Commit Graph

  • cc0f4847ba Casing and validation DefensiveDepth 2024-03-26 08:10:57 -04:00
  • 923b80ba60 Merge pull request #12663 from Security-Onion-Solutions/feature/improve-soc-dashboards Doug Burks 2024-03-26 07:52:54 -04:00
  • 7c4ea8a58e Add Detections SOC Config DefensiveDepth 2024-03-26 07:39:39 -04:00
  • 20bd9a9701 FEATURE: Include additional groupby fields in Dashboards relating to sankey diagrams #12657 #12663 Doug Burks 2024-03-26 07:39:24 -04:00
  • f0cb30a649 Merge pull request #12659 from Security-Onion-Solutions/2.4/remove-playbook #12660 Josh Brower 2024-03-25 21:12:22 -04:00
  • 94ee761207 Remove Playbook ref #12659 DefensiveDepth 2024-03-25 21:11:47 -04:00
  • 0a5dc411d0 Merge pull request #12658 from Security-Onion-Solutions/2.4/remove-playbook Josh Brower 2024-03-25 19:45:51 -04:00
  • d7ecad4333 Initial cut to remove Playbook and deps #12658 DefensiveDepth 2024-03-25 19:42:31 -04:00
  • 49fa800b2b Add bindings for sigma repos DefensiveDepth 2024-03-25 14:45:50 -04:00
  • 446f1ffdf5 merge 2.4/dev reyesj2 2024-03-25 13:55:48 -04:00
  • 57553bc1e5 Merge pull request #12652 from Security-Onion-Solutions/feature/pfsense_suricata weslambert 2024-03-25 10:10:13 -04:00
  • df058b3f4a Merge branch '2.4/dev' into feature/pfsense_suricata #12652 weslambert 2024-03-25 10:08:03 -04:00
  • 5e21da443f Minor verbiage updates Wes 2024-03-25 13:58:32 +00:00
  • 7898277a9b Merge pull request #12651 from Security-Onion-Solutions/issue/12637 Josh Patterson 2024-03-25 09:37:52 -04:00
  • 029d8a0e8f handle yes/no on checksum-checks #12651 m0duspwnens 2024-03-25 09:30:41 -04:00
  • b8d33ab983 Merge pull request #12639 from Security-Onion-Solutions/2.4/enable-detections Josh Brower 2024-03-25 09:30:01 -04:00
  • e124791d5d Merge pull request #12650 from Security-Onion-Solutions/fix/soc_template weslambert 2024-03-25 09:29:19 -04:00
  • 8ae30d0a77 Merge pull request #12640 from Security-Onion-Solutions/cogburn/sigma-repo-support coreyogburn 2024-03-22 14:24:18 -06:00
  • 81f3d69eb9 remove mmap-locked. m0duspwnens 2024-03-22 15:55:59 -04:00
  • 237946e916 Specify Folder in Rule Repo #12640 Corey Ogburn 2024-03-22 13:51:59 -06:00
  • 3d04d37030 Update ElastAlert Config with Default Repos Corey Ogburn 2024-03-22 10:31:09 -06:00
  • bb0da2a5c5 add additional suricata af-packet config items m0duspwnens 2024-03-22 14:34:14 -04:00
  • d6ce3851ec Merge pull request #12644 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-22 13:47:33 -04:00
  • 9c6f3f4808 FIX: Specify that static IP address is recommended #12643 #12644 Doug Burks 2024-03-22 13:41:44 -04:00
  • 1ab56033a2 Merge pull request #12642 from Security-Onion-Solutions/fix/add-event.dataset Doug Burks 2024-03-22 13:22:57 -04:00
  • a78a304d4f FEATURE: Add event.dataset to all Events column layouts #12641 #12642 Doug Burks 2024-03-22 13:19:31 -04:00
  • 5ca9ec4b17 Enable Detections #12639 DefensiveDepth 2024-03-22 10:12:26 -04:00
  • 4e1543b6a8 Get only code #12650 weslambert 2024-03-22 09:56:21 -04:00
  • 0e7d08b957 Merge pull request #12638 from Security-Onion-Solutions/jertel/logs Jason Ertel 2024-03-22 09:53:52 -04:00
  • f889a089bf disregard benign telegraf error #12638 Jason Ertel 2024-03-22 09:48:27 -04:00
  • 2b019ec8fe Merge pull request #12634 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-22 05:52:23 -04:00
  • 5934829e0d Include pfsense config Wes 2024-03-21 20:08:33 +00:00
  • 486a633dfe Add pfsense Suricata config Wes 2024-03-21 20:07:59 +00:00
