Ahmed Shawky 
							
						 
					 
					
						
						
							
						
						d4a9699cdd 
					 
					
						
						
							
							Fix a typeo that stopped the Defender exclusions of \tools directory  
						
						
						
						
					 
					
						2020-03-15 09:40:01 +04:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						e612709f4d 
					 
					
						
						
							
							Whitespace formatting  
						
						
						
						
					 
					
						2020-03-13 12:10:17 -07:00 
						 
				 
			
				
					
						
							
							
								Ahmed Shawky 
							
						 
					 
					
						
						
							
						
						c351643c8c 
					 
					
						
						
							
							Make sure we have a DNS resolution when calling fix_eth1_static_ip.  
						
						
						
						
					 
					
						2020-03-13 11:00:07 +04:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						068e9d8c05 
					 
					
						
						
							
							Merge branch 'master' into ESXi  
						
						
						
						
					 
					
						2020-03-09 14:46:54 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						4e850a5ee6 
					 
					
						
						
							
							Adding final ESXI deployment code  
						
						
						
						
					 
					
						2020-03-09 14:42:58 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						47d4696147 
					 
					
						
						
							
							Update install-redteam.ps1  
						
						
						
						
					 
					
						2020-03-09 00:49:32 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						361b9b0b48 
					 
					
						
						
							
							Adding exclusion folders to install-redteam.ps1  
						
						
						
						
					 
					
						2020-03-07 23:11:44 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						c630b88961 
					 
					
						
						
							
							Removing reference to Invoke-AtomicRedTeam.psm1  
						
						... 
						
						
						
						Fixes https://github.com/clong/DetectionLab/issues/385  
						
						
					 
					
						2020-03-07 20:02:25 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						ac1d2499a2 
					 
					
						
						
							
							Replace inline suricata.yaml edits with resource file  
						
						
						
						
					 
					
						2020-03-01 22:32:26 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						d1cc369e87 
					 
					
						
						
							
							Adding www.splunk.com to DNS cache  
						
						... 
						
						
						
						Logger is sometimes failing to resolve www.splunk.com 
						
						
					 
					
						2020-02-29 23:12:21 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						16003bbd68 
					 
					
						
						
							
							LibVirt fixes  
						
						
						
						
					 
					
						2020-02-17 15:04:32 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						2bd2f20776 
					 
					
						
						
							
							Merge branch 'master' into libvirt_provider  
						
						
						
						
					 
					
						2020-02-17 14:45:09 -08:00 
						 
				 
			
				
					
						
							
							
								Ahmed Shawky 
							
						 
					 
					
						
						
							
						
						fea8f35f0e 
					 
					
						
						
							
							Force powershell to use TLS 1.2 as chocolatey.org throws a TLS error  
						
						
						
						
					 
					
						2020-02-05 02:47:03 +04:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						43cc095193 
					 
					
						
						
							
							Merge branch 'master' into libvirt_provider  
						
						
						
						
					 
					
						2020-01-18 00:10:43 -08:00 
						 
				 
			
				
					
						
							
							
								Ahmed Shawky 
							
						 
					 
					
						
						
							
						
						fefbb9ac54 
					 
					
						
						
							
							Fix a monir bug when importing windows-application-security osquery config into fleet.  
						
						
						
						
					 
					
						2020-01-17 23:08:47 +04:00 
						 
				 
			
				
					
						
							
							
								Selora 
							
						 
					 
					
						
						
							
						
						2a6cb92f51 
					 
					
						
						
							
							Libvirt provider  
						
						... 
						
						
						
						Adding Packer Qemu builder:
* Packer/answer_files/*_virtio: Install the virtio drivers from the ISO (NOT provided)
* windows_*.json needs some manual tweaks to match the virtio drivers ISO path
Adding Vagrant-libvirt provider:
* Uses the QEMU qcow2 images provided by packer to build the DetectionLab
* Vagrantfile needs manual tweaking to match libvirt's host configuration (backing store, network interfaces, etc)
README:
* Added separate README with instructions for libvirt 
						
						
					 
					
						2020-01-15 17:28:54 +00:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						85563d7742 
					 
					
						
						
							
							Fix issue  #362  
						
						... 
						
						
						
						https://github.com/clong/DetectionLab/issues/362  
					
						2019-12-21 01:17:32 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						b5c73ce647 
					 
					
						
						
							
							Include Invoke-AtomicTest in Powershell  
						
						
						
						
					 
					
						2019-12-20 23:46:35 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						ffbca14bd0 
					 
					
						
						
							
							Adding mirrors back  
						
						
						
						
					 
					
						2019-12-20 18:03:48 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						ba7004b283 
					 
					
						
						
							
							Merge branch 'master' into ubuntu_upgrade  
						
						
						
						
					 
					
						2019-12-20 15:51:01 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						7e17727cbb 
					 
					
						
						
							
							Logger bump to Ubuntu 18.04 & Migrate to Zeek  
						
						
						
						
					 
					
						2019-12-20 15:48:13 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						e4bb3c9a43 
					 
					
						
						
							
							Update 20-detectionlab  
						
						
						
						
					 
					
						2019-12-18 13:43:21 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						0393d627ad 
					 
					
						
						
							
							Convert ADSI:Exists to Get-ADOrganizationalUnit  
						
						
						
						
					 
					
						2019-12-04 18:49:28 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						4a8485c28e 
					 
					
						
						
							
							Disable IPv6 on Windows adapters  
						
						
						
						
					 
					
						2019-12-04 13:45:43 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						f64ff20aaf 
					 
					
						
						
							
							Disabling default windows inputs. Adding powershell command for event channel perms  
						
						
						
						
					 
