/elastic_8_8_2
...
Elastic 8.8.2
2023-08-28 09:49:34 -04:00
weslambert
2b9f6b26d8
Elastic 8.8.2
2023-08-28 09:42:23 -04:00
weslambert
f10b67599e
Elastic 8.8.2
2023-08-28 09:41:36 -04:00
Doug Burks
ea03613df3
Merge pull request #11103 from Security-Onion-Solutions/master
...
Merge 2.4 discussion template to dev
2023-08-18 16:21:45 -04:00
Doug Burks
8ffb6b9e1c
Merge pull request #11102 from Security-Onion-Solutions/dougburks-patch-1
...
Create template for Github Discussions in the 2.4 Category
2023-08-18 16:19:04 -04:00
Doug Burks
ffadd4aa42
Create 2-4.yml
2023-08-18 16:13:31 -04:00
Mike Reeves
78ccea12b1
Merge pull request #10919 from Security-Onion-Solutions/master
...
Soup
2023-08-02 12:27:08 -04:00
Doug Burks
8bef5a84f7
Merge pull request #10916 from Security-Onion-Solutions/supersoup
...
Supersoup
2023-08-02 11:58:58 -04:00
Mike Reeves
679775a7d0
Add supersoup mode
2023-08-02 11:21:28 -04:00
Mike Reeves
3f5f93059e
Add supersoup mode
2023-08-02 11:20:23 -04:00
Mike Reeves
d2ae8f81e1
Add supersoup mode
2023-08-02 10:49:51 -04:00
Mike Reeves
fcc369d4b9
Add supersoup mode
2023-08-02 10:46:54 -04:00
Mike Reeves
9bb28fd0b5
Add supersoup mode
2023-08-02 10:31:55 -04:00
Mike Reeves
93c5e6a9e8
Add supersoup mode
2023-08-02 09:49:14 -04:00
Mike Reeves
6a7e756a37
Add supersoup mode
2023-08-02 09:47:35 -04:00
Mike Reeves
f6b9dec2ae
Add supersoup mode
2023-08-02 09:45:29 -04:00
Mike Reeves
37386057d9
Merge pull request #10622 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-06-20 14:52:03 -04:00
Mike Reeves
800945c3b6
Update VERSION
2023-06-20 14:50:29 -04:00
Mike Reeves
b56c0c5e64
Merge pull request #10621 from Security-Onion-Solutions/dev
...
2.3.260
2023-06-20 14:36:16 -04:00
Mike Reeves
01b986cd50
Merge pull request #10620 from Security-Onion-Solutions/2.3.260
...
2.3.260
2023-06-20 09:37:56 -04:00
Mike Reeves
3e862151f3
2.3.260
2023-06-20 09:18:30 -04:00
Doug Burks
15b3982930
Merge pull request #10610 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.260
2023-06-16 13:10:42 -04:00
Doug Burks
3d687f0404
Update soup for 2.3.260
2023-06-16 12:55:52 -04:00
weslambert
e74c2fa1b0
Merge pull request #10605 from Security-Onion-Solutions/fix/analyzer_dependencies
...
Update dependencies
2023-06-16 07:51:50 -04:00
Wes
ffc91393e7
Update pulsedive dependencies
2023-06-15 22:14:41 +00:00
Wes
d0ab2db312
Update dependencies
2023-06-15 21:03:40 +00:00
weslambert
4906068c7f
Merge pull request #10495 from Security-Onion-Solutions/foxtrot
...
Update requests and whoisit
2023-06-05 10:53:49 -04:00
Wes
ef8eece53b
Update dependencies
2023-06-05 13:45:44 +00:00
weslambert
660a50c08d
Update whoisit to 2.7.0
2023-06-03 08:53:02 -04:00
Wes
5d326a3c32
Update dependencies
2023-06-01 16:26:04 +00:00
weslambert
2a907d3de3
Update version to 2.3.260
2023-06-01 12:04:35 -04:00
weslambert
33134b1814
Update requests and whist
2023-06-01 12:03:58 -04:00
weslambert
b0962da758
Update version to 2.3.0-foxtrot
2023-05-31 08:50:51 -04:00
weslambert
8148fd9e56
Merge pull request #10434 from Security-Onion-Solutions/foxtrot
...
Strelka 0.23.05.22 - Remove ScanRuby scanner
2023-05-26 12:45:03 -04:00
weslambert
1ee332b55b
Update version to 2.3.260
2023-05-26 08:31:11 -04:00
weslambert
873632ec4f
Remove ScanRuby scanner
2023-05-25 17:23:44 -04:00
weslambert
f8068d7975
Update version to 2.3.0-foxtrot
2023-05-25 16:14:29 -04:00
weslambert
a79ebea5c3
Update version value to 2.3.250-foxtrot
2023-05-25 15:29:07 -04:00
weslambert
2fdc3874ca
Update version to foxtrot
2023-05-25 14:35:52 -04:00
Mike Reeves
7f52c2015d
Merge pull request #10408 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-05-22 15:25:05 -04:00
Mike Reeves
548e1e6937
Update VERSION
2023-05-22 15:23:52 -04:00
Mike Reeves
c949101d0f
Merge pull request #10406 from Security-Onion-Solutions/dev
...
2.3.250
2023-05-22 15:14:23 -04:00
Mike Reeves
7c1f19b91f
Merge pull request #10405 from Security-Onion-Solutions/2.3.250
...
2.3.250
2023-05-22 11:39:40 -04:00
Mike Reeves
598d6b025e
2.3.250
2023-05-22 11:37:13 -04:00
Jason Ertel
4d0d0714a5
Merge pull request #10401 from Security-Onion-Solutions/jertel/fixwhoisit
...
use the same requests version that's already packaged with the analyzer
2023-05-20 08:45:29 -04:00
Jason Ertel
cb0c078955
use the same requests version that's already packaged with the analyzer
2023-05-19 23:56:39 -04:00
Jason Ertel
aa426244bf
Merge pull request #10394 from Security-Onion-Solutions/jertel/fixwhoisit
...
fix lib dependency issue with whoisit
2023-05-19 14:34:32 -04:00
Jason Ertel
97b2ae8d82
fix lib dependency issue with whoisit
2023-05-19 14:23:12 -04:00
Doug Burks
7047125759
Merge pull request #10386 from Security-Onion-Solutions/2.3/elastic-8.7.1
...
UPGRADE: Elastic 8.7.1 #10269
2023-05-18 15:27:10 -04:00
Doug Burks
43f73abd4d
Update so-kibana-config-load
2023-05-18 15:18:27 -04:00
Doug Burks
51a8684850
Update config_saved_objects.ndjson
2023-05-18 15:17:36 -04:00
Doug Burks
b3c5239787
Merge pull request #10333 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.250
2023-05-11 08:28:53 -04:00
Doug Burks
0f562279ee
Update soup for 2.3.250
2023-05-11 07:26:58 -04:00
weslambert
834f45c0f2
Merge pull request #10286 from Security-Onion-Solutions/fix/strelka_ignore_yara_rules
...
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-08 11:58:11 -04:00
weslambert
d4cf9efeca
Merge pull request #10303 from Security-Onion-Solutions/fix/kibana_pivot_to_pcap_url
...
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 11:55:22 -04:00
Doug Burks
c620983b4a
Merge pull request #10299 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:47:49 -04:00
Wes
ed19c139ea
Surround _id field in double quotes to prevent errors associated with values beginning with a hyphen
2023-05-08 13:44:36 +00:00
Doug Burks
af85c6261b
FIX: Improve soup's local file modification logic #8972
2023-05-08 09:41:26 -04:00
weslambert
e9f58269cd
Ignore "expl_outlook_cve_2023_23397.yar" and "gen_mal_3cx_compromise_mar23.yar" since they are causing problems with YARA compilation
2023-05-04 16:13:59 -04:00
Jason Ertel
208c3d96e9
Merge pull request #10266 from Security-Onion-Solutions/jertel/aws
...
more detection improvements
2023-05-02 08:17:13 -04:00
Jason Ertel
1e888a5d9e
more detection improvements
2023-05-02 07:56:11 -04:00
Jason Ertel
f7ae8d449e
Merge pull request #10259 from Security-Onion-Solutions/jertel/simplifycd
...
simplify cloud detection
2023-05-01 11:33:26 -04:00
Jason Ertel
195274bb11
Merge branch 'dev' into jertel/simplifycd
2023-05-01 11:29:39 -04:00
Jason Ertel
a0ac1d2274
simplify cloud detection
2023-05-01 11:04:43 -04:00
Mike Reeves
3dd39c7f59
Merge pull request #10234 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2023-04-26 14:41:04 -04:00
Mike Reeves
ba846bbf35
Update VERSION
2023-04-26 14:39:31 -04:00
Mike Reeves
0baf8e9471
Merge pull request #10227 from Security-Onion-Solutions/dev
...
2.3.240
2023-04-26 14:31:56 -04:00
Mike Reeves
e30fec7af0
Merge pull request #10226 from Security-Onion-Solutions/2.3.240
...
2.3.240
2023-04-26 09:58:18 -04:00
Mike Reeves
884f5cd3a6
2.3.240
2023-04-26 09:55:19 -04:00
Jason Ertel
11babd2f1c
Merge pull request #10221 from Security-Onion-Solutions/jertel/imdsv2to
...
timeout more quickly on aws imdsv2 detection
2023-04-26 07:59:13 -04:00
Jason Ertel
b440ab5c02
timeout more quickly on aws imdsv2 detection
2023-04-26 07:57:23 -04:00
Jason Ertel
91d667c3ad
Merge pull request #10200 from Security-Onion-Solutions/jertel/imdsv2_23
...
Detect cloud install on forced imdsv2 instances
2023-04-25 09:46:39 -04:00
Jason Ertel
f04c01b28c
Merge pull request #10204 from Security-Onion-Solutions/jertel/2.3.240_soup
...
soup update for 2.3.240
2023-04-25 09:46:28 -04:00
Jason Ertel
71ab8ddf1d
soup update for 2.3.240
2023-04-25 09:42:14 -04:00
Jason Ertel
f1f79d55dc
Detect cloud install on forced imdsv2 instances
2023-04-24 16:26:23 -04:00
Mike Reeves
db1bd16758
Merge pull request #10142 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-04-17 10:56:59 -04:00
Mike Reeves
ef73834d58
Update VERSION
2023-04-17 10:55:38 -04:00
Mike Reeves
3891548d6d
Merge pull request #10141 from Security-Onion-Solutions/dev
...
2.3.230 Release
2023-04-17 10:47:32 -04:00
Mike Reeves
9d6ed8b9b2
Merge pull request #10140 from Security-Onion-Solutions/2.3.230
...
2.3.230
2023-04-17 10:26:59 -04:00
Mike Reeves
ef92815a08
2.3.230
2023-04-17 10:22:39 -04:00
Doug Burks
19b5cdcb0e
Merge pull request #10119 from Security-Onion-Solutions/2.3/fix-suricata-dns
...
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 11:00:13 -04:00
Doug Burks
272b345892
FIX: Suricata DNS A and CNAME parsing #10117
2023-04-13 10:52:37 -04:00
Mike Reeves
7fad9d60ef
Merge pull request #10113 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2023-04-12 10:32:43 -04:00
Mike Reeves
46fc62b8dc
Update init.sls
2023-04-12 10:29:54 -04:00
Doug Burks
ca9a93a4b0
Merge pull request #9998 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.230
2023-03-24 12:38:39 -04:00
Doug Burks
aa2e18fca9
Update soup for 2.3.230
2023-03-24 12:31:51 -04:00
Mike Reeves
7e4ce7b81d
Merge pull request #9877 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2023-03-01 16:37:14 -05:00
Mike Reeves
e5c0058dd1
Update HOTFIX
2023-03-01 16:36:08 -05:00
Mike Reeves
07c5b541a3
Merge pull request #9876 from Security-Onion-Solutions/master
...
