Commit Graph

  • 8a4e180a18 Merge pull request #70 from defensivedepth/osquery Mike Reeves 2019-01-02 09:54:19 -05:00
  • ce43fd7cd4 Moved to dynamic Josh Brower 2019-01-01 11:20:09 -05:00
  • b9f6269925 Moved to dynamic Josh Brower 2019-01-01 11:20:01 -05:00
  • bc7bf5774a Enable osquery parsers for EVAL role Josh Brower 2019-01-01 11:14:38 -05:00
  • 15bfce07e8 Move osquery parsers from custom to dynamic Josh Brower 2019-01-01 11:13:05 -05:00
  • f21e52b431 Add missing character Josh Brower 2019-01-01 11:11:29 -05:00
  • 739c8b8d5e Merge pull request #68 from defensivedepth/osquery Mike Reeves 2018-12-28 14:59:28 -05:00
  • fff13d5861 Tag & initial JSON decode for osquery logs Josh Brower 2018-12-28 13:56:06 -05:00
  • 1917b469ec osquery-tagged logs output to ES Josh Brower 2018-12-28 13:55:02 -05:00
  • 389b57f226 parser for windows event logs shipped by osquery Josh Brower 2018-12-28 13:54:11 -05:00
  • 679a6841f8 Osquery Overview dashboard - initial version Josh Brower 2018-12-28 13:51:44 -05:00
  • 9c3f476f6d add bind for fleet logs Josh Brower 2018-12-28 13:50:43 -05:00
  • 44eed120cb add osquery logs if fleet is enabled Josh Brower 2018-12-28 13:49:53 -05:00
  • 9c62bded2b Merge pull request #23 from TOoSmOotH/master Mike Reeves 2018-12-18 10:53:03 -05:00
  • 94d25d96e9 Merge pull request #66 from weslambert/master #23 Mike Reeves 2018-12-18 10:51:48 -05:00
  • 04cdd2d976 Redis - Re-enable for Fleet live queries Wes Lambert 2018-12-18 15:45:25 +00:00
  • 59964adfe0 Merge pull request #22 from TOoSmOotH/master Mike Reeves 2018-12-14 16:31:20 -05:00
  • 7df029764d Merge pull request #65 from weslambert/master #22 Mike Reeves 2018-12-14 16:30:42 -05:00
  • 9930aac556 Wazuh - Add conditional for config profile Wes Lambert 2018-12-14 21:28:46 +00:00
  • db02a2c135 increment version to 1.0.5 Doug Burks 2018-12-14 16:26:18 -05:00
  • 46546e2952 Readme Update Version to 1.0.5 Mike Reeves 2018-12-14 15:22:22 -05:00
  • d3ddc52035 Merge pull request #64 from weslambert/master Mike Reeves 2018-12-14 13:27:28 -05:00
  • 172c9e0593 Logstash - Wazuh parsing updates Wes Lambert 2018-12-14 18:00:19 +00:00
  • 46372d1384 Merge pull request #63 from weslambert/master Mike Reeves 2018-12-14 10:10:33 -05:00
  • 2f12c36c87 Setup - Clean up old Wazuh stuff and move Curator config to SN Adv Mode Wes Lambert 2018-12-14 14:07:20 +00:00
  • 09f5c24251 SSL - Ensure storage node gets FB cert Wes Lambert 2018-12-14 14:05:35 +00:00
  • 26418cfb26 Merge pull request #62 from dlee35/master Mike Reeves 2018-12-14 08:18:26 -05:00
  • e7c34cb1b8 remove nginx.conf.so-SENSOR dlee35 2018-12-14 08:04:46 -05:00
  • b3cb297813 Merge pull request #61 from weslambert/master Mike Reeves 2018-12-13 22:29:31 -05:00
  • 55a426c347 Cleanup - Lowercase SENSOR Wes Lambert 2018-12-14 03:27:13 +00:00
  • f8b1bd0ffc Merge pull request #59 from weslambert/master Mike Reeves 2018-12-13 20:35:43 -05:00
  • f00e59dea3 Merge pull request #60 from dlee35/master Mike Reeves 2018-12-13 20:35:00 -05:00
  • bd9f8ee2c7 fix filename and grep checks dlee35 2018-12-13 19:31:13 -05:00
  • 9ce41f81b9 Setup - Make sensor minion config consistent Wes Lambert 2018-12-14 00:12:37 +00:00
