Commit Graph

  • 9f83853922 Zeek QUIC support reyesj2 2024-12-31 13:44:20 -06:00
  • ecf094f684 WIP: support all es fleet integrations reyesj2 2024-12-26 16:18:04 -06:00
  • 8f5634d958 Merge pull request #14048 from Security-Onion-Solutions/2.4/sigmaHashes Josh Brower 2024-12-23 15:49:35 -05:00
  • 7237b8971e Refactor pipeline for hash changes #14048 defensivedepth 2024-12-23 15:41:13 -05:00
  • 33239219cb Merge pull request #14046 from Security-Onion-Solutions/TOoSmOotH-patch-1 Mike Reeves 2024-12-23 08:34:01 -05:00
  • 09ef096620 Update soup #14046 Mike Reeves 2024-12-23 08:27:45 -05:00
  • 3c59858f70 improvements to createvm m0duspwnens 2024-12-20 11:42:53 -05:00
  • 6f0161e9da script to create base domain m0duspwnens 2024-12-19 17:36:48 -05:00
  • 6c19a4c68a Merge pull request #14043 from Security-Onion-Solutions/jertel/wip Jason Ertel 2024-12-19 15:01:25 -05:00
  • b8afef1ee4 cloud installs should use the local docker registry data #14043 Jason Ertel 2024-12-19 14:56:40 -05:00
  • f2bd735f51 another script to create raid m0duspwnens 2024-12-19 10:13:05 -05:00
  • 7a8fd8c3e5 handle salt-cloud package m0duspwnens 2024-12-19 10:12:29 -05:00
  • b24aa2f797 fix destroying virbr0 m0duspwnens 2024-12-19 10:11:54 -05:00
  • b3436415dc merge 2.4/dev reyesj2 2024-12-18 14:13:25 -06:00
  • 16a819ff4f Merge pull request #14041 from Security-Onion-Solutions/reyesj2/opencti Jorge Reyes 2024-12-18 12:12:03 -06:00
  • 157185c370 add ti_opencti integration support #14041 reyesj2 2024-12-18 11:33:49 -06:00
  • ace6c5c9e4 Merge pull request #14039 from Security-Onion-Solutions/docsfix Mike Reeves 2024-12-18 11:42:42 -05:00
  • 4a4c8eace2 Update 2-4.yml #14039 Mike Reeves 2024-12-18 10:36:15 -05:00
  • 8183dcf363 Merge pull request #14038 from Security-Onion-Solutions/TOoSmOotH-patch-1 Jason Ertel 2024-12-18 10:38:42 -05:00
  • d4f1772d2e Update 2-4.yml #14038 Mike Reeves 2024-12-18 10:36:15 -05:00
  • dc1c7d8bd2 Merge pull request #14036 from Security-Onion-Solutions/merger Jason Ertel 2024-12-18 10:25:42 -05:00
  • 9c10094914 Fix conflict #14036 Mike Reeves 2024-12-18 10:19:40 -05:00
  • 72fed8d6a7 Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev Mike Reeves 2024-12-18 10:17:04 -05:00
  • ec90adc6d9 Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main Mike Reeves 2024-12-18 10:16:50 -05:00
  • 93f3171a63 Merge pull request #14031 from Security-Onion-Solutions/patch/2.4.111 2.4.111-20241217 Mike Reeves 2024-12-18 10:05:48 -05:00
  • 7d4c6b1174 Merge branch 'patch/2.4.111' of https://github.com/Security-Onion-Solutions/securityonion into patch/2.4.111 #14031 Mike Reeves 2024-12-18 09:29:08 -05:00
  • 3e04bfbd21 2.4.111 Mike Reeves 2024-12-18 09:27:55 -05:00
  • c6ebebc4d0 Merge pull request #14033 from Security-Onion-Solutions/patchfix Josh Brower 2024-12-17 16:05:13 -05:00
  • 17405b849a Delete uneeded files #14033 defensivedepth 2024-12-17 16:01:31 -05:00
  • 897e8f6883 2.4.111 Mike Reeves 2024-12-17 13:03:52 -05:00
  • 5e4f1fc279 only run fix ldap when lief installed m0duspwnens 2024-12-16 10:23:14 -05:00
  • e779d180f9 work around libvirt issue. add raid scripts m0duspwnens 2024-12-13 16:03:17 -05:00
  • 7d06dd4b1d Update HOTFIX Mike Reeves 2024-12-13 09:20:49 -05:00
  • 5bc9fb19a8 Update VERSION Mike Reeves 2024-12-13 09:18:58 -05:00
  • 607aa1b992 Merge pull request #14016 from Security-Onion-Solutions/TOoSmOotH-patch-1 Mike Reeves 2024-12-10 17:40:35 -05:00
