t3chn0m4g3
2a4fe20b88
work in progress (map, wordpot)
2022-02-09 19:13:18 +00:00
t3chn0m4g3
278c7aa61a
bump elastic stack to 7.17.0
2022-02-02 22:57:50 +00:00
t3chn0m4g3
12a413b4cb
replace es-head with elasticvue, tweaking
...
es-head does not support building with ARM64 and had to be replaced with the even better elasticvue
elasticvue will now run within the nginx container, freeing some RAM :) on the way
2022-01-27 02:39:23 +00:00
t3chn0m4g3
cfcf870da3
elasticsearch, kibana: prep for multiarch, move to ubuntu
...
heade: alpine 3.15
2022-01-23 21:12:34 +00:00
t3chn0m4g3
a507bc5f39
logstash cleanup, prep for multiarch, move to ubuntu
...
log4pot tweaking
2022-01-23 14:49:07 +00:00
t3chn0m4g3
3524bafda2
Cleanup, Tweaking
...
Remove old Sensor Edition and replace with Pot Edition
Rename Pot Edition to new Sensor Edition
POT is now called SENSOR
2022-01-20 18:26:43 +00:00
t3chn0m4g3
602d1cc673
bump Elastic Stack to 7.16.3, change deprecated fields
2022-01-20 10:32:10 +00:00
t3chn0m4g3
d301cf0447
tweaking, remove honeypy => deprecated
2022-01-17 17:45:03 +00:00
t3chn0m4g3
c611101987
improve nginx logging
2022-01-17 17:15:04 +00:00
Marco Ochse
cac7cdcec6
fix data fields with regard to the request field, log4pot, nginx
2022-01-17 17:10:48 +01:00
t3chn0m4g3
68d6aa4180
fix data fields with regard to the request field, log4pot, nginx
2022-01-17 14:50:50 +00:00
t3chn0m4g3
0e5986d2df
Tweaking
...
Remove Elasticsearch-Curator in packages, configs and references (BREAKING CHANGE)
Add Index Lifecycle Management in favor of elasticsearch-curator
Point all images to 2203 tags
2022-01-14 15:52:08 +00:00
t3chn0m4g3
e7e521edba
tweaking
2022-01-12 01:28:06 +00:00
t3chn0m4g3
7d012726b7
tweaking
2022-01-11 15:43:45 +00:00
t3chn0m4g3
d6ea4cdde2
prep for elk 8.x, pave way for next t-pot release
2022-01-07 18:03:00 +00:00
t3chn0m4g3
fb49a77180
tweaking, json_batch transfer to hive
2022-01-07 15:41:57 +00:00
t3chn0m4g3
467dfae320
cleanup, move to correct folders
2022-01-04 18:35:44 +00:00
t3chn0m4g3
788a4c4f98
prepare for new attack map feature
...
tweaking, cleanup
2022-01-04 16:16:27 +00:00
t3chn0m4g3
68b080a3a8
Work in progress!
...
This is the foundation for the distributed T-Pot feature,
highly work in progress, only works with local docker image builds,
will be available for prod for upcoming T-Pot 22xx.
2022-01-03 18:24:17 +00:00
t3chn0m4g3
ef1a1fa057
Merge branch 'master' of https://github.com/telekom-security/tpotce
2021-12-21 11:37:18 +00:00
t3chn0m4g3
daf41b4b71
tweaking
2021-12-21 11:36:38 +00:00
t3chn0m4g3
aaccb43471
bump elk stack to 7.16.2
...
ELK 7.16.2 includes log4j 2.17.0 to address latest issues
2021-12-20 11:17:18 +00:00
t3chn0m4g3
b0339610a2
Prep for Log4Pot integration
2021-12-16 20:25:40 +00:00
t3chn0m4g3
a98b447556
ELK 7.16.1 fixes log4j vulns.
2021-12-13 15:59:48 +00:00
t3chn0m4g3
b4c1805551
disable log4j lookups
2021-12-13 10:54:07 +00:00
t3chn0m4g3
0ef2e89cac
remove log4j JndiLookup Class
2021-12-13 10:35:22 +00:00
t3chn0m4g3
5f29516197
tweaking
2021-12-08 23:55:13 +00:00
t3chn0m4g3
ce39e1bd4f
logstash logging for honeypots
2021-11-19 23:20:13 +00:00
t3chn0m4g3
c9b909e51d
finetune new honeypots logging
2021-11-02 19:13:28 +00:00
t3chn0m4g3
ea624351b5
finetuning logstash.conf for new honeypots
2021-10-29 16:28:16 +00:00
t3chn0m4g3
c1eb9f7216
logstash parsing for ddospot, hellpot
2021-10-28 18:57:55 +00:00
t3chn0m4g3
1a844d13ba
start integrating new honeypots into ELK
2021-10-27 16:14:52 +00:00
t3chn0m4g3
348a5d572b
bump elastic stack to 7.15.1
2021-10-26 13:56:38 +00:00
t3chn0m4g3
eefd38a335
bump elastic stack to 7.15.0
...
