Chris Long
7778de6190
Fix ThreatHunting dashboard
...
https://github.com/clong/DetectionLab/issues/625
2021-03-23 17:08:40 -07:00
Chris Long
3ac2b21ccc
Update ThreatHunting, Add Exchange install script
2021-03-08 09:49:10 -08:00
mdtro
a422ad8442
add custom props.conf for Splunk TA for Zeek and update logger_bootstrap
2021-02-06 01:01:08 -06:00
Chris Long
2023e54ece
Monitor eth0 and eth1 with zeek and suricata
2021-01-05 21:56:00 -08:00
Chris Long
5b712a8f86
Filter AutorunsToWinEventlog invocation more widely
2020-08-13 14:14:36 -07:00
Chris Long
769dabf8a6
Update transforms.conf
2020-08-12 23:02:59 -07:00
Chris Long
83f5bf601c
Add transforms to remove eventid description text
2020-08-12 23:02:33 -07:00
Chris Long
34889a8bb6
Many Splunk fixes, add sponsors list to README
2020-08-06 23:50:10 -07:00
Chris Long
84c29f6739
Fix sysmon sourcetype, update ThreatHunting app
2020-08-04 21:58:18 -07:00
Chris Long
a163eb55d1
Updating build.ps1 and ThreatHunting app
2020-07-23 22:46:30 -07:00
Chris Long
8cc591b7d7
Add velociraptor
2020-07-03 01:55:19 -07:00
Chris Long
2823f140d2
Update props.conf
2020-06-01 21:47:32 -07:00
Chris Long
c55b3d6def
Update transforms.conf
2020-06-01 21:46:22 -07:00
Chris Long
10f260bf73
Update logger_dashboard.xml
2020-06-01 01:21:22 -07:00
Chris Long
23e8e288f9
Merge branch 'master' into update_gpo_ena
2020-05-03 17:13:59 -07:00
Chris Long
aeecd1b756
Update DC Auditing GPO and Add Packer Script for ENA
2020-05-03 17:12:05 -07:00
Chris Long
f0a7b1481f
Typo
2020-05-02 22:21:24 -07:00
Chris Long
b314066e06
Fixing Splunk regex
2020-05-02 22:20:48 -07:00
Chris Long
d1d0566773
Add some Splunk nullQueues for noisy events
2020-04-18 15:59:54 -07:00
Chris Long
03c96430a5
Merge branch 'master' into logger_bugfix
2020-04-13 00:09:52 -07:00
Chris Long
a67ce6efb5
Fixing logger bugs, updating vm tools, updating Win10 ISO
2020-04-13 00:05:49 -07:00
Mike Haag
2b37af791d
Bootstrap.sh Error fixes
...
Errors during install:
- logger: Error during app install: failed to extract app from /vagrant/resources/splunk_forwarder/splunk-add-on-for-microsoft-windows_700.tgz to /opt/splunk/var/run/splunk/bundle_tmp/2ade41e05f0e68dc: No such file or directory
- logger: Error during app install: failed to extract app from /vagrant/resources/splunk_server/add-on-for-microsoft-sysmon_1062.tgz to /opt/splunk/var/run/splunk/bundle_tmp/eeef7b83a2d6b716: No such file or directory
1. Fixed the forwarder error by placing the updated TA in the forwarder path.
2. fixed server error, this was caused by a typo in the name.
2020-04-06 09:04:23 -06:00
Chris Long
fd804a083d
Fixing the Splunk nullqueue
2020-03-28 02:30:06 -07:00
Chris Long
34d8a39c43
Multiple bugfixes, add dashboard
2020-03-27 14:53:04 -07:00
Mike Haag
852f20af57
Adding BOTSv3 and Updating Apps
2020-03-19 09:39:58 -06:00
Chris Long
7e17727cbb
Logger bump to Ubuntu 18.04 & Migrate to Zeek
2019-12-20 15:48:13 -08:00
Chris Long
9f392c76cc
Re-create DC Auditing GPO. Update ThreatHunting Splunk App.
2019-11-11 23:01:57 -08:00
Mike Haag
2d5d6f508e
Add BOTS to Logger
...
This will add the BOTSv2 dataset to DetectionLab.
One app required for BOTS:
Splunk Stream - https://splunkbase.splunk.com/app/1809/
Recommended:
Boss of the SOC (BOTS) Advanced APT Hunting Companion App for Splunk - https://splunkbase.splunk.com/app/4430/
2019-09-05 10:02:05 -06:00
Chris Long
9cceafa28e
Update ThreatHunting app to 1.3.4
2019-07-20 00:49:35 -07:00
Chris Long
95d1fb31f4
Updating ASNGen App
2019-06-09 17:53:21 -07:00
Chris Long
e78c312bc5
Actually add files
2019-05-26 21:36:10 -07:00
Chris Long
cd722dab8b
Fix ThreatHunting App, add Lookup Editor, Update VM tools
2019-05-26 21:34:45 -07:00
Olaf Hartong
7916fd1818
added v1.3.2
2019-05-19 22:33:01 +02:00
Olaf Hartong
04bbd7d25e
Updated ThreatHunting app to 1.3
2019-05-19 21:06:04 +02:00
Chris Long
93183a95e2
Update Splunk apps, create vagrantfile_minimum, bugfixes
2019-03-01 22:45:37 -08:00
Chris Long
020af3c936
Add ShutUp10, Upgrade Vagrant, Issue 12
2019-02-18 21:47:03 -08:00
Chris Long
8b9178685a
Adding Olaf's Threat Hunting App. Fixes. Updates.
2018-12-11 00:52:46 -08:00
Chris Long
9a82f140f4
Actually add the app
2018-09-07 14:58:11 -07:00
Chris Long
ca7dec8eb1
Updating build scripts to use vmware_desktop, update TA's, update bootstrap
2018-07-20 22:28:44 -07:00
Olaf Hartong
c9b826fcf4
newer Splunk Sysmon TA
2018-01-20 22:28:18 +01:00
Olaf Hartong
425c94fb7e
Delete add-on-for-microsoft-sysmon_605.tgz
2018-01-20 22:27:49 +01:00
Olaf Hartong
9a42d8729e
Delete add-on-for-microsoft-sysmon_600.tgz
2018-01-20 22:21:42 +01:00
Olaf Hartong
503b771314
newer sysmon TA
2018-01-20 22:21:14 +01:00
Chris Long
1577341ce9
Initial commit
2017-12-11 08:49:25 -08:00