Master to Dev
2023-03-01 16:35:48 -05:00
Mike Reeves
b756b8ea32
Merge pull request #9873 from Security-Onion-Solutions/hotfix/2.3.220
...
Hotfix/2.3.220
2023-03-01 16:32:49 -05:00
Mike Reeves
5b46e57ae1
Merge pull request #9875 from Security-Onion-Solutions/hotfix23220
...
Hotfix for 2.3.220
2023-03-01 16:14:26 -05:00
Mike Reeves
924009afb8
Hotfix for 2.3.220
2023-03-01 16:11:38 -05:00
Mike Reeves
8f5bacc510
Merge pull request #9874 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update init.sls
2023-03-01 14:52:04 -05:00
Mike Reeves
d5e48a7eca
Update init.sls
2023-03-01 14:50:55 -05:00
Mike Reeves
6346a92f0f
Merge pull request #9872 from Security-Onion-Solutions/hotfix23220
...
Hotfix for 2.3.220
2023-03-01 14:20:47 -05:00
Mike Reeves
13a566a9a2
Hotfix for 2.3.220
2023-03-01 14:19:04 -05:00
Mike Reeves
063c6599d8
Hotfix for 2.3.220
2023-03-01 14:17:22 -05:00
weslambert
9fb315c99d
Merge pull request #9870 from Security-Onion-Solutions/fix/curator_configuration_update_8.0.x
...
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 10:19:32 -05:00
Wes
6e0891e586
Update Curator configuration to align with requirements for Curator 8.0.x
2023-03-01 15:16:52 +00:00
Mike Reeves
3a96d59899
Merge pull request #9869 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update HOTFIX
2023-03-01 10:10:47 -05:00
Mike Reeves
5fa945956e
Update HOTFIX
2023-03-01 10:09:19 -05:00
Mike Reeves
b0aab96cf5
Merge pull request #9858 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-02-27 09:40:39 -05:00
Mike Reeves
11def72790
Update VERSION
2023-02-27 09:39:52 -05:00
Mike Reeves
2ca2724a4c
Merge pull request #9857 from Security-Onion-Solutions/dev
...
2.3.220
2023-02-27 09:35:14 -05:00
Mike Reeves
884883a225
Merge pull request #9856 from Security-Onion-Solutions/2.3.220
...
2.3.220
2023-02-27 09:26:28 -05:00
Mike Reeves
5c8ba3af65
2.3.220
2023-02-27 09:23:33 -05:00
Josh Brower
4b5d314adf
Merge pull request #9833 from Security-Onion-Solutions/FleetDMConfigFix
...
Remove unsupported config option
2023-02-21 16:36:58 -05:00
Josh Brower
6e637f559c
Remove unsupported config option
2023-02-21 16:35:11 -05:00
Doug Burks
cc5304e9f7
Merge pull request #9806 from Security-Onion-Solutions/2.3/upgrade-elastic-8.6.2
...
2.3/upgrade elastic 8.6.2
2023-02-17 08:03:01 -05:00
Doug Burks
002403055d
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:04:57 -05:00
Doug Burks
b80b80e825
UPGRADE: Elastic 8.6.2 #9804
2023-02-17 07:03:47 -05:00
Josh Brower
c539d53a02
Merge pull request #9791 from Security-Onion-Solutions/fleetsapassword
...
Fix edge case
2023-02-15 15:30:49 -05:00
Josh Brower
3a22978c2b
Fix password gen edge case
2023-02-15 15:25:35 -05:00
Doug Burks
5b1461e9a1
Merge pull request #9782 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.220
2023-02-14 08:44:09 -05:00
Doug Burks
69f889dbd9
Update soup for 2.3.220
2023-02-14 08:42:35 -05:00
Josh Brower
aefe1cceb8
Merge pull request #9758 from Security-Onion-Solutions/fleetupgrade
...
Fix link for FleetDM standalone nodes
2023-02-09 14:10:45 -05:00
Josh Brower
b7e97eceb3
Fix link for FleetDM standalone nodes
2023-02-09 14:08:48 -05:00
Josh Brower
450e02e874
Merge pull request #9749 from Security-Onion-Solutions/fleetdm-fix
...
FleetDM Upgrade Fix
2023-02-09 09:30:22 -05:00
Josh Brower
09bebf08d6
Fix FleetDM SOC Link
2023-02-09 09:10:50 -05:00
Josh Brower
4dd54cea6c
Use correct variable name
2023-02-08 16:58:47 -05:00
Josh Brower
e07f4bd0ed
Workaround for FleetDM PW Req
2023-02-08 13:03:33 -05:00
Mike Reeves
6adb586bb4
Merge pull request #9734 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-02-07 09:07:06 -05:00
Mike Reeves
2f99821736
Update VERSION
2023-02-07 09:05:16 -05:00
Mike Reeves
db27c22158
Merge pull request #9730 from Security-Onion-Solutions/dev
...
2.3.210
2023-02-07 08:58:36 -05:00
Mike Reeves
2ff284fc7f
Merge pull request #9729 from Security-Onion-Solutions/2.3.210
...
2.3.210
2023-02-06 16:36:06 -05:00
Mike Reeves
5d0a3ef205
2.3.210
2023-02-06 16:32:45 -05:00
Mike Reeves
ac9c10dd3a
2.3.210
2023-02-06 15:46:27 -05:00
weslambert
d4d67b545d
Merge pull request #9699 from Security-Onion-Solutions/fix/strelka_yara_exclusion
...
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:38:29 -05:00
weslambert
2dced35800
Add 'configured_vulns_ext_vars.yar' to exclusion list
2023-02-01 14:24:20 -05:00
Josh Patterson
c2a04a79c5
Merge pull request #9697 from Security-Onion-Solutions/23mysqlpy
...
23mysqlpy
2023-02-01 14:17:24 -05:00
m0duspwnens
d43346a084
hold python mysql
2023-02-01 14:11:27 -05:00
m0duspwnens
0c4a27d120
lock python36-mysql-1.3.12-2.el7 version
2023-02-01 12:33:19 -05:00
Doug Burks
b4530ffffe
Merge pull request #9681 from Security-Onion-Solutions/fix/suricata-dhcp-parsing-2.3
...
2.3: Improve Suricata DHCP parsing and dashboard
2023-01-31 10:18:49 -05:00
Doug Burks
d12aa0ed56
Move host.domain table to end of DHCP tables
2023-01-31 07:14:18 -05:00
Doug Burks
17bcf50ccb
update Suricata DHCP parser to set server.address
2023-01-30 15:57:47 -05:00
Doug Burks
48401f6a3f
Merge pull request #9675 from Security-Onion-Solutions/dougburks-patch-1
...
Update soup for 2.3.210
2023-01-30 09:17:47 -05:00
Doug Burks
a96825f43e
Update soup for 2.3.210
2023-01-30 09:16:00 -05:00
Doug Burks
2d48ae7bca
Merge pull request #9656 from Security-Onion-Solutions/2.3/elastic-8.6.1
...
UPGRADE: Elastic 8.6.1 #9594 (2.3)
2023-01-26 16:24:33 -05:00
Doug Burks
0ff519ed2f
Update to Elastic 8.6.1
2023-01-26 16:09:13 -05:00
Doug Burks
127533492f
Update to Elastic 8.6.1
2023-01-26 16:08:15 -05:00
Mike Reeves
7d4b4a8bd4
Merge pull request #9585 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2023-01-17 09:40:46 -05:00
Mike Reeves
e9fa84d71b
Update VERSION
2023-01-17 09:39:35 -05:00
Mike Reeves
cd8cf4a1ac
Merge pull request #9578 from Security-Onion-Solutions/dev
...
2.3.200
2023-01-17 09:26:23 -05:00
Mike Reeves
9718e61a6a
Merge pull request #9576 from Security-Onion-Solutions/2.3.200
...
2.3.200
2023-01-13 16:12:20 -05:00
Mike Reeves
22ec638e85
2.3.200
2023-01-13 16:08:27 -05:00
Doug Burks
7b0c22f967
Merge pull request #9568 from Security-Onion-Solutions/fix/soup-thehive-errors
...
soup should continue even if thehive errors
2023-01-12 13:28:41 -05:00
Doug Burks
672cab858e
Continue even if thehive errors
2023-01-12 12:48:16 -05:00
Josh Brower
29312d595b
Merge pull request #9559 from Security-Onion-Solutions/idh-skins
...
Fix mispelling
2023-01-11 11:04:29 -05:00
Josh Brower
b54f2e8752
Fix mispelling
2023-01-11 10:59:50 -05:00
Josh Brower
1470e120ef
Merge pull request #9540 from Security-Onion-Solutions/idhskins
...
bug fix - idh skins
2023-01-09 15:49:04 -05:00
Josh Brower
2c747ec837
make sure dir is created
2023-01-09 13:46:10 -05:00
Josh Brower
8cb5cd5fee
Merge pull request #9214 from Security-Onion-Solutions/idhskins
...
Custom IDH HTTP Skins
2023-01-06 15:14:14 -05:00
Doug Burks
a4bae77973
Merge pull request #9271 from Njinx/dev
...
so-status runs some code before checking for root privileges
2023-01-04 16:05:34 -05:00
Doug Burks
96a568f57f
Merge pull request #9515 from Security-Onion-Solutions/fix/so-common-references-2.3
...
fix so-common references
2023-01-04 14:31:57 -05:00
doug
7dcdcc18a5
fix so-common references
2023-01-04 14:28:47 -05:00
Doug Burks
10fc8de9f9
Merge pull request #9513 from Security-Onion-Solutions/fix/jinja-whitespace-2.3
...
fix jinja whitespace 2.3
2023-01-04 13:56:17 -05:00
doug
3482df5ee1
fix jinja whitespace
2023-01-04 13:33:51 -05:00
Doug Burks
9ea3d6bb1f
Merge pull request #9512 from Security-Onion-Solutions/fix/copyright-year-2023
...
Update Copyright year
2023-01-04 12:50:30 -05:00
doug
a67a254edc
update Copyright year
2023-01-04 12:44:18 -05:00
Doug Burks
08a5a9ab31
Merge pull request #9510 from Security-Onion-Solutions/fix/sysmon-fields-2.3
...
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:58:04 -05:00
Doug Burks
e3d32c7871
Improve default sysmon fields and add new network_connection fields
2023-01-04 07:38:18 -05:00
weslambert
20d6ce1ce9
Merge pull request #9501 from Security-Onion-Solutions/fix/elasticsearch_ingest_pipeline_rita_beacon
...
Update RITA beacon parsing
2023-01-03 11:13:55 -05:00
Wes
bd114eb1c4
Update RITA beacon parsing
2023-01-03 16:01:35 +00:00
Doug Burks
55c6fc422b
Merge pull request #9497 from Security-Onion-Solutions/fix/sysmon-parsing-2.3
...
FIX: Sysmon logs are missing event.category and event.dataset #8194
2023-01-03 08:56:16 -05:00
doug
5d060f9832
update Sysmon File dashboard
2022-12-31 14:10:02 -05:00
doug
edcbfd17f5
update sysmon parser
2022-12-30 16:20:06 -05:00
Doug Burks
ff4850d9ce
Merge pull request #9452 from Security-Onion-Solutions/feature/improve-dashboards-2.3
...
