From 483ba8698e39cd61a686111305e665cca236f384 Mon Sep 17 00:00:00 2001 From: d1vious Date: Fri, 4 Feb 2022 11:45:10 -0500 Subject: [PATCH] adding macro and lookup sorting --- bin/doc_gen.py | 7 ++++++- ...18-10-23-wmi_permanent_event_subscription.md | 2 +- ...18-10-23-wmi_temporary_event_subscription.md | 2 +- .../2018-12-06-suspicious_java_classes.md | 2 +- ...t_credential_dumping_through_lsass_access.md | 2 +- ...12-03-detect_mimikatz_using_loaded_images.md | 2 +- ...-06-access_lsass_memory_for_dump_creation.md | 2 +- ...019-12-06-create_remote_thread_into_lsass.md | 2 +- ...02-03-creation_of_lsass_dump_with_taskmgr.md | 2 +- ...zon_eks_kubernetes_cluster_scan_detection.md | 2 +- ...-amazon_eks_kubernetes_pod_scan_detection.md | 2 +- ...-20-first_time_seen_child_process_of_zoom.md | 2 +- .../2020-07-06-windows_event_log_cleared.md | 2 +- ...with_invalid_credentials_from_the_same_ip.md | 2 +- .../2020-07-21-okta_failed_sso_attempts.md | 2 +- ...-21-okta_user_logins_from_multiple_cities.md | 2 +- ...22-suspicious_email_attachment_extensions.md | 2 +- ...or_system_network_configuration_discovery.md | 2 +- ...unburst_correlation_dll_and_network_event.md | 2 +- ...0-12-15-o365_suspicious_rights_delegation.md | 2 +- docs/_posts/2020-12-16-o365_disable_mfa.md | 2 +- ...5_excessive_authentication_failures_alert.md | 2 +- docs/_posts/2020-12-16-o365_pst_export_alert.md | 2 +- ...16-o365_suspicious_admin_email_forwarding.md | 2 +- ...-16-o365_suspicious_user_email_forwarding.md | 2 +- ...6-o365_add_app_role_assignment_grant_user.md | 2 +- .../2021-01-26-o365_added_service_principal.md | 2 +- ...021-01-26-o365_excessive_sso_logon_errors.md | 2 +- ...021-01-26-o365_new_federated_domain_added.md | 2 +- ...-16-detect_regasm_with_network_connection.md | 2 +- ...16-detect_regsvcs_with_network_connection.md | 2 +- .../2021-02-22-cobalt_strike_named_pipes.md | 2 +- ...2021-03-12-ransomware_notes_bulk_creation.md | 2 +- .../2021-03-16-high_file_deletion_frequency.md | 2 +- ...-03-16-high_process_termination_frequency.md | 2 +- ...17-process_deleting_its_process_file_path.md | 2 +- ...ownload_with_urlcache_and_split_arguments.md | 2 +- ...wnload_with_verifyctl_and_split_arguments.md | 2 +- .../2021-03-23-certutil_with_decode_argument.md | 2 +- ...14-office_document_creating_schedule_task.md | 2 +- ...4-14-office_document_executing_macro_code.md | 2 +- ...ll_remote_thread_to_known_windows_process.md | 2 +- ...ocess_connecting_to_ip_check_web_services.md | 2 +- ...-19-wermgr_process_create_executable_file.md | 2 +- ...021-04-21-excessive_usage_of_nslookup_app.md | 2 +- ...-multiple_archive_files_http_post_traffic.md | 2 +- ...21-04-22-plain_http_post_exfiltrated_data.md | 2 +- ...1-04-26-office_product_spawning_bitsadmin.md | 2 +- ...21-04-26-office_product_spawning_certutil.md | 2 +- docs/_posts/2021-04-26-trickbot_named_pipe.md | 2 +- .../2021-04-29-suspicious_driver_loaded_path.md | 2 +- docs/_posts/2021-04-29-xmrig_driver_loaded.md | 2 +- .../2021-05-06-download_files_using_telegram.md | 2 +- .../2021-05-13-cmlua_or_cmstplua_uac_bypass.md | 2 +- .../2021-06-02-modification_of_wallpaper.md | 2 +- .../2021-06-02-wbemprox_com_object_execution.md | 2 +- ...detect_wmi_event_subscription_persistence.md | 2 +- ...-24-excessive_usage_of_sc_service_utility.md | 2 +- ...1-07-01-spoolsv_suspicious_loaded_modules.md | 2 +- ...1-07-01-spoolsv_suspicious_process_access.md | 2 +- ...2021-07-01-spoolsv_writing_a_dll_-_sysmon.md | 2 +- ...21-07-12-uac_bypass_mmc_load_unsigned_dll.md | 2 +- ...hta_spawning_rundll32_or_regsvr32_process.md | 2 +- ...2021-07-19-o365_bypass_mfa_via_trusted_ip.md | 2 +- ...26-rundll32_createremotethread_in_browser.md | 2 +- docs/_posts/2021-07-26-rundll32_dnsquery.md | 2 +- ...6-rundll32_process_creating_exe_dll_files.md | 2 +- ...undll32_create_remote_thread_to_a_process.md | 2 +- .../2021-07-30-drop_icedid_license_dat.md | 2 +- ...icedid_exfiltrated_archived_file_creation.md | 2 +- .../2021-08-03-sqlite_module_in_temp_folder.md | 2 +- ...create_remote_thread_in_shell_application.md | 2 +- ...-08-13-uac_bypass_with_colorui_com_object.md | 2 +- docs/_posts/2021-08-18-esentutl_sam_copy.md | 2 +- ...-19-aws_ecr_container_upload_unknown_user.md | 2 +- ...021-08-20-github_commit_changes_in_master.md | 2 +- ...021-09-01-circle_ci_disable_security_step.md | 2 +- .../2021-09-01-github_commit_in_develop.md | 2 +- .../2021-09-01-github_dependabot_alert.md | 2 +- ...-01-github_pull_request_from_unknown_user.md | 4 ++-- ...2021-09-02-circle_ci_disable_security_job.md | 2 +- ...nge_by_app_connect_and_create_adsi_object.md | 2 +- ...9-09-mshtml_module_load_in_office_product.md | 2 +- ...-ms_scripting_process_loading_ldap_module.md | 2 +- ...3-ms_scripting_process_loading_wmi_module.md | 2 +- ...mpt_to_add_certificate_to_untrusted_store.md | 2 +- docs/_posts/2021-09-16-bits_job_persistence.md | 2 +- .../2021-09-16-bitsadmin_download_file.md | 2 +- ...n_of_shadow_copy_with_wmic_and_powershell.md | 2 +- ...-09-16-detect_psexec_with_accepteula_flag.md | 2 +- docs/_posts/2021-09-16-detect_renamed_psexec.md | 2 +- .../2021-09-29-verclsid_clsid_execution.md | 2 +- ...-windows_curl_download_to_suspicious_path.md | 2 +- ...ndows_task_scheduler_event_action_started.md | 2 +- ...windows_curl_upload_to_remote_destination.md | 2 +- ...2021-11-12-csc_net_on_the_fly_compilation.md | 2 +- ...2021-11-12-runas_execution_in_commandline.md | 2 +- ...1-12-windows_installutil_credential_theft.md | 2 +- .../2021-11-18-loading_of_dynwrapx_module.md | 2 +- ...m_info_gathering_using_dxdiag_application.md | 2 +- ...08-msi_module_loaded_by_non-system_binary.md | 2 +- .../2021-12-13-windows_java_spawning_shells.md | 2 +- ...ws_hunting_system_account_targeting_lsass.md | 2 +- ...indows_non-system_account_targeting_lsass.md | 2 +- ...rocess_dns_query_known_abuse_web_services.md | 2 +- ...suspicious_process_with_discord_dns_query.md | 2 +- ...ssive_file_deletion_in_windefender_folder.md | 2 +- ...01-27-windows_possible_credential_dumping.md | 2 +- docs/static/structure.png | Bin 0 -> 70129 bytes 109 files changed, 114 insertions(+), 109 deletions(-) create mode 100644 docs/static/structure.png diff --git a/bin/doc_gen.py b/bin/doc_gen.py index 87d1dd247d..36e22b69d4 100644 --- a/bin/doc_gen.py +++ b/bin/doc_gen.py @@ -340,7 +340,6 @@ def generate_doc_detections(REPO_PATH, OUTPUT_DIR, TEMPLATE_PATH, attack, messag for macro in detection_yaml['macros']: if 'lookups' in macro: for macro_lookup in macro['lookups']: - print(macro_lookup) detection_lookups.append(macro_lookup) # now any other search lookups additional_detection_lookups = parse_and_add_lookups(detection_yaml['search'], lookups) @@ -350,6 +349,12 @@ def generate_doc_detections(REPO_PATH, OUTPUT_DIR, TEMPLATE_PATH, attack, messag detection_yaml['lookups'] = detection_lookups detection_yaml['lookups'] = detection_lookups + # sort macros and lookups + sorted_macros = sorted(detection_yaml['macros'], key=lambda i: i['name']) + detection_yaml['macros'] = sorted_macros + sorted_lookups = sorted(detection_yaml['lookups'], key=lambda i: i['name']) + detection_yaml['lookups'] = sorted_lookups + # grab the kind detection_yaml['kind'] = manifest_file.split('/')[-2] diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md index 19d4057454..9036fdc4ca 100644 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md @@ -54,8 +54,8 @@ This search looks for the creation of WMI permanent event subscriptions. #### Macros The SPL above uses the following Macros: -* [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml) Note that `wmi_permanent_event_subscription_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md index 87adcb75de..c03fdffb58 100644 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md @@ -53,8 +53,8 @@ This search looks for the creation of WMI temporary event subscriptions. #### Macros The SPL above uses the following Macros: -* [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml) Note that `wmi_temporary_event_subscription_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md index 98109f433a..c2980bf781 100644 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ b/docs/_posts/2018-12-06-suspicious_java_classes.md @@ -44,8 +44,8 @@ This search looks for suspicious Java classes that are often used to exploit rem #### Macros The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) Note that `suspicious_java_classes_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md index 646394fd44..d8cadb9742 100644 --- a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md +++ b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md @@ -53,8 +53,8 @@ This search looks for reading lsass memory consistent with credential dumping. #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `detect_credential_dumping_through_lsass_access_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md index 1f2ac999e1..17935af9b1 100644 --- a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md +++ b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md @@ -54,8 +54,8 @@ This search looks for reading loaded Images unique to credential dumping with Mi #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `detect_mimikatz_using_loaded_images_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md index 1d21b9c7b0..57f9544a47 100644 --- a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md +++ b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md @@ -53,8 +53,8 @@ Detect memory dumping of the LSASS process. #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `access_lsass_memory_for_dump_creation_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md index c8967f31e2..f5c753564c 100644 --- a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md +++ b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md @@ -53,8 +53,8 @@ Detect remote thread creation into LSASS consistent with credential dumping. #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `create_remote_thread_into_lsass_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md index c712154c68..3a48814b20 100644 --- a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md +++ b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md @@ -53,8 +53,8 @@ Detect the hands on keyboard behavior of Windows Task Manager creating a process #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `creation_of_lsass_dump_with_taskmgr_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md index 2689915ab5..7e176a34d8 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md @@ -51,8 +51,8 @@ This search provides information of unauthenticated requests via user agent, and #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `amazon_eks_kubernetes_cluster_scan_detection_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md index 8ebf99391c..e46ba8b2ff 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md @@ -51,8 +51,8 @@ This search provides detection information on unauthenticated requests against K #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `amazon_eks_kubernetes_pod_scan_detection_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index 2b2c35869d..8ac48ea503 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -54,8 +54,8 @@ This search looks for child processes spawned by zoom.exe or zoom.us that has no #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [previously_seen_zoom_child_processes_window](https://github.com/splunk/security_content/blob/develop/macros/previously_seen_zoom_child_processes_window.