Commit Graph

  • 68ba9a89cf Merge pull request #12542 from Security-Onion-Solutions/cogburn/yara-license coreyogburn 2024-03-08 11:42:49 -07:00
  • 6f05c3976b Updated RulesRepo for New Strelka Structure #12542 Corey Ogburn 2024-03-08 11:29:46 -07:00
  • b6b6fc45e7 Merge pull request #12527 from Security-Onion-Solutions/TOoSmOotH-patch-7 Doug Burks 2024-03-08 12:40:15 -05:00
  • e1b27a930e Merge pull request #12540 from Security-Onion-Solutions/dougburks-patch-1 Doug Burks 2024-03-08 12:32:15 -05:00
  • 6680e023e4 Update soc_pcap.yaml #12540 Doug Burks 2024-03-08 12:16:59 -05:00
  • e8ae609012 Add Strelka rules watch back Wes 2024-03-08 16:27:17 +00:00
  • fc66a54902 Add Strelka download and update scripts back Wes 2024-03-08 16:26:14 +00:00
  • 4e32935991 Add Strelka config back Wes 2024-03-08 16:24:37 +00:00
  • 7ec887a327 Merge pull request #12537 from Security-Onion-Solutions/issue/12535 Josh Patterson 2024-03-08 10:13:27 -05:00
  • 3eb6fe2df9 allow managersearch to receiver redis and 5644 #12537 m0duspwnens 2024-03-08 09:52:12 -05:00
  • 6d06aa8ed6 Merge pull request #12526 from Security-Onion-Solutions/jertel/status Jason Ertel 2024-03-07 14:49:17 -05:00
  • 06257b9c4a Update so-minion #12527 Mike Reeves 2024-03-07 14:32:46 -05:00
  • 40574982e4 unswap files #12526 Jason Ertel 2024-03-07 14:25:43 -05:00
  • e2567dcf8d Merge pull request #12521 from Security-Onion-Solutions/jertel/status Jason Ertel 2024-03-07 13:29:48 -05:00
  • fffef9b621 gracefully handle status check failure on ubuntu #12521 Jason Ertel 2024-03-07 12:31:51 -05:00
  • 1633527695 Merge pull request #12519 from Security-Onion-Solutions/fix/error_message_system_syslog weslambert 2024-03-07 10:47:33 -05:00
  • 005930f7fd Add error.message mapping for system.syslog #12519 Wes 2024-03-07 15:41:23 +00:00
  • b5f1733e97 Merge pull request #12513 from Security-Onion-Solutions/newsuripcap Mike Reeves 2024-03-07 10:14:34 -05:00
  • 70f3ce0536 change how maxfiles is calculated #12513 m0duspwnens 2024-03-06 17:32:06 -05:00
  • 17a75d5bd2 Run stig post remediate scan against default ol9 scap-security-guide. #12553 reyesj2 2024-03-06 17:19:01 -05:00
  • 583227290f fix max-files calc m0duspwnens 2024-03-06 15:18:22 -05:00
  • cf232534ca move suricata.pcap to suricata.config.outputs.pcap-log m0duspwnens 2024-03-06 14:42:07 -05:00
  • 7f1e786e3d Consolidate PCAP settings Mike Reeves 2024-03-06 12:56:09 -05:00
  • 9a413a2e31 Fix location of repo Mike Reeves 2024-03-06 12:42:22 -05:00
  • 8f36a8a4b6 Merge pull request #12514 from Security-Onion-Solutions/jertel/annotations Jason Ertel 2024-03-06 11:10:21 -05:00
  • 1cbac11fae detections annotations #12514 Jason Ertel 2024-03-06 11:08:03 -05:00
  • ad12093429 Fix percent calc Mike Reeves 2024-03-06 11:05:06 -05:00
  • 167aff24f6 detections annotations Jason Ertel 2024-03-06 11:03:52 -05:00
  • 9e671621db Merge pull request #12510 from Security-Onion-Solutions/2.4/excludedetections Josh Brower 2024-03-06 10:56:29 -05:00
  • 4dfa1a5626 Move Suricata around Mike Reeves 2024-03-06 10:35:10 -05:00
  • f836d6a61d Update so-minion Mike Reeves 2024-03-06 10:06:17 -05:00
  • a63fca727c Update soc_suricata.yaml Mike Reeves 2024-03-06 10:02:06 -05:00
  • f58c104d89 Update so-minion Mike Reeves 2024-03-06 09:51:56 -05:00
