Commit graph

658 commits

Author SHA1 Message Date
Alfredo Cardigliano
502f4cd106 Delete alerts matching domain when adding exception 2022-05-27 16:50:25 +02:00
MatteoBiscosi
72f814c36c Added vlan support to exclusion lists (#6510) 2022-05-24 12:22:24 +02:00
MatteoBiscosi
08c9de2b7b Removed debug print 2022-05-20 11:36:31 +02:00
MatteoBiscosi
14e85b9888 Unified alert and flow details page style (#6565) 2022-05-20 11:30:44 +02:00
Luca Deri
b0158f89c2 Reworked MAC/IP Reassociation alert used to detect spoofind and MITM (Man In The Middle) Attacks 2022-05-15 19:17:18 +02:00
Alfredo Cardigliano
e35e3464d8 Code to use the flow alerts view 2022-04-20 17:24:09 +02:00
Alfredo Cardigliano
7b2db43e32 Fix Active Monitoring link to Settings 2022-02-24 12:10:39 +01:00
Alfredo Cardigliano
1dff8975d3 Move tag filters info 2022-02-15 11:05:21 +01:00
Alfredo Cardigliano
3aeed99115 Improve flow alert to historical flow lookup 2022-02-14 17:27:13 +01:00
MatteoBiscosi
57a85de50e Cleaned up the code from plugin_utils 2022-02-11 12:07:23 +01:00
Matteo Biscosi
da8609727f Removed half of the monitor plugins (#6224) 2022-01-21 19:21:58 +01:00
Simone Mainardi
705807ad9d Reworks active monitoring plugin structure 2022-01-21 12:21:44 +01:00
Alfredo Cardigliano
5406eb004d Move pcap download dialog. Cleanup filter generation. 2022-01-18 11:28:35 +01:00
Alfredo Cardigliano
2c561072ff Add download of pcap matching alert traffic 2022-01-17 17:56:14 +01:00
Alfredo Cardigliano
257ece18c0 Copyright update (Lua) 2022-01-03 09:42:33 +01:00
Simone Mainardi
38bc12b6d0 Fixes wrong time/timezone in forwarded syslog messages
Addresses #6097
2021-12-21 16:42:58 +01:00
Alfredo Cardigliano
cc6014a220 Add toast to warn about deprecated nindex support. Cleanup code. 2021-12-09 16:34:47 +01:00
MatteoBiscosi
a0b173c93b Implements MS Teams endpoint (#6023) 2021-11-03 16:11:22 +01:00
MatteoBiscosi
c54a85d60f Removed debug print 2021-10-19 10:14:49 +02:00
MatteoBiscosi
bdb4ceb7e0 Implements checkmk timeseries alert integration (#5269) 2021-10-19 10:12:27 +02:00
Simone Mainardi
1dd2b00988 Implements backend and frontend to show risks docs inline
Addresses #5857
2021-10-01 16:27:44 +02:00
MatteoBiscosi
8a359b8897 Fixes link error by adding new interface alert (#5711) and fixes top sites segv 2021-08-13 13:11:34 +02:00
Simone Mainardi
805b99f03c Adds search by tcp flags in SYN scan alert 2021-08-02 18:43:08 +02:00
Simone Mainardi
813d93db16 Adds support to link flows from host alerts with VLANs 2021-07-30 17:37:50 +02:00
Simone Mainardi
820e497253 Unifies epoch-related variables in Lua and JS 2021-07-30 15:38:06 +02:00
Simone Mainardi
f2d9ee41be Improves selection of epochs in alert flows drilldown 2021-07-30 14:56:33 +02:00
Simone Mainardi
af7b722510 Allows "ip" to search for client and server hosts 2021-07-30 12:51:46 +02:00
Simone Mainardi
41b23003a1 Implements generation of link from alerts to past flows
Addresses #5326
2021-07-29 16:54:15 +02:00
Simone Mainardi
50e3f40a8b Fixes attempt to concat boolean value
Fixes #5722
2021-07-29 09:15:57 +02:00
Simone Mainardi
de576aa999 Implements historical floww search function for all host alerts
Addresses #5326
2021-07-28 18:16:32 +02:00
Simone Mainardi
0ccb7b2864 Removes a debug print 2021-07-28 17:22:49 +02:00
Simone Mainardi
b6913c946d Implements skeleton to drilldown historical flows from alerts
Addresses #5326
2021-07-28 17:19:44 +02:00
Alfredo Cardigliano
aa072bef55 Fix flow alerts export (e.g. email) 2021-07-19 10:19:31 +02:00
Simone Mainardi
b117e8a23a Adds new REST API v2/
Addresses #5269
2021-07-08 09:57:46 +02:00
Simone Mainardi
38b3c9ebdc Shows acknowledged messages when present
Addresses #5600
2021-07-06 17:32:37 +02:00
Alfredo Cardigliano
ca6707c54a Rename haveAdminPrivileges -> isAdministratorOrPrintErr (use meaningful names) 2021-07-02 16:51:40 +02:00
Simone Mainardi
e70c16be27 Adds cog icon to configure checks from the flow details page
Addresses #5606
2021-07-01 17:28:37 +02:00
MatteoBiscosi
be198c2a99 Added L7 iface proto behavior analysis and alert (#5499 #5474) 2021-06-29 16:50:56 +02:00
MatteoBiscosi
4620e5c72d Fixes alert utils null indexing 2021-06-28 12:41:56 +02:00
MatteoBiscosi
c3a85560a7 Fixes wrongly formatter used for behavior anomaly alert 2021-06-28 11:38:39 +02:00
MatteoBiscosi
1ad608e905 Changed behavior alert family key into entities id 2021-06-25 15:06:21 +02:00
Simone Mainardi
63168f5ff2 Implements 'Subject' column for interface alerts
Addresses #5563
2021-06-24 15:51:17 +02:00
MatteoBiscosi
47497ca666 Fixes behavior anomaly alert key not found 2021-06-23 22:55:08 +02:00
MatteoBiscosi
fd40e51428 Changed alert behavior location 2021-06-23 17:58:30 +02:00
MatteoBiscosi
a6aa647624 Removed path and timeseries string from behavior alerts 2021-06-23 16:23:45 +02:00
MatteoBiscosi
462eaa384b Fixes ASes and Networks alert behavior 2021-06-23 15:14:03 +02:00
MatteoBiscosi
f4d4543fab Changed behavior anomaly alert (#5521) 2021-06-21 09:41:53 +02:00
MatteoBiscosi
5c4142fdcb Implements behavioral alerts (#5500 #5501) 2021-06-17 17:10:02 +02:00
Simone Mainardi
76fd315d1b Refactors user_scripts into checks (lua) 2021-06-16 18:02:22 +02:00
Simone Mainardi
ccb61a7444 Harmonizes remaining hardcoded Lua scores 2021-05-15 11:00:20 +02:00