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `first_time_seen_child_process_of_zoom_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-06-windows_event_log_cleared.md b/docs/_posts/2020-07-06-windows_event_log_cleared.md index 6b4e3816b4..bb7983c26b 100644 --- a/docs/_posts/2020-07-06-windows_event_log_cleared.md +++ b/docs/_posts/2020-07-06-windows_event_log_cleared.md @@ -53,8 +53,8 @@ The following analytic utilizes Windows Security Event ID 1102 or System log eve #### Macros The SPL above uses the following Macros: * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) * [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml) +* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml) Note that `windows_event_log_cleared_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index 414e2691c0..9cdbfd7cea 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -62,8 +62,8 @@ This search detects Okta login failures due to bad credentials for multiple user #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index 43e9065f06..4a68126027 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -60,8 +60,8 @@ Detect failed Okta SSO events #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `okta_failed_sso_attempts_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index f7531a3385..d76b90acaf 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -61,8 +61,8 @@ This search detects logins from the same user from different cities in a 24 hour #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `okta_user_logins_from_multiple_cities_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index 41d47eec72..fbcd94aa82 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -57,9 +57,9 @@ This search looks for emails that have attachments with suspicious file extensio #### Macros The SPL above uses the following Macros: -* [suspicious_email_attachments](https://github.com/splunk/security_content/blob/develop/macros/suspicious_email_attachments.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [suspicious_email_attachments](https://github.com/splunk/security_content/blob/develop/macros/suspicious_email_attachments.yml) Note that `suspicious_email_attachment_extensions_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md index f0df13e071..ae2b8d16e7 100644 --- a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md +++ b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md @@ -54,9 +54,9 @@ This search looks for fast execution of processes used for system network config #### Macros The SPL above uses the following Macros: -* [system_network_configuration_discovery_tools](https://github.com/splunk/security_content/blob/develop/macros/system_network_configuration_discovery_tools.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [system_network_configuration_discovery_tools](https://github.com/splunk/security_content/blob/develop/macros/system_network_configuration_discovery_tools.yml) Note that `detect_processes_used_for_system_network_configuration_discovery_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md index 78ee1a5d5f..18c5cafaea 100644 --- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md +++ b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md @@ -53,8 +53,8 @@ The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `sunburst_correlation_dll_and_network_event_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md index f9608ba934..e143f9fb30 100644 --- a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md +++ b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md @@ -56,8 +56,8 @@ This search detects the assignment of rights to accesss content from another mai #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_suspicious_rights_delegation_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-16-o365_disable_mfa.md b/docs/_posts/2020-12-16-o365_disable_mfa.md index 60a1af64b8..5c0fda596f 100644 --- a/docs/_posts/2020-12-16-o365_disable_mfa.md +++ b/docs/_posts/2020-12-16-o365_disable_mfa.md @@ -51,8 +51,8 @@ This search detects when multi factor authentication has been disabled, what ent #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_disable_mfa_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md b/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md index e5a25ac9aa..594a99ea9c 100644 --- a/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md +++ b/docs/_posts/2020-12-16-o365_excessive_authentication_failures_alert.md @@ -50,8 +50,8 @@ This search detects when an excessive number of authentication failures occur th #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_excessive_authentication_failures_alert_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-16-o365_pst_export_alert.md b/docs/_posts/2020-12-16-o365_pst_export_alert.md index 98a35f359f..875631c122 100644 --- a/docs/_posts/2020-12-16-o365_pst_export_alert.md +++ b/docs/_posts/2020-12-16-o365_pst_export_alert.md @@ -49,8 +49,8 @@ This search detects when a user has performed an Ediscovery search or exported a #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_pst_export_alert_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md index adc16353f7..415dbd7377 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md @@ -57,8 +57,8 @@ This search detects when an admin configured a forwarding rule for multiple mail #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_suspicious_admin_email_forwarding_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md index 8a85b518f7..13a1a36240 100644 --- a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md +++ b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md @@ -57,8 +57,8 @@ This search detects when multiple user configured a forwarding rule to the same #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_suspicious_user_email_forwarding_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md index d5457b1a9d..082a842ca9 100644 --- a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md +++ b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md @@ -53,8 +53,8 @@ This search detects the creation of a new Federation setting by alerting about a #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_add_app_role_assignment_grant_user_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-26-o365_added_service_principal.md b/docs/_posts/2021-01-26-o365_added_service_principal.md index 69fe81bfd4..c41e86e168 100644 --- a/docs/_posts/2021-01-26-o365_added_service_principal.md +++ b/docs/_posts/2021-01-26-o365_added_service_principal.md @@ -53,8 +53,8 @@ This search detects the creation of a new Federation setting by alerting about a #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_added_service_principal_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md index a1814aef2a..6012bca0bf 100644 --- a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md +++ b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md @@ -52,8 +52,8 @@ This search detects accounts with high number of Single Sign ON (SSO) logon erro #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_excessive_sso_logon_errors_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md index dc6c13308b..ec2fb1c400 100644 --- a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md +++ b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md @@ -53,8 +53,8 @@ This search detects the addition of a new Federated domain. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_new_federated_domain_added_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md b/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md index 7b106fae3b..3665d519a8 100644 --- a/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md +++ b/docs/_posts/2021-02-16-detect_regasm_with_network_connection.md @@ -53,8 +53,8 @@ The following analytic identifies regasm.exe with a network connection to a publ #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `detect_regasm_with_network_connection_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md b/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md index 335ad95718..4e20253732 100644 --- a/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md +++ b/docs/_posts/2021-02-16-detect_regsvcs_with_network_connection.md @@ -53,8 +53,8 @@ The following analytic identifies Regsvcs.exe with a network connection to a pub #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `detect_regsvcs_with_network_connection_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md index 3c204bcbda..cae86a69bd 100644 --- a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md +++ b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md @@ -51,8 +51,8 @@ Upon triage, review the process performing the named pipe. If it is explorer.exe #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `cobalt_strike_named_pipes_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md index 6e95a69274..7f8d61d3e7 100644 --- a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md +++ b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md @@ -51,8 +51,8 @@ The following analytics identifies a big number of instance of ransomware notes #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `ransomware_notes_bulk_creation_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-16-high_file_deletion_frequency.md b/docs/_posts/2021-03-16-high_file_deletion_frequency.md index a5e6268704..b41da01825 100644 --- a/docs/_posts/2021-03-16-high_file_deletion_frequency.md +++ b/docs/_posts/2021-03-16-high_file_deletion_frequency.md @@ -50,8 +50,8 @@ This search looks for high frequency of file deletion relative to process name a #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `high_file_deletion_frequency_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-16-high_process_termination_frequency.md b/docs/_posts/2021-03-16-high_process_termination_frequency.md index 8f43fde336..d52c3f6edd 100644 --- a/docs/_posts/2021-03-16-high_process_termination_frequency.md +++ b/docs/_posts/2021-03-16-high_process_termination_frequency.md @@ -51,8 +51,8 @@ This analytics are designed to indentify a high frequency of process termination #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `high_process_termination_frequency_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md