* define flow to point to correct schemas
* make values code style
* add definitions of ambiguity for url/http
* stage TLS
* just domain
* correct domain terminology to match current OSSEM as well as HELK
* define community id to match HELK. layer7 and layer 3 implementation
* add PR from https://github.com/hunters-forge/OSSEM/pull/54
* update destination further, especially with dst_host_name and hostname vs fqdn vs domain
* documentation/information to delineate domain vs fqdn vs hostname
* update to support dst_host_name
* make implementation intro more clear
* small url schema verbiage updates
* still staging, but cleanup verbiage for now
* toward dns
* host_name schema for searching all
* towards event
* create etl schema
* staging host name (domain) enrichment
* correct flow from master branch
* not necessary to revert lowercase
* update url_host_name
* markdown cleanup
* match guid names
* add link names/paths that are in data dictionaries
filename
* correct AccessReason
* add application generated auditing
* add 4907
* add event XML
* add event XML
* add 4670
* missing AccessReason
* fix SD naming
* match CIM for src and dst ip addresses
* add 4696 xml
* process cleanups, corrections, and HELK<>OSSEM
* add 4797
* add sysmon 255
* update match HELK
* - [x] group schema (name, domain, sid, etc)
- [x] Audit Security Group Management
- [x] Security:4727
- [x] Security:4728
- [x] Security:4729
- [x] Security:4730
- [x] Security:4731
- [x] Security:4732
- [x] Security:4733
- [x] Security:4734
- [x] Security:4735
- [x] Security:4737
- [x] Security:4754
- [x] Security:4755
- [x] Security:4756
- [x] Security:4757
- [x] Security:4758
- [x] Security:4764
- [x] Security:4799
* update .gitignore
* begin adding zeek data dictionaries
* begin adding zeek data dictionaries
* begin adding zeek data dictionaries
* begin adding zeek data dictionaries
* JSpieldenner Moving Forward
* JS102919
* JS102519
* match SidHistory for group to be group_sid_history
* Audit Distribution Group Management
* begin adding zeek data dictionaries
* add VLANs
* add event duration for length of time/event
* add network history/connection states
* complete zeek conn log
* set network protocols
* complete zeek conn log
* zeek event_uid and network proto
* zeek progress on DHCP
* event uid
* duplicate line
* add 4670 from main and fix typo and field to what helk has
for logon_transmitted_services
* use current reporter logon id field, pending confirmation until then
* field type is string NOT ip
* add 4649
* correct field names. update description and correct ordering of reference
* update description and correct ordering of reference
* correct minimum OS, fix and add relative paths
* DnsName to dst_host_name, fix multiple typo's and update description and correct ordering of reference
* correct session id field name. also typo
* conform with similar field types.. like UPN to user_identity. also update description
* add 4825, even though not on microsoft's website :)
* field name typos and update field descriptions a bit
* finish Account Logon/Other Logon/Logoff
* fix typo, update description and match to HELK https://github.com/Cyb3rWard0g/HELK/issues/314
* fill out the rest for object/registry
* update all Zeek categories' descriptions/README's.
* schema
* zeek log examples
* finish dns schema
* add dhcp ip
* finish dns schema
* finish schema
* add user_password
* update etl schema
* forward http
* add src/dst file info
* add ja3/ja3s
* forward ssl/tls
* update example
in "task"
* event example json cleanup
* TransactionId should be transaction_guid
* readme ordering
* missing Service standardized field name
* correct description
* correct object_access_mask value type
* correct object_access_list value type to string
* correct descriptions
* add event id 4659
* add event id 4665, 4666, 4667, 4668
* add event id 5051
* fix relative path links
* directory service changes HELK <> OSSEM
* add network_direction
* HELK <> OSSEM
* scheduled tasks HELK <> OSSEM
* network_direction
* add etl_versioning
* because potential of 3 process ID's, note field just in case
* HELK <> OSSEM user_target_ is target_user_
* directory service object HELK <> OSSEM
* HELK <> OSSEM audit policy change
* 4777
* add 4774 and 4775
* HELK <> OSSEM dpapi
* clean, add error and status codes and network application name
* forward movement
* finish the start of HTTP schema
* hex as string, identify decimal separately
* add sha512 hash
* begin adding x509/certificate info for tls/signed things
* Combine Kerberos TGS and AS as one such a lot of overlap and makes for a better schema