Commit graph

515 commits

Author SHA1 Message Date
Alfredo Cardigliano
f124dab10f Improve reported scan message 2026-01-07 15:21:50 +01:00
Alfredo Cardigliano
332c7d5df5 Add ProfinetTooManyErrorsAlert 2026-01-05 15:33:21 +01:00
Alfredo Cardigliano
e7c62c72c3 Add alert definitions for S7Comm 2025-12-16 11:20:15 +01:00
Matteo Biscosi
3975ed3018 Fixes flow alert description (#9873) 2025-12-04 11:47:21 +01:00
Manuel Ceroni
ff3c9605a5
Fixed quota exceeded alert (#9872) 2025-12-03 17:54:50 +01:00
Matteo Biscosi
bdae6129a0 Modified blacklisted flow alert description 2025-11-21 12:46:34 +01:00
Luca Deri
5f30641db3 Localized scan realtime alert message and improved message 2025-10-28 22:08:04 +01:00
Luca Deri
fbc55ab340 Implemenred support for flow risk NDPI_MISMATCHING_PROTOCOL_WITH_IP 2025-10-18 00:06:26 +02:00
Luca Deri
97c0bbb039 Improved alert formatting 2025-09-28 10:12:36 +02:00
Luca Deri
0e4014d7bf Minor formatting changes 2025-09-27 22:28:14 +02:00
Luca Deri
e13a7208e8 Improved alert reporting 2025-09-27 15:37:12 +02:00
Luca Deri
681d7703c9 Impoved alert formatting 2025-09-11 19:30:07 +02:00
Luca Deri
bdbf22de07 Improved AS changes script 2025-09-11 18:01:08 +02:00
Luca Deri
fe25a7a531 AS ranking alert changes 2025-09-11 17:04:54 +02:00
Alfredo Cardigliano
5fd9089eeb Add alert details page to AS alerts 2025-09-11 15:51:44 +02:00
Alfredo Cardigliano
94ef20b5d6 Safety check 2025-09-11 12:53:42 +02:00
Luca Deri
810ac15922 Fixed AS ranking alert 2025-09-09 23:09:33 +02:00
Luca Deri
e7dbf49932 AS ranking changes 2025-09-09 16:54:32 +02:00
Manuel Ceroni
d3b3a6b681
Removed AS from the message of the AS ranking changed alert (#9633) 2025-09-08 11:55:15 +02:00
Manuel Ceroni
837dc962b6
Implemented AS ranking changed alert (#9626) 2025-09-08 10:11:13 +02:00
Manuel Ceroni
62ef822ad4
Changed the message of the ASN Traffic Rule Alert (#9563) 2025-08-28 12:47:43 +02:00
Manuel Ceroni
33ad9fc7b6
Various fixes to ASN Traffic Rules (#9555)
* Various fixes to ASN Traffic Rules

* Formatted ASN names for ASN traffic rules alerts
2025-08-25 14:51:46 +02:00
Alfredo Cardigliano
ba382f7316 Add AS alert entity. Fix AS threshold crossed. 2025-08-25 14:45:22 +02:00
Manuel Ceroni
5e48729f68
Implemented ASN traffic rules (#9531) 2025-08-19 23:17:25 +02:00
Alfredo Cardigliano
aebf4ccf37 Add nEdge Policy Violation check 2025-08-14 12:33:38 +02:00
Luca
9568fa96aa Added support for unresolved hostname risk 2025-08-04 22:52:19 +02:00
Matteo Biscosi
13ebc1e8d0 Possible fix for issue description and removed Connection Refused alert (#9233) 2025-05-23 11:21:06 +02:00
Matteo Biscosi
52a9c5c0e8 Fixes unexpected server alerts not working 2025-05-22 12:30:10 +02:00
Manuel Ceroni
534048ac4f
Fixed empty description column (#9216) 2025-05-16 12:00:11 +02:00
Matteo Biscosi
3d6d26422a Fixes bidirectional traffic check description 2025-05-13 17:04:03 +02:00
Alfredo Cardigliano
f4e5625669 Add safety check 2025-04-15 11:21:17 +02:00
Alfredo Cardigliano
8e9532680d Fix elephant flows description. Print exceeding threshold only. #9075 2025-04-14 14:36:49 +02:00
Manuel Ceroni
26c23347e7
Improved Scan Alerts with MITRE and fixes (#9127) 2025-04-08 11:33:53 +02:00
Manuel Ceroni
9127b22b76
Improved Scan Realtime Alert (#9122) 2025-04-07 16:26:08 +02:00
Manuel Ceroni
e1328ae36b
Implemented Scan Realtime Alert (#9106)
* Implemented Scan Realtime Alert

* Removed old scan alerts
2025-04-04 12:42:46 +02:00
Alfredo Cardigliano
7dcf3de812 Fix ip_outsite_dhcp_range alert 2025-04-01 13:17:46 +02:00
Manuel Ceroni
486dc0e33e
Implemented nat detected alert (#9074) 2025-03-27 11:28:16 +01:00
Alfredo Cardigliano
eb5df64e5f Fix links 2025-03-26 16:47:40 +01:00
Luca Deri
e0b908b42e Removed obsoleted TLSSuspiciousESNIUsage
Improved device type guessing based on the OS
2025-03-25 21:56:38 +01:00
Luca Deri
a4e09a03e4 Minor cosmetic changes 2025-03-21 16:59:47 +01:00
Manuel Ceroni
fe0975ba2a
Added Service Down check to Scan Alert (#9066) 2025-03-21 16:55:29 +01:00
Alfredo Cardigliano
b077895c01 Fix format 2025-03-18 09:05:55 +01:00
Alfredo Cardigliano
8690becceb Parse query id from syslog alerts 2025-03-17 20:14:56 +01:00
Alfredo Cardigliano
0cff924bf8 Fix ext alert formatter 2025-03-17 18:34:04 +01:00
Manuel Ceroni
43ead976bb
Implemented QoE Issues Alert (#9033)
* Implemented QoE Issues Alert

* Fixed QoE Issue alert serializer
2025-03-14 11:41:25 +01:00
Manuel Ceroni
00c6efdce6
Implemented network and service scan checks, merging them with the port scan check into a single alert (Scan Alert) (#9024) 2025-03-10 21:19:05 +01:00
Matteo Biscosi
34b559e66d Added attacker in port scan (#9009) 2025-03-05 11:52:56 +01:00
Manuel Ceroni
83d6fb24da
Port scan alert aggregation (#9021) 2025-03-04 16:12:13 +01:00
Manuel Ceroni
d4b7a3d375
Implemented port scan alert (clickhouse) (#9006) 2025-02-27 10:44:18 +01:00
Manuel Ceroni
4ad05ce8e5
Implemented an alert for anomalous Redis reads and writes number (#8969) 2025-02-19 17:48:47 +01:00