Showing posts with label hybridhunter. Show all posts
Showing posts with label hybridhunter. Show all posts

Wednesday, June 17, 2020

Security Onion Hybrid Hunter 1.4.0 - Beta 3 Available for Testing!

In 2018, Security Onion Solutions started working on the next major version of Security Onion, code-named Hybrid Hunter:

Today we are proud to release Security Onion "Hybrid Hunter” 1.4.0 AKA Beta 3 and it has some amazing new features and improvements!

In this release, we continue to embrace Community ID as a way to correlate different data types.  Both Zeek and Suricata can natively generate Community ID values, but what about tools that don't natively support Community ID?  We sponsored the development of an Elasticsearch Ingest Processor that can automatically generate Community ID values for ANY logs that contain the necessary IP address and port information.  This means that you can now easily pivot from, for example, Suricata alerts to Zeek logs to Sysmon logs and vice versa.  

From an interface perspective, we've updated our Kibana dashboards and Hunt interface to make better use of those Community ID values.  Hunt also includes a new Auto Hunt toggle that will automatically submit your hunt query after changing filters or groupings.

Finally, there are lots of little bug fixes and improvements and you can find more details in the bullet points below!

Hunt now shows Community ID by default and includes a new Auto Hunt feature


To read more and download Hybrid Hunter, please see:

If you have any questions about Hybrid Hunter, please post a message on our reddit community and prefix the title with [Hybrid Hunter]!

Major Highlights in this Release

Changes:

  • Complete overhaul of the way we handle custom and default settings and data. You will now see a default and local directory under the saltstack directory. All customizations are stored in local.
  • The way firewall rules are handled has been completely revamped. This will allow the user to customize firewall rules much easier.
  • Users can now change their own password in SOC.
  • Hunt now allows users to enable auto-hunt. This is a toggle which, when enabled, automatically submits a new hunt when filtering, grouping, etc.
  • Title bar now reflects current Hunt query. This will assist users in locating a previous query from their browser history.
  • Zeek 3.0.7
  • Elastic 7.7.1
  • Suricata can now be used for meta data generation.
  • Suricata eve.json has been moved to /nsm to align with storage of other data.
  • Suricata will now properly rotate its logs.
  • Grafana dashboards now work properly in standalone mode.
  • Kibana Dashboard updates including osquery, community_id.
  • New Elasticsearch Ingest processor to generate community_id from any log that includes the required fields.
  • Community_id generated for additional logs: Zeek HTTP/SMTP, Sysmon shipped with Osquery or Winlogbeat.
  • Major streamlining of Fleet setup & configuration - no need to run a secondary setup script anymore.
  • Fleet Standalone node now includes the ability to set a FQDN to point osquery endpoints to.
  • Distributed installs now support ingesting Windows Eventlogs via Winlogbeat - includes full parsing support for Sysmon.
  • SOC Downloads section now includes a link to the supported version of Winlogbeat.
  • Basic syslog ingestion capability now included.
  • Elasticsearch index name transition fixes for various components.
  • Updated URLs for pivot fields in Kibana.
  • Instances of hive renamed to thehive.

Known Issues:

  • When prompted for hostname, please only enter the hostname itself and NOT a fully qualified domain name! There should be no dots or other special characters.
  • The Hunt feature is currently considered "Preview" and although very useful in its current state, not everything works. We wanted to get this out as soon as possible to get the feedback from you! Let us know what you want to see! Let us know what you think we should call it!
  • You cannot pivot to PCAP from Suricata alerts in Kibana or Hunt.
  • Navigator is currently not working when using hostname to access SOC. IP mode works correctly.
  • Due to the move to ECS, the current Playbook plays may not alert correctly at this time.
  • The osquery MacOS package does not install correctly.

Thanks

Lots of love went into this release!

Special thanks to all our folks working so hard to make this release happen!

Josh Brower
Jason Ertel
Wes Lambert
Josh Patterson
Mike Reeves
William Wernert

Wednesday, May 20, 2020

Security Onion Hybrid Hunter 1.3.0 - Beta 2 Available for Testing!

