Ahmed Shawky
1a548c10d3
Merge remote-tracking branch 'upstream/master'
2020-03-15 09:51:33 +04:00
Ahmed Shawky
d4a9699cdd
Fix a typeo that stopped the Defender exclusions of \tools directory
2020-03-15 09:40:01 +04:00
Chris Long
e612709f4d
Whitespace formatting
2020-03-13 12:10:17 -07:00
Ahmed Shawky
c351643c8c
Make sure we have a DNS resolution when calling fix_eth1_static_ip.
2020-03-13 11:00:07 +04:00
Chris Long
068e9d8c05
Merge branch 'master' into ESXi
2020-03-09 14:46:54 -07:00
Chris Long
4e850a5ee6
Adding final ESXI deployment code
2020-03-09 14:42:58 -07:00
Chris Long
47d4696147
Update install-redteam.ps1
2020-03-09 00:49:32 -07:00
Chris Long
361b9b0b48
Adding exclusion folders to install-redteam.ps1
2020-03-07 23:11:44 -08:00
Chris Long
c630b88961
Removing reference to Invoke-AtomicRedTeam.psm1
...
Fixes https://github.com/clong/DetectionLab/issues/385
2020-03-07 20:02:25 -08:00
Chris Long
ac1d2499a2
Replace inline suricata.yaml edits with resource file
2020-03-01 22:32:26 -08:00
Chris Long
d1cc369e87
Adding www.splunk.com to DNS cache
...
Logger is sometimes failing to resolve www.splunk.com
2020-02-29 23:12:21 -08:00
Chris Long
16003bbd68
LibVirt fixes
2020-02-17 15:04:32 -08:00
Chris Long
2bd2f20776
Merge branch 'master' into libvirt_provider
2020-02-17 14:45:09 -08:00
Ahmed Shawky
fea8f35f0e
Force powershell to use TLS 1.2 as chocolatey.org throws a TLS error
2020-02-05 02:47:03 +04:00
Chris Long
43cc095193
Merge branch 'master' into libvirt_provider
2020-01-18 00:10:43 -08:00
Ahmed Shawky
fefbb9ac54
Fix a monir bug when importing windows-application-security osquery config into fleet.
2020-01-17 23:08:47 +04:00
Selora
2a6cb92f51
Libvirt provider
...
Adding Packer Qemu builder:
* Packer/answer_files/*_virtio: Install the virtio drivers from the ISO (NOT provided)
* windows_*.json needs some manual tweaks to match the virtio drivers ISO path
Adding Vagrant-libvirt provider:
* Uses the QEMU qcow2 images provided by packer to build the DetectionLab
* Vagrantfile needs manual tweaking to match libvirt's host configuration (backing store, network interfaces, etc)
README:
* Added separate README with instructions for libvirt
2020-01-15 17:28:54 +00:00
Chris Long
85563d7742
Fix issue #362
...
https://github.com/clong/DetectionLab/issues/362
2019-12-21 01:17:32 -08:00
Chris Long
b5c73ce647
Include Invoke-AtomicTest in Powershell
2019-12-20 23:46:35 -08:00
Chris Long
ffbca14bd0
Adding mirrors back
2019-12-20 18:03:48 -08:00
Chris Long
ba7004b283
Merge branch 'master' into ubuntu_upgrade
2019-12-20 15:51:01 -08:00
Chris Long
7e17727cbb
Logger bump to Ubuntu 18.04 & Migrate to Zeek
2019-12-20 15:48:13 -08:00
Chris Long
e4bb3c9a43
Update 20-detectionlab
2019-12-18 13:43:21 -08:00
Chris Long
0393d627ad
Convert ADSI:Exists to Get-ADOrganizationalUnit
2019-12-04 18:49:28 -08:00
Chris Long
4a8485c28e
Disable IPv6 on Windows adapters
2019-12-04 13:45:43 -08:00
Chris Long
f64ff20aaf
Disabling default windows inputs. Adding powershell command for event channel perms
2019-12-04 11:27:35 -08:00
Chris Long
249ce2ec76
Updating channel permissions for Microsoft-Windows-Sysmon
2019-12-03 22:18:20 -08:00
Chris Long
f3fa80299f
Adding rearm to each Windows host
2019-12-03 19:53:59 -08:00
Chris Long
ee9a1f87fd
Removing Splunk forwarder from Windows hosts
2019-12-03 00:42:02 -08:00
Chris Long
905eaca9fa
Adding Guacamole for multi-machine management
2019-11-19 21:01:19 -08:00
Chris Long
17e42182ef
Adding updated manifests
2019-11-11 23:11:36 -08:00
Chris Long
9f392c76cc
Re-create DC Auditing GPO. Update ThreatHunting Splunk App.
