Commit Graph

340 Commits

Author SHA1 Message Date
Chris Long
3f12ac524a Update install-redteam.ps1 2020-04-25 12:20:25 -07:00
Chris Long
203d7a4638 Fixing eth1 ip detection logic
Interfaces can have multiple IP addresses, causing this step to fail in Virtualbox
2020-04-18 22:53:35 -07:00
Chris Long
d1d0566773 Add some Splunk nullQueues for noisy events 2020-04-18 15:59:54 -07:00
Chris Long
7c0b8907db Fix path for install-utilities.ps1 2020-04-17 22:02:29 -07:00
Chris Long
37d7d1dfd1 Fixing Splunk app filename 2020-04-17 13:58:12 -07:00
Chris Long
60f89345af Override Bootstrap DNS Settings 2020-04-16 22:00:05 -07:00
Chris Long
3fde431699 Small logger bugfixes 2020-04-14 13:29:58 -07:00
Chris Long
03c96430a5 Merge branch 'master' into logger_bugfix 2020-04-13 00:09:52 -07:00
Chris Long
a67ce6efb5 Fixing logger bugs, updating vm tools, updating Win10 ISO 2020-04-13 00:05:49 -07:00
Chris Long
dbfa998ec2 Update install-windows_ta.ps1 2020-04-08 00:20:01 -07:00
Mike Haag
2b37af791d Bootstrap.sh Error fixes
Errors during install:
-     logger: Error during app install: failed to extract app from /vagrant/resources/splunk_forwarder/splunk-add-on-for-microsoft-windows_700.tgz to /opt/splunk/var/run/splunk/bundle_tmp/2ade41e05f0e68dc: No such file or directory

-     logger: Error during app install: failed to extract app from /vagrant/resources/splunk_server/add-on-for-microsoft-sysmon_1062.tgz to /opt/splunk/var/run/splunk/bundle_tmp/eeef7b83a2d6b716: No such file or directory

1. Fixed the forwarder error by placing the updated TA in the forwarder path.
2. fixed server error, this was caused by a typo in the name.
2020-04-06 09:04:23 -06:00
Chris Long
fd804a083d Fixing the Splunk nullqueue 2020-03-28 02:30:06 -07:00
Chris Long
c7e013558a Resolving merge conflicts 2020-03-27 14:58:18 -07:00
Chris Long
34d8a39c43 Multiple bugfixes, add dashboard 2020-03-27 14:53:04 -07:00
Chris Long
9437e74c3e Update bootstrap.sh 2020-03-26 11:45:37 -07:00
Chris Long
6525456492 Update install-choco-extras.ps1 2020-03-25 22:46:55 -07:00
Chris Long
b2cf652fdc Update install-utilities.ps1 2020-03-25 22:46:19 -07:00
Chris Long
242e1a7cf3 Adding a failover for the ISO download 2020-03-23 22:51:43 -07:00
Chris Long
5dcc9965d3 Add a wait for autoruns scheduled task 2020-03-23 17:27:57 -07:00
Ahmed Shawky
388ab44a56 Bump zkg version to 2.1.1 2020-03-20 21:59:05 +04:00
Ahmed Shawky
5d10776e4e Merge remote-tracking branch 'upstream/master' 2020-03-20 20:03:58 +04:00
Ahmed Shawky
681aecb2bc Should fix an issue when installing zeek https://github.com/cyberdefenders/DetectionLabELK/issues/1
zkg 2.1.0 has an issue with Python2 https://github.com/zeek/package-manager/issues/60
2020-03-20 20:01:25 +04:00
Mike Haag
e52f8eee5a bootstrap.sh comment fix 2020-03-19 10:41:19 -06:00
Mike Haag
4bc014ca63 Update bootstrap.sh 2020-03-19 09:43:04 -06:00
Mike Haag
852f20af57 Adding BOTSv3 and Updating Apps 2020-03-19 09:39:58 -06:00
Ahmed Shawky
110fa56b5a Disable defender RealtimeMonitoring when installing redteaming tools. 2020-03-15 16:42:26 +04:00
Ahmed Shawky
1a548c10d3 Merge remote-tracking branch 'upstream/master' 2020-03-15 09:51:33 +04:00
Ahmed Shawky
d4a9699cdd Fix a typeo that stopped the Defender exclusions of \tools directory 2020-03-15 09:40:01 +04:00
Chris Long
e612709f4d Whitespace formatting 2020-03-13 12:10:17 -07:00
Ahmed Shawky
c351643c8c Make sure we have a DNS resolution when calling fix_eth1_static_ip. 2020-03-13 11:00:07 +04:00
Chris Long
068e9d8c05 Merge branch 'master' into ESXi 2020-03-09 14:46:54 -07:00
Chris Long
4e850a5ee6 Adding final ESXI deployment code 2020-03-09 14:42:58 -07:00
Chris Long
47d4696147 Update install-redteam.ps1 2020-03-09 00:49:32 -07:00
Chris Long
361b9b0b48 Adding exclusion folders to install-redteam.ps1 2020-03-07 23:11:44 -08:00
Chris Long
c630b88961 Removing reference to Invoke-AtomicRedTeam.psm1
Fixes https://github.com/clong/DetectionLab/issues/385
2020-03-07 20:02:25 -08:00
Chris Long
ac1d2499a2 Replace inline suricata.yaml edits with resource file 2020-03-01 22:32:26 -08:00
Chris Long
d1cc369e87 Adding www.splunk.com to DNS cache
Logger is sometimes failing to resolve www.splunk.com
2020-02-29 23:12:21 -08:00
Chris Long
16003bbd68 LibVirt fixes 2020-02-17 15:04:32 -08:00
Chris Long
2bd2f20776 Merge branch 'master' into libvirt_provider 2020-02-17 14:45:09 -08:00
Ahmed Shawky
fea8f35f0e Force powershell to use TLS 1.2 as chocolatey.org throws a TLS error 2020-02-05 02:47:03 +04:00
Chris Long
43cc095193 Merge branch 'master' into libvirt_provider 2020-01-18 00:10:43 -08:00
Ahmed Shawky
fefbb9ac54 Fix a monir bug when importing windows-application-security osquery config into fleet. 2020-01-17 23:08:47 +04:00
Selora
2a6cb92f51 Libvirt provider
Adding Packer Qemu builder:
* Packer/answer_files/*_virtio: Install the virtio drivers from the ISO (NOT provided)
* windows_*.json needs some manual tweaks to match the virtio drivers ISO path

Adding Vagrant-libvirt provider:
* Uses the QEMU qcow2 images provided by packer to build the DetectionLab
* Vagrantfile needs manual tweaking to match libvirt's host configuration (backing store, network interfaces, etc)

README:
* Added separate README with instructions for libvirt
2020-01-15 17:28:54 +00:00
Chris Long
85563d7742 Fix issue #362
https://github.com/clong/DetectionLab/issues/362
2019-12-21 01:17:32 -08:00
Chris Long
b5c73ce647 Include Invoke-AtomicTest in Powershell 2019-12-20 23:46:35 -08:00
Chris Long
ffbca14bd0 Adding mirrors back 2019-12-20 18:03:48 -08:00
Chris Long
ba7004b283 Merge branch 'master' into ubuntu_upgrade 2019-12-20 15:51:01 -08:00
Chris Long
7e17727cbb Logger bump to Ubuntu 18.04 & Migrate to Zeek 2019-12-20 15:48:13 -08:00
Chris Long
e4bb3c9a43 Update 20-detectionlab 2019-12-18 13:43:21 -08:00
Chris Long
0393d627ad Convert ADSI:Exists to Get-ADOrganizationalUnit 2019-12-04 18:49:28 -08:00