Commit Graph

  • d9edff38df Create compile report for SOC integrity check #13036 weslambert 2024-05-17 16:10:10 -04:00
  • 300d8436a8 Merge pull request #13035 from Security-Onion-Solutions/jertel/eaconfig Jason Ertel 2024-05-17 15:01:54 -04:00
  • 1c4d36760a add support for custom alerters #13035 Jason Ertel 2024-05-17 14:49:39 -04:00
  • 34a5985311 Create tpm enrollment script reyesj2 2024-05-16 21:14:57 -04:00
  • aa0163349b Merge pull request #13031 from Security-Onion-Solutions/issue/13021 Josh Patterson 2024-05-16 16:40:17 -04:00
  • 572b8d08d9 Merge branch '2.4/dev' into issue/13021 #13031 Josh Patterson 2024-05-16 16:39:17 -04:00
  • cc6cb346e7 fix issue/13030 m0duspwnens 2024-05-16 16:31:45 -04:00
  • b54632080e check if exists in override before popping m0duspwnens 2024-05-16 16:04:17 -04:00
  • 44d3468f65 Merge pull request #13029 from Security-Onion-Solutions/revert-13028-issue/13021 Josh Patterson 2024-05-16 15:48:05 -04:00
  • 9d4668f4d3 Revert "dont merge policy from global_overrides if not defined in default index_settings" #13029 Josh Patterson 2024-05-16 15:45:55 -04:00
  • da2ac4776e Merge pull request #13028 from Security-Onion-Solutions/issue/13021 Josh Patterson 2024-05-16 14:33:51 -04:00
  • 9796354b48 dont merge policy from global_overrides if not defined in default index_settings #13028 m0duspwnens 2024-05-16 14:27:32 -04:00
  • aa32eb9c0e Merge pull request #13025 from Security-Onion-Solutions/jertel/suridp Jason Ertel 2024-05-15 19:21:30 -04:00
  • 4771810361 exclude detect-parse errors #13025 Jason Ertel 2024-05-15 19:10:50 -04:00
  • 52f27c00ce Merge pull request #13024 from Security-Onion-Solutions/TOoSmOotH-patch-7 Mike Reeves 2024-05-15 18:07:28 -04:00
  • ab9ec2ec6b Update soup #13024 Mike Reeves 2024-05-15 18:04:01 -04:00
  • 4d7835612d Merge pull request #13022 from Security-Onion-Solutions/soupaml Josh Patterson 2024-05-15 16:37:53 -04:00
  • 8076ea0e0a add another space #13022 m0duspwnens 2024-05-15 16:34:05 -04:00
  • 320ae641b1 Merge pull request #13023 from Security-Onion-Solutions/2.4/sigmapipelineupdates Josh Brower 2024-05-15 16:30:45 -04:00
  • b4aec9a9d0 alphabetical order #13023 DefensiveDepth 2024-05-15 16:29:21 -04:00
  • 6af0308482 add a newline m0duspwnens 2024-05-15 16:26:44 -04:00
  • 08024c7511 Merge pull request #13020 from Security-Onion-Solutions/issue/13012 Josh Patterson 2024-05-15 15:33:01 -04:00
  • 3a56058f7f update description #13020 m0duspwnens 2024-05-15 15:31:31 -04:00
  • 795de7ab07 Merge pull request #13019 from Security-Onion-Solutions/TOoSmOotH-patch-6 Mike Reeves 2024-05-15 14:08:40 -04:00
  • 8803ad4018 Update enabled.sls #13019 Mike Reeves 2024-05-15 14:05:48 -04:00
  • 62a8024c6c Merge remote-tracking branch 'origin/2.4/dev' into issue/13012 m0duspwnens 2024-05-15 13:48:46 -04:00
  • ea253726a0 fix soup m0duspwnens 2024-05-15 13:48:32 -04:00
  • a0af25c314 Merge pull request #13017 from Security-Onion-Solutions/surimigrate Mike Reeves 2024-05-15 11:40:50 -04:00
  • e3a0847867 Update soup #13017 Mike Reeves 2024-05-15 11:31:41 -04:00
  • 7345d2c5a6 Update enabled.sls Mike Reeves 2024-05-15 11:16:20 -04:00
  • 7cbc3a83c6 Merge pull request #13016 from Security-Onion-Solutions/soupaml Josh Patterson 2024-05-15 10:49:56 -04:00
  • 427b1e4524 revert soup_scripts back to common #13016 m0duspwnens 2024-05-15 10:28:02 -04:00
  • 2dbbe8dec4 soup_scripts put so-yaml in salt file system. move soup scripts to manager.soup_scripts m0duspwnens 2024-05-15 10:07:06 -04:00