b/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md index d93f903137..3639071d7f 100644 --- a/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md +++ b/docs/_posts/2021-03-17-process_deleting_its_process_file_path.md @@ -51,8 +51,8 @@ This detection is to identify a suspicious process that tries to delete the proc #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `process_deleting_its_process_file_path_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md b/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md index 4b12acee93..21fba81d1d 100644 --- a/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md +++ b/docs/_posts/2021-03-23-certutil_download_with_urlcache_and_split_arguments.md @@ -50,8 +50,8 @@ Certutil.exe may download a file from a remote destination using `-urlcache`. Th #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `certutil_download_with_urlcache_and_split_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md b/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md index 38b1593a2d..dccf148d4f 100644 --- a/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md +++ b/docs/_posts/2021-03-23-certutil_download_with_verifyctl_and_split_arguments.md @@ -50,8 +50,8 @@ Certutil.exe may download a file from a remote destination using `-VerifyCtl`. T #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `certutil_download_with_verifyctl_and_split_arguments_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-03-23-certutil_with_decode_argument.md b/docs/_posts/2021-03-23-certutil_with_decode_argument.md index ee8d588e56..90c16a6c22 100644 --- a/docs/_posts/2021-03-23-certutil_with_decode_argument.md +++ b/docs/_posts/2021-03-23-certutil_with_decode_argument.md @@ -50,8 +50,8 @@ CertUtil.exe may be used to `encode` and `decode` a file, including PE and scrip #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `certutil_with_decode_argument_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md index 7a693d1251..7bc753ff9e 100644 --- a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md +++ b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md @@ -53,8 +53,8 @@ this search detects a potential malicious office document that create schedule t #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `office_document_creating_schedule_task_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-14-office_document_executing_macro_code.md b/docs/_posts/2021-04-14-office_document_executing_macro_code.md index 4ea71ec1c0..59f4b8372a 100644 --- a/docs/_posts/2021-04-14-office_document_executing_macro_code.md +++ b/docs/_posts/2021-04-14-office_document_executing_macro_code.md @@ -53,8 +53,8 @@ this detection was designed to identifies suspicious office documents that using #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `office_document_executing_macro_code_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md index 51ba9a56c2..2432be91b7 100644 --- a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md +++ b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md @@ -50,8 +50,8 @@ this search is designed to detect suspicious powershell process that tries to in #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `powershell_remote_thread_to_known_windows_process_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md index 7f547f6248..b284f803cb 100644 --- a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md +++ b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md @@ -53,8 +53,8 @@ this search is designed to detect suspicious wermgr.exe process that tries to co #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `wermgr_process_connecting_to_ip_check_web_services_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md index eb8b130c76..0ae120e202 100644 --- a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md +++ b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md @@ -49,8 +49,8 @@ this search is designed to detect potential malicious wermgr.exe process that dr #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `wermgr_process_create_executable_file_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md index 771cb509f5..c8c74bbf9a 100644 --- a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md +++ b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md @@ -54,8 +54,8 @@ This search is to detect potential DNS exfiltration using nslookup application. #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `excessive_usage_of_nslookup_app_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md index 29ecdc775e..84bfbf7b99 100644 --- a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md +++ b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md @@ -56,8 +56,8 @@ This search is designed to detect high frequency of archive files data exfiltrat #### Macros The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) Note that `multiple_archive_files_http_post_traffic_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md index ae1f868b91..f218c4ab5e 100644 --- a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md +++ b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md @@ -53,8 +53,8 @@ This search is to detect potential plain HTTP POST method data exfiltration. Thi #### Macros The SPL above uses the following Macros: -* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml) Note that `plain_http_post_exfiltrated_data_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md index 69aa2dd0bf..378a02bcb7 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md +++ b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md @@ -54,8 +54,8 @@ The following detection identifies the latest behavior utilized by different mal #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `office_product_spawning_bitsadmin_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-26-office_product_spawning_certutil.md b/docs/_posts/2021-04-26-office_product_spawning_certutil.md index e404554b4a..be59d9ec62 100644 --- a/docs/_posts/2021-04-26-office_product_spawning_certutil.md +++ b/docs/_posts/2021-04-26-office_product_spawning_certutil.md @@ -54,8 +54,8 @@ The following detection identifies the latest behavior utilized by different mal #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `office_product_spawning_certutil_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-26-trickbot_named_pipe.md b/docs/_posts/2021-04-26-trickbot_named_pipe.md index 75b9d04697..d31f359c26 100644 --- a/docs/_posts/2021-04-26-trickbot_named_pipe.md +++ b/docs/_posts/2021-04-26-trickbot_named_pipe.md @@ -50,8 +50,8 @@ this search is to detect potential trickbot infection through the create/connect #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `trickbot_named_pipe_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md index 7740190257..6228a76226 100644 --- a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md +++ b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md @@ -55,8 +55,8 @@ This analytic will detect suspicious driver loaded paths. This technique is comm #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `suspicious_driver_loaded_path_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-04-29-xmrig_driver_loaded.md b/docs/_posts/2021-04-29-xmrig_driver_loaded.md index 4987808c8e..7d465dd399 100644 --- a/docs/_posts/2021-04-29-xmrig_driver_loaded.md +++ b/docs/_posts/2021-04-29-xmrig_driver_loaded.md @@ -55,8 +55,8 @@ This analytic identifies XMRIG coinminer driver installation on the system. The #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `xmrig_driver_loaded_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-05-06-download_files_using_telegram.md b/docs/_posts/2021-05-06-download_files_using_telegram.md index 252e5cf3cf..5710545397 100644 --- a/docs/_posts/2021-05-06-download_files_using_telegram.md +++ b/docs/_posts/2021-05-06-download_files_using_telegram.md @@ -49,8 +49,8 @@ The following analytic will identify a suspicious download by the Telegram appli #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `download_files_using_telegram_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md index 786dab457b..342887e653 100644 --- a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md +++ b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md @@ -53,8 +53,8 @@ This analytic detects a potential process using COM Object like CMLUA or CMSTPLU #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `cmlua_or_cmstplua_uac_bypass_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-02-modification_of_wallpaper.md b/docs/_posts/2021-06-02-modification_of_wallpaper.md index 8deae20e99..c5edd79a47 100644 --- a/docs/_posts/2021-06-02-modification_of_wallpaper.md +++ b/docs/_posts/2021-06-02-modification_of_wallpaper.md @@ -49,8 +49,8 @@ This analytic identifies suspicious modification of registry to deface or change #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `modification_of_wallpaper_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md index cf56246092..657442c7b1 100644 --- a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md +++ b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md @@ -53,8 +53,8 @@ this search is designed to detect potential malicious process loading COM object #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `wbemprox_com_object_execution_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md index fb9b081bbd..8ca3d83352 100644 --- a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md +++ b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md @@ -59,8 +59,8 @@ Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToCons #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `detect_wmi_event_subscription_persistence_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md index 43337bd304..5243b58a6b 100644 --- a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md +++ b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md @@ -58,8 +58,8 @@ This search is to detect a suspicious excessive usage of sc.exe in a host machin #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `excessive_usage_of_sc_service_utility_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md index eef30c8e7f..5914e02709 100644 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md +++ b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md @@ -57,8 +57,8 @@ This search is to detect suspicious loading of dll in specific path relative to #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `spoolsv_suspicious_loaded_modules_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md index 735a056595..7808716c14 100644 --- a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md +++ b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md @@ -50,8 +50,8 @@ This analytic identifies a suspicious