mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-07-29 04:03:26 +02:00
Compare commits
11
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4de8f0208f | ||
|
|
4aabf7d638 | ||
|
|
812310088e | ||
|
|
4e17390cfa | ||
|
|
57d629683d | ||
|
|
3666b5b0de | ||
|
|
7f64f143d7 | ||
|
|
162c66a705 | ||
|
|
14d11cc180 | ||
|
|
112fcf7804 | ||
|
|
120b426a79 |
@@ -231,7 +231,7 @@ if [[ $EXCLUDE_KNOWN_ERRORS == 'Y' ]]; then
|
|||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|from NIC checksum offloading" # zeek reporter.log
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|from NIC checksum offloading" # zeek reporter.log
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|marked for removal" # docker container getting recycled
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|tcp 127.0.0.1:6791: bind: address already in use" # so-elastic-fleet agent restarting. Seen starting w/ 8.18.8 https://github.com/elastic/kibana/issues/201459
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-(tychon|aws_billing|microsoft_defender_endpoint|armis|o365_metrics|microsoft_sentinel|snyk|cyera|island_browser).*user so_kibana lacks the required permissions \[(logs|metrics)-\1" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user. This error should not be seen on fresh ES 9.3.3 installs or after SO 3.1.0 with soups addition of check_transform_health_and_reauthorize()
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|TransformTask\] \[logs-.*user so_kibana lacks the required permissions" # Known issue with integrations starting transform jobs that are explicitly not allowed to start as a system user
|
||||||
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # appears in so-dockerregistry log for so-tcpreplay following docker upgrade to 29.2.1-1
|
EXCLUDED_ERRORS="$EXCLUDED_ERRORS|manifest unknown" # appears in so-dockerregistry log for so-tcpreplay following docker upgrade to 29.2.1-1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -242,7 +242,7 @@ versionlock:
|
|||||||
# grain (compound supports nested grain matching via G@<key>:<subkey>:<value>).
|
# grain (compound supports nested grain matching via G@<key>:<subkey>:<value>).
|
||||||
# pillar/vm/soc_vm.sls write path is referenced at salt/_runners/setup_hypervisor.py:856.
|
# pillar/vm/soc_vm.sls write path is referenced at salt/_runners/setup_hypervisor.py:856.
|
||||||
vm:
|
vm:
|
||||||
- state: vm
|
- state: vm.user
|
||||||
tgt: 'G@salt-cloud:driver:libvirt'
|
tgt: 'G@salt-cloud:driver:libvirt'
|
||||||
|
|
||||||
# zeek: sensor_roles + so-import (5 roles).
|
# zeek: sensor_roles + so-import (5 roles).
|
||||||
|
|||||||
@@ -60,6 +60,9 @@ so_repo:
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
- enabled: 1
|
- enabled: 1
|
||||||
- gpgcheck: 1
|
- gpgcheck: 1
|
||||||
|
{% if not GLOBALS.is_manager %}
|
||||||
|
- sslverify: 0
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
# Only assign the kernel repo once this node's running salt matches the version this
|
# Only assign the kernel repo once this node's running salt matches the version this
|
||||||
# SO release ships. During a soup the grid is mid-salt-upgrade; gating here keeps the
|
# SO release ships. During a soup the grid is mid-salt-upgrade; gating here keeps the
|
||||||
@@ -77,6 +80,9 @@ so_kernel_repo:
|
|||||||
{% endif %}
|
{% endif %}
|
||||||
- enabled: 1
|
- enabled: 1
|
||||||
- gpgcheck: 1
|
- gpgcheck: 1
|
||||||
|
{% if not GLOBALS.is_manager %}
|
||||||
|
- sslverify: 0
|
||||||
|
{% endif %}
|
||||||
# Supplementary kernel repo: tolerate it being empty/unreachable (e.g. before the
|
# Supplementary kernel repo: tolerate it being empty/unreachable (e.g. before the
|
||||||
# manager has populated /nsm/kernelrepo) so a missing repomd.xml can't make every
|
# manager has populated /nsm/kernelrepo) so a missing repomd.xml can't make every
|
||||||
# dnf/pkg operation on the grid fail.
|
# dnf/pkg operation on the grid fail.
|
||||||
|
|||||||
@@ -1512,6 +1512,10 @@ soc:
|
|||||||
rulesetName: sos-resources-ag
|
rulesetName: sos-resources-ag
|
||||||
branch: main
|
branch: main
|
||||||
folder: securityonion-normalized
|
folder: securityonion-normalized
|
||||||
|
- repo: file:///nsm/airgap-resources/playbooks/securityonion-resources-playbooks
|
||||||
|
rulesetName: sos-published-ag
|
||||||
|
branch: published
|
||||||
|
folder: sigma
|
||||||
assistant:
|
assistant:
|
||||||
systemPromptAddendum: ""
|
systemPromptAddendum: ""
|
||||||
systemPromptAddendumMaxLength: 50000
|
systemPromptAddendumMaxLength: 50000
|
||||||
@@ -2714,4 +2718,14 @@ soc:
|
|||||||
enabled: true
|
enabled: true
|
||||||
adapter: SOAI
|
adapter: SOAI
|
||||||
charsPerTokenEstimate: 4
|
charsPerTokenEstimate: 4
|
||||||
|
- id: gemma
|
||||||
|
displayName: Gemma
|
||||||
|
origin: USA
|
||||||
|
contextLimitSmall: 256000
|
||||||
|
contextLimitLarge: 256000
|
||||||
|
lowBalanceColorAlert: 500000
|
||||||
|
enabled: true
|
||||||
|
adapter: SOAI
|
||||||
|
charsPerTokenEstimate: 4
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -12,6 +12,30 @@ transformations:
|
|||||||
process.command_line: process.command_line.caseless
|
process.command_line: process.command_line.caseless
|
||||||
process.parent.command_line: process.parent.command_line.caseless
|
process.parent.command_line: process.parent.command_line.caseless
|
||||||
file.path: file.path.caseless
|
file.path: file.path.caseless
|
||||||
|
# entity_id pivots must also match processes that were already running when the
|
||||||
|
# agent started: Defend emits already_running (event.type:info), not start.
|
||||||
|
# Kept out of Playbook sigma query because Sysmon has no equivalent concept.
|
||||||
|
# contains_field is exact, so child pivots (process.parent.entity_id) stay
|
||||||
|
# start-only. Drop must precede add;
|
||||||
|
- id: playbook_process_lifecycle_drop_start_scope
|
||||||
|
type: drop_detection_item
|
||||||
|
field_name_conditions:
|
||||||
|
- type: include_fields
|
||||||
|
fields: ['event.type']
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: process_creation
|
||||||
|
- type: contains_field
|
||||||
|
field: process.entity_id
|
||||||
|
- id: playbook_process_lifecycle_add-fields
|
||||||
|
type: add_condition
|
||||||
|
conditions:
|
||||||
|
event.type: ['start', 'info']
|
||||||
|
rule_conditions:
|
||||||
|
- type: logsource
|
||||||
|
category: process_creation
|
||||||
|
- type: contains_field
|
||||||
|
field: process.entity_id
|
||||||
# file_activity: playbook-only pseudo-category spanning all file operations.
|
# file_activity: playbook-only pseudo-category spanning all file operations.
|
||||||
- id: playbook_file_activity_add-fields
|
- id: playbook_file_activity_add-fields
|
||||||
type: add_condition
|
type: add_condition
|
||||||
|
|||||||
@@ -68,13 +68,25 @@ transformations:
|
|||||||
- type: logsource
|
- type: logsource
|
||||||
category: antivirus
|
category: antivirus
|
||||||
# OS-agnostic process_creation scoping for product-less (NIDS/host-pivot) rules.
|
# OS-agnostic process_creation scoping for product-less (NIDS/host-pivot) rules.
|
||||||
|
# pySigma: rule_cond_expr requires rule_conditions as a mapping, not a list.
|
||||||
- id: process_creation_os_agnostic
|
- id: process_creation_os_agnostic
|
||||||
type: add_condition
|
type: add_condition
|
||||||
conditions:
|
conditions:
|
||||||
event.category: process
|
event.category: process
|
||||||
rule_conditions:
|
rule_conditions:
|
||||||
- type: logsource
|
pc_cat:
|
||||||
category: process_creation
|
type: logsource
|
||||||
|
category: process_creation
|
||||||
|
pc_win:
|
||||||
|
type: logsource
|
||||||
|
product: windows
|
||||||
|
pc_mac:
|
||||||
|
type: logsource
|
||||||
|
product: macos
|
||||||
|
pc_lin:
|
||||||
|
type: logsource
|
||||||
|
product: linux
|
||||||
|
rule_cond_expr: "pc_cat and not (pc_win or pc_mac or pc_lin)"
|
||||||
# Transforms the `Hashes` field to ECS fields
|
# Transforms the `Hashes` field to ECS fields
|
||||||
# ECS fields are used by the hash fields emitted by Elastic Defend
|
# ECS fields are used by the hash fields emitted by Elastic Defend
|
||||||
# If shipped with Elastic Agent, sysmon logs will also have hashes mapped to ECS fields
|
# If shipped with Elastic Agent, sysmon logs will also have hashes mapped to ECS fields
|
||||||
@@ -630,4 +642,4 @@ transformations:
|
|||||||
tags: '*file'
|
tags: '*file'
|
||||||
rule_conditions:
|
rule_conditions:
|
||||||
- type: logsource
|
- type: logsource
|
||||||
category: file
|
category: file
|
||||||
|
|||||||
Reference in New Issue
Block a user