mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
more filter updates
This commit is contained in:
@@ -60,7 +60,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: Lumma Stealer Activity on host $scr_ip$.
|
||||
message: Lumma Stealer Activity on host $src_ip$.
|
||||
risk_objects:
|
||||
- field: src_ip
|
||||
type: system
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@ search: |
|
||||
by src_ip dest_ip dest_port transport signature_id signature class_desc MitreAttackGroups rule InlineResult InlineResultReason app
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `cisco_secure_firewall___lumma_stealer_outbound_connection_attempt`
|
||||
| `cisco_secure_firewall___lumma_stealer_outbound_connection_attempt_filter`
|
||||
how_to_implement: |
|
||||
This search requires Cisco Secure Firewall Threat Defense Logs, which
|
||||
includes the IntrusionEvent EventType. This search uses an input macro named `cisco_secure_firewall`.
|
||||
|
||||
Reference in New Issue
Block a user