Commit Graph

455 Commits

Author SHA1 Message Date
Chris Long
f7940234ec De-duping MAC addresses and adding outputs 2020-03-05 22:28:02 -08:00
Chris Long
52ba931948 Adding an ESXi development branch 2020-03-05 22:07:55 -08:00
Chris Long
fc23f5a2d9 Merge pull request #383 from clong/suricata_yaml
Replace inline suricata.yaml edits with resource file
2020-03-02 11:12:42 -08:00
Chris Long
ac1d2499a2 Replace inline suricata.yaml edits with resource file 2020-03-01 22:32:26 -08:00
Chris Long
cbf2340081 Uploading images for wiki page 2020-02-29 23:46:36 -08:00
Chris Long
d1cc369e87 Adding www.splunk.com to DNS cache
Logger is sometimes failing to resolve www.splunk.com
2020-02-29 23:12:21 -08:00
Chris Long
90f2e305f0 Merge pull request #380 from clong/update_build_1804
Update build server code
2020-02-23 19:46:46 -08:00
Chris Long
78b0458500 Update Packet server from 16.04 -> 18.04 2020-02-23 19:45:33 -08:00
Chris Long
7e32871c88 Update build_machine_bootstrap.sh 2020-02-23 19:44:19 -08:00
Chris Long
456bc1f690 Merge pull request #379 from clong/libvirt_fixes
LibVirt fixes
2020-02-17 15:06:29 -08:00
Chris Long
16003bbd68 LibVirt fixes 2020-02-17 15:04:32 -08:00
Chris Long
f3c40e84b5 Merge pull request #254 from Selora/libvirt_provider
Libvirt provider
2020-02-17 14:51:36 -08:00
Chris Long
2bd2f20776 Merge branch 'master' into libvirt_provider 2020-02-17 14:45:09 -08:00
Chris Long
5675ae42cc Merge pull request #378 from lnxg33k/master
Set WinRM remoteip to any when packing the boxes.
2020-02-15 15:23:54 -08:00
Ahmed Shawky
dc32112404 Set WinRM remoteip to any when packing the boxes. 2020-02-12 23:18:26 +04:00
Chris Long
a9283825a1 Merge pull request #375 from lnxg33k/master
Force powershell to use TLS 1.2 as chocolatey.org throws a TLS error
2020-02-06 19:05:52 -06:00
Ahmed Shawky
fea8f35f0e Force powershell to use TLS 1.2 as chocolatey.org throws a TLS error 2020-02-05 02:47:03 +04:00
Chris Long
46eb701992 Merge branch 'master' into libvirt_provider 2020-01-19 23:41:41 -08:00
Chris Long
24d2d5e9b0 Update README.md 2020-01-18 12:01:42 -08:00
Chris Long
43cc095193 Merge branch 'master' into libvirt_provider 2020-01-18 00:10:43 -08:00
Chris Long
797a9d507a Merge pull request #372 from lnxg33k/master
Fix a monir bug when importing windows-application-security osquery config into fleet.
2020-01-18 00:10:22 -08:00
Ahmed Shawky
fefbb9ac54 Fix a monir bug when importing windows-application-security osquery config into fleet. 2020-01-17 23:08:47 +04:00
Selora
fe2e6404af Fixup: windows2016.json Start headless 2020-01-15 17:48:25 +00:00
Selora
7742744c76 Fixup: windows2016.json Updated provision scripts list 2020-01-15 17:40:55 +00:00
Selora
9f23c7bde2 Fixup: windows2016.json old syntax for CPU and RAM allocation for QEMU fixup 2020-01-15 17:38:58 +00:00
Selora
80f6696034 Fixup: windows2016.json missing user variable 2020-01-15 17:37:24 +00:00
Selora
72ecc00688 Fixup: windows10.json syntax error 2020-01-15 17:33:38 +00:00
Selora
2a6cb92f51 Libvirt provider
Adding Packer Qemu builder:
* Packer/answer_files/*_virtio: Install the virtio drivers from the ISO (NOT provided)
* windows_*.json needs some manual tweaks to match the virtio drivers ISO path

Adding Vagrant-libvirt provider:
* Uses the QEMU qcow2 images provided by packer to build the DetectionLab
* Vagrantfile needs manual tweaking to match libvirt's host configuration (backing store, network interfaces, etc)

README:
* Added separate README with instructions for libvirt
2020-01-15 17:28:54 +00:00
Chris Long
4d13f53866 Forcing DNS Server settings on DC for Terraform
Addresses https://github.com/clong/DetectionLab/issues/370
2020-01-06 22:36:32 -08:00
Chris Long
85563d7742 Fix issue #362
https://github.com/clong/DetectionLab/issues/362
2019-12-21 01:17:32 -08:00
Chris Long
2206c0b944 Merge pull request #365 from clong/invoke_atomictest
Include Invoke-AtomicRedTeam in Powershell
2019-12-20 23:50:51 -08:00
Chris Long
5e720ef398 Merge branch 'master' into invoke_atomictest 2019-12-20 23:50:37 -08:00
Chris Long
b5c73ce647 Include Invoke-AtomicTest in Powershell 2019-12-20 23:46:35 -08:00
Chris Long
6d90874599 Fix fleet URL 2019-12-20 22:02:08 -08:00
Chris Long
828447b508 Merge pull request #364 from clong/ubuntu_upgrade
Logger bump to Ubuntu 18.04 & Migrate to Zeek
2019-12-20 18:04:16 -08:00
Chris Long
ffbca14bd0 Adding mirrors back 2019-12-20 18:03:48 -08:00
Chris Long
ba7004b283 Merge branch 'master' into ubuntu_upgrade 2019-12-20 15:51:01 -08:00
Chris Long
7e17727cbb Logger bump to Ubuntu 18.04 & Migrate to Zeek 2019-12-20 15:48:13 -08:00
Chris Long
e4bb3c9a43 Update 20-detectionlab 2019-12-18 13:43:21 -08:00
Chris Long
beecfbf2e2 Add overview image back 2019-12-04 21:40:20 -08:00
Chris Long
26895efd42 Merge pull request #354 from clong/remove_splunk_forwarder
Modify Splunk Forwarding, MOTD, Sysmon
2019-12-04 21:38:29 -08:00
Chris Long
0393d627ad Convert ADSI:Exists to Get-ADOrganizationalUnit 2019-12-04 18:49:28 -08:00
Chris Long
4a8485c28e Disable IPv6 on Windows adapters 2019-12-04 13:45:43 -08:00
Chris Long
f64ff20aaf Disabling default windows inputs. Adding powershell command for event channel perms 2019-12-04 11:27:35 -08:00
Chris Long
249ce2ec76 Updating channel permissions for Microsoft-Windows-Sysmon 2019-12-03 22:18:20 -08:00
Chris Long
6cb8b1b53d Merge branch 'remove_splunk_forwarder' of https://github.com/clong/detectionlab into remove_splunk_forwarder 2019-12-03 19:57:11 -08:00
Chris Long
ef0c1842cd Merge branch 'master' into remove_splunk_forwarder 2019-12-03 19:54:53 -08:00
Chris Long
f3fa80299f Adding rearm to each Windows host 2019-12-03 19:53:59 -08:00
Chris Long
f7fc93cfb6 Rearm WEF AMI when it's being brought online 2019-12-03 19:46:58 -08:00
Chris Long
a36c90b057 Merge branch 'master' into remove_splunk_forwarder 2019-12-03 00:44:58 -08:00