  • e4db2f4819 Update defaults.yaml #14016 Mike Reeves 2024-12-10 17:19:15 -05:00
  • a84a32c075 increase whiptail by 1 m0duspwnens 2024-12-10 16:24:18 -05:00
  • 9475211417 Refactor Navigator for Detections defensivedepth 2024-12-09 16:31:51 -05:00
  • 5649986834 Merge branch '2.4/dev' into vlb2 m0duspwnens 2024-12-09 15:35:57 -05:00
  • 7eaa8d54dc git ignore dirs m0duspwnens 2024-12-09 15:35:07 -05:00
  • 61a1fbde6e create hypervisor pillars in setup m0duspwnens 2024-12-09 15:30:48 -05:00
  • a0a18973d8 add new salt bootstrap m0duspwnens 2024-12-09 15:29:51 -05:00
  • 9bc20c26bb Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into reyesj2/es-integ-tmp reyesj2 2024-12-06 14:29:25 -06:00
  • 14cb41ea87 Merge pull request #14001 from Security-Onion-Solutions/reyesj2/zeekvpn Jorge Reyes 2024-12-06 12:06:02 -06:00
  • edd90cbed4 Merge pull request #14004 from Security-Onion-Solutions/reyesj2/logcheck Jorge Reyes 2024-12-06 10:28:15 -06:00
  • 1de20e9d43 fix zeek file extract #14004 reyesj2 2024-12-06 09:55:56 -06:00
  • ad8b339a3b fix error due to null reference #14001 reyesj2 2024-12-06 09:07:16 -06:00
  • 9532f21c7b check zeek reporter.log reyesj2 2024-12-05 13:49:44 -06:00
  • 754d28e95d add openvpn & ipsec support to Zeek reyesj2 2024-12-05 09:52:55 -06:00
  • e3b7d82a8f remove all non-core integrations from elasticfleet:packages pillar reyesj2 2024-12-03 08:56:56 -06:00
  • 888145a2ed remove optional integrations from defaults.yaml & soc_elasticsearch.yaml reyesj2 2024-12-03 08:55:43 -06:00
  • 726bdd8735 Merge pull request #13995 from Security-Onion-Solutions/feature/msi Josh Brower 2024-12-02 14:49:22 -05:00
  • 5b9f6b2d52 fix path #13995 defensivedepth 2024-12-02 14:42:56 -05:00
  • aabff98bea Merge pull request #13989 from Security-Onion-Solutions/feature/msi Josh Brower 2024-12-02 09:17:45 -05:00
  • aade3db80d Generate MSI #13989 defensivedepth 2024-11-28 07:00:23 -05:00
  • 129c10dde5 Merge pull request #13981 from Security-Onion-Solutions/reyesj2/integ Jorge Reyes 2024-11-26 00:55:31 -06:00
  • 993d56cb58 ti_rapid7* #13981 reyesj2 2024-11-25 15:51:49 -06:00
  • efa6a533c3 add missing ilm to index template reyesj2 2024-11-25 15:47:47 -06:00
  • 04ffdf9b15 Merge pull request #13958 from Security-Onion-Solutions/2.4/autoenablesigma Josh Brower 2024-11-21 09:47:49 -05:00
  • f61bf1bd67 Remove adv #13958 defensivedepth 2024-11-21 09:15:29 -05:00
  • b1c4e32123 Remove duplicate option defensivedepth 2024-11-21 09:11:44 -05:00
  • 8958da83b3 Deprecate instead defensivedepth 2024-11-20 18:00:26 -05:00
  • 3fcf197bc1 Tweak structure defensivedepth 2024-11-19 11:54:15 -05:00
  • 532dfd7f5a Merge pull request #13966 from Security-Onion-Solutions/jertel/wip Jason Ertel 2024-11-19 09:35:26 -05:00
  • 92ddf2ec6c MFA issuer name shouldn't be an advanced setting #13966 Jason Ertel 2024-11-19 09:27:26 -05:00
  • a703f46a0a Merge pull request #13961 from Security-Onion-Solutions/cogburn/engine-update-config coreyogburn 2024-11-18 14:46:04 -07:00
  • d86c009f55 Add Annotations to Existing Detections Options #13961 Corey Ogburn 2024-11-18 14:06:06 -07:00
  • 56d6857cd6 Addl customization for autoenable sigma defensivedepth 2024-11-18 09:03:17 -05:00
  • 52bc9be6b6 Merge pull request #13956 from Security-Onion-Solutions/jertel/wip Jason Ertel 2024-11-17 18:23:54 -05:00
  • 918f26962a ignore fp from hydra #13956 Jason Ertel 2024-11-17 12:21:06 -05:00
