l3wiz
|
eb869c517f
|
Added vlan description
|
2021-06-17 14:43:25 +02:00 |
|
Simone Mainardi
|
2e8a6de0fc
|
Major terminology unification (user scripts -> checks)
|
2021-06-17 12:39:43 +02:00 |
|
MatteoBiscosi
|
cf363eaa10
|
Changed old info string into lateral movement
|
2021-06-17 12:05:26 +02:00 |
|
MatteoBiscosi
|
48554751f9
|
Removed duplicated info from lateral movement alert
|
2021-06-17 12:02:56 +02:00 |
|
Simone Mainardi
|
4a526c3cdf
|
Decouples checks from alerts (removes unnecessary flag is_alert)
|
2021-06-17 11:43:12 +02:00 |
|
MatteoBiscosi
|
a89c95dba4
|
Migrated Lateral Movement alert from interface to flow (Fixes #5485)
|
2021-06-17 11:07:29 +02:00 |
|
Simone Mainardi
|
25159f0a9b
|
Refactors {host,flow}_callbacks into {host,flow}_checks (lua)
|
2021-06-16 18:59:07 +02:00 |
|
Simone Mainardi
|
9a541f14ba
|
Cleanup unused alert_check_calls_drops.lua
|
2021-06-16 18:48:51 +02:00 |
|
Simone Mainardi
|
e33af8a23c
|
Refactors script_categories into check_categories (c++ and lua)
|
2021-06-16 18:43:55 +02:00 |
|
Simone Mainardi
|
9cc3162513
|
Refactors capability_user_scripts into capability_checks
|
2021-06-16 18:29:26 +02:00 |
|
MatteoBiscosi
|
7980726e8b
|
Fixes pro timeseries not showing
|
2021-06-16 18:12:21 +02:00 |
|
Simone Mainardi
|
76fd315d1b
|
Refactors user_scripts into checks (lua)
|
2021-06-16 18:02:22 +02:00 |
|
Luca Deri
|
3c3aa5a25f
|
Added check to avoid nil value error
|
2021-06-16 17:53:48 +02:00 |
|
MatteoBiscosi
|
8136eca368
|
Added vlan alias formatter name
|
2021-06-16 17:52:30 +02:00 |
|
Alfredo Cardigliano
|
95304bfd54
|
Fix links with severity filter
|
2021-06-16 15:57:05 +02:00 |
|
Simone Mainardi
|
a160ccf2d6
|
Refactors callback to check #defines (c++)
|
2021-06-16 15:56:07 +02:00 |
|
Simone Mainardi
|
40f5c4e821
|
Refactors {flow,host}callbacks into {flow,host}checks (C++)
|
2021-06-16 15:27:38 +02:00 |
|
MatteoBiscosi
|
af75c2443c
|
Fixes Jailed hosts - Unable to remove (#5503)
|
2021-06-15 19:00:02 +02:00 |
|
Simone Mainardi
|
c04fd9004c
|
Fixes alert exclusions not shown with alerts disabled
|
2021-06-15 17:43:42 +02:00 |
|
MatteoBiscosi
|
7467bf8066
|
Fixed wrongly vlan redis key
|
2021-06-15 17:39:39 +02:00 |
|
MatteoBiscosi
|
4b3f46e572
|
Added vlan alias lua methods (#5483)
|
2021-06-15 17:21:32 +02:00 |
|
Simone Mainardi
|
8547fb4192
|
Reworks score in the flow page and implements alert disable
Implements #5498
|
2021-06-15 16:27:07 +02:00 |
|
MatteoBiscosi
|
d78b0a15c3
|
Removed debug timeseries print
|
2021-06-15 12:35:57 +02:00 |
|
MatteoBiscosi
|
131888ecfc
|
Changed behavior counter dump period
|
2021-06-15 12:25:48 +02:00 |
|
Alfredo Cardigliano
|
1abb8e0c0d
|
Improve filtering on l7 ptoto. Fix returned l7 ID.
