No Description

Brad Poulton cd2e3b87c4 splunk-soar okta logo 2 years ago
archive 4698fcd29f Minor cleanup and refresh 2 years ago
files 843c2cefb6 decom notes 3 years ago
images cd2e3b87c4 splunk-soar okta logo 2 years ago
.gitignore b96146e0b2 Re-commit due to Git merge error 4 years ago
AFS Forcepoint Neuterage Notes.md fa1d5f8644 adds stuff 4 years ago
AFS Macbook Notes.md 4529403959 macbook and terragrunt 3 years ago
AFS POP Notes.md fda1952319 little here and little there 5 years ago
AFS ServiceNow AWS Account Request.pdf b9c6d3b6da init 5 years ago
AFS Syslog Notes.md 0053f753cb syslog, sensu 3 years ago
ALSI (Cribl LogStream) Notes.md 955e5fc4fc Update ALSI (Cribl LogStream) Notes.md 2 years ago
AWS CloudWatch Insights.md 783322d3eb Minor Renaming 4 years ago
AWS ECR Notes.md 5a1bbcc30c Format Updates 4 years ago
AWS NVME Notes.md d53fe8445e Major Clean UP 4 years ago
AWS New Account Setup Notes.md 04c8a99a16 AWS new account setup 3 years ago
AWS Notes.md 706737c473 Minor notes on unsubscribing an email address 2 years ago
AWS RDS Notes.md b668384523 RDS, Redhat, Salt, Splunk 3 years ago
AWS VPN Notes.md 4f28f4ca2b aws vpn 3 years ago
AWS Web Application Firewall Add-on Notes.md adf1790c9c Format Updates 4 years ago
Aide Notes.md 5a1bbcc30c Format Updates 4 years ago
Asset Inventory Notes.md 4698fcd29f Minor cleanup and refresh 2 years ago
Atlantis Notes.md d53fe8445e Major Clean UP 4 years ago
Azure Gov Application API Access Notes.md 080acb5e35 Add Azure API Access notes 4 years ago
Bastion.md 19d415a178 Various Artists 3 years ago
Break-Glass-Accounts.md 03d0e2552b Format changes 4 years ago
CA Notes.md a4dde72d64 Minor additions to patch notes, vmray upgrade notes, and CA notes 3 years ago
CIS Benchmark Notes.md 3acfc2e9a3 Format changes 4 years ago
CIS Benchmarks Audit.md e5e7865351 Updates removal of legacy customers and formating 3 years ago
ClamAV notes.md 4013ef33d9 Notes on clamav not running on Ubuntu 3 years ago
Collectd Notes.md 62cdd33d91 Adds notes on checkign for collectd behavior 2 years ago
Customer Search Head Notes.md 3393d9fc5d Note Updates 3 years ago
DNSSEC Notes.md 73be441111 Format Changes 4 years ago
Decommission C2 Notes.md 68afd029ff Adds Splunk Upgrade and Renaming 3 years ago
Decommission Customer Notes.md 3134dd449b some of dis, some of dat 3 years ago
FedRAMP Notes.md 44e30a172a fedramp 3 years ago
Fluentd Notes.md 5a1bbcc30c Format Updates 4 years ago
Freds Braindump.md c0f6417b65 Initial Draft of Fred's Braindump 2 years ago
GitHub Server Notes.md de805135f9 Update GitHub Server Notes.md 2 years ago
GnuPG (gpg) Notes.md f4a76e1e0c Format Updates 4 years ago
Helper Scripts.md 01949be0c3 Adds Helper Script Notes 3 years ago
Jenkins Notes.md 9b61411e06 Removed XDR Prefix 5 years ago
Jira Notes.md 8abcb3a8df Format and syntax updates 2 years ago
Keycloak Notes.md e3a92c8f30 Audit notes 4 years ago
LCP in Azure.md 9bf4bcf5e6 Format changes 4 years ago
MailRelay Notes.md 2cdb33f93d Create MailRelay Notes 3 years ago
New Customer Setup Notes - GovCloud.md 1fbfa34ef4 Added notes on encrypting customer pass4symmkeys 2 years ago
New Customer Setup Notes - Legacy.md 733309a5ac New customer setup added for GC 4 years ago
OSContext Notes.md 4698fcd29f Minor cleanup and refresh 2 years ago
Okta Notes.md 1b2eb3aba1 okta, openvpn, portal 2 years ago
OpenSSL Notes.md ac4b5931c0 Adds notes on renewing the wildcard 3 years ago
POP-LCP Node Notes.md 0d6bb72410 Notes Updates 3 years ago
Packer Notes.md bf3a5f4519 packer, phantom, portal, etc. 3 years ago
Packer Salt Master FIPS Notes.md 56416af4d0 Format changes 4 years ago
Patching Notes--CaaSP.md 065b5e5985 Update Patching Notes--CaaSP.md 2 years ago
Patching Notes.md ed24cb50b4 Updates Notes for Patching and VMRay 2 years ago
Phantom Notes.md c94e0086a2 phantom, tenable 2 years ago
Phantom Upgrade Notes.md 3a518c0ed9 phantom, phantom upgrade 2 years ago
Portal Lamba Notes.md 16dced5e2f Patching, Portal Notes 4 years ago
Portal Notes.md 1fefdc7f3d Phantom, Portal 2 years ago
Portal Upgrade Notes.md 1fefdc7f3d Phantom, Portal 2 years ago
Postfix Notes.md 3393d9fc5d Note Updates 3 years ago
Proxy Notes.md 19d415a178 Various Artists 3 years ago
Qualys Notes.md e90e1b7da1 Format Update 4 years ago
README.md 23005ceae4 Format Changes 3 years ago
RedHat Full Drive Notes.md 5de7df7b4f Redhat 3 years ago
RedHat Notes.md 1deeedf858 Updates RedHat Notes to include lv extension when there's no partition 3 years ago
Reposerver Notes.md 8abcb3a8df Format and syntax updates 2 years ago
SELinux Notes.md 4f6fe94ae9 some selinux notes 4 years ago
Salt Notes.md c7226e126a Format changes 3 years ago
Salt Upgrade Notes.md e50db34a5a salt, macbook 3 years ago
Sensu Go Migration Notes.md b36675518e Format Updates 4 years ago
Sensu Go Notes.md ee32309d67 Macbook, sensu 3 years ago
Sensu Go Upgrade Notes.md 983b586a02 Format & syntax updates 2 years ago
Sophos Notes.md b36675518e Format Updates 4 years ago
Splunk AFS Thaw Request Notes.md e54a0c9dcd Correct typo 3 years ago
Splunk AWS App and Addon Notes.md d21e4de773 Updated yubikey/CA notes 4 years ago
Splunk App Distribution.md 765c12006c Minor updates to the splunk app updater 2 years ago
Splunk ExtremeRules.md 3134dd449b some of dis, some of dat 3 years ago
Splunk Log4j Removal Notes.md c3195e886f Adds notes about the state for log4j removal 3 years ago
Splunk MSCAS Notes.md 5c86974491 Format Changes 4 years ago
Splunk Maxmind Notes.md 4fec480175 splunk maxmind 5 years ago
Splunk Migration from Commercial to GovCloud - 1. Prep and Indexer Cluster.md 00af1301c6 Format Changes 4 years ago
Splunk Migration from Commercial to GovCloud - 2. Search Head.md c7226e126a Format changes 3 years ago
Splunk Migration from Commercial to GovCloud - 3. Remaining Servers.md edaeebebed Format Changes 4 years ago
Splunk NGA Data Pull Request Notes.md 829a741f21 Format Changes 4 years ago
Splunk Notes.md 5d3656c5a0 Splunk,openvpn,tenable 3 years ago
Splunk Process List Whitelisting FedRAMP Notes.md 5c78b84333 Format Changes 4 years ago
Splunk SAF Offboarding Notes.md 9e5e3ae948 okta, phantom, splunk, ma-c19 offboarding 3 years ago
Splunk SmartStore Migration.md 425e5368e7 Update REST search 3 years ago
Splunk Smartstore Thaw Notes.md c7b07024a5 aws, redhat, splunk smartstore 3 years ago
Splunk Upgrade Notes.md 50898e9933 Removed OpenVPN & Qcompliance veribiage 3 years ago
Splunk ma-c19 Offboarding Notes.md b87ce9e175 mac, phantom, smartstore, 3 years ago
Sudo Replay Notes.md 157e432b13 sudo replay notes 4 years ago
Teleport Notes.md 71963df503 Repo, teleport, tenable 3 years ago
Tenable Notes.md c94e0086a2 phantom, tenable 2 years ago
Terraform Notes.md 4698fcd29f Minor cleanup and refresh 2 years ago
Terraform Splunk ASG Notes.md 8675129403 More great changes 5 years ago
Terragrunt Notes.md 4529403959 macbook and terragrunt 3 years ago
ThreatQ Notes.md cafad100e4 Added threatq integration notes 2 years ago
VMRay Notes.md 883a468866 VMray Notes 2 years ago
Vault Notes.md b1aa44f331 phantom, portal, vault 3 years ago
Vault Upgrade Notes.md 57bfba1ca4 vault notes 3 years ago
VictorOps Notes.md d53fe8445e Major Clean UP 4 years ago
VirtualBox Build Notes.md febf393c14 Latest notes. 5 years ago
Yubikey Notes.md 0831e7c53b Update formatting 4 years ago
Zscaler Notes.md 19d415a178 Various Artists 3 years ago
dnsmasq.md febf393c14 Latest notes. 5 years ago
duane-random.md 9f7aaa223b Format Changes 4 years ago
ePO Syslog Notes.md 25bc65916c Adds Notes 4 years ago
salt_splunk_HEC Notes.md 9b61411e06 Removed XDR Prefix 5 years ago
sftp Notes.md b36675518e Format Updates 4 years ago

