Commit Graph

  • b99b19ce58 Merge pull request #898 from Security-Onion-Solutions/feature/strelka_scripts weslambert 2020-06-29 09:11:16 -04:00
  • 9ac85cf674 Add Stelka mgmt scripts #898 Wes Lambert 2020-06-29 13:09:14 +00:00
  • 6f6e8a8853 Merge pull request #897 from Security-Onion-Solutions/fix/strelka_rules weslambert 2020-06-26 16:43:21 -04:00
  • c421bd464a Remove Strelka function (in favor of direct script execution in so-setup) #897 weslambert 2020-06-26 16:42:44 -04:00
  • 22eb81128a Merge pull request #891 from Security-Onion-Solutions/feature/navigator-to-nginx William Wernert 2020-06-26 15:48:46 -04:00
  • 8c47723bc9 Run YARA update script after applying state weslambert 2020-06-26 15:45:52 -04:00
  • 9c388cd6aa Merge pull request #896 from Security-Onion-Solutions/feature/suripillar Josh Patterson 2020-06-26 14:44:36 -04:00
  • 0b1a258a4b change sensor homenet map #896 m0duspwnens 2020-06-26 14:43:27 -04:00
  • 813c243d3d Update so-yara-update weslambert 2020-06-26 13:26:08 -04:00
  • 2079eba0ad Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar m0duspwnens 2020-06-26 13:09:15 -04:00
  • 052c65c05e add the things to pillarize suricata - https://github.com/Security-Onion-Solutions/securityonion/issues/584 m0duspwnens 2020-06-26 13:07:41 -04:00
  • cf7e5f1b6f [fix] Change permissions on so-yara-update + fix indents William Wernert 2020-06-26 09:59:44 -04:00
  • b895d6fa4f Merge pull request #894 from Security-Onion-Solutions/feature/playbook-unit-testing Josh Brower 2020-06-26 06:33:05 -04:00
  • 7f0eacd342 Playbook - Initial Support for Unit Testing #894 Josh Brower 2020-06-26 06:24:09 -04:00
  • 1e4c967afc Fix math for suri loss calulcations Mike Reeves 2020-06-25 14:02:02 -04:00
  • 1e6fab4e6e Fix math for suri loss calulcations Mike Reeves 2020-06-25 13:54:01 -04:00
  • 65687fd28e Update saltstack update to point to correct github Mike Reeves 2020-06-25 13:02:17 -04:00
  • 57d0603e4c Merge branch 'dev' of https://github.com/Security-Onion-Solutions/securityonion-saltstack into dev Mike Reeves 2020-06-25 12:56:38 -04:00
  • 30ac5f9764 ADding Suricata log compression Mike Reeves 2020-06-25 12:56:26 -04:00
  • 5e41bba6db Merge pull request #892 from Security-Onion-Solutions/feature/more_strelka_rules weslambert 2020-06-25 12:33:36 -04:00
  • a24402de99 More Strelka rule config #892 Wes Lambert 2020-06-25 16:31:04 +00:00
  • 63c45be388 Update Strelka init for rules Wes Lambert 2020-06-25 15:49:58 +00:00
  • 6487fdf5e6 Add Strelka YARA function Wes Lambert 2020-06-25 15:46:37 +00:00
  • a45fbb6f5c Revert "[fix] discovery.zen.minimum_master_nodes is deprecated, update the key" William Wernert 2020-06-25 10:53:26 -04:00
  • 00713312c6 Merge pull request #890 from Security-Onion-Solutions/fix/so-elastic-clear bryant-treacle 2020-06-24 15:09:37 -04:00
  • 443332d584 Update so-elastic-clear #890 bryant-treacle 2020-06-24 15:03:25 -04:00
  • ffc9567278 Delete test.test bryant-treacle 2020-06-24 15:01:30 -04:00
  • 08220e3330 Issue #885: so-elastic-clear not removing so-* indices #889 bryant-treacle 2020-06-24 18:40:11 +00:00
  • 83ed21314a Merge pull request #888 from Security-Onion-Solutions/feature/strelka_rules weslambert 2020-06-24 13:28:52 -04:00
  • f5bb831edf Fix comment #888 Wes Lambert 2020-06-24 17:27:59 +00:00
  • a01339039a Update Setup for Strelka rules Wes Lambert 2020-06-24 17:22:55 +00:00
  • 0849014b24 Issue #885: so-elastic-clear not removing so-* indices bryant-treacle 2020-06-24 17:21:58 +00:00
  • 8bfbd77367 Update whiptail for Strelka Wes Lambert 2020-06-24 17:18:05 +00:00
  • 8bd6c067aa [fix] discovery.zen.minimum_master_nodes is deprecated, update the key William Wernert 2020-06-24 13:10:18 -04:00