2019-11-11 23:01:57 -08:00
Chris Long
2b608addb0
Fixing issue #341
...
Add TLS1.2 support
2019-11-07 23:44:03 -08:00
Chris Long
0bd64eb04b
Updating bootstrap.sh
2019-11-06 22:13:19 -08:00
Chris Long
466b54e385
Installing yq via apt-get
...
Fixing the yq issue by using the apt repository
2019-11-04 22:43:25 -08:00
Chris Long
b0b124243b
Updating yq installation check
2019-11-01 08:43:21 -07:00
Chris Long
a9d743ef49
Addressing issue #329
...
Thanks to @protodroidbot for the fix!
2019-10-31 21:33:14 -07:00
Chris Long
84287c4c17
Updating bootstrap.sh to not install BOTSv2 by default
2019-09-30 20:32:19 -07:00
Mike Haag
2d5d6f508e
Add BOTS to Logger
...
This will add the BOTSv2 dataset to DetectionLab.
One app required for BOTS:
Splunk Stream - https://splunkbase.splunk.com/app/1809/
Recommended:
Boss of the SOC (BOTS) Advanced APT Hunting Companion App for Splunk - https://splunkbase.splunk.com/app/4430/
2019-09-05 10:02:05 -06:00
dtrizna
9bfcc8296c
Update Vagrantfile
2019-07-24 14:18:04 +03:00
dtrizna
9694416e33
Update Vagrantfile
2019-07-24 14:16:10 +03:00
Chris Long
a07e9cbaac
Fix bro-pkg issue
...
https://github.com/abiteboul
2019-07-20 23:44:19 -07:00
Chris Long
9cceafa28e
Update ThreatHunting app to 1.3.4
2019-07-20 00:49:35 -07:00
Chris Long
280bce8252
Updating bginfo.bgi to point to the correct .bmp
2019-07-08 00:41:32 -07:00
Chris Long
2480c27200
Remove Prebuilt Vagrantfile
2019-07-07 10:46:59 -07:00
Chris Long
f55b721da2
Remove debugging paths from Vagrantfile
2019-07-06 18:35:02 -07:00
Chris Long
df718b4408
Update to 1903
2019-07-06 18:29:29 -07:00
Sunny Neo
8d7bc4b9dc
Explicitly define the file directory
...
Osquery was not working with Fleet after deployment due to wrong directories.
The following command installs the osqueryd service with --flagfile=\ProgramData\osquery\osquery.flags" however osquery.flags found at "C:\Program Files\osquery\osquery.flags"
``` "c:\Program Files\osquery\osqueryd\osqueryd.exe" -ArgumentList "--install" -Wait
```
The original osquery.flags defines the certfile.crt to be in "C:\programdata\osquery", it should be in "c:\Program Files\osquery\" instead.
2019-06-16 22:56:11 +08:00
Chris Long
95d1fb31f4
Updating ASNGen App
2019-06-09 17:53:21 -07:00
Chris Long
e9ccc17e17
Revert Vagrantfile changes
2019-05-26 21:37:24 -07:00