Brak opisu

Brad Poulton 9fe6830ac7 cahnges 4 lat temu
files 60ed5f4b8a Updates aws config colors 4 lat temu
images febf393c14 Latest notes. 5 lat temu
ACM and PKI Notes.md 0d10018b7d notes 4 lat temu
AFS Forcepoint Neuterage Notes.md ebbf36680a rename to match 5 lat temu
AFS POP Notes.md fda1952319 little here and little there 5 lat temu
AFS ServiceNow AWS Account Request.pdf b9c6d3b6da init 5 lat temu
AWS CloudWatch Insights.md 783322d3eb Minor Renaming 5 lat temu
AWS ECR Notes.md 858957767b AWS ECR Notes 4 lat temu
AWS NVME Notes.md d53fe8445e Major Clean UP 5 lat temu
AWS New Account Setup Notes.md d290023ea1 Fix color 4 lat temu
AWS Notes.md 03f44f3ccc Separate the aws config into a file 4 lat temu
AWS Web Application Firewall Add-on Notes.md d43e8a0530 Explicitly mention a HEC token for easier grepping 4 lat temu
Aide Notes.md 49bbf8cc1f Small things 4 lat temu
Architecture Notes.md c628d51361 VMray has its own account 5 lat temu
Asset Inventory Notes.md d63d47fa05 Update Asset Inventory Notes.md 4 lat temu
Atlantis Notes.md d53fe8445e Major Clean UP 5 lat temu
Bastion.md b986afbead Adds Bastion Notes 4 lat temu
Break-Glass-Accounts.md a4e7a2f597 ACM 4 lat temu
ClamAV notes.md d8fa097751 Salt upgrade notes 4 lat temu
Collectd Notes.md 14b541e897 Adds more stuff 4 lat temu
Customer Decommision Notes.md 400701d390 splunk patching plus more 5 lat temu
DNSSEC Notes.md 4c771cde67 patching, salt, splunk 4 lat temu
FedRAMP Notes.md 8557637aeb Migrates FedRAMP Notes to O365 4 lat temu
Fluentd Notes.md 14b541e897 Adds more stuff 4 lat temu
GitHub Server Notes.md d1d897662f GHE and Salt Notes 4 lat temu
GnuPG (gpg) Notes.md 1a9abd6fef added random password generator 5 lat temu
GovCloud Notes.md febf393c14 Latest notes. 5 lat temu
Interconnects Notes.md fb3b7c27c2 mooooore 5 lat temu
Jenkins Notes.md 9b61411e06 Removed XDR Prefix 5 lat temu
Jira Notes.md 5d713238c4 Jira and Keycloak Notes Added 4 lat temu
Keycloak Notes.md 5d713238c4 Jira and Keycloak Notes Added 4 lat temu
LCP in Azure.md fe0c05d785 LCP in azure 4 lat temu
New Customer Setup Notes - GovCloud.md 9fe6830ac7 cahnges 4 lat temu
New Customer Setup Notes - Legacy.md 733309a5ac New customer setup added for GC 4 lat temu
OSContext Notes.md d9d526d047 Lots o' changes 4 lat temu
Okta Notes.md febf393c14 Latest notes. 5 lat temu
OpenVPN Notes.md 8557637aeb Migrates FedRAMP Notes to O365 4 lat temu
OpenVPN Upgrade Notes.md 3eda556f64 Updates OpenVPN, sft, etc. Notes 4 lat temu
POP-LCP Node Notes.md 0305b39fd8 Adds more notes 4 lat temu
Packer Notes.md 3eda556f64 Updates OpenVPN, sft, etc. Notes 4 lat temu
Packer Salt Master FIPS Notes.md 3eda556f64 Updates OpenVPN, sft, etc. Notes 4 lat temu
Patching Notes--CaaSP.md 7829b75707 Correction to composite matching for victims 4 lat temu
Patching Notes.md 59b810d3fd Patching and new customer setup and a bit of portal notes 4 lat temu
Phantom Notes.md 8916653f4d Phantom and migration note updates 4 lat temu
Phantom Upgrade Notes.md 8916653f4d Phantom and migration note updates 4 lat temu
Portal Lamba Notes.md 9b61411e06 Removed XDR Prefix 5 lat temu
Portal Notes.md 3eb477855f portal 4 lat temu
Portal WAF Notes.md 9b61411e06 Removed XDR Prefix 5 lat temu
Proxy Notes.md c40d9896d3 Updates proxy notes 4 lat temu
Qualys Notes.md 9b61411e06 Removed XDR Prefix 5 lat temu
RDS Notes.md afac49000d Added duanes jira notes 4 lat temu
README.md 9fe6830ac7 cahnges 4 lat temu
RedHat Full Drive Notes.md 92be7c8326 Updates patching notes, new customer setup 4 lat temu
RedHat Notes.md 9fe6830ac7 cahnges 4 lat temu
Reposerver Notes.md 400701d390 splunk patching plus more 5 lat temu
SELinux Notes.md 4f6fe94ae9 some selinux notes 4 lat temu
Salt Notes.md d1d897662f GHE and Salt Notes 4 lat temu
Salt Upgrade 2019 -> 3001 Notes.md d9d526d047 Lots o' changes 4 lat temu
Salt Upgrade 3001.2 -> 3001.6 Notes.md 4c771cde67 patching, salt, splunk 4 lat temu
ScaleFT Notes.md 176dc52b55 Adds msoc_build ssh notes 4 lat temu
Sensu Go Migration Notes.md d53fe8445e Major Clean UP 5 lat temu
Sensu Notes.md 92e64c1bc0 Sensu Notes + Lessons from Migration 4 lat temu
Sophos Notes.md 689d1cdde0 Adds Sophos Notes 5 lat temu
Splunk AFS Thaw Request Notes.md c70188cc80 Updates patching notes 4 lat temu
Splunk AWS App and Addon Notes.md f7fafe601a Minor updates to aws app notes 5 lat temu
Splunk MSCAS Notes.md 400701d390 splunk patching plus more 5 lat temu
Splunk Maxmind Notes.md 4fec480175 splunk maxmind 5 lat temu
Splunk Migration from Commercial to GovCloud - 1. Prep and Indexer Cluster.md c2bf746e5b Split migraiton notes into 2 parts 4 lat temu
Splunk Migration from Commercial to GovCloud - 2. Search Head.md 8916653f4d Phantom and migration note updates 4 lat temu
Splunk Migration from Commercial to GovCloud - 3. Remaining Servers.md fcde992274 Additional MIgration Steps and GitHub Notes 4 lat temu
Splunk NGA Data Pull Request Notes.md d9d526d047 Lots o' changes 4 lat temu
Splunk Notes.md 283e05d86f Adds improvements for new customer setup splunk vault 4 lat temu
Splunk Process List Whitelisting FedRAMP Notes.md d53fe8445e Major Clean UP 5 lat temu
Splunk SAF Offboarding Notes.md 9b61411e06 Removed XDR Prefix 5 lat temu
Splunk Upgrade Notes.md 14b541e897 Adds more stuff 4 lat temu
Sudo Replay Notes.md 157e432b13 sudo replay notes 4 lat temu
Terraform Notes.md d9d526d047 Lots o' changes 4 lat temu
Terraform Splunk ASG Notes.md 8675129403 More great changes 5 lat temu
Terragrunt Notes.md 36296ccd47 More Notes! 4 lat temu
ThreatQ Notes.md 3475b7bd51 Added caveats 4 lat temu
VMRay Notes.md d53fe8445e Major Clean UP 5 lat temu
Vault Notes.md 283e05d86f Adds improvements for new customer setup splunk vault 4 lat temu
Vault Prod Refresh Notes.md 9b61411e06 Removed XDR Prefix 5 lat temu
VictorOps Notes.md d53fe8445e Major Clean UP 5 lat temu
VirtualBox Build Notes.md febf393c14 Latest notes. 5 lat temu
dnsmasq.md febf393c14 Latest notes. 5 lat temu
duane-random.md dc3a22bbcf sigh 5 lat temu
ePO Syslog Notes.md d53fe8445e Major Clean UP 5 lat temu
jira-sucks.md 58be07a107 jira notes 5 lat temu
salt_splunk_HEC Notes.md 9b61411e06 Removed XDR Prefix 5 lat temu
sftp Notes.md 43fd263050 Splunk, sensu, phantom notes 5 lat temu