In 2018, Security Onion Solutions started working on the next major version of Security Onion, code-named Hybrid Hunter:
https://blog.securityonion.net/2018/11/security-onion-hybrid-hunter-101-tech.html

Today we are proud to release Security Onion "Hybrid Hunter” 1.3.0 AKA Beta 2 and it has some amazing new features and improvements!

The biggest new feature in this release is a brand new web interface for hunting through your logs. Once you've logged into the Security Onion Console, click the Hunt link and then choose one of the many pre-defined queries in the drop-down or write your own using Onion Query Language (OQL).  OQL is based on standard Lucene query syntax and allows you to optionally specify one or more fields to group by. For a few examples, check out the screenshot tour at the bottom of this blog post. This is the first public release of this new interface and we are firm believers in "release early, release often". We have lots of ideas for the future of this tool, but we want to hear your ideas as well.

This release also includes a new Standalone installation option that runs all of the major components on one box. It's similar to Eval mode but has more capabilities beyond just doing a quick evaluation.

Finally, this update includes lots of improvements for parsers, visualizations, dashboards, and Elastic Common Schema (ECS) support. We've done lots of testing along the way and we're ready for you to do some testing and let us know what you think!

To read more and download Hybrid Hunter, please see:
https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/ISO
https://github.com/Security-Onion-Solutions/securityonion-saltstack/blob/master/README.md

If you have any questions about Hybrid Hunter, please post a message on our reddit community and prefix the title with [Hybrid Hunter]!
https://www.reddit.com/r/securityonion/


Major Highlights in this Release

Changes:

  • New Feature: Codename: "Onion Hunt". Select Hunt from the menu and start hunting down your adversaries!
  • Improved ECS support.
  • Complete refactor of the setup to make it easier to follow.
  • Improved setup script logging to better assist on any issues.
  • Setup now checks for minimal requirements during install.
  • Updated Cyberchef to version 9.20.3.
  • Updated Elastalert to version 0.2.4 and switched to alpine to reduce container size.
  • Updated Redis to 5.0.9 and switched to alpine to reduce container size.
  • Updated Salt to 2019.2.5
  • Updated Grafana to 6.7.3.
  • Zeek 3.0.6
  • Suricata 4.1.8
  • Fixes so-status to now display correct containers and status.
  • local.zeek is now controlled by a pillar instead of modifying the file directly.
  • Renamed so-core to so-nginx and switched to alpine to reduce container size.
  • Playbook now uses MySQL instead of SQLite.
  • Sigma rules have all been updated.
  • Kibana dashboard improvements for ECS.
  • Fixed an issue where geoip was not properly parsed.
  • ATT&CK Navigator is now it's own state.
  • Standalone mode is now supported.
  • Mastersearch previously used the same Grafana dashboard as a Search node. It now has its own dashboard that incorporates panels from the Master node and Search node dashboards.

Known Issues:

  • The Hunt feature is currently considered "Preview" and although very useful in its current state, not everything works. We wanted to get this out as soon as possible to get the feedback from you! Let us know what you want to see! Let us know what you think we should call it!
  • You cannot pivot to PCAP from Suricata alerts in Kibana or Hunt.
  • Updating users via the SOC ui is known to fail. To change a user, delete the user and re-add them.
  • Due to the move to ECS, the current Playbook plays may not alert correctly at this time.
  • The osquery MacOS package does not install correctly.


Thanks

Lots of love went into this release!

Special thanks to all our folks working so hard to make this release happen!

  • Josh Brower
  • Jason Ertel
  • Wes Lambert
  • Josh Patterson
  • Mike Reeves
  • William Wernert


Screenshots









































Friday, April 17, 2020

Security Onion Hybrid Hunter 1.2.1 - Beta 1 Available for Testing!

In 2018, Security Onion Solutions started working on the next major version of Security Onion, code-named Hybrid Hunter:
https://blog.securityonion.net/2018/11/security-onion-hybrid-hunter-101-tech.html

Today we are proud to release Security Onion codenamed “Hybrid Hunter” 1.2.1 aka Beta 1. Hybrid Hunter 1.2.1 officially supports Ubuntu 18.04 and CentOS 7, which means it no longer supports Ubuntu 16.04.  Our ISO image will continue to be based on CentOS 7 for the foreseeable future. There are plans to support CentOS 8 once podman reaches full compatibility with docker.