no image upgrade before 7.15.1
2021-09-30 20:40:42 +00:00
t3chn0m4g3
ed0c5aa89f
add logstash-output-gelf, fixes #861
2021-09-15 17:39:04 +00:00
t3chn0m4g3
9de1bdd0b5
tweaking, bump elastic stack to 7.14.1, rebuild dashboards
2021-09-15 15:58:44 +00:00
t3chn0m4g3
06ef8850fe
prep for ELK 7.13.4, start full integration of new honeypots
2021-08-25 15:04:27 +00:00
t3chn0m4g3
4cb84166c5
bump ewsposter to 1.2.0, elk stack to 7.13.2
2021-06-28 16:30:40 +00:00
t3chn0m4g3
f51ab7ec0f
prepare to bump elastic stack to 7.13.1
2021-06-10 17:03:22 +00:00
t3chn0m4g3
de38e5e86f
Rebuild Logstash, Elasticsearch
...
Setting static limits for Elasticsearch / Logstash on Xms, Xmx and Container RAM results in unwanted side effects for some installations. With Elastic supporting dynamic heap management for Java 14+ we now use OpenJDK 16 JRE and as such remove limitations. This should improve stability for T-Pot, provided the minimum requirements will be met.
2021-05-26 11:00:49 +00:00
t3chn0m4g3
0c5ab33b8a
bump elastic stack to 7.12.1
2021-05-17 16:32:03 +00:00
t3chn0m4g3
d5f0ceb15b
push elastic stack to 7.11.1
2021-02-19 10:17:30 +00:00
t3chn0m4g3
80d9efa729
bump elk stack images to alpine 3.13
2021-02-12 13:54:42 +00:00
t3chn0m4g3
e5f29f3c90
bump elk stack to 7.11.0
2021-02-12 13:21:35 +00:00
t3chn0m4g3
af6ce8854d
bump elastic stack to 7.10.1
2020-12-10 15:20:18 +00:00
t3chn0m4g3
f3f9f6ae72
cleanup
2020-12-03 00:01:38 +00:00
t3chn0m4g3
8a7e81815e
prep for Elastic Stack 7.10.0
2020-12-02 22:36:17 +00:00
t3chn0m4g3
e3fda4d464
bump dionaea to 0.9.2
2020-10-28 16:45:53 +00:00
t3chn0m4g3
92925cecbd
bump dicompot to latest master
2020-10-27 21:30:33 +00:00
t3chn0m4g3
f204cdf9b8
bump elk to 7.3
2020-10-27 19:43:32 +00:00
t3chn0m4g3
ff4a394e3b
reverting elk to 7.9.1
2020-10-15 12:24:46 +00:00
Brian Lechthaler
84a741ec64
IMPORTANT: Fix Node Version
...
Bump node version to `10.22.1-alpine`
**KIBANA WILL NOT WORK WITHOUT THIS**
2020-10-07 13:53:21 -07:00
Brian Lechthaler
d351a89096
Bump Kibana version to 7.9.2
2020-10-04 18:05:16 -07:00
Brian Lechthaler
488da48df7
Bump Logstash version to 7.9.2
2020-10-04 18:04:15 -07:00
Brian Lechthaler
85da099cd0
Bump Elasticsearch to 7.9.2
2020-10-04 18:03:00 -07:00
listbot
47dca8b835
continue pin / prep images ghcr
2020-09-04 12:37:28 +00:00
t3chn0m4g3
54a6a944aa
prep for ipphoney
2020-08-25 12:25:59 +00:00
t3chn0m4g3
b86d2c715b
prep for ipphoney
2020-08-24 21:36:08 +00:00
t3chn0m4g3
5080151b7c
prep for elk 7.9
2020-08-24 10:35:46 +00:00
t3chn0m4g3
c1f7146800
prep elk stack for 7.9.0
2020-08-20 15:03:16 +00:00
t3chn0m4g3
c28642932a
bump elk stack to 7.8.1
2020-08-13 08:34:44 +00:00
t3chn0m4g3
6d29f504df
provide fix for #669
2020-07-06 23:30:11 +00:00
t3chn0m4g3
16a7cdb975
tweaking
...