README.md

Brads All Encompassing Compendium of the Entirety of XDR Knowledge

BAECEXD (pronounced "bake ext") is a set of notes about how to actually get things done in XDR. Since XDR is a rapidly evolving landscape, some of these notes are likely to be out of date, flawed, or just outright wrong. Use at your own risk.

Rules

  1. All files MUST follow the naming scheme. <Major Topic> <Minor Topic> Notes.md e.g. Salt Upgrade Notes.md . The first letter of each word should be capitalized.

  2. All files MUST follow the proper markdown format. ( work in progress )

    # <filename>
    <Description of notes or project>
         
    ## <Section Title>
    <Today's date>
         
    <arbitrary notes>
         
    ## <Section Title>
    <Today's date>
         
    <arbitrary notes>
    
    # Salt Notes.md
    Salt is the configuration management tool
    
    ## Section 1
    02/28/2020
    
    Salt sucks and we should use puppet.
    
    ## Section 2
    03/15/2020
    
    Salt version 2019.2.3 should always be made public on the internet. 
    
  3. To add a newline that is visible in markdown on the github website, add two newlines to the .md file. DO NOT add <br> or \ to the ends of lines. The primary place to view these files is in a text editor not on github website!

  4. Use three backticks to indicate a section of code or terminal output and single backticks to indicate technical commands or terms.

  5. When referencing other files use a link in the format See <file name> for more details. e.g. See Salt Notes for more details.

  6. For PRs, push directly to master unless they are major changes.

  7. Be kind and think about the engineer after you.