Christian Cloutier

Results 10 issues of Christian Cloutier

When trying to run a simulation on a stopped AR, it would be nice to provide a more user-friendly message. ![image](https://user-images.githubusercontent.com/58239192/185658422-b7a92794-f828-41fe-852f-d8ac7dd2960f.png) Also, cosmetic only, but the messages about the AR...

enhancement

We should look into deploying [TA-aurora](https://github.com/NextronSystems/TA-aurora) as part of Attack Range when the Aurora EDR agent is configured (`install_aurora_agent = 1`). Deploying it after the fact manually is not as...

enhancement

**Is your feature request related to a problem? Please describe.** Could the team expose `tags.atomic_guid` and `tags.required_fields` in ESCU please? That would help a lot track this important information into...

enhancement

It would be nice for PurpleSharp unit tests / playbook tests output to also be logged to `index = attack` like Atomic Red Team test results. This could be achieved...

enhancement
3.0

Fix for issue #124.

bug

### Description This was raised by John Norton on the Outpost Security RBA Slack channel. See screenshot. This comes from using `tstats` on two related MV fields that have to...

bug

### Description The dashboard shows errors for some panels and seems to expect lookups that don't *seem* to be provided as part of this Github/app. ![image](https://github.com/splunk/rba/assets/58239192/c39f603f-4f64-420f-82bf-7f7086a2c45c) When `Show Attack Web`...

bug

### Description The `attack_matrix_risk.xml` dashboard seems to rely (?) on CSS and/or Javascript files that do not seem to be included in this repo. Can we remove them (if no...

bug

It would help for these fields to be exposed to/included in the ESCU app. See https://github.com/splunk/security_content/issues/2904.

### **Describe the bug** We seem to have a mix of fields between `Message` and `ScriptBlockText` for the Powershell rules in ESCU. If my own testing is correct, the `Message`...

bug