  • c7dcbb8dcb Merge remote-tracking branch 'upstream/master' Wes Lambert 2018-12-13 23:57:24 +00:00
  • a662badc5b Firewall - Fix stuff for sensor Wes Lambert 2018-12-13 23:52:15 +00:00
  • 2e78fc2e1e Master Module - I dont' want to talk about it Mike Reeves 2018-12-13 17:19:35 -05:00
  • 5a8ab7830e Master Module - Update acng version Mike Reeves 2018-12-13 17:04:14 -05:00
  • 1d9fae304c Setup - Get Curator disk size when /nsm not present Wes Lambert 2018-12-13 22:01:21 +00:00
  • de7e7df2b8 Merge branch 'master' of https://github.com/TOoSmOotH/securityonion-saltstack Mike Reeves 2018-12-13 16:55:55 -05:00
  • cc5bf1cf64 Setup Script - Install the repo on Ubuntu Mike Reeves 2018-12-13 16:55:48 -05:00
  • 7d5d364bd7 Merge pull request #58 from dlee35/master Mike Reeves 2018-12-13 16:30:43 -05:00
  • 06037d8222 generate self-signed cert for osquery clients dlee35 2018-12-13 16:28:52 -05:00
  • 1326d8d573 Setup Script - Cleanup of some Wazuh Mike Reeves 2018-12-13 14:46:03 -05:00
  • 1d0cb9c20e Setup Script - Cleanup of some Wazuh Mike Reeves 2018-12-13 14:41:50 -05:00
  • 52998d7340 Merge branch 'master' of https://github.com/TOoSmOotH/securityonion-saltstack Mike Reeves 2018-12-13 14:24:47 -05:00
  • 7ff47faa3d Common Module - Update core docker version Mike Reeves 2018-12-13 14:24:40 -05:00
  • fdd6bcdd6b Merge pull request #56 from dlee35/master Mike Reeves 2018-12-13 13:42:13 -05:00
  • 7fd2869159 Merge pull request #57 from weslambert/master Mike Reeves 2018-12-13 13:34:30 -05:00
  • d47e0ac4f8 Setup Script - Add Wazuh Repo for Ubuntu Mike Reeves 2018-12-13 13:33:38 -05:00
  • bd04dc45a3 Wazuh - Fix Jinja Wes Lambert 2018-12-13 18:30:04 +00:00
  • fe56e171d4 add firewall rule option for osquery dlee35 2018-12-13 13:28:37 -05:00
  • 07a2b34583 Merge branch 'master' of https://github.com/TOoSmOotH/securityonion-saltstack Mike Reeves 2018-12-13 13:22:04 -05:00
  • eb04bd1bb4 Setup Script - Add Wazuh Repo for Ubuntu Mike Reeves 2018-12-13 13:21:55 -05:00
  • f538eddb5f Merge pull request #55 from weslambert/master Mike Reeves 2018-12-13 13:01:38 -05:00
  • 75ed258d19 Firewall - Fix Wazuh IP logic for sensors Wes Lambert 2018-12-13 17:57:22 +00:00
  • 4db52ec865 Wazuh - Add logic for sensors Wes Lambert 2018-12-13 17:56:51 +00:00
  • 5e23859557 Salt - Add Wazuh to other roles Wes Lambert 2018-12-13 17:34:19 +00:00
  • 62067f37cf Wazuh - Fix agent ip for storage nodes Wes Lambert 2018-12-13 17:33:12 +00:00
  • d13e7559fe Filebeat - Enabled for master and only enable Bro/Suri inputs when needed Wes Lambert 2018-12-13 17:32:03 +00:00
  • 8163beadb0 Merge pull request #54 from dlee35/master Mike Reeves 2018-12-12 16:34:35 -05:00
  • 90d648cef1 Merge pull request #53 from weslambert/master Mike Reeves 2018-12-12 16:33:48 -05:00
  • 5c737e9fda Updated Fleet init.sls and nginx confs for fleet dlee35 2018-12-12 16:19:35 -05:00
  • 41e9c4c7e0 Logstash - Alter input for Wazuh logs Wes Lambert 2018-12-12 20:52:18 +00:00
  • 54c35cdc0d Filebeat - Add Wazuh archive logs Wes Lambert 2018-12-12 20:51:41 +00:00
  • d12f49aa9d Merge pull request #52 from weslambert/master Mike Reeves 2018-12-12 13:02:14 -05:00