FEATURE: Improve SOC Dashboards #9450 2.3
2022-12-21 15:46:21 -05:00
Doug Burks
3e1a5b6329
Improve Strelka dashboard
2022-12-21 15:34:06 -05:00
Doug Burks
b1709f3ea3
Improve Firewall dashboard
2022-12-21 15:28:41 -05:00
Doug Burks
76a73ea35c
Improve Software dashboard
2022-12-21 15:25:19 -05:00
Doug Burks
991a6ec43c
Improve Intel dashboard
2022-12-21 15:19:54 -05:00
Doug Burks
e2c0607249
Improve FTP dashboard
2022-12-21 14:36:44 -05:00
Doug Burks
82c61e6bc9
improve NIDS Alerts dashboard
2022-12-21 14:32:05 -05:00
Doug Burks
37aa779095
Minor improvements
2022-12-21 13:14:38 -05:00
Doug Burks
9e631ad63d
Improve SOC dashboards
2022-12-21 13:04:12 -05:00
Jason Ertel
fe6a55b58e
Merge pull request #9393 from Security-Onion-Solutions/jertel/soup23200
...
Move Kratos DB to /nsm
2022-12-14 14:26:19 -05:00
Jason Ertel
87cebedc85
Backup the new Kratos location
2022-12-14 14:12:47 -05:00
Jason Ertel
e66c995b1f
remove apparently unused reactor reference
2022-12-14 13:50:20 -05:00
Jason Ertel
e8a8f65ddc
fix typo
2022-12-14 12:56:25 -05:00
Jason Ertel
a7a15117f0
Improve soup wording when the script itself needs updated
2022-12-14 12:03:47 -05:00
Jason Ertel
865ba4264b
Stop backing up kratos since it now lives in /nsm. Ensure kratos is removed when re-installing.
2022-12-14 10:57:24 -05:00
Jason Ertel
6985b0ab27
Move kratos DB to /nsm
2022-12-14 10:50:24 -05:00
Mike Reeves
6e4912f759
Merge pull request #9385 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Fix Highlander Config for Kibana
2022-12-13 13:54:30 -05:00
Mike Reeves
b0d934daf7
Update config.map.jinja
2022-12-13 13:52:13 -05:00
Doug Burks
8e50868abd
Merge pull request #9383 from Security-Onion-Solutions/fix/import-hyperlink
...
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:36:22 -05:00
Doug Burks
aa08803f03
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:23:27 -05:00
Doug Burks
bb346d531d
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 13:22:53 -05:00
Doug Burks
6c057d0b0a
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 12:43:54 -05:00
Doug Burks
47e43e53d9
FIX: so-import utilities should hyperlink to dashboards #9373
2022-12-13 12:43:10 -05:00
weslambert
a8456a4d65
Merge pull request #9369 from Security-Onion-Solutions/fix/sensoroni_analyzers_configuration_check
...
Fix localfile analyzer 'file_path' check and add new list value verification function for helpers
2022-12-13 11:47:10 -05:00
Wes
98a1fb96c2
Add test coverage for empty list value
2022-12-13 16:23:16 +00:00
Wes
874bbd2580
Remove extra whitespace
2022-12-13 16:02:46 +00:00
Wes
90dedbb841
Update tests to account for change in 'file_path' value verification
2022-12-13 15:58:35 +00:00
Wes
df5dd5fe28
Use new list verification function for 'file_path'
2022-12-13 15:57:43 +00:00
Wes
d5ab455485
Add new test for list value verification function
2022-12-13 15:56:58 +00:00
Wes
20b79b7ab0
Add new function to verify list value
2022-12-13 15:56:26 +00:00
Jason Ertel
56019f48ca
Merge pull request #9358 from Security-Onion-Solutions/jertel/es853
...
Upgrade ES to 8.5.3
2022-12-12 13:45:56 -05:00
Jason Ertel
d7dd2d2ef8
Upgrade ES to 8.5.3
2022-12-12 13:43:28 -05:00
weslambert
3d431eaba9
Merge pull request #9341 from Security-Onion-Solutions/fix/analyzers_localfile_file_path
...
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 16:49:29 -05:00
weslambert
f85fb5ecf9
Remove double quotes to fix issue with file path sourcing from 'localfile.py'
2022-12-08 16:35:24 -05:00
Jason Ertel
1716cb0297
Merge pull request #9333 from Security-Onion-Solutions/jertel/mergedev
...
Jertel/mergedev
2022-12-08 09:17:20 -05:00
Jason Ertel
0ec366f075
clear hotfix
2022-12-08 09:15:41 -05:00
Jason Ertel
e9b9e128c6
Merge branch 'master' into jertel/mergedev
2022-12-08 09:14:08 -05:00
Mike Reeves
ef15de130a
Merge pull request #9329 from Security-Onion-Solutions/hotfix/2.3.190
...
Hotfix/2.3.190
2022-12-08 09:08:18 -05:00
Mike Reeves
e975ee0a8e
Merge pull request #9328 from Security-Onion-Solutions/mike4
...
2.3.190 hotfix
2022-12-07 16:22:05 -05:00
Mike Reeves
da94ddca13
2.3.190 hotfix
2022-12-07 16:17:57 -05:00
Mike Reeves
6e94751c65
Merge pull request #9327 from Security-Onion-Solutions/jertel/surifilecheck
...
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:10:30 -05:00
Jason Ertel
d48d473f43
Switch back to older style redirect due to incompatibility with Ub 18
2022-12-07 14:06:24 -05:00
Jason Ertel
cff5a83ad5
Merge pull request #9324 from Security-Onion-Solutions/jertel/surifilecheck
...
Use original style due to pgrep conflict with cron
2022-12-07 12:06:26 -05:00
Jason Ertel
225b7e359c
Use original style due to pgrep conflict with cron
2022-12-07 11:53:42 -05:00
Mike Reeves
9a616caf53
Merge pull request #9322 from Security-Onion-Solutions/mike
...
2.3.190 hotfix
2022-12-07 11:15:30 -05:00
Mike Reeves
0aab268801
2.3.190 hotfix
2022-12-07 11:12:13 -05:00
Mike Reeves
0bb7f5c5e3
Merge pull request #9320 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update HOTFIX
2022-12-07 09:21:17 -05:00
Mike Reeves
4aff1f0fdb
Update HOTFIX
2022-12-07 09:19:51 -05:00
Jason Ertel
35ca08ea88
Merge pull request #9315 from Security-Onion-Solutions/jertel/surifilecheck
...
Suricata support for filecheck; reduce cron noise
2022-12-07 08:17:19 -05:00
Jason Ertel
7b05627d5c
Suricata support for filecheck; reduce cron noise
2022-12-07 07:58:32 -05:00
Mike Reeves
e3c1b6dbba
Merge pull request #9306 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update init.sls
2022-12-06 13:38:35 -05:00
Mike Reeves
f0c3b876a9
Update init.sls
2022-12-06 13:35:03 -05:00
Mike Reeves
531423f49a
Update init.sls
2022-12-06 13:25:03 -05:00
Jason Ertel
dfad5a748c
Merge pull request #9303 from Security-Onion-Solutions/jertel/surifilecheck
...
Jertel/surifilecheck
2022-12-06 11:52:36 -05:00
Jason Ertel
819b39c0bb
Update hotfix
2022-12-06 11:41:00 -05:00
Jason Ertel
0dd2e51e83
Ensure Suricata move events get picked up
2022-12-06 11:39:58 -05:00
Mike Reeves
f7730741c2
Merge pull request #9297 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-12-05 16:12:55 -05:00
Mike Reeves
cb2d6b7876
Update VERSION
2022-12-05 16:07:12 -05:00
Mike Reeves
93ca7548f8
Merge pull request #9273 from Security-Onion-Solutions/dev
...
2.3.190
2022-12-05 15:17:47 -05:00
Mike Reeves
9cbbed1038
Merge pull request #9294 from Security-Onion-Solutions/2.3.190a
...
2.3.190
2022-12-05 13:03:23 -05:00
Mike Reeves
967fd30bb1
2.3.190
2022-12-05 13:00:55 -05:00
weslambert
6c8c8a2d8e
Merge pull request #9292 from Security-Onion-Solutions/fix/strelka_disable_yara_rules_causing_errors
...
Disable additional YARA rules that are causing compilation errors
2022-12-05 11:31:23 -05:00
weslambert
8bb3b22993
Disable additional YARA rules there are causing compilation errors
2022-12-05 11:30:22 -05:00
Jason Ertel
5b6182c003
Merge pull request #9289 from Security-Onion-Solutions/jertel/filechek
...
Update filecheck to support Suricata extracted files
2022-12-05 10:59:44 -05:00
Jason Ertel
69c5a9dd90
ensure tmp files are not processed
2022-12-05 10:31:09 -05:00
Jason Ertel
86c31c129a
add suricata to socore group
2022-12-05 10:27:42 -05:00
Jason Ertel
483a9d477f
undo filecheck location move
2022-12-05 10:15:15 -05:00
Jason Ertel
d7f60a0e58
only check files on inotify
2022-12-05 10:01:40 -05:00
Jason Ertel
f06443f3dd
add suricata to socore group
2022-12-05 09:57:24 -05:00
Jason Ertel
fe798138e3
add suricata to socore group
2022-12-05 09:50:35 -05:00
Jason Ertel
e9bb60dedb
fix filecheck for suricata deployments
2022-12-05 09:28:25 -05:00
Jason Ertel
992ced685f
fix filecheck for suricata deployments
2022-12-05 09:27:31 -05:00
Jason Ertel
592bbf4217
fix filecheck for suricata deployments
2022-12-05 09:21:08 -05:00
Mike Reeves
eacf6238d8
Merge pull request #9274 from Security-Onion-Solutions/2.3.190
...
2.3.190
2022-12-02 15:33:53 -05:00
Mike Reeves
0a7ada314d
2.3.190
2022-12-02 15:31:42 -05:00
Mike Reeves
c8edb43748
Merge pull request #9272 from Security-Onion-Solutions/2.3.190
...
2.3.190
2022-12-02 15:28:02 -05:00
Mike Reeves
f112663a76
2.3.190
2022-12-02 15:21:42 -05:00
Ben Allen
a1b2c28a42
Check privileges much earlier
2022-12-02 14:08:22 -05:00
weslambert
4311d5135b
Merge pull request #9269 from Security-Onion-Solutions/fix/zeek_scripts_bzar_remove_by_default
...
Don't load BZAR script(s) by default
2022-12-02 11:02:07 -05:00
weslambert
2b2d39c869
Don't load BZAR script(s) by default
2022-12-02 10:46:45 -05:00
Mike Reeves
fcc0534572
Merge pull request #9267 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2022-12-02 09:41:03 -05:00
Mike Reeves
a3f9859fdb
Update init.sls
2022-12-02 09:38:13 -05:00
Doug Burks
cf5d5e4fc2
Merge pull request #9257 from Security-Onion-Solutions/dougburks-patch-1
...
Disable ecat_arp_info by default in so-zeek-logs and so-whiptail
2022-12-01 07:31:47 -05:00
Doug Burks
7184b9cb25
disable ecat_arp_info by default in so-zeek-logs
2022-12-01 07:18:05 -05:00
Doug Burks
544d716c19
disable ecat_arp_info by default
2022-12-01 07:17:16 -05:00
weslambert
f1f611cede
Merge pull request #9256 from Security-Onion-Solutions/fix/ics_ingest_pipelines_bsap_node_status
...
Change 'bsap.node.status.byte' to 'bsap.node.status_byte'
2022-11-30 13:04:39 -05:00
weslambert
5988c12773
Change 'bsap.node.status.byte' to 'bsap.node.status_byte'
2022-11-30 13:01:30 -05:00
Mike Reeves
dc5f4ef942
Merge pull request #9253 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Use shutil in case there are multiple filesystems involved.
2022-11-30 11:04:30 -05:00
Doug Burks
91e15c233d
Merge pull request #9252 from Security-Onion-Solutions/dougburks-patch-1
...
update stun, tunnel, and wireguard dashboards in dashboards.queries.json
2022-11-30 11:03:56 -05:00
Mike Reeves
42cde0b6f0
Use shutil in case there are multiple filesystems involved.