README.md

Brads All Encompassing Compendium of the Entirety of XDR Knowledge

BAECEXD (pronounced "bake ext") is a set of notes about how to actually get things done in XDR. Since XDR is a rapidly evolving landscape, some of these notes are likely to be out of date, flawed, or just outright wrong. Use at your own risk.

Rules

  1. All files MUST follow the naming scheme. <Major Topic> <Minor Topic> Notes.md e.g. Salt Upgrade Notes.md . The first letter of each word should be capitalized.

  2. All files MUST follow the proper markdown format. ( work in progress )

    # <filename>
    <Description of notes or project>
         
    ## <Section Title>
    <Today's date>
         
    <arbitrary notes>
         
    ## <Section Title>
    <Today's date>
         
    <arbitrary notes>
    
    # Salt Notes.md
    Salt is the configuration management tool
    
    ## Section 1
    02/28/2020
    
    Salt sucks and we should use puppet.
    
    ## Section 2
    03/15/2020
    
    Salt version 2019.2.3 should always be made public on the internet. 
    
  3. To add a newline that is visible in markdown on the github website, add two newlines to the .md file. DO NOT add <br> or \ to the ends of lines. The primary place to view these files is in a text editor not on github website!

  4. Use three backticks to indicate a section of code or terminal output and single backticks to indicate technical commands or terms.

  5. When referencing other files use a link in the format See <file name> for more details. e.g. See Salt Upgrade Notes.md for more details.

  6. For PRs, push directly to master unless they are major changes.

  7. Be kind and think about the engineer after you.