This repository has been archived by the owner on Apr 16, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 521
2015
Samuel Tarling edited this page Nov 27, 2015
·
9 revisions
Please note that this is all subject to change!
- January 2015
Issue 655: Suricata 2.0.5Issue 658: NSM: fix umask on Snort unified2 outputIssue 548: NSM: run barnyard2 as non-root userIssue 649: nsm_all_del_quick: check for /etc/nsm/servertab and /etc/nsm/sensortab before trying to readIssue 598: so-snorby-wipeIssue 610: NSM: ossec_agent alert level should be configurableIssue 660: Setup: add OSSEC_AGENT_LEVEL to /etc/nsm/securityonion.confIssue 656: ELSA: update parser for bro_conn to parse country codeIssue 659: securityonion-web-page: add ELSA query for bro_conn groupby:resp_country_codeIssue 667: New packages for shellshock and malware-traffic-analysis samplesIssue 673: Suricata 2.0.6Issue 642: Update Salt packages/scripts to 2014.7.0Issue 619: Onionsalt: backup /opt/onionsalt/pillar/top.slsIssue 661: Onionsalt: replicate /usr/local/lib/snort_dynamicrules/Issue 672: sguil-db-purge: check for UNCAT_MAXIssue 663: sosetup: sosetup.conf SGUIL_CLIENT_PASSWORD_1 should say Sguil/Squert/ELSA/SnorbyIssue 664: sosetup: run Bro as non-root userIssue 666: sostat: run Bro as non-root userIssue 665: NSM: run Bro as non-root userIssue 676: NSM: run Sguil as non-root userIssue 671: NSM: /etc/cron.d/sensor-clean needs 2>&1
- February 2015
Issue 668: ELSA: pdbtool errorsIssue 669: ELSA: update parsers for Bro DNS and BINDIssue 670: securityonion-web-page: add queries for updated bro_dns parserIssue 685: securityonion-web-page: update linksIssue 684: NSM: nsm_server_ps-start needs to create /var/log/sguild/ if it doesn't already existIssue 686: NSM: nsm_server_ps-start needs to set permissions on /var/log/nsm/so-elsa/ properlyIssue 687: NSM: nsm_sensor_ps-start should set permissions on /var/log/nsm/ properlyIssue 689: NSM: add USE_DNS option to ossec_agent.confIssue 688: ossec_agent: add option to disable DNS lookupsIssue 680: Bro 2.3.2Issue 683: securityonion-et-rules: update for new ISOIssue 632: ISO: add bridge-utilsIssue 601: ISO: add foremostIssue 614: ISO: add securityonion-samples-shellshockIssue 662: ISO: add securityonion-samples-mtaIssue 675: ISO: add xfsprogsIssue 602: 12.04.5.1 ISO image
- March 2015
Issue 695: Suricata 2.0.7Issue 696: ELSA custom menuIssue 691: NSM: chown -R $BRO_USER:$BRO_GROUP /nsm/bro >/dev/null 2>&1Issue 698: NSM: nsm_server_del line 170 echo_msg 0 "Deleting server: $SERVER_NAME"Issue 699: NSM: Bro node.cfg host=localhostIssue 700: Setup: Bro node.cfg host=localhostIssue 702: Snort 2.9.7.2Issue 703: Move from Google Code to GithubIssue 706: Add Josh Brower's ELSA parsers for process logs and sysmonIssue 709: Add fear.nothing's ELSA parsers for pfSenseIssue 710: securityonion-web-page: add ELSA queries for Firewall logs and Windows Processes
- April 2015
Issue 711: Add "date" command to /usr/bin/sguil-db-purgeIssue 692: sostat: list number of ELSA buffers in queue and warn if higher than 20Issue 701: sostat: include number of CPU coresIssue 681: rule-update: wipe snort_dynamicrules directory on sensorIssue 677: rule-update: create /usr/local/lib/snort_dynamicrules/ if it doesn't already existIssue 678: rule-update: /etc/cron.d/rule-update should have 2>&1Issue 697: rule-update: log snorby reference table update to barnyard2-snorby.logIssue 679: rule-update: run pulledpork as unprivileged userIssue 715: securityonion-rule-update: sensor-only boxes running salt shouldn't try to copy /etc/cron.d/rule-update
- May 2015
Issue 725: Suricata 2.0.8Issue 718: Sphinx 2.1.9Issue 241: NSM scripts should have a timeout period when stopping servicesIssue 392: Patch for lib-nsm-common-utils from Mark SeidenIssue 714: nsm_server_user-disableIssue 705: ossec_agent: improvements from Brian KelloggIssue 716: ossec_agent: tighten regex to only look for -> anchored to hostname or IPIssue 717: ossec_agent: send alerts to sguild immediately instead of waiting for next alert
- June 2015