2022-11-30 10:59:09 -05:00
Doug Burks
1279997ca9
update stun, tunnel, and wireguard dashboards in dashboards.queries.json
2022-11-30 10:59:00 -05:00
weslambert
93e0ec8696
Merge pull request #9249 from Security-Onion-Solutions/fix/ics_ingest_pipelines_additional_field_renames
...
More ICS Field Name Updates
2022-11-30 10:26:36 -05:00
Wes
8f0547beda
Change 'bsap.node.status_byte' to 'bsap.node_status_byte'.
2022-11-30 15:24:53 +00:00
Wes
6cb4c02200
More field updates
2022-11-30 15:22:02 +00:00
weslambert
8c54c44690
Merge pull request #9248 from Security-Onion-Solutions/fix/ics_ingest_pipelines_additional_field_renames
...
Additional ICS field renames and updates
2022-11-30 10:09:44 -05:00
Wes
5d72f8d55a
Additional field renames and updates
2022-11-30 15:01:41 +00:00
Mike Reeves
768225ff5a
Merge pull request #9242 from Security-Onion-Solutions/TOoSmOotH-patch-1
2022-11-29 23:42:15 -05:00
Mike Reeves
571ac4edec
Update soup
2022-11-29 18:36:47 -05:00
weslambert
86cfac4983
Merge pull request #9241 from Security-Onion-Solutions/fix/ics_pipelines_field_renames
...
ICS Pipelines - Various Field Renames
2022-11-29 17:23:34 -05:00
Wes
e00a80feb4
Use native link_id naming scheme for now
2022-11-29 22:05:37 +00:00
Wes
e8e39a7105
Various field renames
2022-11-29 21:32:05 +00:00
Wes
13ea44db95
Use native 'is_orig' since we are already using that field name for other logs
2022-11-29 21:21:41 +00:00
weslambert
7f4f1397e7
Merge pull request #9240 from Security-Onion-Solutions/fix/add_s7comm_upload_download_ingest_pipeline
...
Add Zeek s7comm upload download ingest pipeline
2022-11-29 15:00:26 -05:00
Wes
5db3e22363
Add s7comm_upload_download references in various places
2022-11-29 19:58:18 +00:00
Wes
6fe2857ba5
Add Zeek s7comm_upload_download ingest pipeline
2022-11-29 19:45:56 +00:00
weslambert
56b0bae089
Merge pull request #9238 from Security-Onion-Solutions/fix/opcua_encoding_mask_format
...
Fix OP CUA Encoding Mask Format and Ensure Connection State Is Populated Before Assessing Its Value
2022-11-29 14:16:03 -05:00
weslambert
f947e501cb
Add space per request
2022-11-29 14:14:37 -05:00
weslambert
ff8bbc399f
Add space per request
2022-11-29 14:14:08 -05:00
weslambert
80226a27cc
Add space per request
2022-11-29 14:13:41 -05:00
weslambert
266207cc18
Add space per request
2022-11-29 14:12:52 -05:00
weslambert
5255c120c5
Add space per request
2022-11-29 14:11:20 -05:00
Wes
d44f8e495b
Check if connection.state is populated before trying to assess its value
2022-11-29 19:00:47 +00:00
Wes
13a8cbdabb
Add convert processor for opcua.encoding_mask
2022-11-29 18:59:30 +00:00
Doug Burks
c3c505f8ff
Merge pull request #9237 from Security-Onion-Solutions/dougburks-patch-1
...
add ICS COTP dashboard to dashboards.queries.json
2022-11-29 13:40:24 -05:00
Doug Burks
7ea0aa87e4
add ICS COTP dashboard to dashboards.queries.json
2022-11-29 13:38:19 -05:00
weslambert
82317656b1
Merge pull request #9235 from Security-Onion-Solutions/fix/mobus_read_write_multiple_registers_pipeline_failure_resolution
...
Change 'write' to 'read' to correct name and avoid pipeline failure
2022-11-29 12:56:05 -05:00
weslambert
1cc5961c07
Change 'write' to 'read' to correct name and avoid pipeline failure
2022-11-29 12:54:55 -05:00
weslambert
220e998b45
Merge pull request #9234 from Security-Onion-Solutions/fix/add_dnp3_control_ingest_pipeline
...
Add 'zeek.dnp3_control' ingest pipeline
2022-11-29 12:29:44 -05:00
Wes
16cd1080be
Add dnp3_control reference in various places
2022-11-29 17:23:37 +00:00
Wes
5db643e53b
Add Zeek dnp3_control ingest pipeline
2022-11-29 17:18:24 +00:00
weslambert
745cdef538
Merge pull request #9232 from Security-Onion-Solutions/fix/filebeat_ics_tag_bsap
...
Add 'ics' tag for 'bsap'-prefixed events/logs
2022-11-29 11:37:18 -05:00
weslambert
aa767b8dc1
Add 'ics' tag for 'bsap'-prefixed events/logs
2022-11-29 11:27:41 -05:00
Doug Burks
45cdd16308
Merge pull request #9228 from Security-Onion-Solutions/fix/zeek-ics-eventfields
...
More Zeek ICS changes
2022-11-29 09:18:40 -05:00
doug
1bb76bb251
update zeek s7comm parsers
2022-11-29 07:50:21 -05:00
doug
4251331bd4
update zeek tds parsers and dashboard
2022-11-29 07:43:20 -05:00
doug
124d56f4b9
update zeek cip parsers
2022-11-29 07:36:30 -05:00
doug
02821b97ad
update bacnet parsers
2022-11-29 07:26:11 -05:00
doug
9a50832669
fix more typos
2022-11-29 07:16:30 -05:00
doug
cffbe757a6
fix bsap typos
2022-11-29 06:56:51 -05:00
Doug Burks
14ff5670f7
add bsap entries to hunt.eventfields.json
2022-11-29 06:48:20 -05:00
Doug Burks
92e238aa10
Merge pull request #9227 from Security-Onion-Solutions/fix/zeek-ics-parsers
...
Fix Zeek ICS parsers and add dashboards
2022-11-28 15:58:24 -05:00
doug
8462e66873
fix opcua_binary_browse_description
2022-11-28 13:50:24 -05:00
Doug Burks
2763b5846c
improve dashboard descriptions
2022-11-28 13:10:23 -05:00
Doug Burks
dd4c34397d
improve dashboard descriptions
2022-11-28 13:03:54 -05:00
Doug Burks
a796fa2ff7
make sure that ICS dashboards with sankey also have separate event.dataset table
2022-11-28 12:09:57 -05:00
Doug Burks
268253ce14
update ENIP dashboard
2022-11-28 12:05:35 -05:00
Doug Burks
6a2f886fcc
improve ecat dashboard
2022-11-28 12:01:35 -05:00
Doug Burks
63915b0486
consolidate DNP3 dashboards
2022-11-28 11:58:48 -05:00
Doug Burks
ce7b16a230
more ICS dashboards
2022-11-28 10:06:58 -05:00
Doug Burks
a4f5e7b2a6
add ECAT dashboard
2022-11-28 10:05:15 -05:00
Doug Burks
cfbbc3a1a3
add S7 dashboard
2022-11-28 10:02:33 -05:00
Doug Burks
11a7f051a6
organize dashboards
2022-11-28 09:57:54 -05:00
Doug Burks
cb06269b1a
update DNP3 and MODBUS dashboards
2022-11-28 09:40:42 -05:00
Mike Reeves
d026414bcf
Merge pull request #9226 from Security-Onion-Solutions/bgfix
...
Remove BG for filecheck
2022-11-28 09:12:45 -05:00
Mike Reeves
e15ca408e7
Remove BG for filecheck
2022-11-28 09:11:41 -05:00
Mike Reeves
0e2753393b
Remove BG for filecheck
2022-11-28 09:09:25 -05:00
Doug Burks
b06e9e8477
add new zeek opcua logs to so-zeek-logs
2022-11-26 18:44:28 -05:00
Doug Burks
45892400cb
add new zeek opcua logs to so-whiptail
2022-11-26 18:42:51 -05:00
Doug Burks
1f0c984b98
add new zeek opcua logs to so-functions
2022-11-26 18:41:12 -05:00
doug
6d814d3909
add more zeek opcua parsers
2022-11-26 17:43:58 -05:00
Doug Burks
9ea59355d5
fix opcua_binary_opensecure_channel in so-functions
2022-11-26 17:03:57 -05:00
Doug Burks
c1287a61af
add opcua_binary_opensecure_channel to so-functions
2022-11-26 17:02:04 -05:00
Doug Burks
e44c94c56b
add opcua_binary_opensecure_channel to so-whiptail
2022-11-26 17:01:11 -05:00
Doug Burks
ec0cf71c3f
add opcua_binary_opensecure_channel to so-zeek-logs
2022-11-26 17:00:32 -05:00
doug
73adc571de
add more zeek ics parsers
2022-11-26 10:36:49 -05:00
doug
62c1bb2c0c
disable ecat_arp_info since it records all arp traffic
2022-11-25 18:01:53 -05:00
Doug Burks
692ec05b2d
fix opcua_binary_activate_session in hunt.eventfields.json
2022-11-25 17:51:25 -05:00
Doug Burks
00078fd9e5
add opcua_binary_activate_session_diagnostic_info to hunt.eventfields.json
2022-11-25 17:47:41 -05:00
Doug Burks
13c8fb0004
add ecat_coe_info to hunt.eventfields.json
2022-11-25 17:45:28 -05:00
Doug Burks
920b16e494
add ecat_dev_info to hunt.eventfields.json
2022-11-25 17:42:59 -05:00
Doug Burks
d98c57510a
add opcua_binary_activate_session_locale_id to hunt.eventfields.json
2022-11-25 17:39:17 -05:00
Doug Burks
58aa730437
add opcua_binary_create_session_endpoints to hunt.eventfields.json
2022-11-25 17:37:10 -05:00
Doug Burks
f36da68009
add opcua_binary_create_subscription to hunt.eventfields.json
2022-11-25 17:35:02 -05:00
Doug Burks
0091675ab6
fix opcua_binary_get_endpoints_description in hunt.eventfields.json
2022-11-25 17:32:30 -05:00
Doug Burks
83d25a97d3
add opcua_binary_get_endpoints_description to hunt.eventfields.json
2022-11-25 16:01:40 -05:00
Doug Burks
e536568c8a
add opcua_binary_activate_session to hunt.eventfields.json
2022-11-25 15:59:17 -05:00
Doug Burks
a00eb9071f
add opcua_binary_get_endpoints to hunt.eventfields.json
2022-11-25 15:57:35 -05:00
Doug Burks
c39cd9a290
add opcua_binary_browse_result to hunt.eventfields.json
2022-11-25 15:55:59 -05:00
Doug Burks
cb5483d401
add opcua_binary_create_session to hunt.eventfields.json
2022-11-25 15:53:09 -05:00
Doug Burks
fab0d17314
add opcua_binary_browse_description to hunt.eventfields.json
2022-11-25 15:51:49 -05:00
Doug Burks
465e6c4605
add opcua_binary_create_session_user_token to hunt.eventfields.json
2022-11-25 15:48:11 -05:00
Doug Burks
a119d6a842
add opcua_binary_get_endpoints_user_token to hunt.eventfields.json
2022-11-25 15:46:35 -05:00
Doug Burks
be8ce43b74
add opcua_binary_browse to hunt.eventfields.json
2022-11-25 15:44:22 -05:00
Doug Burks
b2a33d4800
add opcua_binary_browse_response_references to hunt.eventfields.json
2022-11-25 15:41:48 -05:00
Doug Burks
78fac49e66
add opcua_binary_read to hunt.eventfields.json
2022-11-25 15:39:58 -05:00
Doug Burks
ca08989404
add cip_io to hunt.eventfields.json
2022-11-25 15:37:21 -05:00
Doug Burks
4ed757916e
add opcua_binary_status_code_detail to hunt.eventfields.json
2022-11-25 15:35:17 -05:00
Doug Burks
676c543178
add opcua_binary to hunt.eventfields.json
2022-11-25 15:33:13 -05:00
Doug Burks
aa2eab5738
fix zeek ics logs in so-functions
2022-11-25 09:53:11 -05:00
Doug Burks
fe21b8bc17
fix zeek ics logs in so-functions
2022-11-25 09:45:18 -05:00
Doug Burks
33a478ff59
fix zeek ics logs in so-zeek-logs
2022-11-25 09:40:48 -05:00
Doug Burks
62fee1f420
fix zeek ics logs in so-whiptail
2022-11-25 09:39:58 -05:00
Doug Burks
2ada4712bc
fix zeek ics logs in so-zeek-logs
2022-11-25 09:37:52 -05:00
Doug Burks
fad6c46e7c
fix zeek ics logs in so-zeek-logs
2022-11-25 09:35:00 -05:00
Doug Burks
6f27c1b21e
fix zeek logs in so-whiptail
2022-11-25 09:26:54 -05:00
Doug Burks
0afb20ffa8
fix ics entries in so-functions
2022-11-25 09:19:11 -05:00
Doug Burks
40688a6076
add Zeek software to so-functions
2022-11-25 07:36:41 -05:00
Doug Burks
9431bf1c2a
add Zeek software log to so-whiptail
2022-11-25 07:28:48 -05:00
Doug Burks
9f5e75b302
add software to so-zeek-logs
2022-11-25 07:27:50 -05:00
Doug Burks
3f62cddc3b
change . to _
2022-11-23 12:21:12 -05:00
Doug Burks
085420997c
move status_code before status_code.link_id
2022-11-23 12:11:04 -05:00
Doug Burks
723e145eeb
Merge pull request #9221 from Security-Onion-Solutions/dougburks-patch-1
...