  • 52a0ace1b8 Use Strelka rules if enabled Wes Lambert 2020-06-24 17:08:58 +00:00
  • bd36749959 [feat] Remove navigator container references #891 William Wernert 2020-06-24 12:38:32 -04:00
  • 4404a4f312 Merge branch 'dev' of github.com:Security-Onion-Solutions/securityonion-saltstack into dev William Wernert 2020-06-23 17:57:19 -04:00
  • 0a0fe5914a [fix][feat] Move navigator entries to static files + fix indent William Wernert 2020-06-23 17:57:14 -04:00
  • c3651f1b45 Merge pull request #884 from Security-Onion-Solutions/feature/strelka_client weslambert 2020-06-23 14:57:06 -04:00
  • f7eacc2b05 Add FW config for Strelka frontend #884 Wes Lambert 2020-06-23 18:47:23 +00:00
  • 685e3048ac Merge pull request #883 from Security-Onion-Solutions/fix/hunt_files_rename weslambert 2020-06-23 13:49:52 -04:00
  • c0428ce79d Update file dataset name for hunt queries #883 Wes Lambert 2020-06-23 17:48:12 +00:00
  • 13df2e6312 Merge pull request #882 from Security-Onion-Solutions/fix/files_rename weslambert 2020-06-23 13:44:26 -04:00
  • af451573eb Move dataset from files to file #882 Wes Lambert 2020-06-23 17:43:28 +00:00
  • 36a329214a merge eve-log in outputs for suricata meta data generation or zeek/default - https://github.com/Security-Onion-Solutions/securityonion/issues/584 m0duspwnens 2020-06-22 16:56:03 -04:00
  • f1bcd35734 Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar m0duspwnens 2020-06-22 09:13:29 -04:00
  • d7693f9b55 Expose pcap dir to sensoroni for epoch discovery Jason Ertel 2020-06-22 08:27:43 -04:00
  • 1ee3625f61 Ensure certs dir is group readable by socore since Sensoroni process will need to read the client key Jason Ertel 2020-06-21 15:46:36 -04:00
  • 81ed656ba0 Bind both steno and sensoroni processes to host network Jason Ertel 2020-06-21 10:50:10 -04:00
  • 76e3118bd3 Split Sensoroni and Stenographer executables into separate images Jason Ertel 2020-06-21 08:33:09 -04:00
  • 57fa2c5abe Merge remote-tracking branch 'remotes/origin/dev' into feature/suripillar m0duspwnens 2020-06-18 13:49:07 -04:00
  • 6dbe83a77f Update so-docker-refresh Mike Reeves 2020-06-18 12:38:07 -04:00
  • 2f3a99cfb0 fix: indentation is incorrect Jason Ertel 2020-06-17 17:42:35 -04:00
  • fb9ac58ed6 Merge pull request #869 from Security-Onion-Solutions/feature/elastic_indices_rw weslambert 2020-06-17 15:00:23 -04:00
  • 6d25151ab8 Basic index read-only attr removal script #869 Wes Lambert 2020-06-17 18:59:13 +00:00
  • 6794cabf9c Merge pull request #868 from Security-Onion-Solutions/bugfix/fleet-custom-hostname Josh Brower 2020-06-17 14:46:07 -04:00
  • 569fc4ac4d Merge pull request #867 from Security-Onion-Solutions/feature/zeek_custom_policy weslambert 2020-06-17 13:12:38 -04:00
  • 90c278096c Add custom Zeek script dir #867 Wes Lambert 2020-06-17 17:11:27 +00:00
  • 3418f5748c Fleet custom hostname regex fix #868 Josh Brower 2020-06-17 13:08:47 -04:00
  • 6bf8f0af08 Eliminate multiple version definitions in this repo Jason Ertel 2020-06-17 10:46:07 -04:00
  • 3451f74b63 Update version to 2.0.0-rc.1 Jason Ertel 2020-06-17 10:32:39 -04:00
  • b489420002 Merge pull request #865 from Security-Onion-Solutions/feature/cortex_custom weslambert 2020-06-17 09:22:42 -04:00
  • 1beff65cc9 fix typo #865 Wes Lambert 2020-06-17 13:20:32 +00:00
  • cbfe375407 Custom analyzer and responder dirs Wes Lambert 2020-06-17 13:16:52 +00:00
  • ada0d7b8cd Merge pull request #862 from Security-Onion-Solutions/dev 1.4.0 Mike Reeves 2020-06-16 14:47:08 -04:00
  • 6410087994 1.4.0 #862 Mike Reeves 2020-06-16 13:52:37 -04:00
  • 2986926ce9 Merge pull request #861 from Security-Onion-Solutions/bugfix/fleet-kibana Josh Brower 2020-06-16 10:17:26 -04:00
