Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Set execution policy winlogbeat #38

Merged
merged 2 commits into from
Nov 17, 2023

Conversation

cbaxley
Copy link
Collaborator

@cbaxley cbaxley commented Nov 16, 2023

🗣 Add instructions to set execution policy for winlogbeat

Add the instructions to allow powershell to run programs from the internet.

💭 Motivation and context

Programs from the internet sometimes won't run depending on the policy of the server.

🧪 Testing

I had to run this command each time I installed winlogbeat.

✅ Pre-approval checklist

  • This PR has an informative and human-readable title.
  • Changes are limited to a single goal - eschew scope creep!

✅ Pre-merge checklist

  • Revert dependencies to default branches.
  • Finalize version.

✅ Post-merge checklist

  • Create a release.

@mreeve-snl mreeve-snl changed the base branch from main to release-1.1.0 November 16, 2023 19:35
Copy link
Collaborator

@mitchelbaker-cisa mitchelbaker-cisa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

winlogbeat's install script is downloaded from the web so RemoteSigned will restrict execution. I'm fine with Unrestricted and keeping scope for the specific process since this will still prompt the user for their intent to execute the script.

@cbaxley cbaxley merged commit 93530a7 into release-1.1.0 Nov 17, 2023
@cbaxley cbaxley deleted the clint/set_execution_policy_winlogbeat branch November 17, 2023 18:24
mitchelbaker-cisa pushed a commit that referenced this pull request Nov 17, 2023
llwaterhouse added a commit that referenced this pull request Nov 21, 2023
* Adding updates to troubleshooting to address the latest issues.

* Added Filtering.md to documents to discuss how to filter out unnessecary logs

* Change "activate selected" to "Enable"

* Changed "New - User Security" to "User Security" to reflect current dashboard name

* Updated dashboard count and location

* Adds a script to export dashboards

* Adding Compute Software Overview dashboard

* User HR Dashboard Ready for Review and Release

* Bump Elasticsearch Version

* Bump version in readme

* adding alert dashboard (#46)

Co-authored-by: Diabe <[email protected]>
Co-authored-by: Michael Reeves <[email protected]>

* Add a command to allow the execution of the winlogbeat.exe file (#38)

Co-authored-by: Clint Baxley <[email protected]>

* add process_explorer.ndjson file (#37)

Co-authored-by: root <[email protected]>
Co-authored-by: Connor <[email protected]>

* Creating Initial Draft of issue templates (#34)

* Creating Initial Draft of issue templates

Issue Templates to aid with docs_update

* Update bug-or-error-report.md

* Update bug-or-error-report.md

Minor typos

* Proofread bug-or-error-report.md, updated phrasing in some places

---------

Co-authored-by: Chad Poland <[email protected]>
Co-authored-by: Linda Waterhouse <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>

* remove input controls and update filtering with Kibana Control filters for (hostname, process exe, process pid)

* Alert Dashboard review (#49)

* adding alert dashboard

* Create Alerting_dashboard.ndjson

* Rename Alerting_dasboard.ndjson to Alerting_dashboard.ndjson

* Rename Alerting_dashboard.ndjson to alert_dashboard.ndjson

* Delete dasboards directory

---------

Co-authored-by: Diabe <[email protected]>
Co-authored-by: Michael Reeves <[email protected]>

* Delete dasboards directory (#50)

* Update deploy.sh to debug issue #33

Add logging to indicate the script's progress and where it might be failing + introduce a maximum number of 60 attempts to check for Elasticsearch readiness, preventing the script from hanging indefinitely.

* Updates the dashboard menu and all of the dashboards that use it. (#53)

* Change the navigation menu to exclude the old home page and include the new dashboards.

* Delete the security dashboard home

---------

Co-authored-by: Clint Baxley <[email protected]>

* Lme update functionality (#30)

* adding updates to chapter3 for deploy.sh changes

* adding updates to dashboard and lme_update to log and run as better cron jobs

* adding in more notes to chapter3 on update functionality

* Added the following features to deploy.sh:
  - update function to add lme_upadte.sh and dashboard_update.sh to
    root's crontab
  - fixed final permissions so that /opt/lme is readable by `sudo` group
  - y/n on the uninstall options fixed
  - upgrade function updated to check for 1.0 version and only remove
    crontab in  upgrading from 0.5.1
  - usage function to print the usage

* fixing read/write on the files_for_windows.zip

* fixing backups permissions

* Update chapter3.md (#29)

* Update chapter3.md

Changed winlogbeat 8.5.0 link to one, that allows user to download not only zip, but also sha512 control sum and also choose between zip and MSI.

* Update chapter3.md

Changed Winlogbeat to 8.11.1

* Update the readmes to delete old dashboards and import new ones. (#54)

Co-authored-by: Clint Baxley <[email protected]>

* Update Uninstall_Sysmon64.ps1 (#27)

Check if Sysmon is installed, run the uninstall command with elevated privileges, and handle potential errors. 
Remove the Sysmon executable if the uninstallation is successful.

* Deploy upgrade 1.1.0 (#58)

* adding in upgrade command to go from 1.0 -> 1.1.0

* pushing upgrade notes

* adding updates to deploy.sh for upgrading 1.0 -> 1.1.0

* adding CONTRIBUTING.md,RELEASES.md, and Custom PR-Template (#41)

* adding Contribution and release documentation to help standardize these processes

* Update CONTRIBUTING.md

fixed typos.

* documenting PR template to standardize and streamline Pull Requests

* adding a few more changes

* adding formatting changes

* Rename pull_request_template.md to pull_request_template.md

Actually renamed directory PULL_REUQEST_TEMPLATE to PULL_REQUEST_TEMPLATE

---------

Co-authored-by: Linda Waterhouse <[email protected]>

* remove updates that break the installation process, need more refactoring/testing before we can push these changes

* Release 1.1.0 small updates (#61)

* updating deploy.sh with fixes that solve permissions issues and still provide security for files with plaintext passwords

* updating docs to state more accurate required disk sizes

---------

Co-authored-by: Alden Hilton <[email protected]>
Co-authored-by: Clint Baxley <[email protected]>
Co-authored-by: Connor Aubry <[email protected]>
Co-authored-by: Grant (SNL) <[email protected]>
Co-authored-by: Clint Baxley <[email protected]>
Co-authored-by: ddiabe <[email protected]>
Co-authored-by: Diabe <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: root <[email protected]>
Co-authored-by: Connor <[email protected]>
Co-authored-by: Chad Poland <[email protected]>
Co-authored-by: Linda Waterhouse <[email protected]>
Co-authored-by: mitchelbaker-cisa <[email protected]>
Co-authored-by: Dmytro Korzhevin <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants