Chris Long and GitHub
e612709f4d
Whitespace formatting
2020-03-13 12:10:17 -07:00
Ahmed Shawky
c351643c8c
Make sure we have a DNS resolution when calling fix_eth1_static_ip.
2020-03-13 11:00:07 +04:00
Chris Long and GitHub
068e9d8c05
Merge branch 'master' into ESXi
2020-03-09 14:46:54 -07:00
Chris Long
4e850a5ee6
Adding final ESXI deployment code
2020-03-09 14:42:58 -07:00
Chris Long and GitHub
47d4696147
Update install-redteam.ps1
2020-03-09 00:49:32 -07:00
Chris Long and GitHub
361b9b0b48
Adding exclusion folders to install-redteam.ps1
2020-03-07 23:11:44 -08:00
Chris Long and GitHub
c630b88961
Removing reference to Invoke-AtomicRedTeam.psm1
...
Fixes https://github.com/clong/DetectionLab/issues/385
2020-03-07 20:02:25 -08:00
Chris Long
ac1d2499a2
Replace inline suricata.yaml edits with resource file
2020-03-01 22:32:26 -08:00
Chris Long and GitHub
d1cc369e87
Adding www.splunk.com to DNS cache
...
Logger is sometimes failing to resolve www.splunk.com
2020-02-29 23:12:21 -08:00
Chris Long
16003bbd68
LibVirt fixes
2020-02-17 15:04:32 -08:00
Chris Long and GitHub
2bd2f20776
Merge branch 'master' into libvirt_provider
2020-02-17 14:45:09 -08:00
Ahmed Shawky
fea8f35f0e
Force powershell to use TLS 1.2 as chocolatey.org throws a TLS error
2020-02-05 02:47:03 +04:00
Chris Long and GitHub
43cc095193
Merge branch 'master' into libvirt_provider
2020-01-18 00:10:43 -08:00
Ahmed Shawky
fefbb9ac54
Fix a monir bug when importing windows-application-security osquery config into fleet.
2020-01-17 23:08:47 +04:00
Seloraand Selora
2a6cb92f51
Libvirt provider
...
Adding Packer Qemu builder:
* Packer/answer_files/*_virtio: Install the virtio drivers from the ISO (NOT provided)
* windows_*.json needs some manual tweaks to match the virtio drivers ISO path
Adding Vagrant-libvirt provider:
* Uses the QEMU qcow2 images provided by packer to build the DetectionLab
* Vagrantfile needs manual tweaking to match libvirt's host configuration (backing store, network interfaces, etc)
README:
* Added separate README with instructions for libvirt
2020-01-15 17:28:54 +00:00
Chris Long and GitHub
85563d7742
Fix issue #362
...
https://github.com/clong/DetectionLab/issues/362
2019-12-21 01:17:32 -08:00
Chris Long
b5c73ce647
Include Invoke-AtomicTest in Powershell
2019-12-20 23:46:35 -08:00
Chris Long and GitHub
ffbca14bd0
Adding mirrors back
2019-12-20 18:03:48 -08:00
Chris Long and GitHub
ba7004b283
Merge branch 'master' into ubuntu_upgrade
2019-12-20 15:51:01 -08:00
Chris Long
7e17727cbb
Logger bump to Ubuntu 18.04 & Migrate to Zeek
2019-12-20 15:48:13 -08:00
Chris Long and GitHub
e4bb3c9a43
Update 20-detectionlab
2019-12-18 13:43:21 -08:00
Chris Long
0393d627ad
Convert ADSI:Exists to Get-ADOrganizationalUnit
2019-12-04 18:49:28 -08:00
Chris Long
4a8485c28e
Disable IPv6 on Windows adapters
2019-12-04 13:45:43 -08:00
Chris Long
f64ff20aaf
Disabling default windows inputs. Adding powershell command for event channel perms
2019-12-04 11:27:35 -08:00
Chris Long
249ce2ec76
Updating channel permissions for Microsoft-Windows-Sysmon
2019-12-03 22:18:20 -08:00
Chris Long
f3fa80299f
Adding rearm to each Windows host
2019-12-03 19:53:59 -08:00
Chris Long
ee9a1f87fd
Removing Splunk forwarder from Windows hosts
2019-12-03 00:42:02 -08:00
Chris Long
905eaca9fa
Adding Guacamole for multi-machine management
2019-11-19 21:01:19 -08:00
Chris Long
17e42182ef
Adding updated manifests
2019-11-11 23:11:36 -08:00
Chris Long
9f392c76cc
Re-create DC Auditing GPO. Update ThreatHunting Splunk App.
2019-11-11 23:01:57 -08:00
Chris Long and GitHub
2b608addb0
Fixing issue #341
...
Add TLS1.2 support
2019-11-07 23:44:03 -08:00
Chris Long
0bd64eb04b
Updating bootstrap.sh
2019-11-06 22:13:19 -08:00
Chris Long and GitHub
466b54e385
Installing yq via apt-get
...
Fixing the yq issue by using the apt repository
2019-11-04 22:43:25 -08:00
Chris Long and GitHub
b0b124243b
Updating yq installation check
2019-11-01 08:43:21 -07:00
Chris Long and GitHub
a9d743ef49
Addressing issue #329
...
Thanks to @protodroidbot for the fix!
2019-10-31 21:33:14 -07:00
Chris Long
84287c4c17
Updating bootstrap.sh to not install BOTSv2 by default
2019-09-30 20:32:19 -07:00
Mike Haag
2d5d6f508e
Add BOTS to Logger
...
This will add the BOTSv2 dataset to DetectionLab.
One app required for BOTS:
Splunk Stream - https://splunkbase.splunk.com/app/1809/
Recommended:
Boss of the SOC (BOTS) Advanced APT Hunting Companion App for Splunk - https://splunkbase.splunk.com/app/4430/
2019-09-05 10:02:05 -06:00
dtrizna and GitHub
9bfcc8296c
Update Vagrantfile
2019-07-24 14:18:04 +03:00
dtrizna and GitHub
9694416e33
Update Vagrantfile
2019-07-24 14:16:10 +03:00
Chris Long and GitHub
a07e9cbaac
Fix bro-pkg issue
...
https://github.com/abiteboul
2019-07-20 23:44:19 -07:00
Chris Long
9cceafa28e
Update ThreatHunting app to 1.3.4
2019-07-20 00:49:35 -07:00
Chris Long
280bce8252
Updating bginfo.bgi to point to the correct .bmp
2019-07-08 00:41:32 -07:00
Chris Long
2480c27200
Remove Prebuilt Vagrantfile
2019-07-07 10:46:59 -07:00
Chris Long
f55b721da2
Remove debugging paths from Vagrantfile
2019-07-06 18:35:02 -07:00
Chris Long
df718b4408
Update to 1903
2019-07-06 18:29:29 -07:00
Sunny Neo and GitHub
8d7bc4b9dc
Explicitly define the file directory
...
Osquery was not working with Fleet after deployment due to wrong directories.
The following command installs the osqueryd service with --flagfile=\ProgramData\osquery\osquery.flags" however osquery.flags found at "C:\Program Files\osquery\osquery.flags"
``` "c:\Program Files\osquery\osqueryd\osqueryd.exe" -ArgumentList "--install" -Wait
```
The original osquery.flags defines the certfile.crt to be in "C:\programdata\osquery", it should be in "c:\Program Files\osquery\" instead.
2019-06-16 22:56:11 +08:00
Chris Long
95d1fb31f4
Updating ASNGen App
2019-06-09 17:53:21 -07:00
Chris Long
e9ccc17e17
Revert Vagrantfile changes
2019-05-26 21:37:24 -07:00
Chris Long
e78c312bc5
Actually add files
2019-05-26 21:36:10 -07:00
Chris Long
cd722dab8b
Fix ThreatHunting App, add Lookup Editor, Update VM tools
2019-05-26 21:34:45 -07:00