  • e76c2c95a9 Merge pull request #13013 from Security-Onion-Solutions/issue/13012 Josh Patterson 2024-05-15 08:37:15 -04:00
  • 51862e5803 remove idh.services from idh node pillar files #13013 m0duspwnens 2024-05-14 13:08:51 -04:00
  • 27ad84ebd9 Merge pull request #13011 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-05-14 10:15:25 -04:00
  • 67645a662d FEATURE: Add NetFlow dashboard #13009 #13011 Doug Burks 2024-05-14 10:14:16 -04:00
  • 1d16f6b7ed Merge pull request #13010 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-05-14 10:02:40 -04:00
  • 5b45c80a62 FEATURE: Add NetFlow dashboard #13009 #13010 Doug Burks 2024-05-14 10:01:18 -04:00
  • 6dec9b4cf7 Merge pull request #12986 from Security-Onion-Solutions/fix/old_strelka weslambert 2024-05-14 09:27:19 -04:00
  • 13062099b3 Remove YARA script update and reference to exclusions #12986 weslambert 2024-05-13 18:04:16 -04:00
  • 7250fb1188 Merge pull request #13004 from Security-Onion-Solutions/fix/detections_alerts_indices weslambert 2024-05-13 17:02:52 -04:00
  • 437d0028db Merge pull request #13003 from Security-Onion-Solutions/localdirs Josh Patterson 2024-05-13 16:33:04 -04:00
  • 1ef9509aac define local_salt_dir #13003 m0duspwnens 2024-05-13 14:34:22 -04:00
  • d606f259d1 Add detection alerts #13004 weslambert 2024-05-13 14:25:11 -04:00
  • c8870eae65 Add detection alerts template weslambert 2024-05-13 14:23:47 -04:00
  • 2419066dc8 Merge pull request #13001 from Security-Onion-Solutions/2.4/socdefaults Josh Brower 2024-05-13 13:39:31 -04:00
  • e430de88d3 Change rule updates to 24h #13001 DefensiveDepth 2024-05-13 13:15:06 -04:00
  • c4c38f58cb Update descriptions DefensiveDepth 2024-05-13 13:13:57 -04:00
  • 26b5a39912 Change index to detections.alerts weslambert 2024-05-13 12:59:17 -04:00
  • eb03858230 missed one m0duspwnens 2024-05-13 12:44:57 -04:00
  • 2643da978b those functions in so-functions m0duspwnens 2024-05-13 11:51:10 -04:00
  • 649f52dac7 create_local_directories in soup too m0duspwnens 2024-05-13 10:37:56 -04:00
  • 927fe91f25 Merge pull request #13000 from Security-Onion-Solutions/soupz Mike Reeves 2024-05-13 10:12:34 -04:00
  • 9d6f6c7893 Update soup #13000 Mike Reeves 2024-05-13 10:09:35 -04:00
  • 28e40e42b3 Update soc_soc.yaml Mike Reeves 2024-05-13 09:58:32 -04:00
  • 6c71c45ef6 Update soup Mike Reeves 2024-05-13 09:55:57 -04:00
  • 641899ad56 Backup Suricata for migration and remove advanced from reverselookups Mike Reeves 2024-05-13 09:50:14 -04:00
  • d120326cb9 Merge pull request #12999 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-05-13 09:20:01 -04:00
  • a4f2d8f327 Merge pull request #12998 from Security-Onion-Solutions/dougburks-patch-2 Doug Burks 2024-05-13 08:42:33 -04:00
  • ae323cf385 Update README.md to include new Detections screenshot #12998 Doug Burks 2024-05-13 08:34:44 -04:00
  • 788c31014d Update README.md to reference new screenshots for 2.4.70 Doug Burks 2024-05-13 08:30:48 -04:00
  • 154dc605ef Merge pull request #12994 from Security-Onion-Solutions/jertel/testcy Jason Ertel 2024-05-10 16:57:19 -04:00
  • 2a0e33401d support upgrade tests #12994 Jason Ertel 2024-05-10 16:54:50 -04:00
  • 79b4d7b6b6 Merge pull request #12992 from Security-Onion-Solutions/issue/12991 Josh Patterson 2024-05-10 12:43:09 -04:00
  • 986cbb129a pkg not file #12992 m0duspwnens 2024-05-10 12:33:56 -04:00
  • 950c68783c add pkg policycoreutils-python-utils to idh node m0duspwnens 2024-05-10 11:46:00 -04:00