fix descriptions
2022-11-23 11:43:12 -05:00
Doug Burks
0a1d0d35c8
fix description
2022-11-23 11:33:31 -05:00
Doug Burks
9ee96f2280
fix description
2022-11-23 11:32:09 -05:00
Doug Burks
3871268c19
Merge pull request #9220 from Security-Onion-Solutions/fix/zeek-opcua-parsing
...
fix zeek opcua pipelines
2022-11-23 11:17:47 -05:00
doug
bc620b7def
fix zeek opcua pipelines
2022-11-23 10:56:32 -05:00
Josh Brower
5950771003
Merge remote-tracking branch 'remotes/origin/dev' into idhskins
2022-11-22 18:04:38 -05:00
Josh Brower
7c8ce7899b
Initial support for custom IDH http skins
2022-11-22 17:57:51 -05:00
Doug Burks
08d5f494ab
Merge pull request #9208 from Security-Onion-Solutions/dougburks-patch-1
...
Initial dashboards for stun, tds, wireguard, and ics
2022-11-22 16:04:12 -05:00
weslambert
13827f3be5
Merge pull request #9209 from Security-Onion-Solutions/fix/add_missing_opcua_activate_session_pipelines
...
Add Missing OPCUA Activate Session Pipelines
2022-11-22 16:01:33 -05:00
weslambert
3a64362887
Remove extra space used during testing
2022-11-22 15:47:16 -05:00
Wes
e77a60bcbf
Add missing OPCUA 'activate_session' pipelines
2022-11-22 20:44:48 +00:00
weslambert
e560edf493
Merge pull request #9206 from Security-Onion-Solutions/fix/ingest_typos
...
Fix spelling of 'wireguard.responses' field name
2022-11-22 15:35:55 -05:00
Doug Burks
7caf827b77
add ecat_aoe_info to hunt.eventfields.json
2022-11-22 13:33:06 -05:00
Doug Burks
f40ccb7eff
add bacnet_discovery to hunt.eventfields.json
2022-11-22 13:27:26 -05:00
Doug Burks
e0cd550820
update ecat_arp_info in hunt.eventfields.json
2022-11-22 13:23:45 -05:00
Doug Burks
4e5106c863
update ecat_arp_info in hunt.eventfields.json
2022-11-22 13:21:33 -05:00
Doug Burks
5a107c63b8
add source.mac and destination.mac to dashboards.queries.json
2022-11-22 13:16:47 -05:00
Doug Burks
8a9a13865c
add ecat_registers to hunt.eventfields.json
2022-11-22 13:12:24 -05:00
Doug Burks
9cd6273beb
update ecat_log_address in hunt.eventfields.json
2022-11-22 13:10:46 -05:00
Doug Burks
724b26228c
add ecat_log_address to hunt.eventfields.json
2022-11-22 13:09:27 -05:00
weslambert
3c054fd133
Fix spelling of 'wireguard.responses' field name
2022-11-22 13:02:43 -05:00
Doug Burks
24ee38369f
add cotp to hunt.eventfields.json
2022-11-22 12:49:33 -05:00
weslambert
0bbe642d20
Merge pull request #9203 from Security-Onion-Solutions/fix/ics_ingest_field_names
...
Fix ICS Ingest Field Names
2022-11-22 12:30:10 -05:00
weslambert
8e17c23659
Fix format/speliing for 'enip.status_code' field name
2022-11-22 12:05:03 -05:00
weslambert
92170941f0
Fix spelling for 'stun.class' field name
2022-11-22 12:04:07 -05:00
Doug Burks
10ac789fbf
add profinet_dce_rpc to hunt.eventfields.json
2022-11-22 11:08:24 -05:00
Doug Burks
db58a35562
add profinet to hunt.eventfields.json
2022-11-22 11:07:03 -05:00
Doug Burks
1ad7a0db59
add bacnet_property to hunt.eventfields.json
2022-11-22 11:05:26 -05:00
Doug Burks
af626fe3a1
add bacnet to hunt.eventfields.json
2022-11-22 11:03:45 -05:00
Doug Burks
073f5ed789
add dnp3_objects to hunt.eventfields.json
2022-11-22 11:02:21 -05:00
Doug Burks
bbcefea417
add s7comm_plus to hunt.eventfields.json
2022-11-22 10:58:42 -05:00
Doug Burks
73c282595d
update dnp3 in hunt.eventfields.json
2022-11-22 10:57:06 -05:00
Doug Burks
07a53db09a
add cip_identity to hunt.evenfields.json
2022-11-22 10:55:39 -05:00
Doug Burks
80e50fa7b4
add ecat_arp_info to hunt.eventfields.json
2022-11-22 10:53:48 -05:00
Doug Burks
84d333e915
add s7comm to hunt.eventfields.json
2022-11-22 10:51:06 -05:00
Doug Burks
ae582caa55
Add modbus_detailed to hunt.eventfields.json
2022-11-22 10:48:33 -05:00
Doug Burks
264ae2b9ac
add enip to hunt.eventfields.json
2022-11-22 10:45:20 -05:00
Doug Burks
b522c9eea4
reorder fields in hunt.eventfields.json
2022-11-22 10:43:01 -05:00
Doug Burks
51cc047933
add cip to hunt.eventfields.json
2022-11-22 10:40:22 -05:00
Doug Burks
2a805ac1a6
Add tds entries to hunt.eventfields.json
2022-11-22 10:29:55 -05:00
Doug Burks
595f615ed9
Add ICS dashboard
2022-11-22 10:22:55 -05:00
Doug Burks
aa7c39d312
Add dashboards for stun, tds, and wireguard
2022-11-22 10:08:39 -05:00
weslambert
2170d498c5
Merge pull request #9195 from Security-Onion-Solutions/fix/missing_ics_pipelines
...
Add COTP and TDS ingest pipelines
2022-11-22 08:44:02 -05:00
Wes
95a6f9aa7d
Add COTP and TDS ingest pipelines
2022-11-22 13:35:19 +00:00
weslambert
ba65b351a2
Merge pull request #9193 from Security-Onion-Solutions/fix/ics_tag_syntax_error
...
Fix syntax error for 'ics' tag logic
2022-11-22 07:32:40 -05:00
weslambert
4c09c8856b
Fix syntax error for 'ics' tag logic
2022-11-22 07:23:56 -05:00
weslambert
3afa8bd9da
Merge pull request #9188 from Security-Onion-Solutions/feature/filebeat_config_ics_event_tag
...
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 17:06:25 -05:00
weslambert
72eccd2649
Fix indentation
2022-11-21 17:01:16 -05:00
weslambert
310ea633b6
Add 'ics' tag to events generated from ICS protocol logs
2022-11-21 16:43:43 -05:00
Doug Burks
31b4d9cd70
Merge pull request #9187 from Security-Onion-Solutions/dougburks-patch-1
...
Remove descriptions from so-zeek-logs and so-whiptail
2022-11-21 14:13:04 -05:00
Doug Burks
0536d174fe
Fix opcua_binary reference in so-zeek-logs
2022-11-21 14:03:22 -05:00
Doug Burks
96d7429a1c
Remove descriptions from so-whiptail
2022-11-21 13:32:51 -05:00
Doug Burks
a54bb2bad4
Remove descriptions from so-zeek-logs
2022-11-21 13:23:53 -05:00
Doug Burks
d4abbd89ca
Merge pull request #9185 from Security-Onion-Solutions/dougburks-patch-1
...
Update so-functions to enable ICS/SCADA for EVAL and IMPORT
2022-11-21 12:33:06 -05:00
Peter Di Giorgio
bdfab6858d
Merge pull request #9184 from Security-Onion-Solutions/foxtrot
...
Shorten Zeek Log Descriptions for formatting
2022-11-21 11:20:15 -06:00
lock-wire
f80c8b89e4
Shorten Log Descriptions
2022-11-21 09:49:31 -07:00
Peter Di Giorgio
29384d33e1
Merge pull request #9183 from Security-Onion-Solutions/dev
...
Synch Foxtrot from dev
2022-11-21 10:06:44 -06:00
Doug Burks
aebedf9ac6
Update so-functions to enable ICS/SCADA for EVAL and IMPORT
2022-11-21 10:05:18 -05:00
Doug Burks
40ee529c7e
Merge pull request #9178 from Security-Onion-Solutions/dougburks-patch-1
...
Simplify version in README.md to just 2.3
2022-11-21 08:46:22 -05:00
Doug Burks
b9ee2f1e38
Simplify version in README.md to just 2.3
2022-11-21 08:38:27 -05:00
weslambert
089b403a3b
Merge pull request #9166 from Security-Onion-Solutions/foxtrot
...
Merge final protocol analyzers into dev
2022-11-18 08:41:43 -05:00
Peter Di Giorgio
a28e5de5f4
Correct trailing \
2022-11-18 06:29:57 -06:00
Peter Di Giorgio
2e30cefd91
Add remaining protocol parsers
...
- icsnpp-bsap
- icsnpp-s7comm
- zeek-plugin-tds
- zeek-plugin-profinet
- zeek-spicy-wireguard
- zeek-spicy-stun
2022-11-17 10:47:00 -06:00
Peter Di Giorgio
33bf0c6902
Merge pull request #9163 from Security-Onion-Solutions/dev
...
Update Foxtrot from Dev
2022-11-17 10:44:24 -06:00
Peter Di Giorgio
13b6b43324
Update init.sls
2022-11-17 10:42:21 -06:00
weslambert
78bc2a95e5
Add icsnpp-bsap to enabled plugins
2022-11-17 11:20:24 -05:00
weslambert
5bb0e6e8c0
Merge pull request #9160 from Security-Onion-Solutions/feature/additional_ics_scada_ingest_node_pipelines
...