Issue 742: securityonion-suricata package missing debian/installIssue 730: Snort 2.9.7.3Issue 731: Snort DAQ 2.0.5Issue 657: ELSA 1205Issue 447: ELSA syslog-ng.conf rewrite r_pipesIssue 512: ELSA syslog-ng.conf filter f_bro_headersIssue 726: ELSA syslog-ng.conf - add filesystem destinationsIssue 674: ELSA - update bro_notice parser to parse src and dst fieldsIssue 722: securityonion-web-page: update HTTP mime type queries for ELSA 1205Issue 723: CapMe: Update for new ELSA APIIssue 500: sosetup: restart starmanIssue 504: sosetup: avoid writing ELSA_PORT twice in SSH_CONFIssue 547: sosetup: if enabling salt on a sensor, check top.sls to make sure it doesn't already existIssue 740: sosetup: sensor should use sudo to restart apache on masterIssue 741: sosetup: sometimes local salt-minion doesn't check in with local salt-master quickly enoughIssue 732: NSM: only output color codes if running on a ttyIssue 746: ELSA 1205 package enabled perl module on non-ELSA systemsIssue 747: ELSA 1205 package duplicated syslog-ng.conf entries on non-ELSA systemsIssue 748: ELSA 1205 package didn't add the pid column to the query_log table for upgradesIssue 749: Update tcl-tls package and replace DH512 key with DH2048Issue 751: NSM: change watchdog run time to avoid race conditionIssue 744: sosetup: Restart Apache to activate new ELSA apikeyIssue 745: OSSEC 2.8.2
- July 2015
Issue 733: 12.04.5.2 ISO imageIssue 763: sostat: show last updateIssue 761: securityonion-tcpudpflow: remove connection_state_remove event handlerIssue 760: ossec_agent: Add source of syslog as destination IP for Sguil alertIssue 769: sosetup: allow user to enable/disable SnorbyIssue 596: sosetup: sensor should stop/disable Apache and Snorby workerIssue 693: sosetup: improve input validation for email addressIssue 764: sosetup: fix typo in sosetup.confIssue 605: sosetup: replace tmp with mktempIssue 771: sosetup: comment out 2 examples in top.slsIssue 767: securityonion-web-page: add SSL Top Subjects queryIssue 775: securityonion-web-page: add groupby:site to ELSA HTTP SQL Injection query
- August 2015
Issue 743: Bro 2.4Issue 752: securityonion-bro-scripts: update sensortab.bro for Bro 2.4Issue 753: securityonion-bro-scripts: update shellshock module for Bro 2.4Issue 754: securityonion-bro-scripts: update extract.bro for Bro 2.4Issue 762: securityonion-elsa-extras: update bro_conn parser for Bro 2.4Issue 765: securityonion-elsa-extras: update bro_intel parser for Bro 2.4Issue 768: securityonion-elsa-extras: update bro_ssl parser for Bro 2.4Issue 774: securityonion-elsa-extras: update bro_ssh parser for Bro 2.4Issue 773: securityonion-elsa-extras: add Windows and Cisco parsers from Brian KelloggIssue 793: CapMe: Update for Bro 2.4 conn.logIssue 766: Snorby 2.6.3Issue 784: Snort 2.9.7.5Issue 788: DAQ 2.0.6Issue 724: /etc/cron.d/rule-update should avoid overwhelming rule sitesIssue 791: sosetup: change rule-update verbiageIssue 728: securityonion-libcapture-tiny-perl shouldProvides: libcapture-tiny-perl
Issue 797: NSM: update SpoolDir and LogDir in broctl.cfgIssue 799: NSM: add stderr redirect to stdout on adduserIssue 800: Setup: update SpoolDir and LogDir in broctl.cfg
- September 2015
Issue 755: securityonion-elsa-extras: add parser for Bro 2.4 mysql.logIssue 756: securityonion-elsa-extras: add parser for Bro 2.4 kerberos.logIssue 757: securityonion-elsa-extras: add parser for Bro 2.4 rdp.logIssue 758: securityonion-elsa-extras: add parser for Bro 2.4 pe.logIssue 759: securityonion-elsa-extras: add parser for Bro 2.4 sip.logIssue 780: securityonion-elsa-extras: add parser for IIS logsIssue 782: securityonion-elsa-extras: update sysmon parserIssue 776: securityonion-elsa-extras: set version 3.3 in syslog-ng.confIssue 796: securityonion-elsa-extras: Add script to fix ELSA syslogs_archive_1 issueIssue 801: securityonion-web-page: add queries for Bro kerberos logsIssue 802: securityonion-web-page: add queries for Bro mysql logsIssue 803: securityonion-web-page: add queries for Bro pe logsIssue 804: securityonion-web-page: add queries for Bro rdp logsIssue 805: securityonion-web-page: add queries for Bro sip logsIssue 794: securityonion-web-page: add DHCP Servers queryIssue 798: securityonion-web-page: add HTTP sites hosting SWFIssue 795: 12.04.5.3 ISO image
- December 2015
- Issue 814: Move to Ubuntu 14.04
- Issue 739: Salt 2015.5.3
- Issue 829: Apache reverse proxy /elsa-query to ELSA port 3154
- Issue 824: securityonion-web-page: fix links to ELSA
- Issue 810: securityonion-web-page: move SSH Logins query to Host Logs category
- Issue 811: securityonion-tcpudpflow: add SMTP and RDP support
- Issue 807: securityonion-elsa-extras: Remove NameVirtualHost to eliminate warning on apache restart
- Issue 729: Setup: add option for pivot URL (no longer needed since Apache is proxying /elsa-query to ELSA port 3154)
