Commit graph

490 commits

Author SHA1 Message Date
MatteoBiscosi
47497ca666 Fixes behavior anomaly alert key not found 2021-06-23 22:55:08 +02:00
MatteoBiscosi
fd40e51428 Changed alert behavior location 2021-06-23 17:58:30 +02:00
MatteoBiscosi
a6aa647624 Removed path and timeseries string from behavior alerts 2021-06-23 16:23:45 +02:00
MatteoBiscosi
462eaa384b Fixes ASes and Networks alert behavior 2021-06-23 15:14:03 +02:00
Alfredo Cardigliano
279ed66deb Add alert type filter for all families 2021-06-23 12:53:20 +02:00
MatteoBiscosi
638bf881fd Migrated periodicity update alert into flow alert 2021-06-21 17:47:03 +02:00
MatteoBiscosi
6549d19a99 Fixes alert formatting broken (#5536) 2021-06-21 16:16:22 +02:00
MatteoBiscosi
f4d4543fab Changed behavior anomaly alert (#5521) 2021-06-21 09:41:53 +02:00
MatteoBiscosi
7f9cf7a181 Removed debug print 2021-06-18 15:27:42 +02:00
MatteoBiscosi
89071f0a9a Fixes alert score/flow anomaly description (#5522) 2021-06-18 15:19:08 +02:00
MatteoBiscosi
8a1e315496 Fixed lateral movement alert description (#5524) 2021-06-18 11:37:25 +02:00
MatteoBiscosi
5a02d2a0d7 Fixed lateral movement not triggering 2021-06-18 11:08:44 +02:00
MatteoBiscosi
dd3a038a0f Changed lateral movement description (#5517) 2021-06-18 10:07:48 +02:00
Luca Deri
34897cec6b Fix for alert display 2021-06-18 08:51:39 +02:00
MatteoBiscosi
5c4142fdcb Implements behavioral alerts (#5500 #5501) 2021-06-17 17:10:02 +02:00
MatteoBiscosi
cf363eaa10 Changed old info string into lateral movement 2021-06-17 12:05:26 +02:00
MatteoBiscosi
48554751f9 Removed duplicated info from lateral movement alert 2021-06-17 12:02:56 +02:00
MatteoBiscosi
a89c95dba4 Migrated Lateral Movement alert from interface to flow (Fixes #5485) 2021-06-17 11:07:29 +02:00
Simone Mainardi
25159f0a9b Refactors {host,flow}_callbacks into {host,flow}_checks (lua) 2021-06-16 18:59:07 +02:00
Simone Mainardi
9a541f14ba Cleanup unused alert_check_calls_drops.lua 2021-06-16 18:48:51 +02:00
Simone Mainardi
76fd315d1b Refactors user_scripts into checks (lua) 2021-06-16 18:02:22 +02:00
Simone Mainardi
f39401e64a Fixes ogin denied for user 'nil' 2021-06-14 14:32:28 +02:00
Luca Deri
c76cce1c4f Renamed Host Ban to Dangerous Host 2021-06-09 22:54:17 +02:00
Simone Mainardi
fc2db1513b Cleanup of unnecessary items in user scripts config. JSON
Fixes #5456
2021-06-08 18:38:58 +02:00
Simone Mainardi
1ca6effc02 Fixes nils in start/stop ntopng process alerts 2021-06-07 12:13:09 +02:00
Simone Mainardi
f242b94b6d Fixes incomplete active monitoring messages upon check failures
Fixes #5420
2021-06-01 10:13:26 +02:00
Matteo Biscosi
756966c62b Added nProbe license and maintenance infos to iface 2021-05-31 12:28:41 +02:00
Simone Mainardi
4352638cdf Reworks and completes attacker/victim for all flow alerts
Addresses #5310
2021-05-28 17:03:37 +02:00
Simone Mainardi
0ac075c01c Fixes attacker for suspicious DGA domains
Partially addresses #5310
2021-05-27 18:27:29 +02:00
Simone Mainardi
11ed4d076b Fixes for nil ghost network alert 2021-05-26 14:36:05 +02:00
Matteo Biscosi
4e5e72bc12 Removed debug print 2021-05-25 19:15:35 +02:00
Matteo Biscosi
211fc3eb9f Implements policy endpoint and fixed Dangerous Host alert 2021-05-24 16:39:30 +02:00
Matteo Biscosi
bcc717689f Partially Implements traffic blocking (#5387) 2021-05-21 18:40:49 +02:00
Matteo Biscosi
83ff018198 Added fixed len to score anomaly alert category percentage 2021-05-17 18:27:36 +02:00
Matteo Biscosi
bc80a86d73 Added score breakdown to score anomaly alert
Implements #5339
2021-05-17 18:24:01 +02:00
Matteo Biscosi
020b1fd539 Removed confusing icons from alerts/hosts/flows tables 2021-05-17 15:51:10 +02:00
Matteo Biscosi
fdf8fbadb8 Fixes Host/Flow anomaly description
Implements #5337
Implements #5333
2021-05-17 14:53:20 +02:00
Simone Mainardi
bb3f8ed168 Implements efficient unexpected_new_device alert 2021-05-11 19:03:40 +02:00
Simone Mainardi
6fa3a2cc27 Fixes duration for engaged alerts always set to <1 second 2021-05-10 15:42:46 +02:00
Simone Mainardi
bfc9e72193 Fixes label for zero TCP window alerts 2021-05-10 13:02:53 +02:00
Simone Mainardi
87d8c89107 Fixes missing certificate names in TLS mismatch alerts
Fixes #5299
2021-05-10 09:25:09 +02:00
Simone Mainardi
27fcd52bf9 Improves message for obsolete TLS
Addresses #5299
2021-05-10 08:55:49 +02:00
Matteo Biscosi
c550b53352 Fixes missing info in TLS Certificate Expired
Implements #5270
2021-05-06 11:50:27 +02:00
Alfredo Cardigliano
52a483142b Fix alert_remote_access format 2021-05-06 09:50:37 +02:00
Simone Mainardi
c701c5fcfe Fixes TLS-related alert descriptions 2021-05-05 17:06:29 +02:00
Simone Mainardi
286d2cfdbc Fixes descriptions for host alerts 2021-05-05 16:40:31 +02:00
Alfredo Cardigliano
fd977d4924 Cleanup alert on score (lua) 2021-05-05 16:26:46 +02:00
Simone Mainardi
ef61b6db4a Fixes for descriptions of blacklisted and suspicious 2021-05-05 15:23:11 +02:00
Alfredo Cardigliano
ef65671794 Remove alert severity from Alerts. Always use score (convert to severity when required for UI or similar) 2021-05-05 09:54:14 +02:00
gabryon99
e455fbbeca fixed icons size 2021-05-04 12:20:25 +02:00