behavior related to PrintNightmare, or CVE #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `spoolsv_suspicious_process_access_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md index 1073f169cc..87f2a30115 100644 --- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md +++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md @@ -56,8 +56,8 @@ The following analytic identifies a `.dll` being written by `spoolsv.exe`. This #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `spoolsv_writing_a_dll_-_sysmon_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md index f5319301cc..259f510409 100644 --- a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md +++ b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md @@ -55,8 +55,8 @@ This search is to detect a suspicious loaded unsigned dll by MMC.exe application #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `uac_bypass_mmc_load_unsigned_dll_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md index a249382777..c344f38f11 100644 --- a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md +++ b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md @@ -54,8 +54,8 @@ This search is to detect a suspicious mshta.exe process that spawn rundll32 or r #### Macros The SPL above uses the following Macros: -* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) * [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml) +* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) diff --git a/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md b/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md index 6d94e3da3c..fb65e505ce 100644 --- a/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md +++ b/docs/_posts/2021-07-19-o365_bypass_mfa_via_trusted_ip.md @@ -58,8 +58,8 @@ This search detects newly added IP addresses/CIDR blocks to the list of MFA Trus #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [o365_management_activity](https://github.com/splunk/security_content/blob/develop/macros/o365_management_activity.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `o365_bypass_mfa_via_trusted_ip_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md index 7aecac3b8c..9ad410defd 100644 --- a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md +++ b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md @@ -50,8 +50,8 @@ This analytic identifies the suspicious Remote Thread execution of rundll32.exe #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `rundll32_createremotethread_in_browser_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-26-rundll32_dnsquery.md b/docs/_posts/2021-07-26-rundll32_dnsquery.md index 03bf7bddf4..a1a5ab22d8 100644 --- a/docs/_posts/2021-07-26-rundll32_dnsquery.md +++ b/docs/_posts/2021-07-26-rundll32_dnsquery.md @@ -53,8 +53,8 @@ This search is to detect a suspicious rundll32.exe process having a http connect #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `rundll32_dnsquery_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md index 7e4cc71dc8..69c4061d81 100644 --- a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md +++ b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md @@ -53,8 +53,8 @@ This search is to detect a suspicious rundll32 process that drops executable (.e #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `rundll32_process_creating_exe_dll_files_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md index 398d6f1350..91b78c8837 100644 --- a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md +++ b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md @@ -50,8 +50,8 @@ This analytic identifies the suspicious Remote Thread execution of rundll32.exe #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `rundll32_create_remote_thread_to_a_process_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-30-drop_icedid_license_dat.md b/docs/_posts/2021-07-30-drop_icedid_license_dat.md index 22062fd68a..e2c72ed890 100644 --- a/docs/_posts/2021-07-30-drop_icedid_license_dat.md +++ b/docs/_posts/2021-07-30-drop_icedid_license_dat.md @@ -53,8 +53,8 @@ This search is to detect dropping a suspicious file named as "license.dat #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `drop_icedid_license_dat_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md index 77c6fbe855..1dc538318e 100644 --- a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md +++ b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md @@ -53,8 +53,8 @@ This search is to detect a suspicious file creation namely passff.tar and cookie #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `icedid_exfiltrated_archived_file_creation_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md index 99fed7dfe6..f1c40ebc70 100644 --- a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md +++ b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md @@ -49,8 +49,8 @@ This search is to detect a suspicious file creation of sqlite3.dll in %temp% fol #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `sqlite_module_in_temp_folder_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md index 27a436b590..636d0f7c3c 100644 --- a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md +++ b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md @@ -50,8 +50,8 @@ This search is to detect suspicious process injection in command shell. This tec #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `create_remote_thread_in_shell_application_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md index e364aa01b3..37ba7c5c32 100644 --- a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md +++ b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md @@ -53,8 +53,8 @@ This search is to detect a possible uac bypass using the colorui.dll COM Object. #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `uac_bypass_with_colorui_com_object_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-18-esentutl_sam_copy.md b/docs/_posts/2021-08-18-esentutl_sam_copy.md index 975c44c91f..e0068c1937 100644 --- a/docs/_posts/2021-08-18-esentutl_sam_copy.md +++ b/docs/_posts/2021-08-18-esentutl_sam_copy.md @@ -54,8 +54,8 @@ The following analytic identifies the process - `esentutl.exe` - being used to c #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_esentutl](https://github.com/splunk/security_content/blob/develop/macros/process_esentutl.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `esentutl_sam_copy_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md index acf8bb8833..735b973a36 100644 --- a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md +++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md @@ -57,8 +57,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service ( #### Macros The SPL above uses the following Macros: -* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) * [aws_ecr_users](https://github.com/splunk/security_content/blob/develop/macros/aws_ecr_users.yml) +* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `aws_ecr_container_upload_unknown_user_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-08-20-github_commit_changes_in_master.md b/docs/_posts/2021-08-20-github_commit_changes_in_master.md index 4330d6cfa8..63f2b840f0 100644 --- a/docs/_posts/2021-08-20-github_commit_changes_in_master.md +++ b/docs/_posts/2021-08-20-github_commit_changes_in_master.md @@ -52,8 +52,8 @@ This search is to detect a pushed or commit to master or main branch. This is to #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `github_commit_changes_in_master_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md index dca0ed71f3..ba9838d7fc 100644 --- a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md +++ b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md @@ -60,8 +60,8 @@ This search looks for disable security step in CircleCI pipeline. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `circle_ci_disable_security_step_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-01-github_commit_in_develop.md b/docs/_posts/2021-09-01-github_commit_in_develop.md index 1a1c4cbc47..dbd5065cb1 100644 --- a/docs/_posts/2021-09-01-github_commit_in_develop.md +++ b/docs/_posts/2021-09-01-github_commit_in_develop.md @@ -50,8 +50,8 @@ This search is to detect a pushed or commit to develop branch. This is to avoid #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `github_commit_in_develop_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-01-github_dependabot_alert.md b/docs/_posts/2021-09-01-github_dependabot_alert.md index 94945d8496..d2765df053 100644 --- a/docs/_posts/2021-09-01-github_dependabot_alert.md +++ b/docs/_posts/2021-09-01-github_dependabot_alert.md @@ -55,8 +55,8 @@ This search looks for Dependabot Alerts in Github logs. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `github_dependabot_alert_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md index 4475fcc7fd..bcae71cacc 100644 --- a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md +++ b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md @@ -56,9 +56,9 @@ This search looks for Pull Request from unknown user. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) -* [github_known_users](https://github.com/splunk/security_content/blob/develop/macros/github_known_users.yml) * [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml) +* [github_known_users](https://github.com/splunk/security_content/blob/develop/macros/github_known_users.