Security-Onion-Solutions / securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
https://securityonion.net
3.16k stars 492 forks source link

FEATURE: Add Additional ICS Zeek Packages #9149

Closed TOoSmOotH closed 1 year ago

TOoSmOotH commented 1 year ago

New ICS Packages

weslambert commented 1 year ago

Analyzers/Plugins:

https://github.com/Security-Onion-Solutions/securityonion-image/blob/dev/so-zeek/Dockerfile#L43-L59

Dashboards:

https://github.com/Security-Onion-Solutions/securityonion/blob/dev/salt/soc/files/soc/dashboards.queries.json#L51-L62

Hunt Event Fields:

https://github.com/Security-Onion-Solutions/securityonion/blob/dev/salt/soc/files/soc/hunt.eventfields.json#L62-L106

Pipelines:

https://github.com/Security-Onion-Solutions/securityonion/tree/dev/salt/elasticsearch/files/ingest