Chris Long
976b58f126
More linting errors fixed
2020-06-25 23:26:12 -07:00
Chris Long
21477e376a
Fix lint errors, update packer files
2020-06-25 23:11:59 -07:00
Chris Long
7858530c17
Remove from Ansible too
2020-06-21 00:28:38 -07:00
Chris Long
565ca261f1
Fix quote escaping
2020-06-20 23:51:10 -07:00
Chris Long
d466f343c4
Fixing shellcheck lint output
2020-06-20 19:14:09 -07:00
Chris Long
74dda07942
Update ESXi bootstrap too
2020-06-01 22:53:36 -07:00
Chris Long
7dc7e6916c
ESXi RAM Bump, osquery fixes
2020-06-01 22:51:14 -07:00
Chris Long
5398841cfe
Update bootstrap.sh
2020-05-09 13:38:57 -07:00
Chris Long
203d7a4638
Fixing eth1 ip detection logic
...
Interfaces can have multiple IP addresses, causing this step to fail in Virtualbox
2020-04-18 22:53:35 -07:00
Chris Long
37d7d1dfd1
Fixing Splunk app filename
2020-04-17 13:58:12 -07:00
Chris Long
60f89345af
Override Bootstrap DNS Settings
2020-04-16 22:00:05 -07:00
Chris Long
3fde431699
Small logger bugfixes
2020-04-14 13:29:58 -07:00
Chris Long
a67ce6efb5
Fixing logger bugs, updating vm tools, updating Win10 ISO
2020-04-13 00:05:49 -07:00
Chris Long
34d8a39c43
Multiple bugfixes, add dashboard
2020-03-27 14:53:04 -07:00
Ahmed Shawky
388ab44a56
Bump zkg version to 2.1.1
2020-03-20 21:59:05 +04:00
Ahmed Shawky
5d10776e4e
Merge remote-tracking branch 'upstream/master'
2020-03-20 20:03:58 +04:00
Ahmed Shawky
681aecb2bc
Should fix an issue when installing zeek https://github.com/cyberdefenders/DetectionLabELK/issues/1
...
zkg 2.1.0 has an issue with Python2 https://github.com/zeek/package-manager/issues/60
2020-03-20 20:01:25 +04:00
Mike Haag
e52f8eee5a
bootstrap.sh comment fix
2020-03-19 10:41:19 -06:00
Mike Haag
4bc014ca63
Update bootstrap.sh
2020-03-19 09:43:04 -06:00
Mike Haag
852f20af57
Adding BOTSv3 and Updating Apps
2020-03-19 09:39:58 -06:00
Chris Long
e612709f4d
Whitespace formatting
2020-03-13 12:10:17 -07:00
Ahmed Shawky
c351643c8c
Make sure we have a DNS resolution when calling fix_eth1_static_ip.
2020-03-13 11:00:07 +04:00
Chris Long
4e850a5ee6
Adding final ESXI deployment code
2020-03-09 14:42:58 -07:00
Chris Long
ac1d2499a2
Replace inline suricata.yaml edits with resource file
2020-03-01 22:32:26 -08:00
Chris Long
d1cc369e87
Adding www.splunk.com to DNS cache
...
Logger is sometimes failing to resolve www.splunk.com
2020-02-29 23:12:21 -08:00
Chris Long
43cc095193
Merge branch 'master' into libvirt_provider
2020-01-18 00:10:43 -08:00
Ahmed Shawky
fefbb9ac54
Fix a monir bug when importing windows-application-security osquery config into fleet.
2020-01-17 23:08:47 +04:00
Selora
2a6cb92f51
Libvirt provider
...
Adding Packer Qemu builder:
* Packer/answer_files/*_virtio: Install the virtio drivers from the ISO (NOT provided)
* windows_*.json needs some manual tweaks to match the virtio drivers ISO path
Adding Vagrant-libvirt provider:
* Uses the QEMU qcow2 images provided by packer to build the DetectionLab
* Vagrantfile needs manual tweaking to match libvirt's host configuration (backing store, network interfaces, etc)
README:
* Added separate README with instructions for libvirt
2020-01-15 17:28:54 +00:00
Chris Long
85563d7742
Fix issue #362
...
https://github.com/clong/DetectionLab/issues/362
2019-12-21 01:17:32 -08:00
Chris Long
b5c73ce647
Include Invoke-AtomicTest in Powershell
2019-12-20 23:46:35 -08:00
Chris Long
ffbca14bd0
Adding mirrors back
2019-12-20 18:03:48 -08:00
Chris Long
7e17727cbb
Logger bump to Ubuntu 18.04 & Migrate to Zeek
2019-12-20 15:48:13 -08:00
Chris Long
ee9a1f87fd
Removing Splunk forwarder from Windows hosts
2019-12-03 00:42:02 -08:00
Chris Long
905eaca9fa
Adding Guacamole for multi-machine management
2019-11-19 21:01:19 -08:00
Chris Long
9f392c76cc
Re-create DC Auditing GPO. Update ThreatHunting Splunk App.
2019-11-11 23:01:57 -08:00
Chris Long
0bd64eb04b
Updating bootstrap.sh
2019-11-06 22:13:19 -08:00
Chris Long
466b54e385
Installing yq via apt-get
...
Fixing the yq issue by using the apt repository
2019-11-04 22:43:25 -08:00
Chris Long
b0b124243b
Updating yq installation check
2019-11-01 08:43:21 -07:00
Chris Long
a9d743ef49
Addressing issue #329
...
Thanks to @protodroidbot for the fix!
2019-10-31 21:33:14 -07:00
Chris Long
84287c4c17
Updating bootstrap.sh to not install BOTSv2 by default
2019-09-30 20:32:19 -07:00
Mike Haag
2d5d6f508e
Add BOTS to Logger
...
This will add the BOTSv2 dataset to DetectionLab.
One app required for BOTS:
Splunk Stream - https://splunkbase.splunk.com/app/1809/
Recommended:
Boss of the SOC (BOTS) Advanced APT Hunting Companion App for Splunk - https://splunkbase.splunk.com/app/4430/
2019-09-05 10:02:05 -06:00
Chris Long
a07e9cbaac
Fix bro-pkg issue
...
https://github.com/abiteboul
2019-07-20 23:44:19 -07:00
Chris Long
9cceafa28e
Update ThreatHunting app to 1.3.4
2019-07-20 00:49:35 -07:00
Chris Long
95d1fb31f4
Updating ASNGen App
2019-06-09 17:53:21 -07:00
Chris Long
e78c312bc5
Actually add files
2019-05-26 21:36:10 -07:00
Olaf Hartong
04bbd7d25e
Updated ThreatHunting app to 1.3
2019-05-19 21:06:04 +02:00
Chris Long
6b40e372bd
Actually include the files
2019-05-11 01:42:35 -07:00
Chris Long
1261c0dfd8
Adding timestamps to scripts, Vagrantfile_prebuilt, logo
2019-05-06 09:26:59 -07:00
Chris Long
1746b49811
Add Atomic Red Team, Poll Packet for Provisioning, Fixes
2019-04-28 22:02:11 -07:00
Chris Long
3de47b621a
Fix WEF inputs for Splunk
2019-04-28 13:12:53 -07:00