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `github_pull_request_from_unknown_user_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md index 3010724abd..ce6e488c3c 100644 --- a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md +++ b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md @@ -56,8 +56,8 @@ This search looks for disable security job in CircleCI pipeline. #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) Note that `circle_ci_disable_security_job_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md index df79ec020f..4f51e7bb2a 100644 --- a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md +++ b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md @@ -53,8 +53,8 @@ This analytic is to detect an application try to connect and create ADSI Object #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `schcache_change_by_app_connect_and_create_adsi_object_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md index 13c4b59676..a45abf8601 100644 --- a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md +++ b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md @@ -55,8 +55,8 @@ The following detection identifies the module load of mshtml.dll into an Office #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `mshtml_module_load_in_office_product_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md index df997c3d1d..fff24aeb78 100644 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md +++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md @@ -53,8 +53,8 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `ms_scripting_process_loading_ldap_module_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md index 8da9d74d0d..7f40076a7b 100644 --- a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md +++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md @@ -53,8 +53,8 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `ms_scripting_process_loading_wmi_module_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md index 16109e1342..568283a66f 100644 --- a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md +++ b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md @@ -54,8 +54,8 @@ Attempt To Add Certificate To Untrusted Store #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `attempt_to_add_certificate_to_untrusted_store_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-bits_job_persistence.md b/docs/_posts/2021-09-16-bits_job_persistence.md index b0c2534455..18b7535423 100644 --- a/docs/_posts/2021-09-16-bits_job_persistence.md +++ b/docs/_posts/2021-09-16-bits_job_persistence.md @@ -51,8 +51,8 @@ The following query identifies Microsoft Background Intelligent Transfer Service #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `bits_job_persistence_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-bitsadmin_download_file.md b/docs/_posts/2021-09-16-bitsadmin_download_file.md index 9b20acf693..3a0c29d605 100644 --- a/docs/_posts/2021-09-16-bitsadmin_download_file.md +++ b/docs/_posts/2021-09-16-bitsadmin_download_file.md @@ -55,8 +55,8 @@ The following query identifies Microsoft Background Intelligent Transfer Service #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `bitsadmin_download_file_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md index 7a51df97bb..95d6aff2d4 100644 --- a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md +++ b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md @@ -54,8 +54,8 @@ This search detects the use of wmic and Powershell to create a shadow copy. #### Macros The SPL above uses the following Macros: -* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml) +* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) diff --git a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md index 6e80ae0446..24327aeb4e 100644 --- a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md +++ b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md @@ -54,8 +54,8 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_psexec](https://github.com/splunk/security_content/blob/develop/macros/process_psexec.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `detect_psexec_with_accepteula_flag_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-16-detect_renamed_psexec.md b/docs/_posts/2021-09-16-detect_renamed_psexec.md index 467aa754ad..42761a7925 100644 --- a/docs/_posts/2021-09-16-detect_renamed_psexec.md +++ b/docs/_posts/2021-09-16-detect_renamed_psexec.md @@ -54,8 +54,8 @@ The following analytic identifies renamed instances of `PsExec.exe` being utiliz #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_psexec](https://github.com/splunk/security_content/blob/develop/macros/process_psexec.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `detect_renamed_psexec_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-09-29-verclsid_clsid_execution.md b/docs/_posts/2021-09-29-verclsid_clsid_execution.md index 884e5c0933..9a945646b1 100644 --- a/docs/_posts/2021-09-29-verclsid_clsid_execution.md +++ b/docs/_posts/2021-09-29-verclsid_clsid_execution.md @@ -54,8 +54,8 @@ This analytic is to detect a possible abuse of verclsid to execute malicious fil #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_verclsid](https://github.com/splunk/security_content/blob/develop/macros/process_verclsid.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `verclsid_clsid_execution_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md b/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md index 3d148ba6a9..e1db7154f8 100644 --- a/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md +++ b/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md @@ -52,8 +52,8 @@ During triage, review parallel processes for further behavior. In addition, iden #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_curl](https://github.com/splunk/security_content/blob/develop/macros/process_curl.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `windows_curl_download_to_suspicious_path_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md index ce54a18a48..10ae5b6084 100644 --- a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md +++ b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md @@ -52,8 +52,8 @@ The following hunting analytic assists with identifying suspicious tasks that ha #### Macros The SPL above uses the following Macros: -* [wineventlog_task_scheduler](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_task_scheduler.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [wineventlog_task_scheduler](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_task_scheduler.yml) Note that `winevent_windows_task_scheduler_event_action_started_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md b/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md index 54627e630d..7142e64882 100644 --- a/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md +++ b/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md @@ -54,8 +54,8 @@ Adversaries may use one of the three methods based on the remote destination and #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_curl](https://github.com/splunk/security_content/blob/develop/macros/process_curl.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `windows_curl_upload_to_remote_destination_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md b/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md index 63f365604a..1bbc926782 100644 --- a/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md +++ b/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md @@ -54,8 +54,8 @@ this analytic is to detect a suspicious compile before delivery approach of .net #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_csc](https://github.com/splunk/security_content/blob/develop/macros/process_csc.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `csc_net_on_the_fly_compilation_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-12-runas_execution_in_commandline.md b/docs/_posts/2021-11-12-runas_execution_in_commandline.md index 1e51dcb2cc..40c0850991 100644 --- a/docs/_posts/2021-11-12-runas_execution_in_commandline.md +++ b/docs/_posts/2021-11-12-runas_execution_in_commandline.md @@ -56,8 +56,8 @@ This analytic look for a spawned runas.exe process with a administrator user opt #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_runas](https://github.com/splunk/security_content/blob/develop/macros/process_runas.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `runas_execution_in_commandline_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-12-windows_installutil_credential_theft.md b/docs/_posts/2021-11-12-windows_installutil_credential_theft.md index 3791775570..61ca76115c 100644 --- a/docs/_posts/2021-11-12-windows_installutil_credential_theft.md +++ b/docs/_posts/2021-11-12-windows_installutil_credential_theft.md @@ -57,8 +57,8 @@ During triage review resulting network connections, file modifications, and para #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `windows_installutil_credential_theft_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md b/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md index d6d0a21098..03cad349a3 100644 --- a/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md +++ b/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md @@ -55,8 +55,8 @@ DynamicWrapperX is an ActiveX component that can be used in a script to call Win #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `loading_of_dynwrapx_module_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md index 797fe860ba..4eed840474 100644 --- a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md +++ b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md @@ -50,8 +50,8 @@ This analytic is to detect a suspicious dxdiag.exe process command-line executio #### Macros The SPL above uses the following Macros: -* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [process_dxdiag](https://github.com/splunk/security_content/blob/develop/macros/process_dxdiag.yml) +* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) Note that `system_info_gathering_using_dxdiag_application_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md b/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md index c1e89f4337..40afbb3942 100644 --- a/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md +++ b/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md @@ -61,8 +61,8 @@ In addition, `msi.dll` has been abused in DLL side-loading attacks by being load #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `msi_module_loaded_by_non-system_binary_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md index f50ce4b0d8..8309693947 100644 --- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md +++ b/docs/_posts/2021-12-13-windows_java_spawning_shells.md @@ -53,9 +53,9 @@ The following analytic identifies the process name of java.exe and w3wp.exe spaw #### Macros The SPL above uses the following Macros: -* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) * [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml) +* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml) Note that `windows_java_spawning_shells_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md b/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md index adad5e9737..b7a8723dbf 100644 --- a/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md +++ b/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md @@ -53,8 +53,8 @@ The following hunting analytic identifies all processes requesting access into L #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `windows_hunting_system_account_targeting_lsass_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md b/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md index 322ed34f45..d9f95580ac 100644 --- a/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md +++ b/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md @@ -53,8 +53,8 @@ The following analytic identifies non SYSTEM accounts requesting access to lsass #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `windows_non-system_account_targeting_lsass_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md b/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md index dc9b8f18db..2b06a9469c 100644 --- a/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md +++ b/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md @@ -53,8 +53,8 @@ This analytic detects a suspicious process making a DNS query via known, abused #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `suspicious_process_dns_query_known_abuse_web_services_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md b/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md index 9a85bd5f2c..ddaa5127ea 100644 --- a/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md +++ b/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md @@ -53,8 +53,8 @@ This analytic identifies a process making a DNS query to Discord, a well known i #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `suspicious_process_with_discord_dns_query_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md b/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md index 4cd818b2e4..eca7d0f220 100644 --- a/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md +++ b/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md @@ -50,8 +50,8 @@ This analytic will identify excessive file deletion events in the Windows Defend #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `excessive_file_deletion_in_windefender_folder_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/_posts/2022-01-27-windows_possible_credential_dumping.md b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md index 218e72d0ad..9b69e0ec6f 100644 --- a/docs/_posts/2022-01-27-windows_possible_credential_dumping.md +++ b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md @@ -57,8 +57,8 @@ The idea behind using ntdll.dll is to blend in by using native api of ntdll.dll. #### Macros The SPL above uses the following Macros: -* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) * [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml) +* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml) Note that `windows_possible_credential_dumping_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. diff --git a/docs/static/structure.png b/docs/static/structure.png new file mode 100644 index 0000000000000000000000000000000000000000..c484ca06b95a64cca2d3120ce2cc62780dd65938 GIT binary patch literal 70129 zcmd?Q_dA?z*EURu-ibD9B1-g#7G(q>Iw?x@E-`wvC`0rvx@eI^Bq12RcZ0zog29;4 zdmX*bJGq|czVGXO?`!-1fzLKSIp>`7IM-UozSgn!eZ}bOs#B7&lHuXuQEEIoP{Vg6|2%d)Oqvw7WTY1E3Y(3)<&c5mNuoy0Go)kh7T2-|rE}Gkp zJW5MK__s+_;j*t(r8=y{c$vc>{ZeqkRSJa66`WZH)ex()4kqtk^KMdqfBhA3IjBrIQdCm56gegI;7$wRZ!ue$1)92Yt4nRZo2c!ivhCn+ zuc>0)0ct8|uGx=#~ zQCH#OOPkai=hHCf9RFNW%9CO?hH>@}7_b01qtf^JG6JOz&U-tZOC|E$24(0kjHF=HALYII=%F2HTN~cZmf_dD6QhSK4P2OM%&b?QkRjy;Q-j-66+u2+drC4;SLJC4a>w*oYD82fa=XEmXJ-Q#h{ zdw~=8WvCSN&}OwuWRUCb`?>0mlz!aHF9d+|fjQtWNU>!~0br)5D~viW_XX0iC{6F- zu0e<5<&`$fpy#c=252o4Gm!=snCJi(Up|L*^hgzdS;{v!X-Wg$%kbLqeOhLOB+A{L zPs4g7^ahNdAsM+*y0XCK#{$?L){DW`!&fH%@ddM@=V?^^S`T$7e{9XbZZr1hmw=?5 zZ&T(}U1}5;1yCLX23+hH1n{rVHc3NZd5m4^RAbHB3{5iGy^?R7+n-o6Hm9fLifGv~ z_-dWqTBY33%41?a);VjjnW`zi&W=P8;Uxsi;lZEenvLRwi5^ zQSPixi;_i46GphpKCwVvS;7j6Qx1CBe>`Mm-ALVS#j5?~ zx>^$>qse`OCvr-*Dg3cN?>10wY;Iv8Fhw3IT; zw6amj-JG9+2ar6!5ft?E6f7k5{Kgs2*RPk~4+Nc=U*48#PD!~`NXHn87)31bOu zx;7KW?>6URuIejp^^xL@^Q zf2?_u{N{dFTiWS|gU&}q-3dCO%{Tp2pWi@H9g^x1h9KHyZMdYKW4P{=c9xaUp@nNp zc%&*)y0hV{@02Pkg8CXl=B%7z5FygtfP``T3bA>DA77qhFSJT{8ZA#`^GB^ zMiwS2?F^tf>>4te+K$eahJ0HyO6VVZtoK&|fP?JOUU_|L}43vL1f7gsHZ#^cPB;<@)fKE3HgQA!(peil^) z*(SHdnw7a~1fC6v+S&FPflptTmHjl^ z!K0)C$AnuDO2H(}LigqwS7%-#2yF;ZRN_2R)!d$z*T-{Z625Q|KMndB&A`nTH=aq+ z)`vzYM!U|I1=wc^i#J0z8_p9K986uFZWs-Umz1S|+6HR-uk?_qGkRvheFqFU!;qxB z_*6zutp2HxV|iRF0$CI5GOSf*niUk4D7U?4X8r`w6qUr5U*ar4PL2A2^xUOvz#Pv> z)|tOYo~+Ah%`meaa^{13WE+lcCT;f*%A_6;O_0=0yT)zF?VU1l^p6Y2s6JT~N>V{@N>vAVob@>rF6vp1JMsc$@PdwAi>k`c6VDV`rKcq6N>^JdSsTWSzS|8?(FfhP1RTC1KmG~WK>^o-=SZqY`~>-Akr~mHe(Dv!)QXBE zNSC=Zz8o3YsN71vz|;|EfAiTLRq(%HLJy8h_U7!gim=oy^x46no2whs@5+NNB7Ru~ ztaSSSvDNF6B*CK+ffUtPjlkye`oM})g>Sd^78!zp8phqfo>)WC8Ml3Z+RS(*1^Esu zmNapgq?M322-y(igG^mF`K}!;->8+f3ZE_Swx(U_x|eN|8KuMSN(q65f>Gm<(00~2 z>fj5XUtp!SFP7Ng{uA(lPg$@=8iLC(wdbO(l#4KA(QE~Cn@`Ke=FJ^E1m?ZmLv;Qn z1^0x9qQSzzqp4r9l&dmeP{ub3h&rTMADP%gWEgJ+D3t2H?!kz;b;Elq!@??!K{B7} zgDk#B5DU798IFO&x+Cv#oh-XKPusa&CGf6pWOT=D{>)kP;pK8*A=R67N~ra~Un(%Mufl;H?s^a^>Ja*;7C1ORE}*G4 zeF+Ig(#HG7M;(UQ($|K}g<7@$pyy%)7)zxhDVR@+i*lDQD>MDLXp}pyXTxf@v`h){ z=`^4?tR)}5HNc_aU+TO?+zYS(5%Wkr$8Qh?n;u|tMEXUJ*HV*&(hC(O&K7mXG#uFq z%)B@4`G=)4`uxL7W(v^9Hs6=5IQx!QVYSG#LlfVG?QDDc}K zEtR+UoLe&~0A8u#)3mp|Mh#>ecy3Jb-F3_bzdUAvMox~E%Uet*HQymGw@5xZ$N{=s z2DTmMF-c6i$PrD_b9`>;TeUpq@fG@z;{;$?;&fkjmN8P^dD&BY*OvXnKktYyJ-zJ^ zx|&L_3zVAL3{gm-AC?h0V06+1SqZiHjHdSoNA0B6IGT|x=JxNmXLYu^*R}Wzbw7o& zIjfY4Eizni26l(`FGRTx9F6<+^110z$zs||x3_Gm2cWk~Y>~j=9q}SBb{XfkEwgw7 z`7z$#_w&PhmwcnegW;r6j=jsfT?GMLzOKP?2rN9xZTJ|nsc1FPI%UjU$9J8L&I+QQ zl9Su9R_9E)5~*I%DXBjc3a0)+nGh=3?j@=q*fcr#0^wlsY8W_-HZQoxL(CqmbPPhh znXGBJ%Ao^fVa1K+{3F%bfPy)z#tL54a(Xh*saC_@<~xi4M5g$=MUnc;T%k8IJ4|+{ zF7MGq@x;9aKUaG@Dp+&6NBZ%g&i)eR%!9j9G&`Ux%2n;bsI3$H`#uuo3B$s*xjh$X z#`e$nUDrKnyD|lGq06^5BAG?joxW-LYs1QA3aV)h@b!e~2`CEOQBRUWd)p5@tZ9Ru zi99*0JrLA)2Q~An5xb~8ERb8+`xx)>{sj+$_|aTznsX6y_^dV+kki-zU-k48T!z7; zo{u;TeWY9<bLPDia{4k(}PGiwJECvW2Lh>?yySyU(@^GXVwgt zO5E<xS(&d8kfG>Y<~B0-$V9fF##|Ii z#4Vq8heSWJuf5d+xX(k{lkMVzd?<*1dm)@k>iochsgvby~!`;aKEhKa=NTQTDKE|k?TF3ohqrXsCZoAdi z2kgJzS)1U!SMixD5g1n5GE``F7ZRE&HrwbsuuZO)4YrwxWP51{MLyU{9g@2^-pm;? zQifQ6){*AVSyfumYVNMM${yfS>t2l1`Z_@vf<)V6#ICfFu+f$!Qc~QTQDKlR@Hy8nqVd6ikS$3K83fD$iA)x_w z9C*o`WKG~?PR*HB#IqzAY>n>|3A8bWZX`ZLA2jDxNa-fdr;~4d4|q06Us>B+C=q7W zlvmdu589zuleIq_i+{_zs}f0d+`B!ITvH5oSUXsB1jZI3@WfX%o;&tN1X={_w5cC6 zzFRbaQVU*0?M!9Vy{jXb7ndboW|lOBCds=o(ui#NA&UtdcP$?h2SEZ}+Yp?jUC+JM z72{XjK(sfpZrHK}}w zm8|x`840<`_r1d+>;xX6;(Zt;rDlq(wFBhKDQJ#MR$d%B_iJ~gepXL~(joEze~$NH zVNorwl#(Zj2U~M45d~Xv`luUVa~mZlb-O~sRYD4J-7Fjrq=vY>I%!PRx3vPK$P#)n z9*j`*5C!*A=XvQ%8IkuqU2!S8x&sM4`Gyr*1h#Ze7Iq*qmn zZDn2!?V&H)vrSC+rHo}ol{y<{6UXXA*$I;L1Rcvdj31lkRPDX%D`P5`3?PjR5hn;v9Y2n8;5zVml92K7#esB>n7^hwR$&2`y6eZN7fJW)MANG#{@AmbN`%$>T_ z#Scv*t4+Ha6r^eFxkSP*sstMykI zkV0#0oR)>3Pd49I$I&ITJl9F( zxX4;4>gv952EG-ZSsBU;qOztCM|;x;>VVoe`*|A*9SMh1TCP+AKbC&ar6gfU8;x?; z(4p5BXZC~pmw^_V$6V#orp2ka6>Vu~8dXi6$pY@hP{wx{LhX>#p1Sm{4U7OzWk{&_ z=ya4V%Bvihm!2KnQLnTXbtO`vtR{ns-d4ZRe#k9JBtk%HG=~zGGRFCz=G&*e%1Ye5(hiH$1V=~iMB5VVwYiV^s9b-%&Oy%(XX+UfTDRB2haBwoHwNwto8R zGRj+xj!^JvmrFINOpv1-1K>2UlwCa9FcIHwIWWV}Rb;}9bH*>F!o^KaINmnOylx<# zIG(4LHf|w!|8svzaWt1tl6v`r#^-J}1O+N<(?dzs{vfN|a1`IMPg-5){@HYj5AdPv zkzqMZ)ynGjYYXLM8LJEJh1Ka!B5jZrMNO?=^1d0%zS8I1{oGoe7|NB1kSK$CtVqDt z^VfRU(eAm%zclHz?nu#mwYT@+AodhA&J&)*z3XsuOr978T1@X=vvMiL?YV_S?Ph6Z zN2D8Mn+1i{RZ0kTQT3Gb*i|0>rVpwZA^RM0YJ->wyvGQLXZ}5?v4^KLSb+vdi|YcK z$p#4~R=!I4h?Q4B?l1u04X1;Z2Q(>G-qAPb$?rgaRtR%b9pCP4<{j*kWpIxgL3c-1iE~{3f|!g!qBbGbiIsljZ{DNwxp0#gOr!YZj&W==q$cM>)-% zoKVCx&YgaycH7y^(ADaW{1M_>6-Wn4kp<`c44R*^FP~QE1s~HFNl%HNL0)fjv8{sU zqB>CL9h6^n`_0n3g6bK0vBwj%k&rI_gKF{~B3|gcI8?`2Qm{9q_P*IqVJ77#J6>zA zK|f?*fq@E)RnhOm_*9)#vwHC;_|6%R@ijzVFFPFGVKAO@w7k;RV1U$B*Nc2=GzCZy zadm3(Gt3h?iHt_eO~AW}c5M9=<`qD(fuai+BN;;Z#fBgKmUTN#cbmj7C`j}wE5#aY zPSwa?@`vL#=<-CZz(S1b%pbTXbctOGBfUvTUg#W)^PrWOu}Ri%x=6_63Z(-PfvqYc zqb_D*0(C4N>R4J^7tOu@iz`rcrwLIjgxY1ucRm%=IL^+C}_x!-uCvSt+2(bZ93v)=$gSW(QL8+`A2h{`vBC*7s@I*;DWt*PUz8PQKn$7tFRbhr0L z_XykCVD+VBIiZ(aHD*t7 z;mEpo!37Vv!j}5QJx%<5MXgWUP(WuN;O0ec9m3%Nc|x#IM7uLKA!MQQ^W$B57kis> z{AohD%V3O8!hL4F`;%z*mQrMQLF_W<=0{B#n-92 zc*X7IumWmUBC~WbLHwwHBZLC}zlm9J;a!q)>^#W6yWjeEYP;C;H`!Sxo(hCyf_&eZ z?U(#3?o%klEfy&ra)?d7btuk|LWnVZ6t*u?QD@F8wWl_i0=+$A zVhUB_Z6ryl4g4YuAypB**IB`D`-!d9Wl5ILmn$N*LD0k|&2N}Cf2;5${~R)CKcw}m6Sg3$%+JMD z|H1dx#k8giTbHMuiJzdYyNqiTcU$e#%;m1od6~W}kgT`ER+XtCV=QHc?LF;QUFPcT z0hxi^UW~5N%I66w#;~3Yh#xjwBp$~{&HthM=<$Da04!ytzq@@~t^3~f9+zEjxvW>Y zW5|S^WlwA?jVCWJf_TPQZ_9;Wo^=N1&|5F(t?wB4G&pKWtdahm<7H7A#RdF+K=SQTUd zaCu1@#zVvj@0UaV1OPmghBmt#5i6kv&DzT?b-gvw%TbRjQ%_-jJ>+yb;103gG;@HR zYtN-1#Ue>dXf`@xk=gdFR?h92$BPO-NitZLbk1By91~%(Hd2_3KYlU(Bz{1uc*sKR z@xaG8VcY#{a&u-J`3shH+ozS~{>W-}x~8FleH4UcJ^B7ujde>{P$VqK7@p($?6qy> zE@@_7Gi*7Qe0jhpuS3kUa zTzXKw%PX>2r5UcUV86z$-sFB}@g(~BGaG_br+oBjJ&BM9+YxTH-6E!0PqZ=kQyUC6 z7ZAU;zd-qk#2%A^yOxPRzm!-KiHeW^ao3&*a~!4EaoQ4dbAO#I(Lwtjb73*FSDe`3 zjYwQ#y}NKmVpHNT$=t8kacjnwJ@_!}@r2E3pHa2;3*@R!PKXG3?LKicfLBG0^3w2sDHy|UKgVRLE@2*`J8lIgMen4T zSD1h7kvT6I~#l?8K<2KeynW&+Sdol2W%Je+A&3poqz`xpK&s^`h*~YOhJ; zv6o%lr9ET5s$ zC5VLn9Y*apOr<0G;?**QRu4`BGpT$a2c^YZa40bJjgX-T|CRP2Fri%^dw}J^J%^WTJCk*i{w#En z1_(^UC*zo&-I$Rh@mn3%W9z9{pYw$~smFu!A${%}+f_i0R#>v7|)m;;p0thsPVeSlfj0Hag4Eu}S)`BKBHa_&^ zdxPVFL2`8YTAx&&lzppj6@Jw}%w1x`|3(v(D8Kl9--KT9CW&&B&1v5}Cv@`%Zf!G5 z+3XJk`@jpU4T4r{dxhBXztjMIh|!Us^OO7azp_7yR~)3Ib9C~oenK$#LocY;u$iZ4 zOyMF?uV!4%#uiuEQv*m;4NA>1gRaeIYHmHlUPkR|Ij*OX|3kb_^>UmyyO4tcUp7^3PFk6Dp|77j+OaxFT zDX5>(w0Wkg5WhV8=VIcUztl55%%Z)+3cOyM*0PnS9XJ8SVxL5RRlfwRs&Qa24<28z zSQefjjXp)RUY!Sj6W3tqS#h#m6z3a0^F861#lENFl=!1Pv8no5%uz0`&(K8G<YcyYJU%(ROkJSzWvw1A8o z_9vrSER*DT{-Y7ov2IE`sZJI&;&+af$m`X(wGmJLtjrX|_aH2?vGF87OZH&VnB*H# zn?iukuM*Qbk!)>?e=DP$IN35Vc_F(GcOUH!e`70qQAoiQFpa%^4>;~GZ&3;s{egW3 z$+egJ`E!JDBln_0!RvugjQ4dF-M{rv;f94#2a(H6i?O_W8mlwq%tj2>HeDn2w|mqC zz?+va;>Ax73)y7xKYm!c{J&*X-@YR7o;=sR+V_aikNlT-;crT;r_W76GKjPDv;U9l zez@!Ai)4iq|MUPSQOJCETGb7X9L&1SEIf)J-Q8;%zIfTv~rD_Gympj!hz zDaf)^$^F00$>hH&2=f5{ZJ9@F$bU&R{uW2dtN-d`{B7AZ52gQm&F@AU{$au4@Pz+f zE!P{H-?At3dMktdF?i#1dSeGZCFNL|oz%ZCky&A56AiXm8O){8r)>3^3+=B!wO|=f zH2!1%aNT&zb-K+k{=5tC_q$?a!9@pM0^0h-c|-cc>E;_!`#%f+&&_{b4S#Km zQ#wAq{yVD5{q4R+p|2B@4d~qmulAA(6kQgGcg>|G&yEsus>x-KC5huNg35P}z&gWC z-bmWN-S!Zu_TcyAmG$TrDX#1aJzgr-dnva*Q#H@Ie#Y0s{+}QvEc9ADSNKX11Y{)m z(cw(RoJqksa#iyGY)q}Qb)3EtDfVNNtp36Bn1}Vx&xNf!EyM7dP78?juabZ( z@PgvschRFjMbaDCbWH2FGQqj;Y2ZY1XLfJzov!1-(F&fgtE+O{{{gL^oh<_3R8IpK z_$!;4;mp~nKu;vYe@ANJUFKxWEf;tsPys*JV4hye`Q2) z`Kv(jmr`n2)I)H-WLPD$O0FA$kwD3QGGc`6j~?njP9LFTTW&UJC_YfT4iEq@1#(2u z0OZiFJ}@^1Y!qj4^H4fDA*Fz*7fP#h`bu>9r$7MFw#XZcwK*hMs5T6()$r+{f$EayN7!^3!s{BoK^nuK<(8}LeY^Qj@GvJR04}Ih_qecGO&HwP z5|-BniHSxJJ$22-jN6G$p;lTpZzpW4Y>|eAf^Ez61${mSl7Bv zKT>qOtBocN2@aN6epSSn;D`37?V*V>$lbhz&}dVn#@eSRP8$3JsAzSL!vSdk)n!pR z&ejljD>2A?^GAv|q8aFCNX3f!AvCj}vc7a%y^D=XGje590L-5LzB;8=T5Xw|hKK6O z85kZQz-$AtUQXkb<-E48hn+c7b%{P?{fAJI<)XWs@TY#~d;7Y_U*+KP>82WF{>w*- zS>tBx46oE&5zT@YJW4j4c?o0Fg-DA?1G-ztf4p`Rz`n;M zKpkWu_<^XiJ<3k?K7vr`?o@l>haCU()WJ8XES~HIgwhIF(In zJ^N}P-jdzN9n3;)3}s2iOTTJW94Ye7jGp9WOp}Kzl2$-WV`q z?Q2k~C&(vJiM1cNErnHt4lBc?Vh#z^eXa=ix5mSt zt69L7WY+9)(`?B-xCiV#8|PL&^l07gc*G*h%HbKDJs|qUY_6I3<~t%6;r%56c$DVz z&Hw>44zCFR+ry8XIBE%3zI!}Q_y;qRq(h#W zp-F33<*hBORIz`R!_{;O7l*lufy*7(SKmk6kAr%7qH^W#H0+NbczR10+5gV-MvqP% zzZlNTcCkGEjWnD2>euN_%vX%`G%jnFwZL?LpYn$X%^}R#<@Y01Di@*4E<+QCEiL^m zX#eAke%w@mR$|lf$I6F0Oea5O;VoBtNO99Hz`I>0bkY?039ROomZ!_imbBy)=;Wws z7i4DX%qHj2Lmd^*>gRMBNQTQpou1L(TLOM#w=0I!0}lt08X5sB?n-ukn6#Mwhk{2J zR!ZfOtBZ+$^5j6sqdUaSYHO;X%LhFyy{DWMG znd^4ztEx@KO$*WB@%z-Wj%xQk$E__z!4LoPP(x4j{8baWO1U5s-9YA_G@TL@FoCT! z4Z3=Fh~4=!#^EG)xHY>N76>l(g<45N@LgMm)f zUx4b@Yi?=;1({d&ddw_u-1ERlIp4k0OEr`(DmaOD*tScc1ndGiM7OhkR zZt^@vMkURAkknK~g0}(!