Add additional ICS/SCADA ingest node pipelines
2022-11-17 11:18:15 -05:00
Wes
a278194037
Add additional ICS/SCADA ingest node pipelines
2022-11-17 16:16:33 +00:00
lock-wire
1b8e546045
Add s7comm,tds,stun,profinet,wireguard
2022-11-16 21:41:02 -06:00
weslambert
7319cb07e2
Merge pull request #9153 from Security-Onion-Solutions/fix/ics_scada_ingest_pipeline_updates_2_3
...
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 16:17:08 -05:00
Wes
35e131b888
Update ingest node pipelines for ICS/SCADA protocols
2022-11-16 21:09:30 +00:00
Jason Ertel
fd34eb3c26
Merge pull request #9150 from Security-Onion-Solutions/kilo
...
Increase retry count and pause to allow more time for Ubuntu updates
2022-11-16 07:53:04 -05:00
Jason Ertel
02b00d2c87
Increase retry count and pause to allow more time for Ubuntu updates
2022-11-16 07:50:08 -05:00
Mike Reeves
b0e08ed749
Merge pull request #9066 from security-companion/analyzers-patch1
...
fix descriptions in files related to analyzers
2022-11-12 11:32:09 -05:00
Mike Reeves
ec3a688e66
Merge pull request #9128 from Security-Onion-Solutions/dougburks-patch-1
...
Add trailing backslash to bacnet_property in so-functions
2022-11-12 10:33:00 -05:00
Doug Burks
4400c77f7e
Add trailing backslash to bacnet_property in so-functions
2022-11-12 09:13:20 -05:00
Peter Di Giorgio
d890f75cca
Correct typo
2022-11-11 13:59:20 -08:00
Doug Burks
91b6087350
Merge pull request #9126 from Security-Onion-Solutions/dougburks-patch-1
...
fix typo in zeek init.sls icsnpp-opcua-binary
2022-11-11 21:50:36 +00:00
Doug Burks
edcbcec10a
fix typo in zeek init.sls icsnpp-opcua-binary
2022-11-11 16:49:12 -05:00
Doug Burks
18ab90288a
Merge pull request #9124 from Security-Onion-Solutions/dougburks-patch-1
...
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 21:33:52 +00:00
Doug Burks
9bf1c1e869
FIX: Avoid deprecation warning in Zeek file extraction script #9123
2022-11-11 16:27:11 -05:00
Peter Di Giorgio
1e96a0b6a6
Merge pull request #9122 from Security-Onion-Solutions/foxtrot
...
Merge new protocol analyzers into dev
2022-11-11 12:53:57 -08:00
lock-wire
8dc08f66fd
Merge branch 'foxtrot' of https://github.com/Security-Onion-Solutions/securityonion into foxtrot
...
merge remote
2022-11-11 12:18:02 -08:00
lock-wire
73b1e5949b
Add ecat, enip, cip, and opcua
2022-11-11 12:15:54 -08:00
Doug Burks
2d6a4d7c28
Merge pull request #9098 from Security-Onion-Solutions/feature/local-docs
...
FEATURE: Improve local copy of docs in SOC #9097
2022-11-11 16:21:54 +00:00
Peter Di Giorgio
ae389ee487
Merge pull request #9121 from Security-Onion-Solutions/dev
...
Update foxtrot from dev
2022-11-11 07:25:26 -08:00
lock-wire
85d30520ce
Add BSAP protocol
2022-11-11 07:22:55 -08:00
Jason Ertel
934ce9ba64
Merge pull request #9114 from Security-Onion-Solutions/kilo
...
merge master to dev
2022-11-10 16:50:33 -05:00
Jason Ertel
595a95fdf5
merge conflicts
2022-11-10 16:47:52 -05:00
Mike Reeves
fc649a565c
Merge pull request #9107 from Security-Onion-Solutions/patch/2.3.182
...
Patch/2.3.182
2022-11-10 16:30:17 -05:00
Mike Reeves
113b38056b
2.3.182
2022-11-10 15:12:47 -05:00
Mike Reeves
559276534d
2.3.182
2022-11-10 15:06:00 -05:00
Mike Reeves
4acd9f8816
Update soup
2022-11-09 10:10:52 -05:00
security-companion
7ee4eb6101
fix descriptions in files related to analyzers
2022-11-08 22:32:28 +01:00
doug
84b2fc9c17
FEATURE: Improve local copy of docs in SOC #9097
2022-11-08 16:26:09 -05:00
Mike Reeves
a7417a7242
Update soup
2022-11-08 14:48:48 -05:00
Mike Reeves
d18ff69ec9
Update VERSION
2022-11-08 14:45:53 -05:00
Peter Di Giorgio
5532577fdd
Merge pull request #9071 from Security-Onion-Solutions/dev
...
Merge Dev into Foxtrot
2022-11-04 08:01:29 -07:00
Peter Di Giorgio
5ebf470a86
Update zeek.bacnet_discovery
2022-11-03 22:27:04 -07:00
Peter Di Giorgio
4b39ccec6d
Update zeek.bacnet_property
2022-11-03 15:30:20 -07:00
Mike Reeves
18cd7a83c6
Merge pull request #9059 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update init.sls
2022-11-02 13:01:38 -04:00
Mike Reeves
c5bfe6ffdb
Update init.sls
2022-11-02 12:59:46 -04:00
Mike Reeves
4ac365e670
Update init.sls
2022-11-02 12:59:17 -04:00
Mike Reeves
ff1a903895
Update init.sls
2022-11-02 12:58:31 -04:00
Doug Burks
65f8b1ebe3
Merge pull request #9057 from Security-Onion-Solutions/dougburks-patch-1
...
Create README.txt in setup/automation/
2022-11-02 14:24:29 +00:00
Jason Ertel
c23e8e5a7b
Update README.txt
2022-11-02 10:23:19 -04:00
Doug Burks
aa4a9a093f
Create README.txt
2022-11-02 10:20:57 -04:00
Mike Reeves
0af813d7fe
Merge pull request #9056 from Security-Onion-Solutions/TOoSmOotH-patch-4
...
Update init.sls
2022-11-02 10:17:43 -04:00
Mike Reeves
388486ec08
Update init.sls
2022-11-02 10:06:13 -04:00
Mike Reeves
b1b0a7df30
Merge pull request #9044 from Security-Onion-Solutions/watchdogfix
...
watchdog fix
2022-11-01 13:24:05 -04:00
Mike Reeves
f74aee6a03
Update init.sls
2022-11-01 13:21:12 -04:00
Mike Reeves
4c6e66428c
Merge pull request #9037 from Security-Onion-Solutions/soup190
...
Add soup and perms updates
2022-11-01 09:13:26 -04:00
Mike Reeves
16d8e9e5a0
Fix soup and perms updates
2022-11-01 09:05:26 -04:00
Mike Reeves
ee1f55361e
Add soup and perms updates
2022-10-31 16:33:38 -04:00
Mike Reeves
cb33464668
Merge pull request #9033 from Security-Onion-Solutions/strelkafix
...
Add Filechecks
2022-10-31 15:49:40 -04:00
Mike Reeves
06ddae13b5
Update filecheck
2022-10-31 15:41:57 -04:00
Mike Reeves
16d3dead04
Update sensor-rotate.conf
2022-10-31 15:33:10 -04:00
Mike Reeves
f7043f3f62
Update init.sls
2022-10-31 15:25:38 -04:00
Mike Reeves
bf41f2984a
Update init.sls
2022-10-31 14:58:55 -04:00
Mike Reeves
86ca3602f3
Update init.sls
2022-10-31 14:44:01 -04:00
Mike Reeves
416c28fded
Update init.sls
2022-10-31 14:42:23 -04:00
Mike Reeves
297373877a
Update init.sls
2022-10-31 14:36:40 -04:00
Mike Reeves
db9b93a96c
Update init.sls
2022-10-31 14:35:02 -04:00
Mike Reeves
5635375d8d
Update init.sls
2022-10-31 14:30:11 -04:00
Mike Reeves
07e72e4013
Update filecheck
2022-10-31 13:47:49 -04:00
Mike Reeves
518d2aaa9c
Update filecheck.yaml
2022-10-31 13:45:00 -04:00
Mike Reeves
e93e2995b7
Update filecheck
2022-10-31 13:42:18 -04:00
Mike Reeves
d2eb61a830
Update filecheck.yaml
2022-10-31 13:41:45 -04:00
Mike Reeves
4c5a2c0610
Update filecheck
2022-10-31 13:36:42 -04:00
Mike Reeves
e9e7362005
Add Filechecks
2022-10-31 12:57:08 -04:00
Peter Di Giorgio
b97c822800
Add zeek.bacnet_discovery and zeek.bacnet_property
2022-10-27 15:40:52 -07:00
Peter Di Giorgio
71e3b2d1fb
Create zeek.bacnet
2022-10-27 15:40:07 -07:00
Peter Di Giorgio
326ba710ce
Add logs for bacnet
...
bacnet
bacnet_discovery
bacnet_property
2022-10-27 15:38:32 -07:00
Peter Di Giorgio
1ea6feca37
Add icsnpp-bacnet
2022-10-27 15:31:38 -07:00
Peter Di Giorgio
c524442172
Merge pull request #9008 from Security-Onion-Solutions/master
...
Synch Foxtrot with 2.3.181 Release
2022-10-26 13:10:01 -07:00
weslambert
8e4d0db738
Merge pull request #9002 from Security-Onion-Solutions/fix/remove_ja3er_references
...
Remove JA3er references
2022-10-26 10:21:54 -04:00
weslambert
a170c194c8
Remove JA3er references
2022-10-26 10:18:10 -04:00
Peter Di Giorgio
2b51d72585
Rename zeek.read_write_multiple_registers to zeek.modbus_read_write_multiple_registers
2022-10-25 17:20:01 -07:00
weslambert
0d71006f40
Merge pull request #8997 from Security-Onion-Solutions/fix/sensoroni_analyzers_pyyaml_wheel_name
...
Fix PyYAML .whl file name and remove JA3er analyzer
2022-10-25 14:57:35 -04:00
Wes
a91e3b601c
Remove JA3er since it is no longer a valid service
2022-10-25 18:48:37 +00:00
Wes
4940421297
Add PyYAML .whl files back since they were 'deleted' in the previous commit
2022-10-25 18:47:51 +00:00
Wes
58b4a8fbab
Change PyYAML .whl file name to comply with Joliet's 240-character limit
2022-10-25 18:47:02 +00:00
Mike Reeves
bd7e12f682
Merge pull request #8952 from Njinx/dev
...
FEATURE: so-pcap-export can run without needing to be attached to a TTY
2022-10-25 14:38:48 -04:00
Mike Reeves
64e43f07b9
Merge pull request #8993 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update VERSION
2022-10-25 14:36:45 -04:00
Mike Reeves
2d84e2e977
Update VERSION
2022-10-25 14:35:52 -04:00
Mike Reeves
465a1a82d7
Merge pull request #8981 from Security-Onion-Solutions/dev
...
2.3.181
2022-10-25 14:30:50 -04:00
Peter Di Giorgio
61d36d584f
Add Modbus, DNP3, BZAR, and oui-logging
2022-10-25 07:10:52 -07:00
Peter Di Giorgio
2d343110cc
Add DNP3 and Modbus extensions to zeeklogs.sls
2022-10-25 07:09:11 -07:00
Peter Di Giorgio
4502e2c260
Remove logs for OT parsers
2022-10-24 23:16:18 -07:00
Peter Di Giorgio
beb67847f9
Remove modbus,bzar,dnp3,oui-logging
2022-10-24 23:14:32 -07:00
Peter Di Giorgio
9cdc29c482
Fix Syntax for zeeklogs pillar
2022-10-24 14:30:15 -07:00
weslambert
292f66138b
Merge pull request #8983 from Security-Onion-Solutions/revert-8982-fix/sensoroni_analyzers_pyyaml_wheel_name
...