Update logstash config for new Dicompot fields
Revert Dionaea back to 0.8.0, latest master was unstable
2020-06-26 23:48:48 +00:00
t3chn0m4g3
0031980416
cleanup and prepare for docker image rebuilds
2020-06-26 14:34:05 +00:00
t3chn0m4g3
238a08b055
tweaking
...
cleanup index-pattern
add dicompot log to logstash
2020-06-24 13:21:29 +00:00
t3chn0m4g3
99d8cf9b32
fix for query fields
2020-06-24 10:22:09 +00:00
t3chn0m4g3
81c6351cf1
fix for keeping daily index
2020-06-23 21:40:38 +00:00
t3chn0m4g3
65e849cf33
bump elk stack to 7.8
2020-06-21 21:11:21 +00:00
t3chn0m4g3
a396356785
add honeysap logstash config
2020-06-19 22:53:56 +00:00
t3chn0m4g3
2882668826
Add a new elasticsearch honeypot
...
adjust installer
adjust elasticpot configs to T-Pot's environment
create Dockerfile
adjust logstash config
update Readme
2020-06-17 18:09:59 +00:00
t3chn0m4g3
4cc1aa08c2
tweaking
...
Bump ELK stack to 7.7.1
Install curator via pip
Some tweaks
2020-06-08 21:56:16 +00:00
t3chn0m4g3
be918033e0
bump to ELK 7.7.0
2020-05-14 16:27:57 +00:00
t3chn0m4g3
680194adf7
prep for new listbot FQDN
2020-05-12 09:19:09 +00:00
Marco Ochse
ed73d83317
Update update.sh
2020-04-22 17:48:32 +02:00
Marco Ochse
a6c8d3d712
Update Dockerfile
2020-04-22 17:15:44 +02:00
Marco Ochse
1a7b3b3795
Load listbot data from OTC
2020-04-22 16:50:41 +02:00
t3chn0m4g3
73e1842c16
offload listbot from netlify CDN
2020-04-02 13:12:11 +00:00
t3chn0m4g3
df22adb45d
bump elk stack to 7.6.1
2020-03-05 21:20:11 +00:00
t3chn0m4g3
07c68c85bb
tweaking
2020-03-04 14:36:03 +00:00
t3chn0m4g3
f11ad6b523
tweaking
...
ELK 7.6.0 is not ready for production, however it works if APM is enabled (disabled in config, so image wont build as precaution)
Remove SISSDEN from ewsposter, suricata
Bump suricata to 5.0.1
Alpine now support suricata incl. enabled JA3 support, move back to Alpine install
2020-02-14 15:28:06 +00:00
t3chn0m4g3
5ce5911ec1
cleanup
2020-02-03 12:59:21 +00:00
t3chn0m4g3
b9da9f04af
adjust default field
2020-02-03 12:18:43 +00:00
t3chn0m4g3
984ba958fb
logstash template not upgraded
...
with daily index enabled logstash will not be able to put new events into ES
simple solution, just deleting logstash template upon logstash start and leave it to logstash to upload the latest template
.
2020-02-01 14:08:23 +00:00
t3chn0m4g3
64729f5064
remove ilm support, breaks existing index at upgrade
2020-01-31 15:50:34 +00:00
t3chn0m4g3
5a4724bcba
elk 7.x dev test
2020-01-31 14:21:55 +00:00
t3chn0m4g3
fa0fdbb579
prepare for ELK migration to 7.x
2020-01-29 14:21:40 +00:00
t3chn0m4g3
f110eb08b0
prepare for mailoney json logging
2020-01-22 12:17:30 +00:00
t3chn0m4g3
1d0aad3b34
tweak logstash.conf for citrixhoneypot
2020-01-16 18:04:29 +00:00
t3chn0m4g3
a6ed6613a5
prepare citrixhoneypot for ELK integration
2020-01-16 15:13:58 +00:00
t3chn0m4g3
66bb9443f9
bump elk stack to 6.8.2
2019-08-28 11:49:03 +00:00
t3chn0m4g3
bc6e94d329
spiderfoot, head bump to latest master
2019-08-16 17:29:41 +00:00
t3chn0m4g3
bf39c0f5b2
bump elastic stack to 6.7.2
2019-08-15 15:38:12 +00:00
t3chn0m4g3
364831ae58
fix cd
2019-08-15 08:32:04 +00:00
t3chn0m4g3
31d7707d19
download instead of git pull
...
download translation maps rather than running a git pull
translation maps will now be bzip2 compressed to reduce traffic to a minimum
fixes #432
2019-08-14 14:43:47 +00:00
t3chn0m4g3
bbf226aeda
remove glastopf
2019-06-03 19:57:50 +00:00
t3chn0m4g3
a7e553efe9
still working on fatt
2019-06-03 16:13:58 +00:00
t3chn0m4g3
f870c8e885
continue working on fatt
2019-06-03 10:22:07 +00:00
listbot
867bda6ad7
increase number of fields limit
...
#382
2019-05-31 15:34:29 +00:00
listbot
c09547e3a4
adjust group and permissions for /data
2019-05-08 11:16:48 +00:00
t3chn0m4g3
e8d8773863
tweaking
2019-03-19 11:08:23 +00:00