thomashaw
|
60570610c6
|
Update reset actioners (wip - test on laptop)
|
2022-06-30 17:26:08 +01:00 |
|
thomashaw
|
af89fc988d
|
testing the actions - uncommented!
|
2022-04-23 21:28:02 +01:00 |
|
thomashaw
|
abda4c54c3
|
DO NOT MERGE -- temporary change for testing, TODO: parameterise elastalert.service rather than hard-coded aaa_admin
|
2022-04-23 12:04:15 +01:00 |
|
thomashaw
|
3c07201657
|
DO NOT MERGE -- temporary change for testing, TODO: add parameter for account to hidden_file module (check history)
|
2022-04-23 11:52:41 +01:00 |
|
thomashaw
|
3339432d9b
|
Fixing scenario + adding an error message for if a file within '/' is monitored as a goal.
|
2022-04-21 15:15:57 +01:00 |
|
thomashaw
|
0e2edb803b
|
use env file to avoid proxy on EA
|
2022-04-21 11:07:09 +01:00 |
|
thomashaw
|
6dbba54d6f
|
wip fix
|
2022-04-19 20:07:25 +01:00 |
|
thomashaw
|
42b8cc7b34
|
updated logging
|
2022-04-19 19:34:10 +01:00 |
|
thomashaw
|
d2b31ecfbf
|
updated elastalert rule execalerter to include 'raise' keyword
|
2022-04-19 16:12:25 +01:00 |
|
thomashaw
|
8a7c80498f
|
updated owner and group for /opt/alert_router so service runs as aaa_admin rather than root
|
2022-04-19 15:47:40 +01:00 |
|
thomashaw
|
7d0e2fd69b
|
added psql dev packages
|
2022-04-14 10:31:13 +01:00 |
|
thomashaw
|
c20f28689c
|
alert_router service update
|
2022-03-24 16:27:28 +00:00 |
|
thomashaw
|
c4453887dd
|
aaa db initialisation updates
|
2022-03-24 14:04:55 +00:00 |
|
thomashaw
|
bde1b417bf
|
aaa fix service file
|
2022-03-23 20:46:24 +00:00 |
|
thomashaw
|
095667a1a3
|
add db user cont.
|
2022-03-23 20:09:53 +00:00 |
|
thomashaw
|
2207dbcf11
|
add db user
|
2022-03-23 19:42:12 +00:00 |
|
thomashaw
|
220279922c
|
.pp fix
|
2022-03-23 17:10:33 +00:00 |
|
thomashaw
|
15702b24ba
|
.pp fix
|
2022-03-23 15:58:50 +00:00 |
|
thomashaw
|
214a6aff30
|
aaa_config fix
|
2022-03-23 13:27:56 +00:00 |
|
thomashaw
|
348da72153
|
AAA updates: runs as a service w/ alert_events db
|
2022-03-08 21:20:37 +00:00 |
|
thomashaw
|
d1d81667ac
|
AAA DB SQL file
|
2022-03-03 17:05:35 +00:00 |
|
thomashaw
|
0dac6feff1
|
ea fix
|
2022-03-01 16:19:25 +00:00 |
|
thomashaw
|
f91ba131fb
|
fix
|
2022-03-01 16:18:58 +00:00 |
|
thomashaw
|
59884a72f9
|
updating generated rule format and rule target paths
|
2022-02-24 17:23:11 +00:00 |
|
thomashaw
|
ecefe2370f
|
fixing typo
|
2022-02-24 12:10:33 +00:00 |
|
thomashaw
|
e048c2a328
|
updating aaa_client too...
|
2022-02-23 17:33:08 +00:00 |
|
thomashaw
|
5be33225d7
|
updated auditbeat config to track system logins and user changes
|
2022-02-23 17:31:13 +00:00 |
|
thomashaw
|
2b5fdfaa21
|
working... now testing w/o explicit PyYAML version
|
2022-02-22 14:25:20 +00:00 |
|
thomashaw
|
fc42affef1
|
fixing typo + updating test scenario
|
2022-02-22 13:47:34 +00:00 |
|
Z. Cliffe Schreuders
|
e464835192
|
test scenario update, fixing PyYAML install issue...
|
2022-02-21 13:23:30 +00:00 |
|
thomashaw
|
f312c8beb3
|
big_merge merge commit
|
2022-02-17 21:34:08 +00:00 |
|
thomashaw
|
60d3604efd
|
Dynamic generation of goal flags (and some cleanup, removing goal_flags etc.).
|
2022-02-16 15:28:59 +00:00 |
|
thomashaw
|
6fb72ed578
|
adding dynamic goal + flag paths to hidden_file
|
2022-02-14 15:56:41 +00:00 |
|
thomashaw
|
e657f86af5
|
debugging file_to_leak
|
2022-02-14 14:30:36 +00:00 |
|
thomashaw
|
86323b2bba
|
debugging file_to_leak
|
2022-02-14 14:19:33 +00:00 |
|
thomashaw
|
e7cc7fd49e
|
debugging file_to_leak
|
2022-02-14 12:25:09 +00:00 |
|
thomashaw
|
df282d5ac8
|
debugging file_to_leak
|
2022-02-14 12:24:09 +00:00 |
|
thomashaw
|
a1a15fc731
|
elastalert dependency fix wip
|
2022-02-08 21:15:50 +00:00 |
|
thomashaw
|
65adb0d448
|
update pip3
|
2022-02-08 20:31:03 +00:00 |
|
thomashaw
|
5810b462f5
|
update pip3
|
2022-02-08 18:38:13 +00:00 |
|
thomashaw
|
7a2a20de0a
|
wip
|
2022-02-08 17:36:28 +00:00 |
|
thomashaw
|
ee4132ce06
|
wip
|
2022-02-08 16:50:34 +00:00 |
|
thomashaw
|
e30700d11b
|
wip
|
2022-02-08 16:13:33 +00:00 |
|
thomashaw
|
56726d9632
|
test_scenario.xml update: test symlinks
|
2022-02-08 16:09:35 +00:00 |
|
thomashaw
|
a44a8bfec2
|
wip
|
2022-02-08 15:15:30 +00:00 |
|
thomashaw
|
abae0fa5e5
|
hidden_file changes: Updating metadata + scenarios for testing w/ static file_path_to_leak passed from scenario
|
2022-02-08 14:16:53 +00:00 |
|
thomashaw
|
bc0ea15beb
|
Adding goals to hidden_file: moving the full_path calculation logic from puppet to secgen level, so we can use that data the file to read for the goal
|
2022-02-08 13:56:41 +00:00 |
|
thomashaw
|
a7251e16f6
|
added static read_file goal to hidden_file
|
2022-02-04 10:57:02 +00:00 |
|
thomashaw
|
39b24ce3c9
|
(wip)
|
2022-02-03 19:57:23 +00:00 |
|
thomashaw
|
39199dba29
|
WIP - Testing challenger homedir bug... (2)
|
2022-02-03 16:27:44 +00:00 |
|