  • 5acefb5d18 Merge pull request #12511 from Security-Onion-Solutions/jertel/annotations Jason Ertel 2024-03-06 08:40:24 -05:00
  • 0f12297f50 add new pcap annotations #12511 Jason Ertel 2024-03-06 08:19:42 -05:00
  • 12653eec8c add new pcap annotations Jason Ertel 2024-03-06 08:14:33 -05:00
  • 1b47537a3f Add Exclusion toggle #12510 Josh Brower 2024-03-06 07:16:50 -05:00
  • 73b45cfaf8 Merge pull request #12508 from Security-Onion-Solutions/jppsensoroni Josh Patterson 2024-03-05 17:53:28 -05:00
  • eaef076eba Update so-minion #12508 Josh Patterson 2024-03-05 17:52:24 -05:00
  • ac9db8a392 Merge branch '2.4/dev' into jppsensoroni Josh Patterson 2024-03-05 17:51:32 -05:00
  • 5687fdcf57 fix pcapspace function m0duspwnens 2024-03-05 17:46:43 -05:00
  • d5b08142a0 Merge pull request #12507 from Security-Onion-Solutions/jertel/annotations Jason Ertel 2024-03-05 16:44:56 -05:00
  • 4b5f00cef4 fix oinkcodes with leading zeros #12507 Jason Ertel 2024-03-05 16:42:20 -05:00
  • 185a160df0 Merge pull request #12500 from Security-Onion-Solutions/feature/additional_integrations_5 weslambert 2024-03-05 16:12:05 -05:00
  • b9707fc8ea Merge pull request #12502 from Security-Onion-Solutions/TOoSmOotH-patch-5 Mike Reeves 2024-03-05 15:10:02 -05:00
  • a686d46322 Update so-minion #12502 Mike Reeves 2024-03-05 15:09:02 -05:00
  • 6eb608c3f5 Update so-minion Mike Reeves 2024-03-05 15:05:03 -05:00
  • b9ebe6c40b Update VERSION #12500 weslambert 2024-03-05 12:58:34 -05:00
  • 781f96a74e Merge pull request #12497 from Security-Onion-Solutions/jppsensoroni Josh Patterson 2024-03-05 10:36:12 -05:00
  • c0d19e11b9 fix } placement #12497 m0duspwnens 2024-03-05 10:07:32 -05:00
  • 1a58aa61a0 only import pcap and suricata if sensor m0duspwnens 2024-03-05 09:54:40 -05:00
  • 08f2b8251b add GLOBALS.is_sensor m0duspwnens 2024-03-05 09:53:35 -05:00
  • bed42208b1 Add journald integration weslambert 2024-03-05 09:49:55 -05:00
  • 2a7e5b096f Change version for foxtrot weslambert 2024-03-05 09:48:59 -05:00
  • d8e8933ea0 Add AWS Security Hub template weslambert 2024-03-05 09:25:41 -05:00
  • d85ac39e28 Add AWS Inspector template weslambert 2024-03-05 09:23:17 -05:00
  • 1514f1291e Add AWS GuardDuty template weslambert 2024-03-05 09:21:48 -05:00
  • b64d61065a Add AWS Cloudfront template weslambert 2024-03-05 09:19:43 -05:00
  • 58d222284e Merge pull request #12271 from Security-Onion-Solutions/suripcap Mike Reeves 2024-03-04 17:27:38 -05:00
  • fe238755e9 Fix df #12271 Mike Reeves 2024-03-04 16:52:51 -05:00
  • 018e099111 Modify setup Mike Reeves 2024-03-04 14:53:15 -05:00
  • 9fd1653914 Merge pull request #12487 from Security-Onion-Solutions/2.4/elastic-agent-fim Josh Brower 2024-03-04 07:41:36 -05:00
  • f28f269bb1 Fix FIM #12487 Josh Brower 2024-03-04 07:38:32 -05:00
  • f3dce66f03 Merge pull request #12482 from Security-Onion-Solutions/2.4/sigma-pipeline Josh Brower 2024-03-01 15:29:13 -05:00
  • d832158cc5 Drop Hashes field #12482 Josh Brower 2024-03-01 15:26:02 -05:00
  • b017157d21 Add antivirus mapping Josh Brower 2024-03-01 14:04:56 -05:00
  • d911b7bfc4 Merge pull request #12469 from Security-Onion-Solutions/reyesj2-patch-4 Jorge Reyes 2024-02-29 16:21:44 -05:00
  • 53761d4dba FIX: EA installers not downloadable from SOC + fix stg logging #12469 reyesj2 2024-02-29 16:15:26 -05:00
