Commit graph

7586 commits

Author SHA1 Message Date
Matteo Biscosi
76972653e3 Fixes historical charts not correctly working 2025-04-18 16:44:57 +02:00
Alfredo Cardigliano
27d7a7e812 Fix call to get local hosts 2025-04-18 09:21:42 +02:00
Matteo Biscosi
f94ed11c50 Added QOE to Historical flows 2025-04-17 19:03:22 +02:00
Alfredo Cardigliano
51f24891dc Show toasts when the flows/hosts limit is exceeded 2025-04-17 17:06:54 +02:00
Luca Deri
fe4cba574d Reworked flow dump
Conditionally enabled clickhouse flow dump based on preference
2025-04-15 17:48:08 +02:00
Alfredo Cardigliano
c4c2a2d3a3 Fix #9153 2025-04-15 17:27:46 +02:00
Alfredo Cardigliano
f4e5625669 Add safety check 2025-04-15 11:21:17 +02:00
Manuel Ceroni
389f8f30e0
Added preference to dump pcap flows to clickhouse (#9150) 2025-04-15 10:16:43 +02:00
Alfredo Cardigliano
8e9532680d Fix elephant flows description. Print exceeding threshold only. #9075 2025-04-14 14:36:49 +02:00
Alfredo Cardigliano
1bd1568240 Fix format_utils.round 2025-04-14 13:25:38 +02:00
GabrieleDeri
ce4238ff06
Initial component for d3 alerts geomap (#9141) 2025-04-11 12:32:18 +02:00
Manuel Ceroni
3859b5adae
Implemented STARTTLS preference (#9124)
* Implemented STARTTLS preference

* Fixed STARTTS preference
2025-04-08 11:57:48 +02:00
Manuel Ceroni
26c23347e7
Improved Scan Alerts with MITRE and fixes (#9127) 2025-04-08 11:33:53 +02:00
Manuel Ceroni
9127b22b76
Improved Scan Realtime Alert (#9122) 2025-04-07 16:26:08 +02:00
Luca Deri
2e00f9fe50 Implemented discover.getOsId 2025-04-04 18:59:42 +02:00
Luca Deri
ab12565da2 Added check 2025-04-04 14:19:23 +02:00
Manuel Ceroni
e1328ae36b
Implemented Scan Realtime Alert (#9106)
* Implemented Scan Realtime Alert

* Removed old scan alerts
2025-04-04 12:42:46 +02:00
Matteo Biscosi
53b975777c Added packets breakdown 2025-04-03 15:39:52 +02:00
Matteo Biscosi
753b830b60 Added snmp_context lint 2025-04-02 11:34:45 +02:00
Matteo Biscosi
92c4fba362 Added import/export assets (#9079) 2025-04-02 09:39:38 +02:00
Alfredo Cardigliano
0eac289ecd Update lint 2025-04-01 18:12:49 +02:00
Alfredo Cardigliano
7dcf3de812 Fix ip_outsite_dhcp_range alert 2025-04-01 13:17:46 +02:00
GabrieleDeri
ceb521a381
Started implementing flow alerts graph (#9096)
* Removed CVE col from hosts table

* Removed CVE col from hosts table

* Started implementing alerts graph

* Added tooltip init
2025-03-31 21:25:19 +02:00
Luca Deri
80b71567b8 Cleaned-up OS type and aligned to nDPI 2025-03-31 13:07:48 +02:00
Luca Deri
0078c73b90 Cleanup 2025-03-29 20:46:54 +01:00
Luca Deri
dfa01cc736 Improved MAC address handling when 0.0.0.0 is used so that in this case we take inte MAC address into account
The flow details page now reports the correct MAC
2025-03-29 14:42:05 +01:00
Alfredo Cardigliano
236520afbf Update os_type validation 2025-03-28 10:38:42 +01:00
Alfredo Cardigliano
7b99f64158 Add safety checks 2025-03-28 09:00:43 +01:00
Luca Deri
7d8b599a8c DHCP fingerprint is now reported on flows
Fixed OS inconsistencies
2025-03-27 21:43:48 +01:00
Manuel Ceroni
486dc0e33e
Implemented nat detected alert (#9074) 2025-03-27 11:28:16 +01:00
Alfredo Cardigliano
eb5df64e5f Fix links 2025-03-26 16:47:40 +01:00
Luca Deri
e0b908b42e Removed obsoleted TLSSuspiciousESNIUsage
Improved device type guessing based on the OS
2025-03-25 21:56:38 +01:00
Luca Deri
bd422d221d Added MacMini device models 2025-03-25 15:43:48 +01:00
Luca Deri
fbe9b86d88 Added function for displaying device model 2025-03-25 15:35:19 +01:00
Luca Deri
809a83bdd5 Typo 2025-03-22 08:45:31 +01:00
Luca Deri
97997589c7 Updated Mac models list 2025-03-22 08:44:13 +01:00
Luca Deri
54f5b00098 Assets improvements 2025-03-21 18:57:34 +01:00
Luca Deri
a4e09a03e4 Minor cosmetic changes 2025-03-21 16:59:47 +01:00
Manuel Ceroni
fe0975ba2a
Added Service Down check to Scan Alert (#9066) 2025-03-21 16:55:29 +01:00
Alfredo Cardigliano
a35455bf27 Add utility function to mask IPs 2025-03-21 09:03:48 +01:00
Luca Deri
346e67fe27 Assets improvements 2025-03-20 21:50:00 +01:00
Alfredo Cardigliano
b6a95b82c8 Fix macOS label 2025-03-20 17:31:44 +01:00
Luca Deri
254af8566b Assets improvements 2025-03-18 22:32:31 +01:00
Luca Deri
14457b3818 Assets improvement 2025-03-18 20:58:09 +01:00
Luca Deri
704bb92b5b Asset rework 2025-03-18 18:01:44 +01:00
Alfredo Cardigliano
b077895c01 Fix format 2025-03-18 09:05:55 +01:00
Alfredo Cardigliano
b1fb4322f9 Fix correlation of suricata alerts for dns flows 2025-03-18 08:59:46 +01:00
Alfredo Cardigliano
8690becceb Parse query id from syslog alerts 2025-03-17 20:14:56 +01:00
Alfredo Cardigliano
0cff924bf8 Fix ext alert formatter 2025-03-17 18:34:04 +01:00
Manuel Ceroni
f5ea2e1062
Updated scan alert to display network address instead of network ID (#9043) 2025-03-17 15:39:59 +01:00