  • a9df5d75b0 Beta3 Kibana dashboard updates #861 Josh Brower 2020-06-16 10:16:31 -04:00
  • 0c9c7002dc [fix] Simplify if statements and apply mine.update during setup William Wernert 2020-06-16 08:38:50 -04:00
  • 0961fe7091 Merge pull request #857 from Security-Onion-Solutions/feature/metasuri Mike Reeves 2020-06-15 21:52:41 -04:00
  • 4573b346f8 Merge remote-tracking branch 'remotes/origin/dev' into feature/metasuri #857 Mike Reeves 2020-06-15 21:46:07 -04:00
  • 3681f91c37 Suricata Conn Mike Reeves 2020-06-15 21:46:04 -04:00
  • 97d127218a fix: stop updating salt mine - this is an attempt to sort out why the CA intermittently disappears from the mine Jason Ertel 2020-06-15 17:40:53 -04:00
  • 9340b633e2 Merge pull request #855 from Security-Onion-Solutions/quickfix/searchnode2node Josh Patterson 2020-06-15 17:01:50 -04:00
  • fe39179ba1 fix so-status for searchnode #855 m0duspwnens 2020-06-15 17:01:23 -04:00
  • 3b920b2cd8 Merge pull request #854 from Security-Onion-Solutions/quickfix/searchnode2node Josh Patterson 2020-06-15 16:59:55 -04:00
  • 91a50c0915 place searchnode role with node where referenced #854 m0duspwnens 2020-06-15 16:58:30 -04:00
  • 578e2b5d1d Merge pull request #853 from Security-Onion-Solutions/quickfix/playbook Josh Patterson 2020-06-15 15:15:23 -04:00
  • b396c39352 fix for master not having a node:mainip pillar - playbook #853 m0duspwnens 2020-06-15 15:13:29 -04:00
  • a91dbf0d1d Fix wording for Suricata meta data in whiptail Mike Reeves 2020-06-15 15:10:16 -04:00
  • 1a6fc3ef6c Merge pull request #852 from Security-Onion-Solutions/quickfix/fleetfwsetup Josh Patterson 2020-06-15 13:51:39 -04:00
  • 51e500f521 add firewall rules for fleet standalone #852 m0duspwnens 2020-06-15 13:50:37 -04:00
  • 91c32725fb Merge pull request #851 from Security-Onion-Solutions/fix/es_field_fixes weslambert 2020-06-15 12:59:01 -04:00
  • f3c9f2e5ea update templates #851 Wes Lambert 2020-06-15 16:57:46 +00:00
  • 206261fbe6 rename id to log.id.fuid for X509 Wes Lambert 2020-06-15 16:55:14 +00:00
  • 18547e8ea8 enforce field types Wes Lambert 2020-06-15 16:54:33 +00:00
  • 8403d72b8e Merge pull request #849 from Security-Onion-Solutions/quickfix/fleetfwsetup Josh Patterson 2020-06-15 10:40:03 -04:00
  • dc56c449b7 add another pillar default to self hostgroup #849 m0duspwnens 2020-06-15 10:38:58 -04:00
  • 896f081f70 Merge pull request #847 from Security-Onion-Solutions/quickfix/fleetfwsetup Josh Patterson 2020-06-15 09:43:35 -04:00
  • aaa6cf816a set firewall during setup for fleet standalone #847 m0duspwnens 2020-06-15 09:42:06 -04:00
  • 87514e7da3 revert: Use consistent casing for package names Jason Ertel 2020-06-14 09:47:59 -04:00
  • 8b64f5b499 Use consistent casing for package names Jason Ertel 2020-06-13 10:19:24 -04:00
  • ce5d678ed9 change portgroup assignment for dockernet on searchnode m0duspwnens 2020-06-12 17:09:08 -04:00
  • f8b5593bca Merge pull request #845 from Security-Onion-Solutions/bugfix/standalonessl Josh Patterson 2020-06-12 16:25:43 -04:00
  • a125a94808 fix issue with ssl state that prevented other node types being adding to a standalone node #845 m0duspwnens 2020-06-12 16:24:46 -04:00
  • e25560bf6b add missing roles fire firewall m0duspwnens 2020-06-12 15:37:43 -04:00
  • 1f305352a0 Merge pull request #844 from Security-Onion-Solutions/quickfix/addfwrules Josh Patterson 2020-06-12 15:04:04 -04:00
  • befc793a96 Improve files query #804 Doug Burks 2020-06-12 14:25:38 -04:00
  • d157c0da00 Improve DNS queries #804 Doug Burks 2020-06-12 14:21:36 -04:00
  • bfee999688 Merge pull request #843 from Security-Onion-Solutions/quickfix/firewallsetup Josh Patterson 2020-06-12 13:55:28 -04:00