V1D1AN/S1EM
This project is a SIEM with SIRP and Threat Intel, all in one.
Change tcpreplay for replay.
Update ELK to 7.17.10 Add the choice for cluster elasticsearch ( 1 node or 3 node elasticsearch ) Correction bugs
Update docker-compose to docker compose
Add Velociraptor
Add Licence MIT Update ELK to 7.17.9 Suppress Stoq Suppress Clamav Update Cortex to 3.1.7-4 Add plugin Analyzer Mwdb for Cortex Add plugin Analyzer Capa for Cortex Add docker file4thehive Change yara rules for malpedia yara rules Add automation with SOAR
Add Zircolite to S1EM Update file-upload to version 1.1
Correction of bugs
Add PR of mcdave2k1 Update the configuration of MISP
Update ELK to 7.17.6 Correction of multiple bugs
Update ELK 7.17.3 Correction configuration for Misp Modification for Auditbeat
ELK 7.17.2 Spiderfoot 4.0.0 Correction of bugs
ELK 7.17.1 Arkime 3.4.0 Homer Spiderfoot CodiMd Shuffle.io
Correction bugs Thehive4 with elasticsearch
Update ELK to 7.16.1 Add ILM configuration for beats Add volume for clamav
Update ELK to 7.15.2
Add heartbeat 7.15.1 for monitoring service of S1EM Add cpu limit for elasticsearch
Update ELK to 7.15.1 Update Zeek to 4.1.x Suppress FleetDM ( Use Elastic Agent ) Add Mwdb-core from CERT-Poslka Add Start.me of Kidrek Add Clamav Add Clamav plugin for Stoq Add tcpreplay and file-upload for replay pcap Change the processus of deployment ( Automatic configuration of TheHive/Cortex/Mwdb ) Extract files with Zeek
Update ELK to 7.14.2 Update Arkime to 3.0.0 Add start.me of kidrek to Heimdall
Update ELK to 7.14.1 Update Cortex to 3.1.1-3
Update ELK to 7.14.0 Add pfelk into S1EM
Add Certs for Fleet
Update ELK to 7.13.2 Elasticsearch with multi-nodes and SSL Dashboard for Suricata ECS Generation automatic of Certificates Monitoring Logstash with Metricbeat
Update to ELK 7.13.1
Update to ELK 7.13.0 Add Arkime 2.7.1
📋 Changes
- Update to Suricata 6
📋 Changes
- ELK 7.12.1
- Update rules for Suricata, Yara, Sigma
📋 Changes
- Integration of heimdall
- Integration of différents script
📋 Changes
- Initial release