This release moves us to Elastic 7 and begins to embrace Elastic Common Schema (ECS). This change includes overhauled dashboards and a new prefix of "so-" for Elasticsearch indices. Among other advantages, migrating to ECS means that other products using ECS should more easily inter-operate with Hybrid Hunter. Over the next few releases, we plan to embrace ECS more fully. Stay tuned!

Finally, we are very excited to announce the introduction of the Security Onion Console! Over the next few releases, we will continue to improve and add more functionality to the Security Onion Console. Check it out and let us know what you think!

To read more and download Hybrid Hunter, please see:
https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/ISO
https://github.com/Security-Onion-Solutions/securityonion-saltstack/blob/master/README.md

If you have any questions about Hybrid Hunter, please post a message on our reddit community and prefix the title with [Hybrid Hunter]!
https://www.reddit.com/r/securityonion/


Major Highlights in this Release

  • Full support for Ubuntu 18.04. Ubuntu 16.04 is no longer supported for Hybrid Hunter.
  • Elastic 7.6.1 with ECS support
  • New set of Kibana dashboards that align with ECS
  • Introduction of the Security Onion Console. Once logged in you are directly taken to the SOC.
  • New authentication using Kratos
  • Community ID support for Zeek, osquery, and Suricata. You can now tie host events to connection logs!
  • During install you must specify how you would like to access the SOC UI. This is for strict cookie security.
  • Ability to list and delete web users from the SOC UI
  • The soremote account is now used to add nodes to the grid vs using socore.
  • Eval mode no longer uses Logstash for parsing (Filebeat -> ES Ingest)
  • Ingest node parsing for osquery-shipped logs (osquery, Windows event logs, Sysmon)
  • Fleet standalone mode with improved Web UI & API access control
  • Improved Fleet integration support
  • Playbook now has full Windows Sigma community ruleset builtin
  • Automatic Sigma community rule updates
  • Playbook stability enhancements
  • Zeek health check. Zeek will now auto restart if a worker crashes
  • zeekctl is now managed by salt
  • Grafana dashboard improvements and cleanup
  • Moved logstash configs to pillars
  • Salt logs moved to /opt/so/log/salt
  • Strelka integrated for file-oriented detection/analysis at scale

Thanks

Lots of love went into this release!

Special thanks to all our folks working so hard to make this release happen!

Josh Brower
Jason Ertel
Wes Lambert
Josh Patterson
Mike Reeves
William Wernert


Screenshots

Security Onion Console - User Administration

Security Onion Console - User Details

Security Onion Console - Deleting User

Security Onion Console - Downloads



Thursday, February 13, 2020

Security Onion Hybrid Hunter 1.1.4 - Alpha 4 Available for Testing!

In 2018, we started working on the next major version of Security Onion, code-named Hybrid Hunter:
https://blog.securityonion.net/2018/11/security-onion-hybrid-hunter-101-tech.html

We're excited to announce that Hybrid Hunter 1.1.4 is now available for testing and is considered our ALPHA 4 release!
https://github.com/Security-Onion-Solutions/securityonion-saltstack/blob/master/README.md

This is our last planned alpha release for Hybrid Hunter.  If all goes according to plan, our next Hybrid Hunter release should be Beta!

Major Highlights in this Release


  • Added new in-house auth method Security Onion Auth.
  • Web user creation is done via the browser now instead of so-user-add.
  • New Logstash pipeline setup. Now uses multiple pipelines.
  • New Master + Search node type and well as a Heavy Node type in the install.
  • Change all nodes to point to the docker registry on the Master. This cuts down on the calls to dockerhub.
  • Zeek 3.0.1
  • Elastic 6.8.6
  • New SO Start | Stop | Restart scripts for all components (eg. so-playbook-restart).
  • BPF support for Suricata (NIDS), Steno (PCAP) & Zeek (docs).
  • Updated Domain Stats & Frequency Server containers to Python3 & created new Salt states for them.
  • Added so-status script which gives an easy to read look at container status.
  • Manage threshold.conf for Suricata using the thresholding pillar (docs).
  • The ISO now includes all the docker containers for faster install speeds.
  • You now set the password for the onion account during the iso install. This account is temporary and will be removed after so-setup.
  • Updated Helix parsers for better compatibility.
  • Updated telegraf docker to include curl and jq.
  • CVE-2020-0601 Zeek Detection Script.
  • ISO Install now prompts you to create a password for the onion user during imaging. This account gets disabled during setup.
Thanks

Lots of love went into this release!