  • 77ac342786 Merge pull request #12632 from Security-Onion-Solutions/fix/remove_temp_yara weslambert 2024-03-21 10:11:32 -04:00
  • 8429a364dc Remove Strelka rules watch #12632 weslambert 2024-03-21 10:09:36 -04:00
  • 1568f57096 Remove Strelka config weslambert 2024-03-21 10:07:27 -04:00
  • f431e9ae08 Remove Strelka config weslambert 2024-03-21 10:06:25 -04:00
  • 4b03d088c3 Merge pull request #12611 from Security-Onion-Solutions/2.4/enable-detections Josh Brower 2024-03-21 08:04:03 -04:00
  • 4a33234c34 Default update to 24 hours #12611 DefensiveDepth 2024-03-21 07:26:19 -04:00
  • 778997bed4 FEATURE: Add Events column layout for event.module system #12628 #12634 Doug Burks 2024-03-20 17:07:37 -04:00
  • 655d3e349c Merge pull request #12627 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-20 16:11:33 -04:00
  • f3b921342e FIX: Annotations for BPF and Suricata PCAP #12626 #12627 Doug Burks 2024-03-20 16:06:25 -04:00
  • fff4d20e39 Update soc_suricata.yaml Doug Burks 2024-03-20 16:03:45 -04:00
  • d2fb067110 FIX: Annotations for BPF and Suricata PCAP #12626 Doug Burks 2024-03-20 15:57:32 -04:00
  • 876690a9f6 FIX: Annotations for BPF and Suricata PCAP #12626 Doug Burks 2024-03-20 15:49:46 -04:00
  • 4c2f2759d4 Merge pull request #12601 from Security-Onion-Solutions/jertel/suripcap Jason Ertel 2024-03-20 12:11:15 -04:00
  • dd603934bc Merge pull request #12619 from Security-Onion-Solutions/TOoSmOotH-patch-1 Mike Reeves 2024-03-20 11:06:05 -04:00
  • d4d17e1835 Update VERSION #12619 Mike Reeves 2024-03-20 11:04:40 -04:00
  • b658c82cdc Merge pull request #12616 from Security-Onion-Solutions/2.4/dev 2.4.60-20240320 Mike Reeves 2024-03-20 10:55:42 -04:00
  • 7779a95341 Merge pull request #12617 from Security-Onion-Solutions/2.4/main #12616 Mike Reeves 2024-03-20 10:53:09 -04:00
  • 68ea2836dd Merge pull request #12615 from Security-Onion-Solutions/2.4.60 Mike Reeves 2024-03-20 10:43:08 -04:00
  • bb3bbd749c 2.4.260 #12615 Mike Reeves 2024-03-20 10:20:04 -04:00
  • d84af803a6 Enable Autoupdates DefensiveDepth 2024-03-20 08:48:31 -04:00
  • 68eb2d3ceb Merge pull request #12614 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-19 16:48:25 -04:00
  • 595f965183 Update soup for 2.3.300 #12614 Doug Burks 2024-03-19 16:44:01 -04:00
  • 020eb47026 Change Detections defaults DefensiveDepth 2024-03-19 13:53:37 -04:00
  • c6df805556 Add SOC template Wes 2024-03-18 14:53:36 +00:00
  • 834d18b77c Merge pull request #12603 from Security-Onion-Solutions/jertel/ld Jason Ertel 2024-03-18 09:41:21 -04:00
  • 4849da1c11 Merge branch 'master' into jertel/ld #12603 Jason Ertel 2024-03-18 09:31:17 -04:00
  • fbbddc2aaf Merge pull request #12602 from Security-Onion-Solutions/jertel/lock Jason Ertel 2024-03-18 09:29:04 -04:00
  • 4b24500b79 re-schedule lock jobs #12602 Jason Ertel 2024-03-18 07:37:42 -04:00
  • 47d447eadd Merge branch '2.4/dev' into jertel/suripcap #12601 Jason Ertel 2024-03-18 07:34:43 -04:00
  • af5b3feb96 re-schedule lock jobs Jason Ertel 2024-03-18 07:34:18 -04:00
  • 4237210f0b Merge pull request #12587 from Security-Onion-Solutions/TOoSmOotH-patch-10 Mike Reeves 2024-03-14 11:37:35 -04:00
  • fd835f6394 Update soc_suricata.yaml #12587 Mike Reeves 2024-03-14 11:36:45 -04:00
  • 284e0d8435 Update soc_suricata.yaml Mike Reeves 2024-03-14 11:33:47 -04:00
  • 09bff01d79 Merge pull request #12584 from Security-Onion-Solutions/jertel/suripcap Jason Ertel 2024-03-13 21:35:06 -04:00
