Chris Long 
							
						 
					 
					
						
						
							
						
						ff3e595235 
					 
					
						
						
							
							Adding ATA to Packer image, adding evtx-attack-samples  
						
						
						
						
					 
					
						2020-09-29 17:36:32 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						aa51e77663 
					 
					
						
						
							
							nits  
						
						
						
						
					 
					
						2020-09-23 23:58:06 -07:00 
						 
				 
			
				
					
						
							
							
								p-zim 
							
						 
					 
					
						
						
							
						
						ccb39ea145 
					 
					
						
						
							
							Update install-redteam.ps1  
						
						... 
						
						
						
						PurpleSharp part throws an error and Vagrant stops since the script did not check if the PurpleSharp folder was already existing when for example re-running "vagrant reload dc --provision" 
						
						
					 
					
						2020-09-24 00:05:37 +02:00 
						 
				 
			
				
					
						
							
							
								Ahmed Shawky 
							
						 
					 
					
						
						
							
						
						779bb91bf5 
					 
					
						
						
							
							Add a logrotate config for Suricata  
						
						
						
						
					 
					
						2020-09-22 02:49:07 +00:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						7c539edcc7 
					 
					
						
						
							
							Update provision.ps1  
						
						
						
						
					 
					
						2020-09-20 21:13:50 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						cc63e1dfb1 
					 
					
						
						
							
							Update bootstrap.sh  
						
						
						
						
					 
					
						2020-09-20 21:11:14 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						e3365d827a 
					 
					
						
						
							
							Improve velociraptor release URL resolution  
						
						... 
						
						
						
						The Velociraptor project sometimes creates releases that don't follow a URL convention and add a "-1" to the build number and URL. This update should help handle those cases. 
						
						
					 
					
						2020-09-16 15:46:27 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						086df6f534 
					 
					
						
						
							
							Update ESXI netplan, de-hardcode Velociraptor URL  
						
						
						
						
					 
					
						2020-09-07 23:19:04 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						59374ca601 
					 
					
						
						
							
							Merge branch 'master' into add-hyperv  
						
						
						
						
					 
					
						2020-08-28 14:21:52 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						52599dffdc 
					 
					
						
						
							
							Adding in check for both Vbox and VMware being installed  
						
						
						
						
					 
					
						2020-08-27 21:31:42 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						2b3c3ba624 
					 
					
						
						
							
							Fix typo  
						
						
						
						
					 
					
						2020-08-27 19:54:43 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						bee5d4ce1b 
					 
					
						
						
							
							Replace build scripts with prepare scripts  
						
						
						
						
					 
					
						2020-08-27 18:14:41 -07:00 
						 
				 
			
				
					
						
							
							
								man715 
							
						 
					 
					
						
						
							
						
						85a5990b2f 
					 
					
						
						
							
							Copy the Splunk app to the temp directory of the VM before installing.  
						
						
						
						
					 
					
						2020-08-25 13:01:39 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						4ed4d9ed4a 
					 
					
						
						
							
							Update detectionlab.com endpoint  
						
						
						
						
					 
					
						2020-08-15 23:29:04 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						25e8ce0b22 
					 
					
						
						
							
							Whitespace  
						
						
						
						
					 
					
						2020-08-14 01:36:10 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						1c35d1b39e 
					 
					
						
						
							
							Reverting the UF update  
						
						
						
						
					 
					
						2020-08-14 01:35:46 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						5b712a8f86 
					 
					
						
						
							
							Filter AutorunsToWinEventlog invocation more widely  
						
						
						
						
					 
					
						2020-08-13 14:14:36 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						769dabf8a6 
					 
					
						
						
							
							Update transforms.conf  
						
						
						
						
					 
					
						2020-08-12 23:02:59 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						83f5bf601c 
					 
					
						
						
							
							Add transforms to remove eventid description text  
						
						
						
						
					 
					
						2020-08-12 23:02:33 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						0bf5a631fa 
					 
					
						
						
							
							Filter out Splunk and osqueryd events  
						
						
						
						
					 
					
						2020-08-12 23:01:06 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						97c98f332b 
					 
					
						
						
							
							Update install-splunkuf.ps1  
						
						
						
						
					 
					
						2020-08-12 20:27:38 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						d1f78d153f 
					 
					
						
						
							
							Update the Splunk UF  
						
						
						
						
					 
					
						2020-08-12 20:27:26 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						34889a8bb6 
					 
					
						
						
							
							Many Splunk fixes, add sponsors list to README  
						
						
						
						
					 
					
						2020-08-06 23:50:10 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						ec4c5d1483 
					 
					
						
						
							
							Remove inputsconf  
						
						
						
						
					 
					
						2020-08-05 13:38:46 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						165ba4ae41 
					 
					
						
						
							
							Fixing fix-second-network.ps1  
						
						
						
						
					 
					
						2020-08-05 00:28:30 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						84c29f6739 
					 
					
						
						
							
							Fix sysmon sourcetype, update ThreatHunting app  
						
						
						
						
					 
					
						2020-08-04 21:58:18 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						3fc3119be2 
					 
					
						
						
							
							Update bootstrap.sh  
						
						
						
						
					 
					
						2020-08-02 23:43:58 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						4a26eb6cf9 
					 
					
						
						
							
							Update install-microsoft-ata.ps1  
						
						
						
						
					 
					
						2020-08-02 19:49:27 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						9085136f17 
					 
					
						
						
							
							Insert hardcoded Velociraptor URL  
						
						... 
						
						
						
						Workaround for issue #497  
						
						
					 
					
						2020-08-02 15:26:52 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						77f0cb3025 
					 
					
						
						
							
							Merge branch 'master' of  https://github.com/clong/detectionlab  
						
						
						
						
					 
					
						2020-07-27 22:20:02 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						fcb8001bbe 
					 
					
						
						
							
							ESXi fixes  
						
						
						
						
					 
					
						2020-07-27 22:19:10 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						6393da6c3a 
					 
					
						
						
							
							Update bootstrap.sh  
						
						
						
						
					 
					
						2020-07-27 21:54:54 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						f68a8a4120 
					 
					
						
						
							
							Fixing Velociraptor install  
						
						
						
						
					 
					
						2020-07-26 17:43:21 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						2058aae44e 
					 
					
						
						
							
							Re-fix threathunting app and update ESXi logger role  
						
						
						
						
					 
					
						2020-07-26 15:24:26 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						cbaa7643d6 
					 
					
						
						
							
							Actually comitting files  
						
						
						
						
					 
					
						2020-07-26 14:47:09 -07:00 
						 
				 
			
				
					
						
							
							
								Ahmed Shawky 
							
						 
					 
					
						
						
							
						
						f1299990b2 
					 
					
						
						
							
							Point splunk to the right osquery path  
						
						
						
						
					 
					
						2020-07-26 16:55:13 +04:00 
						 
				 
			
				
					
						
							
							
								Ahmed Shawky 
							
						 
					 
					
						
						
							
						
						2eec4ec46e 
					 
					
						
						
							
							Update fleet installer  
						
						
						
						
					 
					
						2020-07-26 16:48:10 +04:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						a163eb55d1 
					 
					
						
						
							
							Updating build.ps1 and ThreatHunting app  
						
						
						
						
					 
					
						2020-07-23 22:46:30 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						bf2b89275e 
					 
					
						
						
							
							Fixing Microsoft ATA on Azure  
						
						
						
						
					 
					
						2020-07-20 17:19:17 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						230e4ee882 
					 
					
						
						
							
							Fixing dumb mistakes  
						
						
						
						
					 
					
						2020-07-04 15:14:01 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						2e678190d0 
					 
					
						
						
							
							Fix velociraptor install on Ubuntu  
						
						
						
						
					 
					
						2020-07-03 02:10:23 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						8cc591b7d7 
					 
					
						
						
							
							Add velociraptor  
						
						
						
						
					 
					
						2020-07-03 01:55:19 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						dae906b421 
					 
					
						
						
							
							More fixes  
						
						
						
						
					 
					
						2020-06-25 23:37:01 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						976b58f126 
					 
					
						
						
							
							More linting errors fixed  
						
						
						
						
					 
					
						2020-06-25 23:26:12 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						21477e376a 
					 
					
						
						
							
							Fix lint errors, update packer files  
						
						
						
						
					 
					
						2020-06-25 23:11:59 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						5c22a8a2a4 
					 
					
						
						
							
							Update fix-windows-expiration.ps1  
						
						
						
						
					 
					
						2020-06-25 17:39:13 -07:00 
						 
				 
			
				
					
						
							
							
								Ahmed Shawky 
							
						 
					 
					
						
						
							
						
						54a84b8640 
					 
					
						
						
							
							Make sure WinDefend service is not running when uninstalling Windows-Defender and Windows-Defender-Features features.  
						
						
						
						
					 
					
						2020-06-25 04:22:55 +04:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						ab5c0b2452 
					 
					
						
						
							
							Standardize logging  
						
						
						
						
					 
					
						2020-06-21 12:28:44 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						c735f52934 
					 
					
						
						
							
							Fixing the loop logic  
						
						
						
						
					 
					
						2020-06-21 11:49:18 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						ded6656cb7 
					 
					
						
						
							
							Update operator  
						
						
						
						
					 
					
						2020-06-21 09:16:50 -07:00