Latest release

LOKI version 0.28.1

@Neo23x0 Neo23x0 released this Jun 8, 2018 · 5 commits to master since this release

  • Minor bugfix: handle cases in which PESieve didn't produce JSON output (some error)

LOKI version 0.28.0

@Neo23x0 Neo23x0 released this Apr 14, 2018 · 10 commits to master since this release

  • Don't show every rule during startup but only a count (use --debug to see them)
  • LOKI upgrader allows a signature clean-up to handle errors caused by old (most likely renamed) rules (--clean)
  • Bugfix: Exclude LOKI's processes from checks
  • Bugfix: Error fix in loki-upgrader (cannot create output directory)

LOKI version 0.27.5

@Neo23x0 Neo23x0 released this Apr 14, 2018 · 15 commits to master since this release

  • Bugfix: Removed demo code

LOKI version 0.27.4

@Neo23x0 Neo23x0 released this Apr 13, 2018 · 16 commits to master since this release

screen shot 2018-04-14 at 00 59 57

LOKI version 0.27.3

@Neo23x0 Neo23x0 released this Apr 12, 2018 · 17 commits to master since this release

  • Added support for PESieve's "implanted" process detection

LOKI version 0.27.1

@Neo23x0 Neo23x0 released this Apr 10, 2018 · 19 commits to master since this release

  • Bugfix in process memory scan (thx to Didier)

LOKI version 0.27.0

@Neo23x0 Neo23x0 released this Mar 17, 2018 · 20 commits to master since this release

  • Log format of TEXT and SYSLOG output changed and now includes the reporting module
  • Bugfix: Don't run PESieve on Windows XP

Log Format Changes

From:

LOKI: [Level]: [Message]

To:

LOKI: [Level]: MODULE: [Module] MESSAGE: [Message]

screen shot 2018-03-17 at 09 26 46

Splunk App & Add-on

The changes to the log format allow you to use the THOR Splunk App and Addon for your LOKI log file analysis

THOR App https://splunkbase.splunk.com/app/3717/
THOR Addon https://splunkbase.splunk.com/app/3718/

screen shot 2018-03-17 at 09 22 43

Make sure to:

  1. Select the sourcetype "thor" for your inputs

screen shot 2018-03-17 at 08 03 39

  1. Set the index to be "searched by default" if you create a new index

screen shot 2018-03-17 at 08 20 07

IMPORTANT: I will not support every dashboard but the App helps to you search and filter the LOKI results based on fields. The most important dashboard named "Universal Dashboard" should work. If you want to fix or improve other dashboard views, please send me your improvements. All this work (LOKI, the signatures and the Apps) are offered for free and most of the work is done in my spare time on weekends. Please consider this before reporting bugs in the dashboards that could be fixed in 2 minutes of your own time. If you want Enterprise grade tools and support, please visit our website and ask for a trial https://www.nextron-systems.com of such tools.

LOKI version 0.26.2

@Neo23x0 Neo23x0 released this Feb 19, 2018 · 26 commits to master since this release

  • Bugfix: Removed legacy code for old filename IOC format that caused problems with newest filename IOC format (many false positives with negative score values in "description" and a score of "60")

LOKI version 0.26.1

@Neo23x0 Neo23x0 released this Feb 13, 2018 · 27 commits to master since this release

  • New hash IOC whitelist
  • Better hostname evaluation on Linux / OSX
  • Code refactoring
  • Better messages