t3chn0m4g3
540d5574d1
cleanup, tweaking, updating
...
make tpotinit aware of sigterm events to unload blackhole routes, firewall rules
fixes #1204 where citrixhoneypot logs use logs instead of log folder
bump ELK stack to 8.12.2
add wordpot logs to logstash pipeline
bump t-pot attackmap to 2.2.0, alpine 3.19
2024-03-12 17:03:43 +01:00
Marco Ochse
7ae6c73b88
Testing and developing in alpha branch
2024-02-14 19:23:25 +01:00
t3chn0m4g3
1da37b5f85
re-implement distributed feature, without ssh
...
add sensor compose file
add distributed option to tpot config
housekeeping / cleanup
2024-01-05 20:19:50 +01:00
t3chn0m4g3
c1808161e4
fixes #1346
2023-06-07 05:54:17 +00:00
Marco Ochse
e3b1fd298a
Prepare fix for #1336 .
2023-05-31 17:21:15 +02:00
t3chn0m4g3
1a2d34c013
bump elk to 8.6.2, rebuild images
2023-05-30 14:35:45 +00:00
t3chn0m4g3
f438be7e27
Allow for automatic geoip db downloads
2023-05-07 18:10:23 +02:00
t3chn0m4g3
efd5f4c54c
fixes #1320
2023-05-03 22:01:36 +00:00
t3chn0m4g3
35188ef28e
add option to retrieve ENVs from file
2023-05-02 13:11:05 +02:00
t3chn0m4g3
7e60b46732
fixes #1254 , fixes #1253
...
- #1254 : new ELK images will be provided shortly
- #1253 : documentation and updater will now reflect that an update from 20.06.x is no longer possible
2023-01-26 10:49:24 +00:00
t3chn0m4g3
c178d878ab
bump ELK to 8.5.3
2023-01-23 16:33:09 +00:00
t3chn0m4g3
2641d1e743
bump elastic stack to 8.4.3
2022-11-02 16:37:01 +00:00
t3chn0m4g3
1122d3728e
Bump ELK Stack to 8.3.3
2022-08-17 16:34:53 +00:00
t3chn0m4g3
a3bda5de8f
bump Elastic stack to 8.2.3
2022-06-15 14:29:23 +00:00
t3chn0m4g3
5f0c337f09
bump elk, log4pot, honeytrap, dionaea to ubuntu 22.04
2022-06-14 10:47:11 +00:00
t3chn0m4g3
73b54f5504
Bump Elastic Stack to 8.2.2
2022-06-01 10:26:49 +00:00
t3chn0m4g3
55da6a4841
Bump Elastic Stack to 8.2.0, update objects
2022-05-25 14:53:29 +00:00
t3chn0m4g3
f13d08287f
prep for elk 8.1.2
2022-04-15 13:11:25 +00:00
Marco Ochse
c2aa0af2f3
Merge branch 'master' into 22.x
2022-04-11 16:47:44 +02:00
t3chn0m4g3
36774d0b71
update tags / version to 2204, tweaking README
2022-04-08 13:45:53 +00:00
t3chn0m4g3
5f18f7f17f
finetune logstash image and compose settings
2022-03-31 14:46:56 +00:00
t3chn0m4g3
572d540ead
tweaking ntp and logstash
...
remove ntp and replace with timesyncd (client only)
adjust logstash config
2022-03-30 20:32:24 +00:00
t3chn0m4g3
9705538dba
fix typo
2022-03-30 18:00:15 +00:00
t3chn0m4g3
22276d1cc6
fix permissions for distributed setup
2022-03-30 15:53:08 +00:00
t3chn0m4g3
e2752458d4
bump elk to 7.17.0 to support 8.0.1 in 22.x
2022-03-18 16:23:27 +00:00
t3chn0m4g3
b7096d6df6
bump elk to 8.0.1
2022-03-18 07:58:00 +00:00
t3chn0m4g3
9d7c24892d
image tweaking
2022-03-08 23:36:03 +00:00
t3chn0m4g3
5237215bf0
tweaking, add sentrypeer to logstash config
2022-02-24 17:39:57 +00:00
t3chn0m4g3
656c99446e
fix template
2022-02-20 16:38:15 +00:00
t3chn0m4g3
a73c4b67d9
reduce index refresh to 1s
2022-02-18 19:55:31 +00:00
t3chn0m4g3
7ee263e8e8
bump elastic stack to 8.0.0
2022-02-16 02:55:20 +00:00
t3chn0m4g3
278c7aa61a
bump elastic stack to 7.17.0
2022-02-02 22:57:50 +00:00
t3chn0m4g3
a507bc5f39
logstash cleanup, prep for multiarch, move to ubuntu
...
log4pot tweaking
2022-01-23 14:49:07 +00:00
t3chn0m4g3
3524bafda2
Cleanup, Tweaking
...
Remove old Sensor Edition and replace with Pot Edition
Rename Pot Edition to new Sensor Edition
POT is now called SENSOR
2022-01-20 18:26:43 +00:00
t3chn0m4g3
602d1cc673
bump Elastic Stack to 7.16.3, change deprecated fields
2022-01-20 10:32:10 +00:00
t3chn0m4g3
d301cf0447
tweaking, remove honeypy => deprecated
2022-01-17 17:45:03 +00:00
t3chn0m4g3
c611101987
improve nginx logging
2022-01-17 17:15:04 +00:00
Marco Ochse
cac7cdcec6
fix data fields with regard to the request field, log4pot, nginx
2022-01-17 17:10:48 +01:00
t3chn0m4g3
68d6aa4180
fix data fields with regard to the request field, log4pot, nginx
2022-01-17 14:50:50 +00:00
t3chn0m4g3
0e5986d2df
Tweaking
...
Remove Elasticsearch-Curator in packages, configs and references (BREAKING CHANGE)
Add Index Lifecycle Management in favor of elasticsearch-curator
Point all images to 2203 tags
2022-01-14 15:52:08 +00:00
t3chn0m4g3
fb49a77180
tweaking, json_batch transfer to hive
2022-01-07 15:41:57 +00:00
t3chn0m4g3
467dfae320
cleanup, move to correct folders
2022-01-04 18:35:44 +00:00
t3chn0m4g3
788a4c4f98
prepare for new attack map feature
...
tweaking, cleanup
2022-01-04 16:16:27 +00:00
t3chn0m4g3
68b080a3a8
Work in progress!
...
This is the foundation for the distributed T-Pot feature,
highly work in progress, only works with local docker image builds,
will be available for prod for upcoming T-Pot 22xx.
2022-01-03 18:24:17 +00:00
t3chn0m4g3
ef1a1fa057
Merge branch 'master' of https://github.com/telekom-security/tpotce
2021-12-21 11:37:18 +00:00
t3chn0m4g3
daf41b4b71
tweaking
2021-12-21 11:36:38 +00:00
t3chn0m4g3
aaccb43471
bump elk stack to 7.16.2
...
ELK 7.16.2 includes log4j 2.17.0 to address latest issues
2021-12-20 11:17:18 +00:00
t3chn0m4g3
b0339610a2
Prep for Log4Pot integration
2021-12-16 20:25:40 +00:00
t3chn0m4g3
a98b447556
ELK 7.16.1 fixes log4j vulns.
2021-12-13 15:59:48 +00:00
t3chn0m4g3
0ef2e89cac
remove log4j JndiLookup Class
2021-12-13 10:35:22 +00:00