|
2021-06-15 11:39:43 +02:00 |
|
MatteoBiscosi
|
1670d6188c
|
Fixed behavior timeseries formatter
|
2021-06-15 10:21:22 +02:00 |
|
Alfredo Cardigliano
|
6624e382ab
|
HaEnable support for OR in ninde flow explorer. Cleanup operator separator (configured in tag_utils). Cleanup code.
|
2021-06-14 17:26:50 +02:00 |
|
Simone Mainardi
|
8cd62f79e9
|
Implements ability to filter/delete alert exclusions by host
|
2021-06-14 16:56:29 +02:00 |
|
Matteo Biscosi
|
7a71e564a9
|
Changed timeseries table merge order
|
2021-06-14 16:46:12 +02:00 |
|
Simone Mainardi
|
c897b19fa5
|
Adds host names in alert exclusions page
|
2021-06-14 15:45:34 +02:00 |
|
Simone Mainardi
|
f39401e64a
|
Fixes ogin denied for user 'nil'
|
2021-06-14 14:32:28 +02:00 |
|
Matteo Biscosi
|
9be0364102
|
Fixed partially timeseries not showing
|
2021-06-11 16:49:46 +02:00 |
|
Simone Mainardi
|
a2f891378d
|
Prints other issues in alerts sorted by score then alphabetically
Addresses #5402
|
2021-06-11 16:19:08 +02:00 |
|
l3wiz
|
5ea463a457
|
Disabled tooltip on x axis(Issue #5282)
|
2021-06-11 12:29:52 +02:00 |
|
Simone Mainardi
|
190a43c095
|
Fixes link for the all alerts page
Addresses #5486
|
2021-06-11 09:39:16 +02:00 |
|
Simone Mainardi
|
6e5d5ff5eb
|
Disables empty alert pages, reworks historical/engaged links
Addresses #5486
|
2021-06-11 09:33:09 +02:00 |
|
Matteo Biscosi
|
f12934ef9e
|
Implements Traffic TX/RX and Score Behavior analysis (#5473) (#5472)
|
2021-06-10 17:31:29 +02:00 |
|
Alfredo Cardigliano
|
20eeb76f7e
|
Fix cetegory id validation
|
2021-06-10 15:51:12 +02:00 |
|
Alfredo Cardigliano
|
e1b9723809
|
Add extended description to host alerts
|
2021-06-10 12:16:03 +02:00 |
|
Alfredo Cardigliano
|
09b5520134
|
Remove dbg tracing
|
2021-06-10 10:46:26 +02:00 |
|
Luca Deri
|
c76cce1c4f
|
Renamed Host Ban to Dangerous Host
|
2021-06-09 22:54:17 +02:00 |
|
Luca Deri
|
d674167498
|
Script is not enabled by default
|
2021-06-09 22:14:45 +02:00 |
|
Simone Mainardi
|
507d8dce28
|
Implements the ability to list/configure alarm exceptions
Implements #5461
|
2021-06-09 19:35:42 +02:00 |
|
Alfredo Cardigliano
|
2acca71f1d
|
Use meaningful param names
|
2021-06-09 16:29:26 +00:00 |
|
Alfredo Cardigliano
|
a2863d5b9e
|
Add l4_proto_list
|
2021-06-09 15:17:38 +00:00 |
|
Matteo Biscosi
|
0d2b764c84
|
Added asn to nindex flows (#5468)
|
2021-06-09 15:34:56 +02:00 |
|
Matteo Biscosi
|
8179d4749a
|
Added host name to alert select
|
2021-06-09 11:46:10 +02:00 |
|
Matteo Biscosi
|
d554f084f6
|
Added href, percentage and refresh on filters (#5476)
|
2021-06-09 11:22:04 +02:00 |
|
Luca
|
28368ac887
|
Harmonized host names in flows and used ASN instead of the meaningless MAC for remote hosts
|
2021-06-09 11:09:27 +02:00 |
|
Alfredo Cardigliano
|
1c50397e5b
|
Add tot count to alert_store get_stats
|
2021-06-09 08:41:04 +00:00 |
|