  • 3bf7870729 Merge pull request #13955 from Security-Onion-Solutions/jertel/wip Jason Ertel 2024-11-16 21:31:08 -05:00
  • 0eebe48492 soup corrections #13955 Jason Ertel 2024-11-16 21:20:24 -05:00
  • e02cb30f1b Merge branch '2.4/dev' of github.com:Security-Onion-Solutions/securityonion into 2.4/dev Mike Reeves 2024-11-16 20:41:31 -05:00
  • d005f0d7d6 Merge branch '2.4/main' of github.com:Security-Onion-Solutions/securityonion into 2.4/main Mike Reeves 2024-11-16 20:41:20 -05:00
  • cc44558f40 Merge pull request #13954 from Security-Onion-Solutions/jertel/wip Jason Ertel 2024-11-16 12:08:49 -05:00
  • 73521dd7a7 revert prev commit #13954 Jason Ertel 2024-11-16 11:09:44 -05:00
  • 3041d7d2b1 Merge pull request #13951 from Security-Onion-Solutions/reyesj2/integ Jorge Reyes 2024-11-15 15:02:04 -06:00
  • b6ab5249f1 Merge pull request #13953 from Security-Onion-Solutions/jertel/wip Jason Ertel 2024-11-15 14:32:37 -05:00
  • dc838e7148 connect #13953 Jason Ertel 2024-11-15 14:25:52 -05:00
  • f290e52fbd connect Jason Ertel 2024-11-15 14:25:11 -05:00
  • e4de376394 connect api #13952 Jason Ertel 2024-11-15 13:42:02 -05:00
  • 44ec237447 additional integration support - cisco secure email gateway - rapid7 threat command #13951 reyesj2 2024-11-15 11:39:01 -06:00
  • ec5a6aec41 Merge pull request #13946 from Security-Onion-Solutions/foxtrot Jorge Reyes 2024-11-14 14:52:48 -06:00
  • 7f96d20eb4 Merge pull request #13944 from Security-Onion-Solutions/saltbootstrap Josh Patterson 2024-11-14 10:25:16 -05:00
  • dfd9108f39 Merge pull request #13945 from Security-Onion-Solutions/2.4/dev #13946 Jorge Reyes 2024-11-14 09:13:00 -06:00
  • e07c1e6958 Merge pull request #13943 from Security-Onion-Solutions/zeek7 Jorge Reyes 2024-11-14 09:11:08 -06:00
  • 1113c3924f zeek http2 #13943 reyesj2 2024-11-14 09:09:23 -06:00
  • b1ddaa7211 support installing specified version for rhel variants. remove bootstrap -x python3 since not needed #13944 m0duspwnens 2024-11-14 09:07:41 -05:00
  • ff00ddeb3c Merge pull request #13935 from Security-Onion-Solutions/ilm-detection #13945 Jorge Reyes 2024-11-13 15:07:29 -06:00
  • ba7a6dbbf0 Remove tuning/defaults "Remove in v7.1 The policy/tuning/defaults package is deprecated. The options set here are now the defaults for Zeek in general." reyesj2 2024-11-12 18:37:46 -06:00
  • f3a88de0c3 so-(case/detection)history uses same ilm policy as so-(case/detection) #13935 reyesj2 2024-11-12 16:28:01 -06:00
  • 4e0b5569dc Merge pull request #13933 from Security-Onion-Solutions/ilm-detection Jorge Reyes 2024-11-12 15:22:05 -06:00
  • a4d763c1e5 use curl vs es query to force PUT request #13933 reyesj2 2024-11-12 14:50:04 -06:00
  • 33fdc23965 remove salt repo files created by saltbootstrap m0duspwnens 2024-11-12 11:31:42 -05:00
  • aaf9f53695 update soup; check for index before applying new index setting reyesj2 2024-11-11 22:40:06 -06:00
  • 59cf049a06 Merge pull request #13930 from Security-Onion-Solutions/jertel/wip Jason Ertel 2024-11-11 18:53:46 -05:00
  • 5b74a55c3c ensure roles file exists since no longer syncing clients to es #13930 Jason Ertel 2024-11-11 17:21:42 -05:00
  • f2ce070833 Merge pull request #13927 from Security-Onion-Solutions/saltbootstrap Josh Patterson 2024-11-11 16:17:23 -05:00
  • ce9bd18947 no error when versionlock dir exists after re-running soup reyesj2 2024-11-11 14:59:42 -06:00
  • 9e5d0e88de fix soversion path #13927 m0duspwnens 2024-11-11 15:56:01 -05:00