  • f6a765addc Merge pull request #12467 from Security-Onion-Solutions/TOoSmOotH-patch-3 Mike Reeves 2024-02-29 14:13:44 -05:00
  • 8b56c0a744 Update VERSION #12467 Mike Reeves 2024-02-29 14:12:35 -05:00
  • b31d38e734 Merge pull request #12463 from Security-Onion-Solutions/dev 2.3.290-20240229 Mike Reeves 2024-02-29 14:07:11 -05:00
  • 1fe8f3d9e4 Merge pull request #12405 from Security-Onion-Solutions/repochange Mike Reeves 2024-02-29 14:01:48 -05:00
  • b1db4137d0 Merge pull request #12462 from Security-Onion-Solutions/2.3.290 #12463 Mike Reeves 2024-02-29 09:15:41 -05:00
  • 44ef164713 2.3.290 #12462 Mike Reeves 2024-02-29 09:08:37 -05:00
  • aa3b917368 Merge pull request #12456 from Security-Onion-Solutions/feature/detections-airgap Josh Brower 2024-02-28 09:41:13 -05:00
  • e2dd0f8cf1 Only update rule files if AG #12456 Josh Brower 2024-02-28 09:39:23 -05:00
  • d1e55d5ab7 Merge pull request #12450 from Security-Onion-Solutions/fix/suricata_max_age weslambert 2024-02-27 17:28:07 -05:00
  • df3943b465 Daily rollover #12450 weslambert 2024-02-27 17:24:27 -05:00
  • d5fc6ddd2c Merge pull request #12449 from Security-Onion-Solutions/issue/12391 Josh Patterson 2024-02-27 15:38:33 -05:00
  • fcc0f9d14f redo classifications #12449 m0duspwnens 2024-02-27 13:20:58 -05:00
  • 59af547838 Fix download location Josh Brower 2024-02-27 09:49:54 -05:00
  • a817bae1e5 Merge pull request #12437 from Security-Onion-Solutions/feature/detections-airgap Josh Brower 2024-02-26 16:47:26 -05:00
  • c6baa4be1b Airgap Support - Detections module #12437 Josh Brower 2024-02-26 16:19:32 -05:00
  • 8b7f7933bd suricata container watch classification.config m0duspwnens 2024-02-26 15:29:13 -05:00
  • 466dac30bb soup for classifications m0duspwnens 2024-02-26 12:15:17 -05:00
  • 52580fb8c4 Merge pull request #12434 from Security-Onion-Solutions/feature/improve-endpoint-columns Doug Burks 2024-02-26 12:05:30 -05:00
  • acf7dbdabe Merge pull request #12432 from Security-Onion-Solutions/fix/endpoint_diag_template weslambert 2024-02-26 12:01:29 -05:00
  • 1d099f97d2 Update pattern for endpoint diagnostic template #12432 weslambert 2024-02-26 11:27:56 -05:00
  • f8424f3dad Update defaults.yaml #12434 Doug Burks 2024-02-26 11:22:09 -05:00
  • 9a7e2153ee add classification.config m0duspwnens 2024-02-26 11:01:53 -05:00
  • c8a95a8706 FEATURE: Add new endpoint dashboards #12428 Doug Burks 2024-02-26 09:59:07 -05:00
  • 4df21148fc FEATURE: Add default columns for endpoint.events datasets #12425 Doug Burks 2024-02-26 09:40:51 -05:00
  • ca249312ba FEATURE: Add new SOC action for Process Info #12421 Doug Burks 2024-02-26 09:38:14 -05:00
  • 66b815d4b2 Merge pull request #12431 from Security-Onion-Solutions/feature/brower-detections Josh Brower 2024-02-26 08:43:33 -05:00
  • a6bb7216f9 Add Detection AutoUpdate config #12431 Josh Brower 2024-02-26 08:18:42 -05:00
  • 77cb5748f6 Merge pull request #12430 from Security-Onion-Solutions/feature/sigma-pipeline Josh Brower 2024-02-26 08:00:00 -05:00
  • d6cb8ab928 update events_x_process in defaults.yaml Doug Burks 2024-02-23 17:09:40 -05:00
  • daf96d7934 fix new eventFields in merged.map.jinja Doug Burks 2024-02-23 17:07:48 -05:00
  • 58f4fb87d0 fix new eventFields in soc_soc.yaml Doug Burks 2024-02-23 17:06:29 -05:00
  • b7ef1e8af1 add more endpoint.events.x fields to soc_soc.yaml Doug Burks 2024-02-23 15:38:53 -05:00