>3`LjFVySOa=yxoFY5>t=$uuh?S8q8D)~4PZ9}(>l*js<9-%pm`W(N zBYLvFCU|_(TmJ_A%Ol|s3v(QPlGv~jvNTuatGA10X|QFc^>R|-T)maZpYAoR*SJ5j z)e7<*`PvZhGzQ1APRav;O%pA+hJVx7o7C(D&R(c3;Uk7P7Ab1C@6!p>dqRyHnUhb6h02 zU%U2a`wj_=o1ZVen(~eH>Q*K^iSrtv-r<{cUldFTa&n`~cwW9-`xm%;ql^3^FS0Bl z(Epqr;Q0xW9rNV)@oG=hd)>7sOB4kw^$%=R*wh|fhZvMlX`LVLrn7v!B0kcYKsuRC zti039%c|+H;*@mtTOk5EY>#FO0&jGNe&6RP7E(nR2bQzdiJrQ)hvh|qd#T9B7=7LYPNVR|=P(edR37`CxtR=JbmoR-)j zD>m_c)ws)$H8+BnE#N4$NQ#_OL4c(dLzAH}xYN--PmsdBE*VMmCP*cSH+O_MT8933 zT;||(TVnWTS++Z=G8c)_M{KdE;{7Jyt>Km>w*BirJWHU@VLHvN^8w4m7!o^|Jsx9g zC#+q2avNkVOJ9{4eNp!+4(fs9WAsKdKGZ8nH@tPtw2JV zDrKp#KGmddSodq=PSq~Kf+i9it*-=JyAxz%38OZzQ2*7UUT4>xRoH*pZ(Di2HyK{> z%r!fGyKA-Ia%XvYcyNHdO~K@{Il>1D`%Dbat%k9%` z9u`ptrJK`F(!AwQKBb-SJZBg?7S~HB=a3b@&;I$K1?7`4R~8#xiH5xVeHb4-D%q2TVg`j-_{6zfol@6pXErG>$)~P_*TL+k1{UxOsos@?!tUp*TUwTa z2;uIZSyIqL7H;`fG3{j6koH85Pnb894k;Gz-Gq7%(7Tn zx9|y)i{(L}5`1pOtGy}=JEIKZYVPi4=v%Gt8Kl&->5x6S7?!bEf0s;EmWR!u2asr3 zV`T=z#Nuui$Saa}edM5y(VPdQ<2Z^Y&MKGV*|-)D<067`az!_Kz-jKn;)}RkH0gHa z=p949VDzli=^lC)`9UID)c|CP0w2(FQmvuMP1SH#74G=m*m#b1leeEfDR12?1S)!9 zXZjt1XIDP+^wfcJvexjloX@(WW@JH+5uc51^(}-e=3DLkwZc+)a#)SO-u75+UK}KLK9bS94#4<0NXS{ zx*(a$Pc2nf{lzr9j;ah?@ew{@>Sf8GniI956_@Cq$RP*qesd=I%g&ZcpFo@(Pe=gx zBp~HLuF!m>%CSp?-jIFYjg;~e!UO3(D~{cmY&vP(KM)|HRpWXv2t1nx_WbF8#vbfy zy*=7c$@0x4JzLMl742BB;CI$bx6Acp%OKym-n@#}^f!P38!?XfifNu!w$BRLlO^7M zuyw|bAvDinaV65dnJ8&Q8cw0q{HY5!tU%*NK=E8252vwUZk`vHLIgk61#w-YH?(Y2 zlEH;3h;~!#UOkWM7s`Gzz5469EpR+Ig%(Y~nEPzo^bC`@^kVf^ ziaO)+z)akU8Box~Wl+qb!iT3;?=0oOVnJtKd3C1x26wPF&kqwefTnI(6jvabkbk||H6Quw*ZKhpNA_FU(>c#zTI${ehCU`;%M-$<%D|jOW8pW3Ue}R?s8k3MpN4I zl^Oe(87h3F_f@yRCbG*=G*(AhLt!$Zs^5voO2`*K5SVpp!b>I@&d&?zyQ~;zvXfw18Dy1HL6D)-Jq}(%Sesx}XZW<3vstHwwECr7jJZR{0W`$?&bT4B zDEyPefSw=J$N-GBdoado!~y4sb7&ABm=LOX5^-07R=Y3MYJ0De%dSV6h9teCgz!#* zi}G_4CP>lU#c}?6x6%=76m2vhP|x_$LcH9nT@V*F@nm1nT@Rj<=chod&$!0MM(P;} z^{$kx{I+LU#$lgjYkHw3Rb8S-G#I6f3DtPiovG_MUo5TB*0AILO_AcY`w=>zlF zMC3u`jj)mS0_(-d6(^-8RPtw+E&HgJKQILVRAX5 zllT|+zp2>8^h6E-^*R zKO#M7rl18?k3A?5;%Rc-OfZOVi*gkPa?Y5#ES$_b8-a1-WJmXR$*3pIOOiqNi<0HN z-MG)@OCs!s&B^+IlrW@porv;qUVclyJk@FyEfmCxM=_*$>AE7XkI5tKqJEO~gHggf z*wa_sCNky8Ao;0+fSDok{$jEOm#N({=b!>9&6&VWSyZKDQ7r?a}k*u1h~e|B$4-D(lyE6RTDJ-EaBwCW&@Vj^19(7$fN*u&9Q%G-tsXy*H?3~)$$6&J!Q)WHur0g_lv_i zAGrm#CbP+mfr(E=2B+(in@_wgqh!XLjJUHae(ZAEV}py6&HNhM;59~~JjH_oJm53y zvzmy@3q7*_v*KGRl#>Sq#OUgr6j{O)WB?(u{_>VqQE zC`Cl2DyV0|P2I~9^3b9bEz#mq%W!y|eMB98PbEApOX6SBaL0~U0tN?Lw}Tg&f7~Te z9y1nL&NN^2B5)IR<_?!ZOQMQT%m%`va8?SYiC z^hGa@X{dMUyAFkj75rbU7=N$wdolLxI{7`P^9<7zf3^@#j4IYHe%a)G;MO5M6u(H;ua$HwWf=M53A6~hwj=jo!dBZ>8|C56eYVBNO8IC*TrJ?3pGVrv_(|(w z_%Q9r$XwE6g_)oWhLjnR6Z>NJasK!&*kK zMn%c{_X-n;q%2rxo6hdX`@_V7X#uC4UH%KK5libAmkmh@)ycmn1GvN9cBh6Cko6a? z%jzjsCSUGsD|@bAD&KdyDJs)^%+fYo!L74u7u`ct7G--oP2Q`Gi9?1@?ZFXqFW;am zl9M)Kvna`o^L8)MCS!^t=iY7j?<4Yl_{?c72}z*gq{ZB>WG7Ld-sa}nT+w7#Bh$V8f6 zlyNZ}t?iU^jz&1!f@3Ie{h8=}Y9$x^Nc+@HUi5Cq8G*p=y$KeyM}ihOg-f9{%T%U5Ro37OxK?nabV6Rc6z1%^j;l^(;NikR{FN%tqX( z`g{4f{VsuO7Ed)juWqMa{Wy(QBGeaK#IK#r;Zwx5yCsDkA@Q{|g!_=h59Go9z2u;` z-Kl%7E34)$VVrN<%BJ{lSqr~FRGFH95=Xe z=V<2T!j6REP*RF$DkOaqD!^^8K@tI#3%#~JooPj???|G!qB%*J&_NIghe612GXXc){=9+o# z1P44dA+op+vmd6#UC;?+*-hWVRhyoA4`2J&Bs}>|#HHRRwvG4!0qfH{huvIUn)^~g zZ8zU01u%a=yW?J89AEsF9OHWXvzxP$Dg!462e0??%ity!J%#WmSG*TKp5JhPXT|Xj z6I0?60Jh!{RUsaY4*TTVCpha3Iro{OZ6+I7k000+3@EkFinEJz%t3x|2~5J3%}o@j zAPby!>6!*{Fdbj`>)sjpFutZ^aktJ6em(=2;I-@}in*7#6AHc?*R zX?(@BAas4Hv9z%qAkTPx=xeGb?E+c|yRfK^+UUoSEW+JLzqFrBi-(}DErI>oy2@@3 zHVy@QqoyB-$Y_`12Tx`_C#lvqv9G_CbzI3^;rjnsV$1|q5u`6Wm#azKD}B{|41rFJ zf9)_y7>G!(1=3&DFEx~@!TQ>8!MW!Qx^sdqxVbdz&bMQo^5o}f4ota2^8>BJ;C{QEFDz2wq)(lg##h8;abb_;f7rhl#O z&kgCc-}B;r&-w{4P+#K9^P-wLFm7IE+tyK?E{2?|&+G8bdch=Ul_1FG?CFq-1!=qd zP)l3Q)(-;yT33@HLhw0Z=uw;t8wieJLoyF=L7B>&kuS_uMfA^D`Y?@gnxoLdOHLdF`+gk zTG#Hf_Mt05n!(;OOQ;uJr_^S%*>gc&7}vzT0c0pp9AVYdrg2UHVI;g>k1`Z%nmW7FajCL!T8dB!GeK#)QqaW66HFiBsKU9Yu@g3TYO|bXZk=8KSRf!EPy}xQ zY1fs4<+HGe+Oc*Z_WD+Ik5DD1ap__=lWhSjNG{<-5w@2nrrgoFN-_TOV@4o=4ElTA zOF7J&pi7hxY#7y=aXvl-ZOG>uI(W||*C!(bfx<4Aj|Y7nz9-AoaSvd~;r9w1A%WOK z(=0!^cYR$ow@zP6og=R=68Pdm_(;*P=GnxG zqw&{FR!j|Sh>Y!ib9Beu=AS39FPbhAD_IGkC@F z-jhyXB(LlCR;KQXBCN%GuZO##)%?tF;_MzzxOFaW^DK91I&5v+9XIpZPe!3;*D&91 zyN@3Z353rC&}=dsP+I0_ypv(rXd!R4B>&;7dG*?OM{6tP#AckEXYiDFiDS`pZ6Kmo zcU$-#&t<-);qGVZ_BHNMYj#j@Bw8+sSAsIaX?33Q71s+)RJk~n7R&kkN6eYGgXg%8 zn8s7^73#d2$Zr+)#B9P1m;LQPS6i2xP*S}#=|JglJta6>DDF+Xon!a|N(wZ2E3rgb zIAMcajo8aU3d|8~K7@qKd+`^^{TOacne3>_*oOQls55a2?X2EL8p+@|Ej_7jI{16} z&Q2i+YBVP{cP%Yi`+nJkg(PY_Csr08W7zJzwNaqM=^hXQMGYZ8F$bBuJU7-a5!o38 z;#oqipjz@?=1RQx!L;ap!YoTHm?*t?OH^2ll~|BmytRz0?cF8I9vK3T&3e{JHYNc0 zOfm}g!zp9ft-&t{T}x&Y2JsOITU2O(*j%`7Z14MagZ-$m#1>AchkUf64>9~Ve-j1u zrm4g&FdUFX%lsOw2$joC^*<3dYhr;SYv8p%{^}^bH8EgwbI&TQBgZA|ptq3F=j8)c z@$rqtw@H8Xl!=t4w!l`T1NsF`=BWJNdVodj9p*y~VXZ9b_9p0x5}{}o3&4}%K5&tw z|JXtohW#5pd2Pjnk#2LX0!{cH=k*d^*5a@Ao#(>AJP#~(2qo&JM?;Ivh(*xkaW|Ex z*27{_8A|Rz>l4|Bs2D7&jZZ^+V|j2h3?$}T!!Nppg9l~>k}&SN2EVA8gJ_xe^%*-b z!_V%*1HY&l^KpGxxiorf59J-Z#i;jcANeLw9ldd#=dsutuunBW)wRi?j1!E=>1CxsY>cS1G<|uFH!5bpH7ik@ZE2vejIC-eHd>qQf}P$Vr?YbB zofD=S{(}MydxvjNEW=0U$mh5;&rJeL>5eLf*4qapHEDLiY>a{&`~`8_G{Mm0O2kO$ zg%w{=#eF~A%74Kfz52}T9Ocn6%|+iSQUP;&Zc;|hw6~eERLl^r7{yUUKD`C&g|SqN zv{kKRdYc>?jM7j4+H|h2V47(Ha_6E)RYgQ2%;|)gJ4H3ao8GM8(4B7C#@&x$AL&T8 zS}{JW>|o3IFw*B0Dpb^v_U-#T-WpR*!dO|ggm5!8*K6L!9=w_g<024Wg#mfzwYAxA zNF|kbrU8ApyJ2UjfrAvEg>TKDrr=Y?N(0Csa7O~|T8xaBVu$1eGb+)PN6fQVAU!ES z8w@GszXZZ&A0Mj6!xyJEpXO z=XbR(Qk#V)!4rbzF)-%7{6kt;DewyD*NZ$3Aw6{aX#d9*E(bNS@5dmXt*6_tw5^&$ zGT25j8fhv!XH?iZ}7`|3~$U4Ic_pO93d7vFx^K zb3f&sk^YPLoB5aUYTGlKsa<1-d+x&IInAqx5edR-!GfZwy%vOO;_;_to@jhPF;IW; z|FB1pUgl#-P}fQFBVq3+5>-ne@4jE3779a9Y+O;k ziJI9+|I<+VD%Af|ZSpf!RoA-HA<>@e1&l#pNZ6VsR`6VRA5kd$4#e|zDHORGbV6yI zbrK0oz=J>~$!WS#$8kaFMi%Uw^LyHFCIz6#P!>{-bmXjNWFLxLkNAQ|{X7rJCvMxd zXNhJcR=9|^fQ2jY%=>6f(E{%Uy1NT**=&M=mg@GL@8jJiW4R)oePiAOZ#l%>Ae}4^ zwGRVaNZ&OpL=WIC!m;ww{dS zWo5*fI(iG3yL7D$>W>4{vqso`JPU2=(=9B2tMcSY)OB3D&x#(13>f^Cs8%jMM6Fi> z>m$goAaGemzz)BQNp7LK-c9V(0pu6#Y8BeT)EzM1jE(=+lm(LVeAO>g6a|S_9Xm9W zzJb}sgq1NgW0IC65f!x+gfq@-F+5_bM1vbBLSRR%GblRiW5kWdt3}`*koQyg+XW)* z6n5Sy4z3RShr!brMrX20KsVSJ4sO8kW)1^q^UFG;0~5*WIQcs_+KFCMt^)9vZ$fBc z1d5Fh?FSMXr7NYZ^?a%I+oC5Es}GHUk!d$7{*K5;EFcjX)+E`2qq5Y%qe2v*9y5<| zy+7b3d_ci8f_+SZ2n33h!3i##D-CyM+pbvXuEAG??7vBWQ`~1G9{qOLvip_ys@v^} zaP7}^7{z|hUci~~aInpb8cInQm?b;=ZElnM%tk*A!SM9Zf_IsRAQTp3LmiI6>`&SB zW5ue>&?q%6&+pVCYY4Rf&zsbk;T%z@k(W&?8rb~uIV1HkRHMz`^MPi;`cQ+dTS*z( z+_4m974H7a8qlZk+v$Hvbs6LCju4$FZ%&Ua8tuCMwAQPrp~B+`89P!|$?&x4meyazd?D zs>aHj$Hpbg08UZS8J*}R$q>uwq1fj=+H4X1^b4{A4u|@Q$IqR`myG(@cCdelqJHp7*Ep?s>P}wYqkgg5xSBLEGK$n(qN?TK#x{htiyi zazsR)sw{|)(;$M#XhmPULr_1@wT*WTZ>`?BI$`hh0HIva?u2$v6Egaw8(0Ual}aE~ z@~k+j))wmQKBN-xjGP9`)pn*H#+`BLAX?TQUyu|a8BUPhR$g|h>eflrO!zq@)_B$Z z(oaYKi2=_5#?lG_-E$6HXV6cJeo6)zLL3~*_y^7cnLf>Xwcmc{#fmitzm`k!l;U7Z z_wU$f9KetD^`oP3!gvXt_+6)thpA~QKjb93Us=PC*@6V{}FSaTZ8^l)Pwo8Olnhl?jK-ipw8F$%D>7Pw3)#+$R z#!KG&T5lQxoS1q|Qkmymv*?$xmetMYAC$YuZmfn@mf~_+Aa#8`AFcO?s_NZ5?-w*K zew}}{0ln8R1zfdKt$e5JM0I?S~@C)kj_YHo{29(uzinIbbE zLQxr}zA`LXZ7>-7t3Ib|88_BC2mK%Z-y8HbgIZlWzB~OVKyYE+?Vhcvh85iQ=)7g{ zVf>~7!|jRK^cWc7Y~h#zFTykNBKW_ z?EaX%Du?=P+k@PcXCjTT@JQub;L~^D%(+_18a(?`^^7XDU?svo)sy3!4jdc92FY`^ zwl-#6TP_&@4-#}H|4C9o43V?e*0=l`t>RIi+hgH9_nq;qNuNdBB~_$8_uf?K@B;_K z@id(#)b}P^K?7^)tbQWSvU!Y-!SsQjBj(*kKdZ~ML`peWz}|~JOP5WzI#)q3+BCc1 zZT#BU=-ygmYz%Kvc0B97o-+UVwsfWwo(hv zit64B%I~@6_CxJKhlSKWl4KyEA+)T1H;&5)kP_0;s-UpXtce5%*w)^LD?Qza2X^q~ zMW3Jrasg@$=C=p_-JUyWFC0Ee|9`e#5Wb;A>rv6m0Wb!@R2p^@r9X}K>VJv=n_PWAs=CnuqDSx_ZR2#dGB^y$E zGQ3Os#_N;DS&MDo83HqQ5HTIU?-(8>f9j8-RJ&CR`Sm~uoR!z zL=GP^O8zS`dKjg}HNXBrURs{V;Up`Rk<^_qh{KW$|4F^CEo5Zn{gYHlF9|wAjiYwH zWAlm*;n6TQxZ+B83iBT7=8E`Sh9e10uO{9Bm9+&221{kQFJ0u|TVXdxiKHAPy63qa zTX)x%#4o)%j0Vx(1C&vQhxk|9RxoLl;n4Xc>wVXF`}8xKf5`9CI7;5ObPd@URXxGu z43-u;^r34h4bM7S7J*$7PW1(JdBUsu0gsMcyGm#1Fq=AuG{-C9g>|Br>C*F!3K$@W z6cVKVXz8uwF^m5znekAKGY_X@S$QJR#*k!O?}<>5LwIx`=`Q%~LGB+MN*4dob{6=b z_A*pQc-n#U>|r{WaFBe)wJ=$q09UL-iFkpdYm2=foRIzvKHYOM=f5>$NLZalNj3)M z`=40_F;PKn5*U2zlzAME&up`Fp0Q=))4v12F5Ds-RybuMZY z4P|5YYAw2{L$`NhEqXf{-_9l2fA+_Gpz+lzoa&=*5q+cH= z94l}|{rTnSja@6=R)$YFC6P%B+dNwa>ipg;K#3Y2d{$%hZN6Jb%PE&lp&f?`CQN<+q9qoUj+8ZmOQ>4Eui1;(WUiM!-y4sju?cPo0f6*|8~#CBFJN<18Jy$8pCv z4w5&=E+JXB{Jic@RzG)5Nd=Hv28Y#l5m~%2bO?BRNNfCw8+ZSoX%q4$%@z(|nDVBN zYd*2SPRO?gx)f`#JuUBHQ`A!}m&RZNjeo$ric^S;&CY zhOu7;?Na=v*l6rKRpfauDpyuCIhk_0@sOx7Un9?zy)0CWv)kc&)92PpeB?G~Tjn89 zL`>l?gCsoff6rBhssKrN&rhGM%kjX|tX_x;R+U77580M#XnPs*ioNZj|Mk(W|Is&~ zspO<7$0{t0O|xqs`J>f(7`=nArAlYwV`VGKyk&q>m9*R2qVN`Lxqr&$8+O$SzU0tG z?qniRD4~xSiUlyGOsS}^Gq+CJc(jtB-Jwk<3y!kx;Wqw1kTmm*>7pDr| zXneblv;jz8vUwhHfFyv`G}pWAU|X$8cAeNcKJ$4lg!pmT_Ad zm2q2@4_`~Z4!63Sld1djRp#WhW^EpbL=RTw<67DuA9RKuY8dmxgKtOq zTWq{Vj{<3XrQzst-eDmRRVXMZ-9>}YhC}uztR>82MHh1GhQIb6>(-nRls;Mqj2UxN z`bH?+>u)!bT$VmxD41-MWHagU=;xmI4BkVX&+pHH%*`S~QLplbFYLKZe%c=$c_1!wc!Ce+SIuE+MCMph4LsKiLqK{qjL+IK%8t4h!%}`|!1(=QsdC1b4Vt2zOZChBO(`vAG*?S_+=o)gViD6h3wIobOD! zJJK}+Bf@0rWDqg}uS;aye)e?kH9M0fuiB6$H?mz_7?s@y9>51r>HL)#TWh@GM!Zj0 z^m#d0GIDg4W@rz6;CA6_MP?hf+%b((e+dI&gdQFq3=f1!F`|5GzmwoY7JPhsp~rX2 zYt-@CK3XRF$gMPc)HN|XpM#7duKME}yXRk{7535ul*G2+D?bV6T-BMqqKnV4+PD3= zx7MyW;iN(5H-3PKiO<`Jf~p@N=_$Aj_>LpAy-aEvvRULv=UyYqvnCz)z5D2>KZWrm z1x@bo%McN!uQ~Skh&HVY1yKS68N(b6o*5q)R`vX@9c7M?z~;cN%ExDl3V$JmxAAyh zeKZXH*`r}*BJN6jh}<3{VLi~t<%%ARyqaadeg$g;b*~5oe|24BUD|~xLr|^OvC^{} zR+IV#@F-yQ%#5Y$llh4(&QG1AfR-wU=@`Cc)I6<)gzqFqKZui!P@Kv8$*bQB169he zHnBlg!@@-Mgd)|~GOISzR9Q=hiMM!L=RUJyn)R!Of)A+B@#-b+UxG!9`-umC;JE@L zm3T`MZM#0>^^AM?nxK~tEa*Gd4tBG7HJ@v|%*hIO_}VW_oZ*`koZ(atzx!r04wl{O z_4&Y4L$jtyt2~B3>wsd+<{ryn++R;!`rl*hzLO3`Y|@)3-CUkJb{@GfwywWqxN)60 zzwV5IaQ~&bpfk!fJ3U|Oy7&|6E+Zx6JsUs49*Xhk-e{rh6%q-WZxAP|&K{2WFH*hF z2I;KN+X%_4GG2g6`%7dZd(*?h8-?v^)`zcO++$wcJK76euU45KpQI5h4DR#otco*Z zY$YdXN4GCFNruTNs>z`BPSbM|Y2YSUni8ccEd{gEl{NO)GmoGit4;ZUUa8y+L;sLH zjx)CO>?*Q)Kh3fnS(&Ixn9fN=6yh%{{i#0L#(AX{xl*Q4`_5&Cx{O@Wv8 zaLOnuhapIxN>RHMWdAt7Taf9Xf@22dZ@5S(^S0v9b9H=vAF=$Ll6 zP@g|DRIdV@`WRH>P{wVs*Uv{yhUw9AS34e2K|w*1#FrK=hb#C<{CN~n>isQU7u}|V zIil?F2@A#OIX!Mg{PDgaRp^a@LpLsy1Y&6lk=JpG)Lg`|e6^7Lajo=ni9`hlo3U6* z250+uG3s_$g1MB;eds3+B}EW69qG3EzzZZA@;x#wQe4icp!~wEyUpe{_lfLZ?g!6X zH<#QmvrjuFP9?p(UVD1I_Ody+Ub^4-_%ju+fX}X&_a;Xhbo9NVv~=v_=3xsD8^%+1 zhSuHNcT!yzh&Qvb?RVsFQCKO{C4AZa*Xu+K1) z)3K$2Ms^m@RG>Ncwm7kBx%H~?BF7$~V_1F=e`5{>ZLb=#^~dGjL?P9B+DXt!-hX%U z-}|?W;V_znoTH+@S zhsSu8{Q3a~h|76or>zcIWyWvbELx zyZP{pwTnl&hlbO7O;q&>4q6CGVUEgqUorZtC+Q5EEv{fqL&M`bl|@xx@%@#RpYKwx zZ-Y2<%Sm`*tR>uu1mEp2D+H)lEZ(sDPE8RJzt+ID= zL@9mcBn~8}!R;BHIh=@T#l8j`Fx^4y9Ej`n4~qNo$AnhWH3y6DmZv*ShPpoCArwC* zH#Y7gG)+v#5Dj{q1>XAMY4>?J84;w#7G4#6gUG=oUWv!<=pk$<{)v)GX2lw8*aKIq z#vnp0fr72U`fuN25cii}ZIB2JVfbxx+c_-qVCH#Sq%=j>?e+IQ^Wp5pFCOY!i&A2G zX}0sPn zCIA)V4JE0; z?Q)c{P)(Mc>#)D&y}8#05k8G8rWWN!Gb#9aP!lQBmzx$){ZhYC$Y(;~Pwyz7dOwDA z3aH#4x)qR(i-saiPP*zXToahbQ**yNKm)-@(%3E0+*@dpToNv*Em2ygnXB2|J(KTp z2NW~ny$)(wc&&ZF)r8aRe!vSH-$#Pha0on?{=kNW=Aedu)6o70m~vy^u;Ayw^tQEA zuEUAm$2wg$1ZDj_W8Y=?5?P3V?8{pSKU|ao3oS&A}r7CN4g zKDyWoeV3)|FelWzhY(OfWWjJJFD})u1IpdnoS)vMz&7y_udCZcej}P;r8;8LR3K&l zNqMb*tpbl@=D3nOL^jVf$FyU0M;+m_J)yGBSzx3W`P z4QSp#i3?)Td`lTSbXotd+=x&jmo|_ldjVxQ(que zz?ibE!