  • 844cfe55cd handle airgap when detections not enabled #12584 Jason Ertel 2024-03-13 20:52:17 -04:00
  • 927fe9039d handle airgap when detections not enabled Jason Ertel 2024-03-13 20:50:03 -04:00
  • cc1356c823 Merge pull request #12581 from Security-Onion-Solutions/jertel/suripcap Jason Ertel 2024-03-13 14:20:22 -04:00
  • 275a678fa1 removed unused property #12581 Jason Ertel 2024-03-13 13:49:44 -04:00
  • 3d33c99f53 Merge pull request #12579 from Security-Onion-Solutions/m0duspwnens-patch-1-dontshowchanges Josh Patterson 2024-03-13 11:26:20 -04:00
  • b9702d02db Update init.sls #12579 Josh Patterson 2024-03-13 11:24:26 -04:00
  • 292ab0e378 Merge pull request #12577 from Security-Onion-Solutions/jppsocerino Josh Patterson 2024-03-13 10:30:00 -04:00
  • 1a829190ac remove modules if detections disabled #12577 m0duspwnens 2024-03-13 09:46:44 -04:00
  • dc3eace718 Merge pull request #12576 from Security-Onion-Solutions/2.4/regenpackages Josh Brower 2024-03-13 07:53:08 -04:00
  • 06013e2c6f Gen packages post-SOUP #12576 DefensiveDepth 2024-03-13 07:23:43 -04:00
  • 603483148d Merge pull request #12567 from Security-Onion-Solutions/TOoSmOotH-patch-9 Mike Reeves 2024-03-12 10:20:41 -04:00
  • 3e0fb3f8bb Update so-saltstack-update #12567 Mike Reeves 2024-03-12 10:18:27 -04:00
  • 5deebe07d8 Merge pull request #12564 from Security-Onion-Solutions/TOoSmOotH-patch-8 Mike Reeves 2024-03-12 09:24:56 -04:00
  • 197791f8ed Merge pull request #12565 from Security-Onion-Solutions/2.4/detections-defaults Josh Brower 2024-03-12 06:17:30 -04:00
  • 72acb11925 Update soc_suricata.yaml #12564 Mike Reeves 2024-03-11 19:04:51 -04:00
  • 0f41f07dc9 Merge remote-tracking branch 'origin/2.4/dev' into 2.4/detections-defaults #12565 DefensiveDepth 2024-03-11 16:41:26 -04:00
  • 47ab1f5b95 Merge pull request #12563 from Security-Onion-Solutions/kilo Josh Brower 2024-03-11 16:39:31 -04:00
  • b7f058a8ca Merge pull request #12561 from Security-Onion-Solutions/jppnocap Josh Patterson 2024-03-11 15:57:16 -04:00
  • 61a183b7fc Add regex defaults DefensiveDepth 2024-03-11 15:55:39 -04:00
  • ba32b3e6e9 fix bpf for transition #12561 m0duspwnens 2024-03-11 14:07:45 -04:00
  • 8c54a19698 Merge pull request #12560 from Security-Onion-Solutions/jertel/email Jason Ertel 2024-03-11 14:06:52 -04:00
  • cd28c00d67 auto-convert email addresses to lowercase during setup #12560 Jason Ertel 2024-03-11 13:47:31 -04:00
  • b5d8df7fb2 auto-convert email addresses to lowercase during setup Jason Ertel 2024-03-11 13:45:57 -04:00
  • 907cf9f992 transition pcap m0duspwnens 2024-03-11 12:20:28 -04:00
  • 4355d5b659 Merge pull request #12544 from Security-Onion-Solutions/jertel/status Josh Patterson 2024-03-11 10:29:33 -04:00
  • 2ca96c7f4c Merge pull request #12555 from Security-Onion-Solutions/reyesj2-patch-osc Jorge Reyes 2024-03-11 09:40:20 -04:00
  • a8403c63c7 Create local salt dir for stig #12555 reyesj2 2024-03-11 09:35:54 -04:00
  • 34d5954e16 Fix indent #12563 weslambert 2024-03-11 09:12:05 -04:00
  • f4725bf6d4 Merge pull request #12553 from Security-Onion-Solutions/reyesj2-patch-osc Jorge Reyes 2024-03-11 07:52:07 -04:00
  • b622cf8d23 Merge pull request #12545 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-08 16:45:29 -05:00
  • a892352b61 Update soc_pcap.yaml #12545 Doug Burks 2024-03-08 16:43:29 -05:00
  • a55e04e64a pcap improvements #12544 Jason Ertel 2024-03-08 15:48:53 -05:00
  • 4a9e8265ce Merge remote-tracking branch 'origin/2.4/dev' into kilo Josh Brower 2024-03-08 14:48:04 -05:00