Chris Long 
							
						 
					 
					
						
						
							
						
						8cc591b7d7 
					 
					
						
						
							
							Add velociraptor  
						
						
						
						
					 
					
						2020-07-03 01:55:19 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						2823f140d2 
					 
					
						
						
							
							Update props.conf  
						
						
						
						
					 
					
						2020-06-01 21:47:32 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						c55b3d6def 
					 
					
						
						
							
							Update transforms.conf  
						
						
						
						
					 
					
						2020-06-01 21:46:22 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						10f260bf73 
					 
					
						
						
							
							Update logger_dashboard.xml  
						
						
						
						
					 
					
						2020-06-01 01:21:22 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						23e8e288f9 
					 
					
						
						
							
							Merge branch 'master' into update_gpo_ena  
						
						
						
						
					 
					
						2020-05-03 17:13:59 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						aeecd1b756 
					 
					
						
						
							
							Update DC Auditing GPO and Add Packer Script for ENA  
						
						
						
						
					 
					
						2020-05-03 17:12:05 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						f0a7b1481f 
					 
					
						
						
							
							Typo  
						
						
						
						
					 
					
						2020-05-02 22:21:24 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						b314066e06 
					 
					
						
						
							
							Fixing Splunk regex  
						
						
						
						
					 
					
						2020-05-02 22:20:48 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						d1d0566773 
					 
					
						
						
							
							Add some Splunk nullQueues for noisy events  
						
						
						
						
					 
					
						2020-04-18 15:59:54 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						03c96430a5 
					 
					
						
						
							
							Merge branch 'master' into logger_bugfix  
						
						
						
						
					 
					
						2020-04-13 00:09:52 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						a67ce6efb5 
					 
					
						
						
							
							Fixing logger bugs, updating vm tools, updating Win10 ISO  
						
						
						
						
					 
					
						2020-04-13 00:05:49 -07:00 
						 
				 
			
				
					
						
							
							
								Mike Haag 
							
						 
					 
					
						
						
							
						
						2b37af791d 
					 
					
						
						
							
							Bootstrap.sh Error fixes  
						
						... 
						
						
						
						Errors during install:
-     logger: Error during app install: failed to extract app from /vagrant/resources/splunk_forwarder/splunk-add-on-for-microsoft-windows_700.tgz to /opt/splunk/var/run/splunk/bundle_tmp/2ade41e05f0e68dc: No such file or directory
-     logger: Error during app install: failed to extract app from /vagrant/resources/splunk_server/add-on-for-microsoft-sysmon_1062.tgz to /opt/splunk/var/run/splunk/bundle_tmp/eeef7b83a2d6b716: No such file or directory
1. Fixed the forwarder error by placing the updated TA in the forwarder path.
2. fixed server error, this was caused by a typo in the name. 
						
						
					 
					
						2020-04-06 09:04:23 -06:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						fd804a083d 
					 
					
						
						
							
							Fixing the Splunk nullqueue  
						
						
						
						
					 
					
						2020-03-28 02:30:06 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						34d8a39c43 
					 
					
						
						
							
							Multiple bugfixes, add dashboard  
						
						
						
						
					 
					
						2020-03-27 14:53:04 -07:00 
						 
				 
			
				
					
						
							
							
								Mike Haag 
							
						 
					 
					
						
						
							
						
						852f20af57 
					 
					
						
						
							
							Adding BOTSv3 and Updating Apps  
						
						
						
						
					 
					
						2020-03-19 09:39:58 -06:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						7e17727cbb 
					 
					
						
						
							
							Logger bump to Ubuntu 18.04 & Migrate to Zeek  
						
						
						
						
					 
					
						2019-12-20 15:48:13 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						9f392c76cc 
					 
					
						
						
							
							Re-create DC Auditing GPO. Update ThreatHunting Splunk App.  
						
						
						
						
					 
					
						2019-11-11 23:01:57 -08:00 
						 
				 
			
				
					
						
							
							
								Mike Haag 
							
						 
					 
					
						
						
							
						
						2d5d6f508e 
					 
					
						
						
							
							Add BOTS to Logger  
						
						... 
						