  • cec75ba475 Merge pull request #12989 from Security-Onion-Solutions/dougburks-patch-2 Doug Burks 2024-05-10 08:06:29 -04:00
  • 26cb8d43e1 FIX: so-index-list typo #12988 #12989 Doug Burks 2024-05-10 08:01:56 -04:00
  • a1291e43c3 FIX: so-index-list typo #12988 Doug Burks 2024-05-10 07:58:13 -04:00
  • 45fd07cdf8 Merge pull request #12987 from Security-Onion-Solutions/jertel/testcy Jason Ertel 2024-05-09 18:08:08 -04:00
  • fecd674fdb Add quick action to find related alerts for a detection #12987 Jason Ertel 2024-05-09 17:55:41 -04:00
  • dff2de4527 Merge pull request #12984 from Security-Onion-Solutions/jertel/testcy Jason Ertel 2024-05-09 15:50:37 -04:00
  • 19e1aaa1a6 exclude detection rule errors #12984 Jason Ertel 2024-05-09 15:45:33 -04:00
  • 074d063fee tests will retry on any rule import failure Jason Ertel 2024-05-09 14:52:58 -04:00
  • 6ed82d7b29 Remove YARA download in setup Wes 2024-05-09 17:27:46 +00:00
  • ea4cf42913 Remove old YARA update script Wes 2024-05-09 17:26:54 +00:00
  • 8a34f5621c Remove old YARA download script Wes 2024-05-09 17:26:45 +00:00
  • 823ff7ce11 Remove exclusions and repos Wes 2024-05-09 17:03:13 +00:00
  • fb8456b4a6 Merge pull request #12983 from Security-Onion-Solutions/fix/strelka Josh Patterson 2024-05-09 12:04:40 -04:00
  • c864fec70c allow strelka.manager to run on standalone #12983 m0duspwnens 2024-05-09 11:53:50 -04:00
  • a74fee4cd0 strelka compiled rules m0duspwnens 2024-05-09 11:26:02 -04:00
  • 3a99624eb8 seperate manager states for strelka m0duspwnens 2024-05-09 10:03:02 -04:00
  • 656bf60fda Merge pull request #12973 from Security-Onion-Solutions/TOoSmOotH-patch-5 Mike Reeves 2024-05-08 16:42:19 -04:00
  • cdc47cb1cd Merge pull request #12975 from Security-Onion-Solutions/fix/strelka_watch weslambert 2024-05-08 16:39:49 -04:00
  • 01a68568a6 Use state #12975 weslambert 2024-05-08 16:37:13 -04:00
  • 2ad87bf1fe merge 2.4/dev reyesj2 2024-05-08 16:30:45 -04:00
  • eca2a4a9c8 Logstash consumer threads should match topic partition count - Default is set to 3. If there are too many consumer threads it may lead to idle logstash worker threads and could require decreasing this value to saturate workers reyesj2 2024-05-08 16:17:09 -04:00
  • dff609d829 Add basic read-only metric collection from Kafka reyesj2 2024-05-08 16:13:09 -04:00
  • b916465b06 Merge pull request #12974 from Security-Onion-Solutions/fix/strelka_yara weslambert 2024-05-08 15:59:20 -04:00
  • 0567b93534 Remove mode #12974 weslambert 2024-05-08 15:39:59 -04:00
  • ad9fdf064b Update config.sls #12973 Mike Reeves 2024-05-08 15:24:29 -04:00
  • 77e2117051 Account for 0 active rules and change watch Wes 2024-05-08 18:47:52 +00:00
  • 5b7b6e5fb8 FEATURE: Add more fields to the SOC Dashboards URL for so-import-pcap #12972 #12999 Doug Burks 2024-05-08 14:00:23 -04:00
  • c7845bdf56 Merge pull request #12970 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-05-08 13:28:05 -04:00
  • 5a5a1e86ac FIX: Adjust so-import-pcap so that suricata works when it is pcapengine #12969 #12970 Doug Burks 2024-05-08 13:26:36 -04:00
  • 796eefc2f0 Merge pull request #12965 from Security-Onion-Solutions/orchit Josh Patterson 2024-05-08 10:24:33 -04:00
  • 1862deaf5e add copyright #12965 m0duspwnens 2024-05-08 10:14:08 -04:00
  • 0d2e5e0065 need repo and docker first m0duspwnens 2024-05-08 09:50:01 -04:00
  • 5dc098f0fc remove test file m0duspwnens 2024-05-08 08:54:24 -04:00