Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"policy manager" for Malcolm and Hedgehog Linux (meta-issue) #477

Closed
mmguero opened this issue May 15, 2024 · 2 comments
Closed

"policy manager" for Malcolm and Hedgehog Linux (meta-issue) #477

mmguero opened this issue May 15, 2024 · 2 comments
Labels
arkime Relating to Malcolm's use of Arkime enhancement New feature or request policy Related to issues dealing with "policy" (rules, configuration, etc.) management sensor For issues dealing with the Hedgehog OS capture sensor suricata Relating to Malcolm's use of Suricata UI Relating to general UI experience zeek Relating to Malcolm's use of Zeek
Milestone

Comments

@mmguero
Copy link
Collaborator

mmguero commented May 15, 2024

This is needs to be broken down into multiple sub-tasks, but we'll keep the high-level ideas here.

Users have requested a way to "manage sensors and rules" from Malcolm. What this has entailed in discussions is:

  • Being able to enable/disable/add/remove "rules" for Malcolm. This might include
    • Suricata rules
    • YARA rules
    • Arkime rules
    • Custom Zeek intel files
    • configuration? or anything else listed here?
  • There are other "subscriptions" that we can manage today (for example, external suricata rule sources, zeek intel feeds, etc.), do we want to have those lists be part of "policy" as well?
  • management of "rule sets" for the above
  • API calls to manage the above
  • the ability for hedgehog linux sensors to use the rules/rulesets above
  • a user interface for said policy (this is way further down the line, last priority after everything else is working)

I'm going to create a "policy" label to assign to issues associated with this one.

@mmguero mmguero added enhancement New feature or request arkime Relating to Malcolm's use of Arkime zeek Relating to Malcolm's use of Zeek sensor For issues dealing with the Hedgehog OS capture sensor suricata Relating to Malcolm's use of Suricata UI Relating to general UI experience labels May 15, 2024
@mmguero mmguero added this to Malcolm May 15, 2024
@mmguero mmguero moved this to Todo (design) in Malcolm May 15, 2024
@mmguero mmguero added this to the z.staging milestone May 15, 2024
@mmguero mmguero removed this from the z.staging milestone Aug 20, 2024
@mmguero
Copy link
Collaborator Author

mmguero commented Aug 27, 2024

see also #430 which may be related, as well as #221

@mmguero
Copy link
Collaborator Author

mmguero commented Nov 4, 2024

Kamino closed and cloned this issue to cisagov/Malcolm

@mmguero mmguero closed this as completed Nov 4, 2024
@github-project-automation github-project-automation bot moved this from Todo (design) to Done in Malcolm Nov 4, 2024
@mmguero mmguero moved this from Done to Migrated in Malcolm Nov 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
arkime Relating to Malcolm's use of Arkime enhancement New feature or request policy Related to issues dealing with "policy" (rules, configuration, etc.) management sensor For issues dealing with the Hedgehog OS capture sensor suricata Relating to Malcolm's use of Suricata UI Relating to general UI experience zeek Relating to Malcolm's use of Zeek
Projects
Status: Migrated
Development

No branches or pull requests

1 participant