						
						
						This will add the BOTSv2 dataset to DetectionLab.
One app required for BOTS:
Splunk Stream - https://splunkbase.splunk.com/app/1809/ 
Recommended:
Boss of the SOC (BOTS) Advanced APT Hunting Companion App for Splunk -  https://splunkbase.splunk.com/app/4430/  
						
						
					 
					
						2019-09-05 10:02:05 -06:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						9cceafa28e 
					 
					
						
						
							
							Update ThreatHunting app to 1.3.4  
						
						
						
						
					 
					
						2019-07-20 00:49:35 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						95d1fb31f4 
					 
					
						
						
							
							Updating ASNGen App  
						
						
						
						
					 
					
						2019-06-09 17:53:21 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						e78c312bc5 
					 
					
						
						
							
							Actually add files  
						
						
						
						
					 
					
						2019-05-26 21:36:10 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						cd722dab8b 
					 
					
						
						
							
							Fix ThreatHunting App, add Lookup Editor, Update VM tools  
						
						
						
						
					 
					
						2019-05-26 21:34:45 -07:00 
						 
				 
			
				
					
						
							
							
								Olaf Hartong 
							
						 
					 
					
						
						
							
						
						7916fd1818 
					 
					
						
						
							
							added v1.3.2  
						
						
						
						
					 
					
						2019-05-19 22:33:01 +02:00 
						 
				 
			
				
					
						
							
							
								Olaf Hartong 
							
						 
					 
					
						
						
							
						
						04bbd7d25e 
					 
					
						
						
							
							Updated ThreatHunting app to 1.3  
						
						
						
						
					 
					
						2019-05-19 21:06:04 +02:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						93183a95e2 
					 
					
						
						
							
							Update Splunk apps, create vagrantfile_minimum, bugfixes  
						
						
						
						
					 
					
						2019-03-01 22:45:37 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						020af3c936 
					 
					
						
						
							
							Add ShutUp10, Upgrade Vagrant, Issue 12  
						
						
						
						
					 
					
						2019-02-18 21:47:03 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						8b9178685a 
					 
					
						
						
							
							Adding Olaf's Threat Hunting App. Fixes. Updates.  
						
						
						
						
					 
					
						2018-12-11 00:52:46 -08:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						9a82f140f4 
					 
					
						
						
							
							Actually add the app  
						
						
						
						
					 
					
						2018-09-07 14:58:11 -07:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						ca7dec8eb1 
					 
					
						
						
							
							Updating build scripts to use vmware_desktop, update TA's, update bootstrap  
						
						
						
						
					 
					
						2018-07-20 22:28:44 -07:00 
						 
				 
			
				
					
						
							
							
								Olaf Hartong 
							
						 
					 
					
						
						
							
						
						c9b826fcf4 
					 
					
						
						
							
							newer Splunk Sysmon TA  
						
						
						
						
					 
					
						2018-01-20 22:28:18 +01:00 
						 
				 
			
				
					
						
							
							
								Olaf Hartong 
							
						 
					 
					
						
						
							
						
						425c94fb7e 
					 
					
						
						
							
							Delete add-on-for-microsoft-sysmon_605.tgz  
						
						
						
						
					 
					
						2018-01-20 22:27:49 +01:00 
						 
				 
			
				
					
						
							
							
								Olaf Hartong 
							
						 
					 
					
						
						
							
						
						9a42d8729e 
					 
					
						
						
							
							Delete add-on-for-microsoft-sysmon_600.tgz  
						
						
						
						
					 
					
						2018-01-20 22:21:42 +01:00 
						 
				 
			
				
					
						
							
							
								Olaf Hartong 
							
						 
					 
					
						
						
							
						
						503b771314 
					 
					
						
						
							
							newer sysmon TA  
						
						
						
						
					 
					
						2018-01-20 22:21:14 +01:00 
						 
				 
			
				
					
						
							
							
								Chris Long 
							
						 
					 
					
						
						
							
						
						1577341ce9 
					 
					
						
						
							
							Initial commit  
						
						
						
						
					 
					
						2017-12-11 08:49:25 -08:00