MozDef/alerts
Guillaume Destuynder 816d7ffeb7 Initial support for squid alerts coming from EC2
Matches on DENIED string from squid ("1091084609.110 351 10.49.4.0 TCP_DENIED/407 2112 GET http://www.mozilla.org/ -
NONE/- text/html ") for ex.
2015-10-22 17:25:52 -07:00
..
lib update aggregation mechanisms to allow specifying the dict path as key.subkey.subkey.etc, closes #275 2015-05-27 13:23:05 -07:00
plugins add pager duty sample alert plugin, closes #249 2015-03-22 21:01:34 -07:00
__init__.py averez-147-celery-alerts: more comments in the code 2014-07-15 16:31:21 -07:00
alertWorker.py add alert plug in system, closes #162 2015-03-22 20:15:17 -07:00
bro_intel.py fix up dashboard-style alerts to match new function names 2015-07-14 12:56:58 -07:00
bro_intel_dashboard.json averez-147-celery-alerts: make some alerts public + adapt docker config 2014-07-17 23:17:00 -07:00
bro_intel_pyes.py update alerts to match the new aggregation functions 2015-05-27 13:23:42 -07:00
bro_notice.py internz mix they tabs and spaces 2014-08-13 16:56:11 -07:00
bro_notice_dashboard.json averez-147-celery-alerts: make some alerts public + adapt docker config 2014-07-17 23:17:00 -07:00
bruteforce_ssh.py fix up dashboard-style alerts to match new function names 2015-07-14 12:56:58 -07:00
bruteforce_ssh_dashboard.json averez-147-celery-alerts: make some alerts public + adapt docker config 2014-07-17 23:17:00 -07:00
bruteforce_ssh_pyes.py update alerts to match the new aggregation functions 2015-05-27 13:23:42 -07:00
celeryconfig.py add deadman alerts, refactor celeryconfig to allow args/kwargs, closes #257 2015-03-20 12:51:31 -07:00
cloudtrail.py internz mix they tabs and spaces 2014-08-13 16:56:11 -07:00
cloudtrail_dashboard.json averez-147-celery-alerts: make some alerts public + adapt docker config 2014-07-17 23:17:00 -07:00
cloudtrail_pyes.py update alerts to match the new aggregation functions 2015-05-27 13:23:42 -07:00
correlated_alerts_pyes.py add docs URL to alerts, closes #241 2015-03-24 15:37:29 -07:00
duo_fail_open.py update alerts to match the new aggregation functions 2015-05-27 13:23:42 -07:00
fail2ban.py internz mix they tabs and spaces 2014-08-13 16:56:11 -07:00
fail2ban_dashboard.json averez-147-celery-alerts: make some alerts public + adapt docker config 2014-07-17 23:17:00 -07:00
fail2ban_pyes.py update alerts to match the new aggregation functions 2015-05-27 13:23:42 -07:00
httperrors_pyes.py add docs URL to alerts, closes #241 2015-03-24 15:37:29 -07:00
multiple_intel_hits_pyes.py update alerts to match the new aggregation functions 2015-05-27 13:23:42 -07:00
squiderrors_pyes.py Initial support for squid alerts coming from EC2 2015-10-22 17:25:52 -07:00
sshbruteforce_bro_pyes.py minor: include url as an example 2015-03-25 16:52:19 -07:00
ssl_blacklist_hit_pyes.py Add tons of new alerts and improve some old ones. 2015-02-26 19:42:51 +01:00
unauth_ssh_pyes.conf add an alert plugin for unauthorized ssh account usage 2015-08-25 17:17:10 -05:00
unauth_ssh_pyes.py add an alert plugin for unauthorized ssh account usage 2015-08-25 17:17:10 -05:00