Special thanks to all our folks working so hard to make this release happen!


  • Mike Reeves
  • Wes Lambert
  • Josh Brower
  • Josh Patterson
  • William Wernert


Screenshots

so-status

Registering first user account

Logging in

Creating additional user

Warnings and Disclaimers


  • This ALPHA release is BLEEDING EDGE and TOTALLY UNSUPPORTED!
  • If this breaks your system, you get to keep both pieces!
  • This is a work in progress and is in constant flux.
  • This is intended to build a quick prototype proof of concept so you can see what our new platform might look like. This configuration will change drastically over time leading up to the final release.
  • Do NOT run this on a system that you care about!
  • Do NOT run this on a system that has data that you care about!
  • This should only be run on a TEST box with TEST data!
  • Use of this ALPHA RELEASE may result in nausea, vomiting, or a burning sensation.


Ready to try it out?

If you want to try our new ISO image, please follow the instructions here:
https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/ISO

Otherwise, you can install Hybrid Hunter on Ubuntu 16.04 or CentOS 7 using the instructions here:
https://github.com/Security-Onion-Solutions/securityonion-saltstack

Feedback
If you have questions, problems, or other feedback regarding Hybrid Hunter, please post to our subreddit and prefix the title with [Hybrid Hunter]:
https://www.reddit.com/r/securityonion/

Monday, December 16, 2019

Security Onion Hybrid Hunter 1.1.3 - Alpha 3 Available for Testing!

In 2018, we started working on the next major version of Security Onion, code-named Hybrid Hunter:
https://blog.securityonion.net/2018/11/security-onion-hybrid-hunter-101-tech.html

We're excited to announce that Hybrid Hunter 1.1.3 is now available for testing and is considered our ALPHA 3 release!
https://github.com/Security-Onion-Solutions/securityonion-saltstack/blob/master/README.md

Major Highlights in this Release
  • Cortex integration with TheHive
  • Pre-loaded plays in Playbook from the Sigma community repo
  • OS patch scheduling
  • Python 3 for CentOS
Screenshots


TheHive Cortex Integration

TheHive Alerts - Playbook NIDS

TheHive - NIDS Alert

TheHive - Playbook Alert

Playbook - Bulk Activate

Playbook - Sigma Community Rules - Sysmon 
so-playbook-ruleupdate


Warnings and Disclaimers

  • This ALPHA release is BLEEDING EDGE and TOTALLY UNSUPPORTED!
  • If this breaks your system, you get to keep both pieces!
  • This is a work in progress and is in constant flux.
  • This is intended to build a quick prototype proof of concept so you can see what our new platform might look like. This configuration will change drastically over time leading up to the final release.
  • Do NOT run this on a system that you care about!
  • Do NOT run this on a system that has data that you care about!
  • This should only be run on a TEST box with TEST data!
  • Use of this ALPHA RELEASE may result in nausea, vomiting, or a burning sensation.

Ready to try it out?

If you want to try our new minimal ISO image, please follow the instructions here:
https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/ISO

Otherwise, you can install Hybrid Hunter on Ubuntu 16.04 or CentOS 7 using the instructions here:
https://github.com/Security-Onion-Solutions/securityonion-saltstack

After you've installed, if you want to try out the new Playbook functionality, take a look at:
https://github.com/Security-Onion-Solutions/securityonion-saltstack/wiki/Playbook

Feedback
If you have questions, problems, or other feedback regarding Hybrid Hunter, please post to our subreddit and prefix the title with [Hybrid Hunter]:
https://www.reddit.com/r/securityonion/

Search This Blog

Featured Post

Security Onion 3.3.0 Hotfix 20260911 Now Available!

Earlier this week, we released Security Onion 3.3.0: https://blog.securityonion.net/2026/09/security-onion-330-now-available.html Today we a...

Popular Posts

Blog Archive