Commit graph

434 commits

Author SHA1 Message Date
Alfredo Cardigliano
b24905747c Add local_explorer flag to alert format callback 2023-11-13 13:02:07 +01:00
Nicolo Maio
6187ee30b8 [VS] Fix alert description. 2023-11-13 11:01:43 +01:00
Luca Deri
463b906b59 Added supporto for ModBUS Scattered Holding Register Read 2023-11-10 11:36:35 +01:00
Nicolo Maio
5ad7b64874 [VS] Add scan type in alert message (#7969) 2023-11-06 11:32:21 +01:00
Alfredo Cardigliano
5de25b0dfb Improve VS alert description (#7969) 2023-11-02 15:05:41 +01:00
Matteo Biscosi
b970d0859e Fixes shutting down doesn't insert alerts in CH (#7949) 2023-10-25 11:41:53 +00:00
Matteo Biscosi
f9a55743b6 Added malware host contacted check 2023-10-18 10:40:54 +00:00
Nicolo Maio
3aeab7041c [VS] Fix nil check cases. 2023-10-18 12:38:47 +02:00
Nicolo Maio
200190d301 Fix host and iface rules with ndpi:protocol metrics. (#7912) 2023-10-16 18:33:37 +02:00
Matteo Biscosi
ec3545df2d Fixes interface name (#7908) 2023-10-16 09:32:46 +00:00
Nicolo Maio
be6c2e0d4f [VS] Fix alert generation. 2023-10-12 16:58:55 +02:00
Nicolo Maio
3d44707cc8 [VS] Add UDP port handler and implement numerous fixes. 2023-10-12 15:17:05 +02:00
Nicolo Maio
225cd81bcb Add port service name and fix alerts (#7859) 2023-10-02 18:40:48 +02:00
Nicolo Maio
92ce0298d0 Remove tprint. 2023-09-07 16:01:16 +02:00
Nicolo Maio
08620ecdec Add traffic RX and TX (#7754) 2023-08-29 15:59:52 +02:00
Matteo Biscosi
dc291cf89e Changed VS alert message 2023-08-18 14:41:37 +00:00
Matteo Biscosi
f88f512ac2 Added debug print to VA 2023-08-18 12:52:34 +00:00
Matteo Biscosi
ad2e918f8d Moved vulnerability scan alert into active monitoring alerts (#7761) 2023-08-18 10:18:23 +00:00
Nicolo Maio
7d3696c076 Add host pools and networks in Local Traffic Rules. (#7754) 2023-08-17 17:45:32 +02:00
Nicolo Maio
2fb921e5f9 Fix server IP in unexpected DHCP server alert. 2023-08-14 16:21:20 +02:00
Nicolo Maio
481b135457 Remove useless comment and tprint. 2023-08-10 15:22:16 +02:00
Nicolo Maio
d812ae6043 Fix host rules alert. (#7737) 2023-08-08 17:34:40 +02:00
Matteo Biscosi
7eaa652d0e Fixes vulnerability scan alert 2023-08-04 15:18:46 +00:00
Matteo Biscosi
3ca4ad98ae Added vulnerability issues alert (#7717) 2023-08-04 13:24:27 +00:00
Matteo Biscosi
41d97dae8f Added possibility to load table with preloaded search 2023-08-01 14:59:07 +00:00
Matteo Biscosi
5e49c8e8ae Fixes device connection/disconnection alert 2023-07-26 09:28:09 +00:00
Alfredo Cardigliano
7a314e9d69 Add sample custom query for host alerts. Fix host alerts format to handle empty fields. 2023-07-24 15:50:59 +02:00
Nicolo Maio
9c3acf2f06 Add alert notification retention policy by default 1h. (#6240) 2023-07-19 16:25:32 +00:00
Alfredo Cardigliano
1bdf0680c6 Fix format of longlived alerts 2023-07-18 11:34:50 +02:00
Matteo Biscosi
4795779785 Fixes incorrect alert description 2023-07-10 17:23:56 +00:00
Nicolo Maio
1c10820858 Fix threshold sign. (#7645) 2023-07-07 16:18:45 +00:00
Matteo Biscosi
fcd6102ad0 Reworked behavior analysis alerts 2023-06-16 14:32:02 +00:00
Nicolo Maio
30f429d1de Add blacklist name. (#7549) 2023-06-14 11:56:13 +00:00
Nicolo Maio
78565f9fc0 Fix SNMP Alert Error Messages. (#7526) 2023-06-07 10:09:40 +00:00
Nicolo Maio
672a9de40a Fix snmp rules check. (#7512) 2023-06-06 15:16:06 +00:00
Nicolo Maio
8ad8d69b4e Fix snmp rules alert. (#7512) 2023-06-06 14:33:35 +00:00
Nicolo Maio
64c62e1586 Revert "Fix SNMP alerts in case of bad port number provided by the check"
This reverts commit 488f80f476.
2023-06-06 10:43:13 +00:00
Alfredo Cardigliano
488f80f476 Fix SNMP alerts in case of bad port number provided by the check 2023-06-06 10:35:43 +00:00
Luca Deri
e86cd0f2ce added Modbus Invalid Transition Alert 2023-06-05 00:53:27 +02:00
Luca Deri
4a13dc41d5 Implemented Modbus exceptions 2023-06-01 22:53:59 +02:00
Alfredo Cardigliano
6760c2bb77 Fix formatting of quota exceeeded alert 2023-05-19 15:57:38 +02:00
Alfredo Cardigliano
2434ae9e76 Cleanup deprecated code 2023-05-18 18:36:25 +02:00
Nicolo Maio
5bf92eec23 Add backend endpoint to handle checks. (#7446) 2023-05-15 16:12:17 +00:00
Matteo Biscosi
31d35583c2 Fixes device exclusion alert and added more info 2023-04-26 12:18:28 +00:00
Alfredo Cardigliano
64ab8b6bae Trigger External Host alerts directly from Lua (also for inactive hosts) (fix #7170) 2023-04-21 18:20:14 +02:00
Nicolò Maio
8cdda7cc69
Add flow exporter device check rules. (#7082) (#7364)
* Add flow exporter device check rules. (#7082)

* Remove debugger.

* Minor fix.

* Update en.lua
2023-04-07 16:28:24 +02:00
Luca Deri
96e10b12a5 Added stub for RareDestination check/alert implementation #6416 and #6417 2023-03-22 15:11:53 +01:00
Matteo Biscosi
76267099a2 Fixes alerts inconsistent alerts and checks names (#7314) 2023-03-14 15:36:07 +00:00
Matteo Biscosi
fc82eff56b Updated alert to NDPI_NUMERIC_IP_HOST 2023-03-02 15:18:40 +00:00
Nicolò Maio
b4b8307739
Fix alert_remote_to_local_insecure_proto alert message. (#7265) (#7277) 2023-02-27 13:01:45 +01:00