Revert "Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold"
2022-10-24 16:49:19 -04:00
weslambert
0087768946
Revert "Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold"
2022-10-24 16:47:30 -04:00
Peter Di Giorgio
01d177366d
Fix Zeek Pillar
2022-10-24 12:00:43 -07:00
weslambert
712340a027
Merge pull request #8982 from Security-Onion-Solutions/fix/sensoroni_analyzers_pyyaml_wheel_name
...
Change PyYAML .whl file name to comply with Joliet's 240-character limit/threshold
2022-10-24 14:14:45 -04:00
Wes
1caac3f0b0
Add PyYAML .whl files back since they were 'deleted' in the previous commit.
2022-10-24 18:06:19 +00:00
Wes
54a5dd6cbd
Change name of PyYAML .whl file to remain under Joliet's 240-character limit/threshold
2022-10-24 18:05:15 +00:00
Mike Reeves
6570177b0c
Merge pull request #8979 from Security-Onion-Solutions/2.3.181
...
2.3.181
2022-10-24 11:39:08 -04:00
Mike Reeves
f7ed992f24
2.3.181
2022-10-24 11:33:31 -04:00
Mike Reeves
4a18f8d18a
2.3.181
2022-10-24 11:32:19 -04:00
Peter Di Giorgio
24cf481f4a
Merge pull request #8973 from lock-wire/patch-3
...
Add Modbus, DNP3, BZAR, and oui-logging
2022-10-21 18:06:13 -07:00
Peter Di Giorgio
cd4e0c1f8e
Add DNP3 and Modbus extensions to zeeklogs.sls
...
Add DNP3 and Modbus extenstions to zeeklogs to ensure filebeat.yml is configured properly to ship lots. Need to move these behind the OT flag.
2022-10-21 14:19:21 -07:00
Peter Di Giorgio
4a60310dc8
Add Modbus, DNP3, BZAR, and oui-logging
...
This is an initial proof of concept. Need to migrate these entries behind a flag.
2022-10-21 14:04:40 -07:00
weslambert
930620fce6
Merge pull request #8971 from lock-wire/patch-2
...
Add Ingest pipeline for Modbus and DNP3 extensions
2022-10-21 16:28:52 -04:00
Peter Di Giorgio
7a60d0987c
Update zeek.conn to include client.oui
2022-10-21 13:02:01 -07:00
Peter Di Giorgio
9ac06057c1
Create zeek.read_write_multiple_registers
2022-10-21 13:00:12 -07:00
Peter Di Giorgio
e5c69c3236
Create zeek.modbus_mask_write_register
2022-10-21 12:58:36 -07:00
Peter Di Giorgio
39f050c6e4
Rename modbus_detailed to zeek.modbus_detailed
2022-10-21 12:56:59 -07:00
Peter Di Giorgio
4ee083759c
Rename dnp3_objects to zeek.dnp3_objects
2022-10-21 12:56:35 -07:00
Peter Di Giorgio
072bfd87b7
Create Ingest for Modbus Detailed
2022-10-21 12:53:30 -07:00
Peter Di Giorgio
b7aaaa80bb
Create Ingest for DNP3 Objects extension
2022-10-21 12:51:13 -07:00
Jason Ertel
b8884b6ac9
Merge pull request #8968 from Security-Onion-Solutions/181soup
...
update soup for 2.3.181
2022-10-21 12:00:58 -04:00
Jason Ertel
05e271af47
update soup for 2.3.181
2022-10-21 11:52:54 -04:00
Mike Reeves
58e80a9db8
Merge pull request #8964 from Security-Onion-Solutions/TOoSmOotH-patch-2
...
Update VERSION
2022-10-21 10:45:44 -04:00
Mike Reeves
e16fc3605e
Update VERSION
2022-10-21 10:43:34 -04:00
Ben Allen
f13f05eb94
Run without needing to be attached to a TTY
2022-10-19 14:11:11 -04:00
weslambert
a54fc4cead
Merge pull request #8942 from Security-Onion-Solutions/master
...
Update Foxtrot to .180
2022-10-18 16:39:21 -04:00
Mike Reeves
2127ba90ee
Merge pull request #8925 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update VERSION
2022-10-17 10:51:02 -04:00
Mike Reeves
3373aef87d
Update VERSION
2022-10-17 10:50:14 -04:00
Mike Reeves
fa45e8ded7
Merge pull request #8924 from Security-Onion-Solutions/dev
...
2.3.180
2022-10-17 10:41:06 -04:00
Mike Reeves
6d0ead7b5b
Merge pull request #8923 from Security-Onion-Solutions/2.3.180
...
2.3.180
2022-10-17 09:47:06 -04:00
Mike Reeves
a2a6625f3b
2.3.180
2022-10-17 09:39:07 -04:00
Mike Reeves
3c2510acd7
Merge pull request #8920 from Security-Onion-Solutions/dev
...
Merge Dev into Foxtrot
2022-10-17 09:34:57 -04:00
Doug Burks
0d807d20f4
Merge pull request #8914 from Security-Onion-Solutions/dougburks-patch-1
...
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 13:03:51 +00:00
Doug Burks
f4042263a3
Remove destination_geo.organization_name from Sysmon Network sankey diagram
2022-10-13 08:59:10 -04:00
Doug Burks
a930f8233d
Merge pull request #8899 from Security-Onion-Solutions/dougburks-patch-2
...
Update soup for 2.3.180
2022-10-11 17:14:55 +00:00
Doug Burks
7401008523
Update soup for 2.3.180
2022-10-11 12:58:37 -04:00
Doug Burks
5199ea483e
Merge pull request #8878 from Security-Onion-Solutions/feature/improve-sysmon-dashboards
...
FEATURE: Add new Sysmon dashboards #8870
2022-10-07 16:47:02 +00:00
doug
454a7a4799
FEATURE: Add new Sysmon dashboards #8870
2022-10-07 11:52:49 -04:00
Doug Burks
6fb7733d8c
Merge pull request #8875 from Security-Onion-Solutions/dougburks-patch-1
...
Increment SO to 2.3.180 and Elastic to 8.4.3
2022-10-07 11:13:13 +00:00
Doug Burks
ab17cbee31
Update Elastic to 8.4.3
2022-10-07 07:03:10 -04:00
Doug Burks
9991f0cf95
update Elastic to 8.4.3
2022-10-07 07:02:24 -04:00
Doug Burks
44d46b06a2
increment version to 2.3.180
2022-10-07 06:58:07 -04:00
Mike Reeves
ba7231f07d
Merge pull request #8841 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update VERSION
2022-10-03 08:46:19 -04:00
Mike Reeves
8dc11ea23a
Update VERSION
2022-10-03 08:43:39 -04:00
Mike Reeves
116a6a0acd
Merge pull request #8806 from Security-Onion-Solutions/dev
...
2.3.170
2022-10-01 08:13:09 -04:00
Mike Reeves
311b69dc4a
Merge pull request #8805 from Security-Onion-Solutions/2.3.170
...
2.3.170
2022-09-23 15:34:49 -04:00
Mike Reeves
fd59acce5d
2.3.170
2022-09-23 15:26:14 -04:00
Mike Reeves
956d3e4345
Merge pull request #8793 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update soup
2022-09-22 09:22:20 -04:00
Mike Reeves
b8355b3a03
Update soup
2022-09-22 09:10:12 -04:00
bryant-treacle
535b9f86db
Merge pull request #8633 from Security-Onion-Solutions/bryant-sysmon
...
Fix issues: 8591-8953
2022-09-19 11:53:34 -04:00
Mike Reeves
97c66a5404
Merge pull request #8639 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
dev to 170
2022-08-31 08:23:48 -04:00
Josh Brower
6553beec99
Merge pull request #8644 from Security-Onion-Solutions/upgrade/elastic-8.4.1
...
Upgrade/elastic 8.4.1
2022-08-30 16:37:56 -04:00
Josh Brower
e171dd52b8
Upgrade Elastic to 8.4.1
2022-08-30 16:11:40 -04:00
Josh Brower
27a837369d
Upgrade Elastic to 8.4.1
2022-08-30 16:09:57 -04:00
Mike Reeves
043b9f78e2
Merge pull request #8638 from Security-Onion-Solutions/master
...
Merge pull request #8627 from Security-Onion-Solutions/dev
2022-08-30 14:42:18 -04:00
Mike Reeves
2f260a785f
Update README.md
2022-08-30 14:41:41 -04:00
Mike Reeves
001b2dc6cc
Update VERSION
2022-08-30 14:39:41 -04:00
Mike Reeves
b13eedfbc2
Merge pull request #8627 from Security-Onion-Solutions/dev
...
2.3.160
2022-08-30 14:33:36 -04:00
Mike Reeves
dd70ef17b9
Merge pull request #8636 from Security-Onion-Solutions/fixitup
...
Merge pull request #8571 from Security-Onion-Solutions/dev
2022-08-30 14:31:35 -04:00
bryant-treacle
82dff3e9da
Fix issues: 8591-8953
2022-08-30 13:48:53 +00:00
Mike Reeves
d9cfd92b8f
Merge pull request #8626 from Security-Onion-Solutions/2.3.160
...
2.3.160
2022-08-29 15:00:08 -04:00
Mike Reeves
33cb771780
2.3.160
2022-08-29 14:56:43 -04:00
Mike Reeves
76cca8594d
Merge pull request #8623 from Security-Onion-Solutions/TOoSmOotH-patch-6
...
Update soup
2022-08-29 09:50:06 -04:00
weslambert
5c9c95ba1f
Merge pull request #8622 from Security-Onion-Solutions/fix/strelka_yara_gen_webshells_ignore
...
Ignore gen_webshells.yar
2022-08-29 09:40:51 -04:00
Mike Reeves
e62bebeafe
Update soup
2022-08-29 09:39:41 -04:00
weslambert
8a0e92cc6f
Add 'gen_webshells.yar' and re-arrange to put ignored rules in alphabetical order
2022-08-29 09:37:29 -04:00
Mike Reeves
3f9259dd0a
Merge pull request #8621 from Security-Onion-Solutions/TOoSmOotH-patch-5
...
Update soup
2022-08-29 09:34:29 -04:00
Mike Reeves
30b9868de1
Update soup
2022-08-29 09:32:46 -04:00
Doug Burks
e88243c306
Merge pull request #8602 from Security-Onion-Solutions/dougburks-patch-1
...
increment to 2.3.160
2022-08-26 08:06:22 -04:00
Doug Burks
2128550df2
increment to 2.3.160
2022-08-26 07:50:08 -04:00
Jason Ertel
db67c0ed94
Merge pull request #8577 from Security-Onion-Solutions/kilo
...
Increment version to 2.3.160
2022-08-23 07:14:05 -04:00
Jason Ertel
2e32c0d236
Increment version to 2.3.160
2022-08-23 07:00:14 -04:00
Mike Reeves
4b1ad1910d
Merge pull request #8571 from Security-Onion-Solutions/dev
...
2.3.150
2022-08-22 15:22:43 -04:00
Mike Reeves
c337145b2c
Merge pull request #8570 from Security-Onion-Solutions/2.3.150
...
2.3.150
2022-08-22 14:35:29 -04:00
Mike Reeves
bd7b4c92bc
2.3.150
2022-08-22 14:31:36 -04:00
Mike Reeves
33ebed3468
2.3.150
2022-08-22 14:31:04 -04:00
weslambert
616bc40412
Merge pull request #8558 from Security-Onion-Solutions/fix/soup_local_mods_check_skip_prompt
...
