-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdefault.yaml
More file actions
156 lines (156 loc) · 2.77 KB
/
Copy pathdefault.yaml
File metadata and controls
156 lines (156 loc) · 2.77 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
load_profile: lite
runtime:
prefer: notorch
collector: {}
window:
size: 60
stride: 5
train:
epochs: 25
batch_size: 32
lr: 0.001
val_ratio: 0.2
seed: 42
cnn_weight: 0.55
iforest_weight: 0.45
recall_target: 0.85
monitor: {}
ensemble:
default_threshold: 0.5
host_weight: 0.6
agent_weight: 0.4
risk_threshold: 0.7
host:
id: null
perimeter:
fail_threshold: 8
fail_window_sec: 60
scan_unique_ips: 8
scan_window_sec: 60
state_path: state/perimeter.json
jsonl_out: reports/perimeter.jsonl
denylist_paths:
- configs/denylist.txt
alert_new_egress: false
suspicious_domains:
- malware.test
- c2.example
auto_ban:
enabled: false
rules:
- bruteforce_ssh
- egress_denylist_hit
- honeypot_hit
- lockdown_inbound
ttl_sec: 3600
response:
mode: observe
never_ban_cidrs: []
learn_hours: 24
recon:
auto: false
nmap: false
cooldown_sec: 900
dir: reports/recon
passive_dns_url: null
telegram:
bot_token: null
chat_id: null
token_secret: null
allow_destructive_sims: false
require_console_unlock: true
unlock_ttl_sec: 7200
health_ping_hours: 0
web:
enabled: false
host: 127.0.0.1
port: 8765
public_url: null
siem:
webhook_url: null
webhook_secret: null
lab:
mode: false
nmap_targets:
- 127.0.0.1
- ::1
honeypot:
enabled: false
port: 2222
canary:
enabled: false
ports:
- 3377
- 4488
- 5599
bind: 0.0.0.0
sessions:
enabled: true
learn_sec: 120
poll_sec: 15
allow_users: []
allow_cidrs: []
root_watch:
enabled: false
learn_sec: 300
poll_sec: 60
allow_comms: []
flow:
enabled: true
backend: netview
window_sec: 30
syn_threshold: 120
unique_port_threshold: 60
agent:
enabled: true
auto_start: true
socket: null
binary: null
jsonl: reports/agent.jsonl
score_window_sec: 120
score_threshold: 0.65
iforest: null
require_same_uid: true
require_hmac: true
hmac_secret: state/agent_hmac.secret
root_watch: true
root_learn_sec: 300
mode: ebpf
fim:
enabled: true
interval_sec: 300
baseline_path: state/fim-baseline.json
feedback:
if_refit: false
widen_rules: comm_prefix
model_dir: artifacts
kirk:
enabled: true
trust: auto
require_tpm: false
auto_isolate: false
auto_isolate_host_risk: false
host_risk_threshold: 0.99
isolate_ttl_sec: 3600
allow_ssh_cidrs: []
ima_watch: true
ima_state_path: state/ima_offset.txt
baseline_path: state/kirk-baseline.json
vmi: false
watchdog:
phoenix: true
kernel_protect: false
alerts:
strict_secrets: true
allow_private_sinks: false
sinks:
- type: file
path: reports/alerts.jsonl
role: generic-linux
model:
path: artifacts
supply_chain:
enforce: false
public_key: null
manifest_name: artifacts.manifest.json
signature_name: artifacts.manifest.json.minisig