  • 8496834f8b Wazuh - Re-order top.sls so Filebeat does not overrite Wazuh logs Wes Lambert 2018-12-12 15:48:59 +00:00
  • 9d86744e07 Filebeat - Fix Wazuh alerts path Wes Lambert 2018-12-12 15:19:51 +00:00
  • e20ab3b407 Filebeat - Config for Wazuh alerts Wes Lambert 2018-12-12 14:48:17 +00:00
  • 5822842d2e Wazuh - Add sleep to wait for API Wes Lambert 2018-12-12 13:36:13 +00:00
  • a99ec40506 Setup - Remark Wazuh agent config Wes Lambert 2018-12-12 13:10:27 +00:00
  • 8404897fe3 Wazuh - Move agent config to init.sls Wes Lambert 2018-12-12 06:05:13 +00:00
  • 823a589fae Wazuh - Set mode for agent registration script Wes Lambert 2018-12-12 04:01:13 +00:00
  • 1a4a7382e2 Wazuh - Fix Wazuh agent registration script name Wes Lambert 2018-12-12 03:18:55 +00:00
  • 86a72984c7 Setup - Add auth pillar to eval mode Wes Lambert 2018-12-12 02:58:09 +00:00
  • 113f030873 Wazuh - Add agent register script to init.sls Wes Lambert 2018-12-12 02:26:38 +00:00
  • 634c435ad6 Setup - Configure Wazuh agent Wes Lambert 2018-12-12 01:51:30 +00:00
  • 9a021164ac Wazuh - Fix port, add agent conf, and agent registration script Wes Lambert 2018-12-12 01:42:05 +00:00
  • 223237f8c2 Wazuh - Expose both UDP and TCP ports Wes Lambert 2018-12-11 19:45:56 +00:00
  • 6cdf1ef857 Firewall - Add rules for Wazuh Manager Wes Lambert 2018-12-11 19:44:32 +00:00
  • dd15a6e31a SSL Module - Fixed it so certs do not keep renewing Mike Reeves 2018-12-11 12:27:57 -05:00
  • bea4286054 Setup - Fix static file creation Mike Reeves 2018-12-11 11:57:27 -05:00
  • a54a5ede8c MySQL Module - fix password designation Mike Reeves 2018-12-11 11:32:37 -05:00
  • 8c1a7b3e0c Setup - Change so passwords survive re-install Mike Reeves 2018-12-11 11:19:54 -05:00
  • 4c88f89835 Merge pull request #51 from weslambert/master Mike Reeves 2018-12-10 15:23:22 -05:00
  • 0f5fbadaf5 Filebeat - Switch negation to equals Wes Lambert 2018-12-10 20:17:41 +00:00
  • 10d6c0f5a9 Setup - Remark Wazuh user section completely Wes Lambert 2018-12-10 19:55:53 +00:00
  • 2544984433 Wazuh - add to top.sls for Eval Mode Wes Lambert 2018-12-10 19:51:57 +00:00
  • e70db05a0f Filebeat - Modify config for Wazuh alerts Wes Lambert 2018-12-10 19:50:55 +00:00
  • cb68f502ee Wazuh - Changes to init.sls Wes Lambert 2018-12-10 19:49:14 +00:00
  • 0a33204726 Setup - Only add Wazuh repo Wes Lambert 2018-12-07 18:16:03 +00:00
  • e6469d505a Wazuh - initial init.sls Wes Lambert 2018-12-07 18:13:42 +00:00
  • cdc8b577bd Redis Module - Update REDIS version to address vuln Mike Reeves 2018-12-07 10:28:43 -05:00
  • 65d6b07f6d Merge pull request #50 from weslambert/master Mike Reeves 2018-12-07 08:46:56 -05:00
  • 6a9a537cf8 Wazuh - Remove filebeat.yml Wes Lambert 2018-12-07 13:39:10 +00:00
  • e355503324 Filebeat - Update for Wazuh logs Wes Lambert 2018-12-07 13:38:31 +00:00
  • e11aadf730 Wazuh - agent install for CentOS Wes Lambert 2018-12-07 13:36:11 +00:00
  • f5e2b7f210 Setup - Adjust to prevent unary operator error Wes Lambert 2018-12-07 04:22:11 +00:00
  • 6bfb813cdf Setup - Adjust syntax Wes Lambert 2018-12-07 04:18:28 +00:00
  • e21c67f553 Setup - Fix typo Wes Lambert 2018-12-07 04:14:30 +00:00