From bad71b2be5b58c13ae118b2794e54ac45ca5df22 Mon Sep 17 00:00:00 2001 From: Doug Burks Date: Tue, 4 Jun 2024 18:10:39 -0400 Subject: [PATCH 1/3] fix SOC markdown reference to dashboards screenshot --- soc-customization.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/soc-customization.rst b/soc-customization.rst index 66c1c9da..00dd860d 100644 --- a/soc-customization.rst +++ b/soc-customization.rst @@ -27,7 +27,7 @@ You can add images but they must be hosted from another host that is accessible :: - ![SOC Dashboards](https://docs.securityonion.net/en/2.4/_images/51_dashboards.png) + ![SOC Dashboards](https://docs.securityonion.net/en/2.4/_images/53_dashboards.png) Links ----- From 8b168d782e6a88cc2e76c7bd68f5272f4adc7858 Mon Sep 17 00:00:00 2001 From: Doug Burks Date: Tue, 4 Jun 2024 18:15:41 -0400 Subject: [PATCH 2/3] update faq --- faq.rst | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/faq.rst b/faq.rst index 59544360..5c37f78b 100644 --- a/faq.rst +++ b/faq.rst @@ -201,6 +201,7 @@ Please see the :ref:`detections` section. Can I connect Security Onion to Active Directory or LDAP? ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -We understand the appeal of integrating with directory services like Active Directory and LDAP, but we typically recommend against joining any security infrastructure (including Security Onion) to directory services. The reason is that when you get an adversary inside your network, one of their first goals is going to be gaining access to that directory. If they get access to the directory, then they get access to everything connected to the directory. For that reason, we recommend that all security infrastructure (including Security Onion) be totally separate from directory services. + +Please see the :ref:`oidc` section. `back to top <#top>`__ From 6a41d29f3e9c4fcd3627c453605e6d19a94eb8cb Mon Sep 17 00:00:00 2001 From: Doug Burks Date: Tue, 4 Jun 2024 18:19:05 -0400 Subject: [PATCH 3/3] update faq --- faq.rst | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/faq.rst b/faq.rst index 5c37f78b..5bcaea78 100644 --- a/faq.rst +++ b/faq.rst @@ -199,8 +199,8 @@ How can I add local rules? Please see the :ref:`detections` section. -Can I connect Security Onion to Active Directory or LDAP? -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +Can I connect Security Onion to Active Directory or another OIDC provider? +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Please see the :ref:`oidc` section.