					
						2019-12-04 11:27:35 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						249ce2ec76 
					 
					
						
						
							
							Updating channel permissions for Microsoft-Windows-Sysmon  
						
						
						
						
					 
					
						2019-12-03 22:18:20 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						f3fa80299f 
					 
					
						
						
							
							Adding rearm to each Windows host  
						
						
						
						
					 
					
						2019-12-03 19:53:59 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						ee9a1f87fd 
					 
					
						
						
							
							Removing Splunk forwarder from Windows hosts  
						
						
						
						
					 
					
						2019-12-03 00:42:02 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						905eaca9fa 
					 
					
						
						
							
							Adding Guacamole for multi-machine management  
						
						
						
						
					 
					
						2019-11-19 21:01:19 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						17e42182ef 
					 
					
						
						
							
							Adding updated manifests  
						
						
						
						
					 
					
						2019-11-11 23:11:36 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						9f392c76cc 
					 
					
						
						
							
							Re-create DC Auditing GPO. Update ThreatHunting Splunk App.  
						
						
						
						
					 
					
						2019-11-11 23:01:57 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						2b608addb0 
					 
					
						
						
							
							Fixing issue  #341  
						
						... 
						
						
						
						Add TLS1.2 support 
						
						
					 
					
						2019-11-07 23:44:03 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						0bd64eb04b 
					 
					
						
						
							
							Updating bootstrap.sh  
						
						
						
						
					 
					
						2019-11-06 22:13:19 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						466b54e385 
					 
					
						
						
							
							Installing yq via apt-get  
						
						... 
						
						
						
						Fixing the yq issue by using the apt repository 
						
						
					 
					
						2019-11-04 22:43:25 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						b0b124243b 
					 
					
						
						
							
							Updating yq installation check  
						
						
						
						
					 
					
						2019-11-01 08:43:21 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						a9d743ef49 
					 
					
						
						
							
							Addressing issue  #329  
						
						... 
						
						
						
						Thanks to @protodroidbot for the fix! 
						
						
					 
					
						2019-10-31 21:33:14 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						84287c4c17 
					 
					
						
						
							
							Updating bootstrap.sh to not install BOTSv2 by default  
						
						
						
						
					 
					
						2019-09-30 20:32:19 -07:00 
						 
				 
			
				
					
						
							
							
								Mike Haag 
							
						 
					 
					
						
						
							
						
						2d5d6f508e 
					 
					
						
						
							
							Add BOTS to Logger  
						
						... 
						
						
						
						This will add the BOTSv2 dataset to DetectionLab.
One app required for BOTS:
Splunk Stream - https://splunkbase.splunk.com/app/1809/ 
Recommended:
Boss of the SOC (BOTS) Advanced APT Hunting Companion App for Splunk -  https://splunkbase.splunk.com/app/4430/  
						
						
					 
					
						2019-09-05 10:02:05 -06:00 
						 
				 
			
				
					
						
							
							
								dtrizna 
							
						 
					 
					
						
						
							
						
						9bfcc8296c 
					 
					
						
						
							
							Update Vagrantfile  
						
						
						
						
					 
					
						2019-07-24 14:18:04 +03:00 
						 
				 
			
				
					
						
							
							
								dtrizna 
							
						 
					 
					
						
						
							
						
						9694416e33 
					 
					
						
						
							
							Update Vagrantfile  
						
						
						
						
					 
					
						2019-07-24 14:16:10 +03:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						a07e9cbaac 
					 
					
						
						
							
							Fix bro-pkg issue  
						
						... 
						
						
						
						https://github.com/abiteboul  
					
						2019-07-20 23:44:19 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						9cceafa28e 
					 
					
						
						
							
							Update ThreatHunting app to 1.3.4  
						
						
						
						
					 
					
						2019-07-20 00:49:35 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						280bce8252 
					 
					
						
						
							
							Updating bginfo.bgi to point to the correct .bmp  
						
						
						
						
					 
					
						2019-07-08 00:41:32 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						2480c27200 
					 
					
						
						
							
							Remove Prebuilt Vagrantfile  
						
						
						
						
					 
					
						2019-07-07 10:46:59 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						f55b721da2 
					 
					
						
						
							
							Remove debugging paths from Vagrantfile  
						
						
						
						
					 
					
						2019-07-06 18:35:02 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						df718b4408 
					 
					
						
						
							
							Update to 1903  
						
						
						
						
					 
					
						2019-07-06 18:29:29 -07:00 
						 
				 
			
				
					
						
							
							
								Sunny Neo 
							
						 
					 
					
						
						
							
						
						8d7bc4b9dc 
					 
					
						
						
							
							Explicitly define the file directory  
						
						... 
						
						
						
						Osquery was not working with Fleet after deployment due to wrong directories. 
The following command installs the osqueryd service with --flagfile=\ProgramData\osquery\osquery.flags" however osquery.flags found at "C:\Program Files\osquery\osquery.flags" 
``` "c:\Program Files\osquery\osqueryd\osqueryd.exe" -ArgumentList "--install" -Wait  
```
The original osquery.flags defines the certfile.crt to be in "C:\programdata\osquery", it should be in  "c:\Program Files\osquery\" instead. 
						
						
					 
					
						2019-06-16 22:56:11 +08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						95d1fb31f4 
					 
					
						
						
							
							Updating ASNGen App  
						
						
						
						
					 
					
						2019-06-09 17:53:21 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						e9ccc17e17 
					 
					
						
						
							
							Revert Vagrantfile changes  
						
						
						
						
					 
					
						2019-05-26 21:37:24 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						e78c312bc5 
					 
					
						
						
							
							Actually add files  
						
						
						
						
					 
					
						2019-05-26 21:36:10 -07:00