Commit Graph

1300 Commits

Author SHA1 Message Date
thomashaw
60570610c6 Update reset actioners (wip - test on laptop) 2022-06-30 17:26:08 +01:00
thomashaw
af89fc988d testing the actions - uncommented! 2022-04-23 21:28:02 +01:00
thomashaw
abda4c54c3 DO NOT MERGE -- temporary change for testing, TODO: parameterise elastalert.service rather than hard-coded aaa_admin 2022-04-23 12:04:15 +01:00
thomashaw
3c07201657 DO NOT MERGE -- temporary change for testing, TODO: add parameter for account to hidden_file module (check history) 2022-04-23 11:52:41 +01:00
thomashaw
3339432d9b Fixing scenario + adding an error message for if a file within '/' is monitored as a goal. 2022-04-21 15:15:57 +01:00
thomashaw
0e2edb803b use env file to avoid proxy on EA 2022-04-21 11:07:09 +01:00
thomashaw
6dbba54d6f wip fix 2022-04-19 20:07:25 +01:00
thomashaw
42b8cc7b34 updated logging 2022-04-19 19:34:10 +01:00
thomashaw
d2b31ecfbf updated elastalert rule execalerter to include 'raise' keyword 2022-04-19 16:12:25 +01:00
thomashaw
8a7c80498f updated owner and group for /opt/alert_router so service runs as aaa_admin rather than root 2022-04-19 15:47:40 +01:00
thomashaw
7d0e2fd69b added psql dev packages 2022-04-14 10:31:13 +01:00
thomashaw
c20f28689c alert_router service update 2022-03-24 16:27:28 +00:00
thomashaw
c4453887dd aaa db initialisation updates 2022-03-24 14:04:55 +00:00
thomashaw
bde1b417bf aaa fix service file 2022-03-23 20:46:24 +00:00
thomashaw
095667a1a3 add db user cont. 2022-03-23 20:09:53 +00:00
thomashaw
2207dbcf11 add db user 2022-03-23 19:42:12 +00:00
thomashaw
220279922c .pp fix 2022-03-23 17:10:33 +00:00
thomashaw
15702b24ba .pp fix 2022-03-23 15:58:50 +00:00
thomashaw
214a6aff30 aaa_config fix 2022-03-23 13:27:56 +00:00
thomashaw
348da72153 AAA updates: runs as a service w/ alert_events db 2022-03-08 21:20:37 +00:00
thomashaw
d1d81667ac AAA DB SQL file 2022-03-03 17:05:35 +00:00
thomashaw
0dac6feff1 ea fix 2022-03-01 16:19:25 +00:00
thomashaw
f91ba131fb fix 2022-03-01 16:18:58 +00:00
thomashaw
59884a72f9 updating generated rule format and rule target paths 2022-02-24 17:23:11 +00:00
thomashaw
ecefe2370f fixing typo 2022-02-24 12:10:33 +00:00
thomashaw
e048c2a328 updating aaa_client too... 2022-02-23 17:33:08 +00:00
thomashaw
5be33225d7 updated auditbeat config to track system logins and user changes 2022-02-23 17:31:13 +00:00
thomashaw
2b5fdfaa21 working... now testing w/o explicit PyYAML version 2022-02-22 14:25:20 +00:00
thomashaw
fc42affef1 fixing typo + updating test scenario 2022-02-22 13:47:34 +00:00
Z. Cliffe Schreuders
e464835192 test scenario update, fixing PyYAML install issue... 2022-02-21 13:23:30 +00:00
thomashaw
f312c8beb3 big_merge merge commit 2022-02-17 21:34:08 +00:00
thomashaw
60d3604efd Dynamic generation of goal flags (and some cleanup, removing goal_flags etc.). 2022-02-16 15:28:59 +00:00
thomashaw
6fb72ed578 adding dynamic goal + flag paths to hidden_file 2022-02-14 15:56:41 +00:00
thomashaw
e657f86af5 debugging file_to_leak 2022-02-14 14:30:36 +00:00
thomashaw
86323b2bba debugging file_to_leak 2022-02-14 14:19:33 +00:00
thomashaw
e7cc7fd49e debugging file_to_leak 2022-02-14 12:25:09 +00:00
thomashaw
df282d5ac8 debugging file_to_leak 2022-02-14 12:24:09 +00:00
thomashaw
a1a15fc731 elastalert dependency fix wip 2022-02-08 21:15:50 +00:00
thomashaw
65adb0d448 update pip3 2022-02-08 20:31:03 +00:00
thomashaw
5810b462f5 update pip3 2022-02-08 18:38:13 +00:00
thomashaw
7a2a20de0a wip 2022-02-08 17:36:28 +00:00
thomashaw
ee4132ce06 wip 2022-02-08 16:50:34 +00:00
thomashaw
e30700d11b wip 2022-02-08 16:13:33 +00:00
thomashaw
56726d9632 test_scenario.xml update: test symlinks 2022-02-08 16:09:35 +00:00
thomashaw
a44a8bfec2 wip 2022-02-08 15:15:30 +00:00
thomashaw
abae0fa5e5 hidden_file changes: Updating metadata + scenarios for testing w/ static file_path_to_leak passed from scenario 2022-02-08 14:16:53 +00:00
thomashaw
bc0ea15beb Adding goals to hidden_file: moving the full_path calculation logic from puppet to secgen level, so we can use that data the file to read for the goal 2022-02-08 13:56:41 +00:00
thomashaw
a7251e16f6 added static read_file goal to hidden_file 2022-02-04 10:57:02 +00:00
thomashaw
39b24ce3c9 (wip) 2022-02-03 19:57:23 +00:00
thomashaw
39199dba29 WIP - Testing challenger homedir bug... (2) 2022-02-03 16:27:44 +00:00