- Issue 821: Setup: fix domain name cancellation
- Issue 822: Setup: remove alphanumeric password requirement
- Issue 828: Setup: desktop shortcuts
- Issue 790: sostat: remove snorby
- Issue 830: soup: remove old linux kernels
- Issue 815: NSM: add log directory creation to postinst
- Issue 831: Snort Community Ruleset has moved
- Issue 812: Bro 2.4.1
- Issue 820: Snort 2.9.7.6
- Issue 816: Snort needs liblzma
- Issue 818: Suricata 3.0
- January 2016
- February 2016
- Issue 825: NSM: remove extra Bro output
- Issue 833: soup: error checking
- Issue 813: Setup: bug when configuring 10 or more interfaces
- Issue 826: Bro intel linter
- Issue 817: sostat: awk division error when Bro doesn't report stats correctly
- Issue 819: soup: check to see if PF_RING updates are available
- Issue 727: Argus 3.0.8.1
- Issue 690: http_agent: ---disable-inotify
- Issue 615: NSM: add "exit $RET" where necessary
- Issue 588: NSM: purge old OSSEC logs
- Issue 561: nsm_server_backup-config should check FORCE_YES
- Issue 523: sensor-clean: add option to skip removal of bro or argus logs
- Issue 534: NSM: Patches for adding PCAP snap length for Netsniff-NG
- Issue 645: NSM scripts don't check if a sensor is disabled before performing operations when a --sensor-name= is specified
- Issue 652: NSM: barnyard sending blank interface to ELSA
- Issue 653: NSM: nsm_sensor_ps-stop should kill the processes tailing the snort.stats files
- Issue 654: NSM: set SNORT_PERF_STATS in snort_agent.conf to 0 when ENGINE=suricata
- Issue 643: Rotate logs in /var/log/nsm/
- Issue 571: securityonion-web-page: add Security Onion cheat sheet PDF
- Issue 644: sostat-quick: check server/sensor
- Issue 792: soup: add note about running on master server before running on sensor
- Issue 591: Bro Intel Whitelist
- Issue 418: netsniff-ng 0.6.0
- Issue 737: Bro transcript debug output gets rendered in the transcript
- Issue 736: CapME: Debug information occasionally gets rendered inside the transcript
- Issue 492: CapMe needs to handle UDP better
- Issue 738: CapME: handle large pcaps more gracefully
- Issue 493: CapMe: send credentials interactively to avoid exposing on command line
- Issue 608: Update bash scripts to use /bin/sh
- Issue 304: sosetup: support unique interface names
- Issue 592: sosetup: add -y option
- Issue 593: sosetup: checking for Internet access takes a while if DNS doesn't immediately fail
- Issue 480: sosetup: running on sensor should automatically create autossh account on server
- Issue 532: sosetup: Limit what autossh keys can do
- Issue 559: sosetup: support for NIC bonding configuration
- Issue 735: sosetup: Advanced Setup should automatically configure PF_RING instances based on number of CPU cores
- Issue 777: sosetup: refactor into more functions
- Issue 789: sosetup: add ability to write an answer file
- Issue 785: sostat: show number of available updates
- Issue 772: onionsalt: replicate ELSA parsers in /etc/elsa/patterns.d/local
- Issue 708: OSSEC 2.9
- Issue 707: Add Josh Brower's OSSEC decoders/rules for sysmon
- Issue 778: QA tests
- Issue 603: securityonion-bro-scripts: drwatson
- Issue 331: securityonion-elsa: update dependencies
- Issue 604: ELSA: parsers for Bro drwatson logs
- Issue 808: securityonion-elsa-extras: Sysmon RemoteThread ELSA parsers
- Issue 806: rule-update: replace for with while when LOCAL_NIDS_RULE_TUNING=yes
- Issue 558: Add VirusTotal uploader
- Issue 369: Arpwatch
- Issue 651: ELSA: starman restart doesn't work properly
- Issue 336: When configuring ELSA log node, change MySQL port using /etc/mysql/conf.d/
- Issue 467: ELSA dashboard for Snort performance
- Issue 594: securityonion-sudoers: 10_securityonion
- Introduction
- Use Cases
- Hardware Requirements
- Release Notes
- Download/Install
- Booting Issues
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthrough
- Videos
- Architecture
- Cheat Sheet
- Conference
- Elastic Stack
- Elastic Architecture
- Elasticsearch
- Logstash
- Kibana
- ElastAlert
- Curator
- FreqServer
- DomainStats
- Docker
- Redis
- Data Fields
- Beats
- Pre-Releases
- ELSA to Elastic
- Network Configuration
- Proxy Configuration
- Firewall/Hardening
- Email Configuration
- Integrating with other systems
- Changing IP Addresses
- NTP
- Managing Alerts
- Managing Rules
- Adding Local Rules
- Disabling Processes
- Filtering with BPF
- Adjusting PF_RING for traffic
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs