Commit graph

7310 commits

Author SHA1 Message Date
Simone Mainardi
98bebc850c Fixes dynamic loading of Lua flow risk alerts
Addresses #5743
2021-09-15 16:11:09 +02:00
Simone Mainardi
b5640f2b7b Implements lua {check,alert}_definitions for all unhandled risks
Addresses #5743
2021-09-15 16:08:44 +02:00
Simone Mainardi
fef7723445 Implements dynamic loading of flow risk alerts in Lua
Addresses #5743
2021-09-15 13:57:43 +02:00
Simone Mainardi
b01f8e50b8 Fixes TLS version for obsolete TLS alerts via ZMQ
Addresses #5860
2021-09-13 10:21:33 +02:00
Simone Mainardi
5f70c1eff7 Implements support for obsolete client SSH version
Addresses #5861
2021-09-10 12:32:42 +02:00
Simone Mainardi
4b55e02899 Reworks check for Obsolete SSH that was not handling cli and srv
Addresses #5861
2021-09-10 11:58:46 +02:00
Simone Mainardi
2cb849c98f Implements alert filters by score
Implements #5859
2021-09-09 18:27:01 +02:00
MatteoBiscosi
d468ee8f45 Added score to flow alert description (#5862) 2021-09-09 17:01:18 +02:00
MatteoBiscosi
6b7bcef800 Added flow verdict icon (#5854) 2021-09-09 16:37:32 +02:00
MatteoBiscosi
8c0c153bb0 Changed flow verdict position (#5854) 2021-09-09 11:57:47 +02:00
Simone Mainardi
a8f5055d35 Fixes regression causing missing host ARP chart
Fixes regression introduced with 60f309ae52
2021-09-08 17:54:09 +02:00
Simone Mainardi
ce11755559 Fixes ARP stats not selecting the interface 2021-09-08 17:53:20 +02:00
Vasilis Tako
72cd143267 White Mode UI Fixes 2021-09-08 17:32:23 +02:00
Vasilis Tako
c6e9e753dd Fixed Restart Modal 2021-09-08 16:38:43 +02:00
Simone Mainardi
e011bd2c26 Fixes flow verdict shown for packet interfaces 2021-09-08 16:23:44 +02:00
Matteo Biscosi
120cd82c39 Changed format and position of Flow Verdict information 2021-09-08 15:47:23 +02:00
Vasilis Tako
f08b66fa01 Removed deprecated donation field(#5850) 2021-09-08 13:50:00 +02:00
MatteoBiscosi
031c006f6d Fixes top senders/receivers only showing local hosts (#5832) 2021-09-07 15:45:12 +02:00
Alfredo Cardigliano
bd7f390d02 Move updates js to the footer to reduce noise 2021-09-07 15:44:44 +02:00
MatteoBiscosi
040dfcbbf8 Added non nil session check 2021-09-07 12:27:11 +02:00
MatteoBiscosi
a1e4e21c01 Removed threshold configuration from Score Anomaly check (#5845) 2021-09-07 11:45:16 +02:00
MatteoBiscosi
c15b62407c Separated Score Threshold and Anomaly alert (#5845) 2021-09-07 11:38:48 +02:00
Simone Mainardi
00787c0e7e Implements support for nProbe field L7_INFO
Addresses #5844
2021-09-06 14:35:16 +02:00
Simone Mainardi
243bcce623 Adds DNS request type to flow details
Implements #5841
2021-09-06 11:02:51 +02:00
MatteoBiscosi
f83a474f17 Added AS Name to nindex flow export (#5834) 2021-09-03 17:08:49 +02:00
MatteoBiscosi
b697113866 Added at simbol to username pattern (#5835) 2021-09-02 18:21:03 +02:00
MatteoBiscosi
b577afcf0e Generalized get first ip from mac function 2021-09-02 11:13:57 +02:00
Luca Deri
d50ee908ce Disable ARP from ZMQ interfaces (#5824) 2021-09-01 13:21:23 +02:00
Alfredo Cardigliano
e79c7fca66 Fix observation point lookup. Fix indentation. 2021-09-01 09:35:20 +02:00
Matteo Biscosi
ca786b6a8c Fixes no flows shown using observation Points (#5821) 2021-08-31 18:53:58 +02:00
MatteoBiscosi
d4f0396568 Changed alerted flow title position (#5820) 2021-08-31 12:46:54 +02:00
MatteoBiscosi
04347a99d8 Implements host pools edit button (#4916) 2021-08-31 11:08:32 +02:00
Vasilis Tako
1ae418344f Implemented date format user preference (#4399) 2021-08-30 19:58:59 +02:00
MatteoBiscosi
c4e8c9e499 Fixes Local HTTP Servers no data (#5817) 2021-08-30 12:57:59 +02:00
MatteoBiscosi
f263fffd6e Added extra space in filter flows stats (#5813) 2021-08-30 10:35:31 +02:00
MatteoBiscosi
cce12ef8bd Geo Map customization settings setted as default enabled (#5802) 2021-08-28 11:03:10 +02:00
MatteoBiscosi
494cc23a2d Fixes date format user preference (#4399) 2021-08-27 17:10:09 +02:00
MatteoBiscosi
b199478e03 Added Geo Map preferences redirection (#5802) 2021-08-27 16:43:11 +02:00
Vasilis Tako
fe0806a09d Implemented date format UI preference (#4399) 2021-08-27 16:31:12 +02:00
Vasilis Tako
af1ab037e9 Fixed geomap zoom button. Fixed ZMQ interface icon 2021-08-27 16:03:31 +02:00
MatteoBiscosi
b0e4dc5d40 Implements Geo Map stats customization (#5802) 2021-08-27 12:27:35 +02:00
Vasilis Tako
432fd040f6 Added custom notes to host config (Issue #5619) 2021-08-26 16:31:10 +02:00
MatteoBiscosi
b82cbe76c9 Reduced length of suspicious dga domain (#5804) 2021-08-26 12:15:19 +02:00
MatteoBiscosi
954f68a5c9 Implements interface dropdown pref to show only name (#5505) 2021-08-26 11:53:13 +02:00
MatteoBiscosi
70e32fd566 Changed redirect icon loc. and added redirect to SuspiciousDgaDomain alert (#5806) 2021-08-26 10:51:12 +02:00
MatteoBiscosi
37267ab935 Removed not used DES structure and Fixed non working alert (#5713) 2021-08-25 16:45:16 +02:00
Francesco Amodeo
de27966413
Implemented countries host check (#5713)
* Added check and alert implementation

* Fixed size of estimation and some typo

* Added HLL counters and DES structure
Co-authored-by: Paolo Junior Mollica <p.mollica@studenti.unipi.it>

* fixes according comments of PR

* decreased memory footprint

* resolved conflicts

* fixed HostCheckID

* Removed wrongly committed file

Co-authored-by: paolo-junior-mollica <paolo.junior.mollica@gmail.com>
Co-authored-by: Matteo Biscosi <49585191+MatteoBiscosi@users.noreply.github.com>
2021-08-25 15:50:07 +02:00
MatteoBiscosi
5df881478d Fixes domain names contacts alert not working 2021-08-25 12:34:38 +02:00
Gaetano Barresi
f650a3700a
Domain Names host check (#5723)
* Adding/modifying .cpp for Domain Names host check

* Adding/modifying .h/.lua for Domain Names host check

* minor synstax fix

* dns_contacts

Co-authored-by: Stefano Russo <55586218+D0kken@users.noreply.github.com>
Co-authored-by: Stefano Russo <s.russo41@studenti.unipi.it>
2021-08-25 11:22:41 +02:00
MatteoBiscosi
a582aa6243 Fixes header alignment different from data alignment (#5774) 2021-08-25 11:11:03 +02:00