Commit Graph

309 Commits

Author SHA1 Message Date
Chris Long 5b712a8f86 Filter AutorunsToWinEventlog invocation more widely 2020-08-13 14:14:36 -07:00
Chris Long 769dabf8a6 Update transforms.conf 2020-08-12 23:02:59 -07:00
Chris Long 83f5bf601c Add transforms to remove eventid description text 2020-08-12 23:02:33 -07:00
Chris Long 0bf5a631fa Filter out Splunk and osqueryd events 2020-08-12 23:01:06 -07:00
Chris Long 97c98f332b Update install-splunkuf.ps1 2020-08-12 20:27:38 -07:00
Chris Long d1f78d153f Update the Splunk UF 2020-08-12 20:27:26 -07:00
Chris Long 34889a8bb6 Many Splunk fixes, add sponsors list to README 2020-08-06 23:50:10 -07:00
Chris Long ec4c5d1483 Remove inputsconf 2020-08-05 13:38:46 -07:00
Chris Long 165ba4ae41 Fixing fix-second-network.ps1 2020-08-05 00:28:30 -07:00
Chris Long 84c29f6739 Fix sysmon sourcetype, update ThreatHunting app 2020-08-04 21:58:18 -07:00
Chris Long 3fc3119be2 Update bootstrap.sh 2020-08-02 23:43:58 -07:00
Chris Long 4a26eb6cf9 Update install-microsoft-ata.ps1 2020-08-02 19:49:27 -07:00
Chris Long 9085136f17 Insert hardcoded Velociraptor URL
Workaround for issue #497
2020-08-02 15:26:52 -07:00
Chris Long 77f0cb3025 Merge branch 'master' of https://github.com/clong/detectionlab 2020-07-27 22:20:02 -07:00
Chris Long fcb8001bbe ESXi fixes 2020-07-27 22:19:10 -07:00
Chris Long 6393da6c3a Update bootstrap.sh 2020-07-27 21:54:54 -07:00
Chris Long f68a8a4120 Fixing Velociraptor install 2020-07-26 17:43:21 -07:00
Chris Long 2058aae44e Re-fix threathunting app and update ESXi logger role 2020-07-26 15:24:26 -07:00
Chris Long cbaa7643d6 Actually comitting files 2020-07-26 14:47:09 -07:00
Ahmed Shawky f1299990b2 Point splunk to the right osquery path 2020-07-26 16:55:13 +04:00
Ahmed Shawky 2eec4ec46e Update fleet installer 2020-07-26 16:48:10 +04:00
Chris Long a163eb55d1 Updating build.ps1 and ThreatHunting app 2020-07-23 22:46:30 -07:00
Chris Long bf2b89275e Fixing Microsoft ATA on Azure 2020-07-20 17:19:17 -07:00
Chris Long 230e4ee882 Fixing dumb mistakes 2020-07-04 15:14:01 -07:00
Chris Long 2e678190d0 Fix velociraptor install on Ubuntu 2020-07-03 02:10:23 -07:00
Chris Long 8cc591b7d7 Add velociraptor 2020-07-03 01:55:19 -07:00
Chris Long dae906b421 More fixes 2020-06-25 23:37:01 -07:00
Chris Long 976b58f126 More linting errors fixed 2020-06-25 23:26:12 -07:00
Chris Long 21477e376a Fix lint errors, update packer files 2020-06-25 23:11:59 -07:00
Chris Long 5c22a8a2a4 Update fix-windows-expiration.ps1 2020-06-25 17:39:13 -07:00
Ahmed Shawky 54a84b8640 Make sure WinDefend service is not running when uninstalling Windows-Defender and Windows-Defender-Features features. 2020-06-25 04:22:55 +04:00
Chris Long ab5c0b2452 Standardize logging 2020-06-21 12:28:44 -07:00
Chris Long c735f52934 Fixing the loop logic 2020-06-21 11:49:18 -07:00
Chris Long ded6656cb7 Update operator 2020-06-21 09:16:50 -07:00
Chris Long 7858530c17 Remove from Ansible too 2020-06-21 00:28:38 -07:00
Chris Long 565ca261f1 Fix quote escaping 2020-06-20 23:51:10 -07:00
Chris Long d466f343c4 Fixing shellcheck lint output 2020-06-20 19:14:09 -07:00
Chris Long 8fca376f4a Merge branch 'master' into osquery_refactor 2020-06-20 18:34:28 -07:00
Chris Long bb12246e74 Refactor osquery and add retry-loop for OU 2020-06-20 18:32:28 -07:00
Chris Long 9e6670b1e2 Update fix-windows-expiration.ps1
Add try/catch for the regex matching
2020-06-20 16:32:55 -07:00
Chris Long 2708f4fa4e Update install-microsoft-ata.ps1
Add additional write-host statements
2020-06-15 00:53:35 -07:00
Chris Long a033ea2b60 Update configure-ou.ps1 2020-06-14 17:53:06 -07:00
Chris Long 7f837cbb1d Typos 2020-06-13 22:43:10 -07:00
Chris Long 1dbe8a75b2 Add a retry to configure-ou.ps1 2020-06-13 22:35:15 -07:00
Chris Long dfa0a09d43 Update create-domain.ps1 2020-06-13 21:50:00 -07:00
Chris Long f8cc4a9ec7 Update join-domain.ps1 2020-06-13 21:49:41 -07:00
Chris Long add22be68b Update create-domain.ps1
Don't change DNS settings for azure provisioning
2020-06-13 21:47:59 -07:00
Chris Long 69320e2b16 Update install-botsv3.sh
Add Splunk restart after app installation
2020-06-08 17:57:37 -07:00
Chris Long 74dda07942 Update ESXi bootstrap too 2020-06-01 22:53:36 -07:00
Chris Long 7dc7e6916c ESXi RAM Bump, osquery fixes 2020-06-01 22:51:14 -07:00