Allow local modification acceptance prompt to be skipped when passing 'skip-prompt' as a parameter value to check_local_mods() function
2022-08-19 16:11:23 -04:00
weslambert
f00d9074ff
Allow local modification acceptance prompt to be skipped when passing 'skip-prompt' as a parameter value to check_local_mods() function
2022-08-19 16:07:14 -04:00
Mike Reeves
9a692288e2
Merge pull request #8557 from Security-Onion-Solutions/TOoSmOotH-patch-3
...
Update rulecat.conf
2022-08-19 13:14:32 -04:00
Mike Reeves
fea2b481e3
Update rulecat.conf
2022-08-19 13:12:49 -04:00
weslambert
c17f0081ef
Merge pull request #8550 from Security-Onion-Solutions/fix/soup_elastalert_indices_check_delete_if_less_than_es_8
...
SOUP: Ensure Elastalert indices are not deleted for major Elasticsearch version 8 or greater
2022-08-18 09:45:00 -04:00
weslambert
fbf0803906
Update verbiage around major Elasticsearch version and not requiring Elastalert index maintenance
2022-08-18 09:16:22 -04:00
weslambert
5deda45b66
Update elastalert_indices_check() function to only delete Elastalert indices if major Elasticsearch version is less than 8
...
Update elastalert_indices_check() function to only delete Elastalert indices if major Elasticsearch version is less than 8. Also clean up the output to only emit one notification regarding index deletion, and additional verbiage around function operation.
2022-08-18 09:11:38 -04:00
Josh Patterson
3b8d8163b3
Merge pull request #8544 from Security-Onion-Solutions/issue/8369
...
remove pipeline time panel
2022-08-17 09:56:01 -04:00
m0duspwnens
2dfd41bd3c
remove pipeline time panel - https://github.com/Security-Onion-Solutions/securityonion/issues/8369
2022-08-17 09:17:27 -04:00
Mike Reeves
49eead1d55
Merge pull request #8543 from Security-Onion-Solutions/kilo
...
Merge master into dev
2022-08-17 09:03:49 -04:00
Jason Ertel
54cb3c3a5a
Merge branch 'master' into kilo
2022-08-17 08:58:32 -04:00
Mike Reeves
9f2b920454
Merge pull request #8535 from Security-Onion-Solutions/hotfix/2.3.140
...
Hotfix/2.3.140
2022-08-15 15:06:37 -04:00
Mike Reeves
604af45661
Merge pull request #8534 from Security-Onion-Solutions/2.3.140hotfix3
...
2.3.140 Hotfix
2022-08-15 13:09:14 -04:00
Mike Reeves
3f435c5c1a
2.3.140 Hotfix
2022-08-15 13:03:25 -04:00
Mike Reeves
7769af4541
Merge pull request #8531 from Security-Onion-Solutions/dougburks-patch-1
2022-08-12 15:05:04 -04:00
Mike Reeves
9903be8120
Merge pull request #8532 from Security-Onion-Solutions/2.3.140-20220815
2022-08-12 15:04:00 -04:00
Doug Burks
991a601a3d
FIX: so-curator-closed-delete-delete needs to reference new Elasticsearch directory #8529
2022-08-12 13:21:06 -04:00
Doug Burks
86519d43dc
Update HOTFIX
2022-08-12 13:20:15 -04:00
Doug Burks
179f669acf
FIX: so-curator-closed-delete-delete needs to reference new Elasticsearch directory #8529
2022-08-12 13:10:47 -04:00
Doug Burks
a02f878dcc
Merge pull request #8517 from Security-Onion-Solutions/fix/cases-tlp-2.0
...
Fix/cases tlp 2.0
2022-08-11 15:55:21 -04:00
Doug Burks
32c29b28eb
revert to lower case #8469
2022-08-11 15:33:30 -04:00
Doug Burks
7bf2603414
revert to lower case #8469
2022-08-11 15:32:49 -04:00
Doug Burks
4003876465
FIX: Fix TLP options in Cases to align with TLP 2.0 #8469
2022-08-11 08:49:54 -04:00
Doug Burks
4c677961c4
FIX: Fix TLP options in Cases to align with TLP 2.0 #8469
2022-08-11 08:49:25 -04:00
weslambert
e950d865d8
Merge pull request #8485 from Security-Onion-Solutions/foxtrot
...
Improve local file modification check in SOUP
2022-08-08 10:06:13 -04:00
weslambert
fd7a118664
Invoke check_local_mods() function earlier so we don't have to wait for Docker image downloads or OS updates before checking and potentially exiting SOUP
2022-08-08 08:58:19 -04:00
weslambert
d7906945df
Add extra set of brackets for comparison of integers
2022-08-08 08:24:38 -04:00
weslambert
cb384ae024
Ensure check_local_mods() runs at the beginning of SOUP, in addition to the end, and also that it prompts (forces) the user to accept/review local modifications.
2022-08-05 11:25:33 -04:00
weslambert
7caead2387
Merge pull request #8476 from Security-Onion-Solutions/dev
...
Merge dev into foxtrot
2022-08-05 11:11:51 -04:00
Josh Patterson
4827c9e0d4
Merge pull request #8475 from Security-Onion-Solutions/issue/8441
...
add SYSTEMD_UNIT_FILE back to map file
2022-08-05 10:55:44 -04:00
m0duspwnens
3b62fc63c9
add SYSTEMD_UNIT_FILE back to map file
2022-08-05 10:53:07 -04:00
Josh Patterson
ad32c2b1a5
Merge pull request #8472 from Security-Onion-Solutions/issue/8441
...
ensure ExecStartPre is removed from default salt-minion service file
2022-08-04 16:36:16 -04:00
m0duspwnens
f02f431dab
ensure ExecStartPre is removed from default salt-minion service file
2022-08-04 16:34:06 -04:00
Josh Patterson
812964e4d8
Merge pull request #8460 from Security-Onion-Solutions/issue/8441
...
ensure parent dirs are created
2022-08-03 17:01:50 -04:00
m0duspwnens
99805cc326
ensure parent dirs are created
2022-08-03 16:54:22 -04:00
Josh Patterson
8d2b3f3dfe
Merge pull request #8457 from Security-Onion-Solutions/issue/8441
...
fix the requisite
2022-08-03 15:17:44 -04:00
m0duspwnens
15f7fd8920
fix the requisite
2022-08-03 15:16:12 -04:00
Josh Patterson
50460bf91e
Merge pull request #8456 from Security-Onion-Solutions/issue/8441
...
manage salt-minion start delay with systemd drop-in file
2022-08-03 13:44:09 -04:00
weslambert
ee654f767a
Merge pull request #8453 from Security-Onion-Solutions/fix/elasticsearch_geoip_local
...
Configure Elasticsearch to use local GeoLite2 databases by default
2022-08-03 09:40:23 -04:00
weslambert
8c694a7ca3
Disable ingest.geoip.downloader by default
2022-08-03 09:21:40 -04:00
weslambert
9ac640fa67
Remove airgap-specific logic for ingest.geoip.downloader
2022-08-03 09:21:03 -04:00
m0duspwnens
db8d9fff2c
manage salt-minion start delay with systemd drop-in file - https://github.com/Security-Onion-Solutions/securityonion/issues/8441
2022-08-02 16:22:26 -04:00
weslambert
811063268f
Merge pull request #8447 from Security-Onion-Solutions/feature/kibana_version_8_3_3
...
Update Kibana version to 8.3.3
2022-08-02 15:27:22 -04:00
weslambert
f2b10a5a86
Update Kibana version to 8.3.3
2022-08-02 11:32:01 -04:00
weslambert
c69cac0e5f
Update Kibana version to 8.3.3
2022-08-02 11:31:35 -04:00
weslambert
fed4433088
Merge pull request #8446 from Security-Onion-Solutions/fix/airgap_elasticsearch_geoip
...
Update Elasticsearch defaults file and config.map.jinja to allow for local GeoIP database use when airgap is enabled
2022-08-02 11:20:35 -04:00
Wes Lambert
839cfcaefa
Update Elasticsearch defaults file and config.map.jinja to allow for local GeoIP database use when airgap is enabled
2022-08-02 14:32:17 +00:00
weslambert
3123407ef0
Update Elastic version to 8.3.3
2022-08-01 10:41:39 -04:00
weslambert
d24125c9e6
Update Elastic version to 8.3.3
2022-08-01 10:40:57 -04:00
weslambert
64dc278c95
Merge pull request #8432 from Security-Onion-Solutions/dev
...
Merge dev into foxtrot
2022-08-01 10:12:35 -04:00
Doug Burks
626a824cd6
Merge pull request #8409 from Security-Onion-Solutions/dougburks-patch-1
...
increment version
2022-07-29 16:31:32 -04:00
Doug Burks
10ba3b4b5a
increment version
2022-07-29 16:30:12 -04:00
Doug Burks
1d059fc96e
Merge pull request #8408 from Security-Onion-Solutions/fix/dashboards-pivot-pcap
...
FIX: Display PCAP menu action on Dashboards page #8343
2022-07-29 16:29:32 -04:00
Doug Burks
4c1585f8d8
FIX: Display PCAP menu action on Dashboards page #8343
2022-07-29 14:50:10 -04:00
Josh Patterson
e235957c00
Merge pull request #8405 from Security-Onion-Solutions/issue/8404
...
https://github.com/Security-Onion-Solutions/securityonion/issues/8404
2022-07-29 10:07:52 -04:00
m0duspwnens
2cc665bac6
https://github.com/Security-Onion-Solutions/securityonion/issues/8404
2022-07-29 09:55:20 -04:00
Jason Ertel
d6e118dcd3
Merge pull request #8403 from Security-Onion-Solutions/kilo
...
Increment version
2022-07-29 08:28:14 -04:00
Jason Ertel
1d2534b2a1
Increment version
2022-07-29 08:24:57 -04:00
Doug Burks
484aa7b207
Merge pull request #8336 from Security-Onion-Solutions/hotfix/2.3.140
...
Hotfix/2.3.140
2022-07-19 16:13:47 -04:00
Mike Reeves
6986448239
Merge pull request #8333 from Security-Onion-Solutions/2.3.140hotfix
...
2.3.140 Hotfix
2022-07-19 14:47:50 -04:00
Mike Reeves
f1d74dcd67
Merge pull request #8334 from Security-Onion-Solutions/2.3.140hotfix
...
2.3.140 Hotfix
2022-07-19 14:47:29 -04:00
Mike Reeves
dd48d66c1c
2.3.140 Hotfix
2022-07-19 14:39:44 -04:00
Mike Reeves
440f4e75c1
Merge pull request #8332 from Security-Onion-Solutions/dev
...
Merge Hotfix
2022-07-19 13:30:20 -04:00
weslambert
c795a70e9c
Merge pull request #8329 from Security-Onion-Solutions/fix/elastalert_stop_check_enabled
...
Check to ensure Elastalert is enabled and suppress missing container error output
2022-07-19 13:27:35 -04:00
weslambert
340dbe8547
Check to see if Elastalert is enabled before trying to run 'so-elastalert-stop'. Also suppress error output for when so-elastalert container is not present.
2022-07-19 13:25:09 -04:00
Mike Reeves
52a5e743e9
Merge pull request #8327 from Security-Onion-Solutions/TOoSmOotH-patch-1
...
Update HOTFIX
2022-07-19 11:17:13 -04:00
Wes Lambert
5ceff52796
Move Elastalert indices check to function and call from beginning of soup and during pre-upgrade to 2.3.140
2022-07-19 14:54:39 +00:00
Wes Lambert
f3a0ab0b2d
Perform Elastalert index check twice
2022-07-19 14:48:19 +00:00
Wes Lambert
4a7c994b66
Revise Elastalert index check deletion logic
2022-07-19 14:31:45 +00:00
Mike Reeves
07b8785f3d
Update soup
2022-07-19 10:23:10 -04:00
Mike Reeves
9a1092ab01
Update HOTFIX
2022-07-19 10:21:36 -04:00