^#{(akY=Euls_a#V?x3(r-8_w94DDk}>B)tx_PuD~^j}hg^O?db{~jG6w6r zWmVw)(FXHP(`H7qI^fS%J7H2uBFW|}`Q)9Y0&g#(DzxQ4(zJC^P$RG~T6-yIJjbvv zFS9@DagE;E>Uh3vaUO{HSXPoTFUX^|>>>T`OMck7v1Ul z*9eS0?uhXQrC?ycSZI>KW++i5;E9Vclk&o`coSbHjnLtM7vdLc`a3g^V4i9YS4wMX ze1+BCbQiSLX{_|&G5rzX(hMlb|8gqebH3Hz4TTfa5K>kPg15}1MBS%)SEDGtq8_4=`S}`J0Er!GTn2n<{tYi{gskb5*jKdZ%E*$mapbM#-DB7L&=y?_*X&!6A(EQ zzCNUuq&T>R^i}8lLXUlp+uQz}J@Phq?x+bTec>%pzyDR)V?|ABX&(@_KR?L_BZo{a zEiGuXdfNy6L}T!}b-?H?_#_-S?#G#lb4l@KrtX#WLOxe!pN(`o3=Iu^pv1r&Q9xiJ z;w%H*V%h`p7+30j)Mdtks~5t9UlF0O-H5)s1;RFGbqYK`sKw=|Eu!#?>`v|NZ@!5a z&`-F8R0A%xEp`f-ox2TZZ>6!BANx-#x<})q;xSb2f8Ur;JT$)h-Kdera7)BXiW9Cr zyg^9A#T&5l)c@<=WKHwua(G4Spty7UzZ8b+JqxN$Jq(w#a$*_Zi^lUUE-6M^`ls*i zFzb5%!k5kGSX0iD--{RNqEXERm9fC-tTNAKqD^=^niwCU4ylJGbiX1pGV*px|( z207-#H1Nj=(i1&Y)5uaqlYdf}JdK>IZL0fxQd2*p4qp`Vort}+rN9aA-7t3t@EDu@ zU!`rA`zH#!!a^FK$glC40m-09yCpriCg?7Q#*XBfl^W$tgv_L^A|u%?QPRO;wZ2f zH(bWTy^auq+P+bKdj4}gvVHN3WBfIuM&aFR{$Cxo4h4KIcDJr0GjHUn4j(Jz(l_mk zU4t2C_Pb!dpzf8B7Th*+g`r$3vn65!DC|puRy&rq=LANHlkH&!X{to>Z;Fq=CnLmv z-gjVl_#Vgb?#11U{@v{Bf_{vVcnY4tX5HPL*)bu(ei!1u27C74gwbn#wOQ~;lb2r> z*z`pTtjRBU6q{*FD>DI({c%5r1oZ*K)4F9`0Y@1Q(k4<|ZsG2f8i`lUZ%pn>iF^Jk zlXcX?ErA4ie5K8n+-;I^BSex0Ga#iZ63Ne=Tx)KaUF`iCl;#F_%40nBk-xur8}&ws+KqpPAm>MeMJz5 z2umaH2D32Ur^-sd^F506${m&E>jcj`xda~!}FvxKLcA}CQPMySS=9^eRikYpHn!&LFr018Ob@cNO1s9 zrJxp=G#15tb_JESJWQ#TnEL@itPT2lFWTKI7s-u7}S0fq_oPyJN=mOMb)qpPh4*Pz%4^rYiW`{i)5N04ou)F(HUT zv1TT&kJsI$vH`tX%$&>dec63;UEQA=m3ErH68iIS$S*T%dT-yy--)&;3mp=KY3q1b zDF;O47ys+2u-|ry>R06m)V9avat?&T$?ebnwLp1?AX$Y=L{|BT^0sW*UqdPhe^5vC zC&CiuEyJrX`kWQ7^PredQRN&sG=Nh*sF>3<)G|E&CV!cCDtJKXMG% zMASOH`Rq?hQ=QFUWE!wLXK6V^8UvpHBBaOQy z6Vp`tZlIVL>Rx{+*XTN9)cNb2e@MT?&rX+-g`kRRgj?&$-|pgPl-5nv{&10QP|s3Z zFa7-8y_YFvPP3v{VCYltKms8tIS`fJatddQz1|4`Uj!P=4z06K%uMOg7V@@lt{IpL zKdg*n8Ct4vdH9`?nc-Cvm#136RlH>a_RegH`o}Lfn)*LhCNb$LpOt1_rEnXa?Ma88 zv6FMhtT&>ymiIk%W+b-q6Ifu1A@bP^ddJYG(k zJDRF8I`4?37%JuQ^ITWC@BUF@XP3xhRt@&+C+g9OJam{Nd^Q^!!5}gyWGyM|+XSE7 z7=sF=|LVuMiglcS>tS88B=PR83AJj#QlpE7X6`n5p4iSOVB|95_oU*kMpjow)^1>* z1HgS!ea?%JwEZ6sBn2x`q%VWqgg0L_wmg1bD^*#JDhMC*$S<@ zz9Zqj@e3rf7{2wrj|3;F^ll+}R&?2utA|@sV9B?!# z2zih!ukZ@Yy!n}@eN6@}SUYe{(58e=HrH8hM)8{ni?F%3#{R5^m-D<{VBl0KX#be( z35q4cKa!q$&k~K7Qh-H?X12a;sYaE;#K@%Tax}-tEBDZ8;nUE?7E!Ur!My&Z-Lj8g4bV~+SXQK^Y>s5{8^OwduZ)<|Tr)nhl`B+vc# zNl&?UsN2tQd(GweA_a7xC^G-wjkwhV*TQkMRK?6nNlT6DAM+*E7^$W^+5&ipod{h- zBYYi~(b4D;@TU>kBmNnLRHZc^K2;d$4lJo#*zp73%3>wR9dypiNd1@WV*uF;>YP~$ z;5wH-`E~cTfqEb-qDu=_ml3Awq z3g)q%D-;37IRAEkfh$4B*UtYnu*2Ussmrn#ZLzadA@KJxn^b={62gAVEhfzzW|J)PkAKl&S{Zf1#F%ivFW&kx}yZ5V%0ZuK1UtCpW$o>%P7&gOv4 z+)S6+m}fO6J1{T5rdc&Wi~-%YWM&8Hou(BCto!1-ZgVM-KOTvm1(TJHe+7_!LzK{#&cs$?rL!Z&d)CcAMyvi=$R1)nfiFf{Z5f9W31r=jPG?2ni|8bb&Aj#9_zM)4gqV zl^%m2sar7Cue*M)?tm2e87R5sS(@<@`1K`SXH0XRg|skpi;z+W?3Ey+sJW?|Ie;jw z?ECUQX?jyquH&kZC~w6|?vdhTezXY%#u@ZwNzia|_VSLUo4oV*0YvdL&paKmJF${C z{t63Uy~xFG@p6CGCu$SP?D|=w6P?i*3UgNZBd&sB*M7>QiL7`%hi>LxlbhuHByZLh z>+-(!sj}Sx*~p#A#Wu`dg^xQsE8fq}QK1&Uj$qK;1@XX6(+&juW+nG|s2y%q#pjUK zs6{DB2r5110l(^)524jUL*FR;Wb01x5iO;+?$u@JJN%tFevZ{x{QmdmdE2Z9{8-P5 znMZ*TebB!pu{HVhWNB<(R9)jkU=qFOcd5lrZO5bW>%-F8vzE0m!<#zxA7$2!EJgg) zv|8hi4^T#(^h-Qid-Ger!P+$K>Q=41IV8#a-aExRywFwMOs_X*UJ9?AT7C@X>2lVx zNSS*}hp+oXd#V+BK2sos?m|?+dYZ44RLtJOV(=X{L*^2P z@XBzv4sxl2+TLQ@fhyP(H*FB~+;i)8)jYH&lAc0yJqHxs#+?SBs)I+>Fvhnlt`c?T=RI^zLX^P zu^0f2x;?b0Ln88@zAx^y)pCIrNCx+?TKhBCNxqb%fCg_P31Z-3h0qaa1lL>$i?Xm( zcenS1P9^k+Dg=3drJSWr)U-eqe`P9a9dj_>>Hj+hH@!6mA3WFa_^8rl7uAkp$cQ&e z4T1`#$Rvi9?h8jq4DsiLJcI{j^nNaU=OI_*PEZ4B4iYB-x%}_#v zyW@@X#2Gz7O)iN?h2DXr-cv8Qr8B+V#y)`JGl~1VYF$~dUJgGOm%u4}48&o^UvCXW z-lbD~Yu$fHiG-C3gQt=~H*maZ7r(G*POjMzRj_LKrQ4?rr%8oydZJBA9^Hbnexx+X z^+L0TJ7--+B3ASbzOK{vho}`2#3!Edvx|_&g>#3mxFL0@&qokJR0QcbEAGVE( zQT!YgMde1-ECv9-JroWD#R{|Md4R~+I+TT4bRh1KD&Us}DVCcQ@hxOH3SWK9%wfJ1 z-1R06e)2)cu0o`xe;1hmMK9#&^n`Ir_^82LSqWSt`3GM*4iln!<)bd$PJ2WM9WlI- z(>XqE5os8R!3#GpSkfxsqd1X#XKCA-|9@W>agRU2=cfcnQu+#&YtrQ;jqC{e`hw?!zoucC?0zgvXcX-GHHIj|#|K5aS_xuC3IO76Tt7`*t6@k; zK}gDS(mKyLNjGGc6rJ(7DN^0%0SGzYAxRFkjB;|eHZqTca1RxD3&|5<9bLT{bY)T; zch=*lQ6;c04FF4i&p*W=H-h$m-bjS?jR?@*Xfm32Uc1E%CY=(m)o{YkkDu($?!rx; z4J@$(Q1REyZGuAUkbgS`+Z8Od^(dB$f&LhLTypjAGztlER4FnR{_UPKT+i)Bzt7#W z0N4bT;JtK%n&v-Vlo+2jIG^@?e`hA(iyz7?60M~$V|19@K~U{Y(PoeX1P}0 z%WheZ;h9@;fWx(0Gz>JVBo~31!85&zc{aUTwnyQc7}lH4Vp$4~O2_^$12Cw5i9qs) zPanPRTkrrw5ZqG3FxsmWcUpj>xcGf`^e+(C<4*IX&B%1_DMfldoy&tM`NMX9-%0|k*u4KabY+Zj@jix6wURZ|rq*+k zRdT1y6i|ysoDt)d;*O!Ct_WT#pjt3yR@ITxkF?Y4)kt3+BbyK3G$9 zpX0;qd_tEkjwk_wii+7=oYRi|6@%6f~#HvKW@4E zV)3NR*!^L#4LBnUMEjT81(OKYz8wyHHQnuXBnYZqo(>F$0*fe()5KxR?uw*OA8#l; z61~MBd}5f4{E=S4C)c)=jaYn*&zfhMTg5rme-K;8U(69N(!Oj~Cb$;i)I58xLh_U# z`3Hpwi=IQK|4%vp(M&D=A~g;!T~l$(FZ6=029>;6u^<0Oq}UiQF#EbHeuC-qXkN;H zq-%}BSBuZbn|jyiBwiH z7Ud_AA4PUO9gT)=LTX!v|Hq%0uZ-%H2a0ET8-2E|2gHUf9VFo8yRCLD+UwGWV@bEC zTQJ*0ku3l$mgv|5=y{V1Jk%J$@9{vC_ul1wcKLwaD;sa5R1%9Ht78zL&Dr*7w&E=C zOs#QcE>_@(Hv+6dM)njHNNN26VSV}+s8(kwFK=;^QR`wgdWJbEApLK%;B$#GG)HV( z{n>v=B8>YZEOiVbt}w_cA!@oHI_Z@*PEyn*9akt!WV|z+j3(;(NUC8UBccI>wLZpq z=2v@(8H}XW(+m6(DxH;9z9(*6*eihxktRe~IFn1Ja&p>YJmeZmm2=%5ezL%Ud60h& z#Ku+3Ef;J&>BN~aKzXZZh8DBFsh@Km~5#YUP}m-=1?QVo$d+? zXP)@^U)Rq-_pj2I9$Z@15Vu-B!f7zKRNTsjD1@&pO(|GLG1>O(Y+e%^}e{b>Y)fJ2U6;q`;lyi)zDOGyoMFps3HL>W-S$rFa3WLOxBD#@zVlG+}Ot>LnvUegN?H+HhE;#SoOrZ$;Us#aQlIh{ZaCDxODMfGYv90!!ZwYXcb?dc zem66%XG>RHh^%-${u8KbXom5F0y_NLI&F?2{ulkxH*vC$CTGV#lyr63X;&J%AF&%X zpuia}f};oRx~XL$*u4$(-|Az`hEe4}N$1kD5Jr--j$Qz1dGK z9HSGr^9~^uZq0WV-6r+x2_CqpH%-`J5_vCnE~sGQ4SB!KmeZVG_+}Ap2p%%suK=wQ z-uK(F_-ZvRs^Qk-iCpRVn3>mNU8)EH41 z-;%_V51f36(U70r(lx3GOp=!SCHf|nehzBM)uChf3C_wz>r*;@W%%O1ZflgH00j(z zMx?|bhwdr!V4MyR*0-<8DdtHyiOnO*0*$?c?_Buh!q@#Y9);om*uO^VMVSpg)w#>; z)1jQ`!CWGzm5syRv8>q+EvN9-)+Bev2+VpReF}>9hk_t|H}w?ThP!OLbZt%jCw1?4 zuObYDUlY^h0?6Y8wWwxu_2(bWV|fhEN-4e1f-!f-tBiIh#Leyl+kNVD!B$G&tDS|5 zhLG>VTO%)dOtZDnY&n6iG|>w|az1u#8pz+i?fQIap^hFN+=&~3$GBKn& zb&?`&v0iHLj_u342~r9c?P)+i;Xmne+DTPb%3oSwFU|4uxW8#=l9iy({2dgvx+y(= z&#&FwM!|zu+H!RrV3@m@+UXzK^>cY_f<;)fW=OyC`)uZ|cSU(<;BqS%EHt~mbeQ!_ zV!VG}nYVxwYlm2BJo^q7#~G~$Luh&?I5;RfRctXO`P z$WC8E0x-m5zWU+V@?-e|zx^8Vn4^?}0vXKbg7+%vQl5@3Jql}MguCw?$ySeMZ+*Qg zXX51m@Wud1<~bQ}|e=*E5=O7%_9kd;1HmiNVL!M#jl zaQ9Z~Xo=OkY1N5Mt{IC`kBukmr?^)qGk<4KHU1q;bSOX|)l8UT+H3!ksNsb?4I876 ze36LvX)EefxsybIeqO2GWn~9B3lPCIiBF$y_r}?`;M!kINC2>8s6Vpy>t5_fKcz$m zpA2@yQ;=y#;KaJdDJi{~$2=oM{iZiAA>TV}(OD%VJ7jg5Wb#LL@O~a-AexQ{w!E*O z*+`GH?I>*{`u#QnVop6b#5lmPojtLN?DC4F52L*%93+AgDL900yvB?y91&d`@@}x% zTg`|YDhu_)_!zyZ2(UdpYI<}&lBhx8(N5izwla$$CvBx2U5$pw0_+g3F2`_n`lWQX zv5>sXmHR~S$Z6N9=iJQ-Dqm7g_bKqG{hX1ezWe=vJDE8hQ?>@P4muE6i z4Haq^`~62z0a@Y7KzLinqZs~wADLPvJE1DsF-BnvU>(3%HJpwdNVv8cruDmcGW+3zJ@Et#wHiFSGB8<<8 zo6@?p?HkjXVcgJD@s2((a5lCMG#O+*s}A&z1bUbKASq}^9Me^8kC``PE2AKjBvM-U z$Ui=&P^^2Bz8^A&RkHEDh4k3({qZ)NrS9A~V2KI2{JCS zmrQ$>r3y%VDLKZ=0lX8_Z$PdfHPVj35h4lEfhQ;+Vt#MOu*bp3NDxCq`o-G+Q+#L8<~L*KhM*Vft9ZF&!Vnw( z5=)N`n7X5N4Q>cNn)^gfs@P6f-mfpi`Zzg})595IeO$;teZN0ps7}Z z#n_ObmoqX%4eSYOyDgXduIx8pJ{=hJlzajumq}i;5 z;YOvB+JM9jO?$<+>Watzi?mLn^zbOY5|^V@`VLbVKr1OZ zQ{0#X`;>zhaDtf*9gKCF`tru}bjEl!#vBDmpeOw#g1Z2})NB$9avRA=>Z6BZ$EPi? zNCqR}jBLIx@jo>(l=IQu#-j4UewwBg^EUyB)9fClfDDo2hhhCk6u~v&Vbk&7Bb#2q zibTN8*3qILqnZ^wG+NoeHPDA!BaV`UfBt%-j<7?sPx;dS0hE*yIG;b7E*C$#8eo}o zMrC@2!D3K`AKv5N{5&H8>gLTF`3ECBhWGTsF7nHWkv@i}%u|%z?T#0h4BL6&&x&JT z$peh{Iu0p{jCjDL`I74Ek|Y27Uhx>E95N9+$I)5dw3Zif!K0wY+&}x4r9rsKAT{}X zgest~#X+0-phh=AdzP6^+(kfL_7Dso&sB}G6h}}H3Cx*@$y|D3m38Z}Q3rr?9iFGY zjnf|@qes82c1iO*<$|j9L#`*v#)fPgq*=dgZEGsLoQSDkh^2y7>87g3Y8A@5Cw&*d z`%?lTzB@-#9S+qd|A7cYm=Xbw#vPo1Ri$OzVHJM+MCxuh3%QlvOnps7vAa!hU(@b} zL8b=oZVM*(h_Z8okdKB7uPqWFLeD9o!cQ9?lN~yC^TV}Y#GA>f=hkxIw&wFpS!7=3 zAji_CR}q{^vm4xyiYu9hL4=4L{LMZstLAQ(wS=!+PmKM3e3o-N)b=Xt{RTNtmP#fO zvi$8zCJOvckE*o581DU6tGh2&^qiMBlI9t`1589P+_Myi-@|1N58o6g7BLm7AM}z6 z5%)OP8?J6^aKTwAC>sUksP|7ZCf^iy?@CDqORXJ}bp5jufh+%YP1|dJHJmxE8o5nK zL^X9Uld^xJ+u=#M$Vt+SF@(QPE~o>4*K*B{D2f1ph1~2gqVSxS|K(u|JT#Q4_q-Kh z2Un?vpp#BgEw|G%R6^71WDOT-(SfGKIWQ=T(?}au1yf5_A|}W7WkG0?^zGcKzBFm> zEj^(v(cmMwM^!DiHypexX4X*YdNaFm+WeW{srWwX=8&v(N<1;l+{asFnhzYu`qKK| zBT8WbF9y`v;l%LFi>m(D8vw?l+5UA#KbUruIQdMnqUs-JfqFNfC9b$P9Fz zaU6{}HxR-JUipL1=IZEDlH7h*w^6qrU`0tM`3Eq)mEc?-{Rfw4>!bqWh=Zdi=KxcR zvvJ5XXLmu7#6B*L?~mEYKB?3zEl==ks*I0HK~D*Rqm%u&&Ae#fFbCcR=FK?2kK1c%m_LI5T=fkp7Wy`lV5SK2mB^d!2Bf)bzC>seBR zfR^Hy+g{BQ#sz((A=8O+s)|Zn!Q7kvQq9;bK68EC%-|&kIwMDhg>0OdZbffMQI~q_1Kil8nEr{G z3tZn)*tXmb;1qw0nDlD=2RO_1mxGc)3Qv|xIPBAC*L;v~VLRfl#*m#oo)ub-?`a^6@S)yOnWf)ujmT;EX1B(piP7O)drK{QZa# zfa70aW91{44hL$jXYeLU?C1l>DM_N!PJKPeC!IGR@mi?&)-WXgb&bU7+sNUbchI%_ zR+Jom!>OaGx`D$k7X0DLudz#!0#;pT88uhfiGJUbLDjbz6l}tAyY)WlvVGCs&&r!w z;j1ICUb^!|>=c6!Z%#L4_&%W0ih95Xl(aWz+XyoCcm*DcK0FG2l=yGE31w|CEuH1P znXUMR4}AhNUxSyD;40NLhg``RXj zWDO^RH54MNek{<~)ligoGxuoLM#LnX--alK?t-nNhxUw@8G0?57si`OnJT)q@tq!F zc$Nd@0-}Hvd|7d#)?&(gS$pC~4AsJTg*+^PEBFr({@3ZtD0Nv`nj;b^(*FnMkD+qi zs3wK0qrf9fC*68Znzok;czR=FIR*dQR`L%v>k-=KcZ#O(+-xWu6%PLIk-6uHaQ$z2 zH^khn+kZHMfB#rO&#H03SD894PUe+O0)O>neRe?mC^Y*2)c5U-utd9N=llW5Z-)4< zSbV*ZAzW6D11v2Nu5$j3S-EFus1*ZdXEOCw{({0n`2YR0rcE1^FMi5Tlg`cS#&>xD z^h)=a&GCOm#0w7vlm05*Q~xiozIQ=Yqw)Vb*Z%(cfMKN}xs3{EN`K1jvDM!9pDBgA z#M{JR4F+=9s!}Fda{g?`0aM8yMBdPw$>Xxc`%}yQhK%wH0{Jc+LkQC$j`Nv6n?v|G z%RRlD;58%iBII;q(#5^>Je;B=;?=kI`v}6tEOJ(s+a>W+)dBVOjaLsRv&hN66iN9f zD?A+!vOe~cM0p&aXL6?uli&qU`9Dp0SFa)@+*Zz3Z~6|^boq7^ z3!>{Bf0;Ij=(FzMbUgSh(k{v56Li+B)6x3nAp%tDd-z$qX<~6Pn}xx{IMQV_#M!wd)vtUVrQRs|+^wrRX^Wx92iHo69=?l4kr3jjp=iCQmJV#u~Sk zo>Pk3imD`&{DHX%#)UiEVoB?(GlDD@gsa+vC4;txV_KXB*F4+-=J)gp3-1b)de_ye z71b`xik?|7TWH(*ga+4ZI^227(tSMSvEp6}E80onRBzo{o&%cFUdu9AekebTCdA0G zYI-peEoWmdHg@3tliIFrfTZowIKTQ|r{>$&VYJYmT`?xP;ug_oGWHRW66xb_I8;zA zDA*7LIbc<*17!%KnPC5^#@R&uUrfOl^O`5bDuk9Ay*`_@8$f_L-# z8n@MY|C}`Giom`bJ($DsW1qG?`(}v}nHeJakGgpoJ#wifR`u70u63KYp`dr(e9*O0 zxRYM})L-xXm4Pbz5}46>l|4|}al7T4?~u*Epu->g2X%a%Rvy;}p5Hi{bfd>hqZx9T z-4k0_45uEWtJW*6HMGo9kr=IuZgFj(-#E4{uPjPWo0&!UFG^nqKc?P4B64 zEmLrxWSICeE*a>5ohA!i{O?D`5ktimHE9?i+P3eRJpBBkLI{pK$ZM+_ z4~2NYHlv>w0m+Hw+Pi7&=&c{Vfl&QUT6t&6E{;KQ#FB@HI@;V9`cb)-OwADC zMsbyoe>}? z#-0n3Z>_x~7&|L7iXHA{z@${{u9_ECeudumis6UVopjBGd|)6Vc^fSQcl25rQEzlP z{;fn*y;=UIS)y11h276u;#(a{hKw)3Bn*|usF=N%B$q*&?ri`8;Pkz|j3P;D)Gy_Sqbz~uV|GUx8Lxkjuj11dEj3tWxaJ^?U zNZA$Lv|6?*`qYIOvKW7UZT3%kJjvgn#$O9uY`J;V6l}5k68Ctql7;kU8uyE51jDlvs@ckN)75(IX-WHO`*W(P z6oXdPPd$X0pV@UG&$`keHSbmMXP@~6`g(kT#JQ~)ll(fHZ7bc{@u?ZkSg&!5kE`iT zU{S6Sx=a&gZbr-Vuk{09{OwVJdN#;Ok-D)`KhwzH8me&BoEb4b0k_f@4MK2?IW5aM ziy~&)2eY9*cBL${E&-^^fU+)fwltIgFA#}%uV4zKW)G>M!Z#v$rqd`W2)}16 zZXj<;IGgBD-NfODabYo*a=C96bSsR+j2s;-K79KUItX?Q9CVn6wsDjRLeHHk-kBsh zx1}Pfpub~Sldmx<9a}zC*aI-3%eaH<6E&fAs8btfD*@x@Rz&C?`djTB2|V7iTuMq| z?3DlEQLkAt(Vsqy(IMOZkzUPsMs=!mC7UB3v?bc1 z7Y}#Kf#jd8(foRXU$7lUf8$MI?cRF!ScP*|;n!2HiG3+vn(7L^JAXNc$e3Qcx9VNg zw=79~qpOb|NkmQM_hl4Belh#?iLouDWhfg|VZx zEPZQ$_CgDgCCj+m4|9k>&Cxhnubgsusya*%KWU*SmlB85<+3Jye>0Y`r;Y?EcfklG z)r))i$P6mud&l`SZis^`!8Q9uj#q5N%5R8TgEPgnDp;b|A@%;_nd^I@2Q0R35RL9Ru*yFGuZaNYGz}9VXNzYS5z2YnDeb z;JmcgLpXP5qpS5VFSdHhoPc8nSU;;YKpYOh+giDhx8d7{&g&PSu;j z1l@c`%(WX^tS_|kGf2uN?`_qu>Hz}3A`mgSXsJ$+Rwda6xuv8hs}RMqwgCAgPuy;a z8OblpgE^v?KX@6#|21m_y|}75XFyjX=)s-J`V$WOULgGX^8WP~)1@VF+!2QZmGb&~ z;lmbhztEvGza{|OAPXc}fatc}weD0eo(E?e8t9RZ3v*+MVw|DL*dK&<`d*M;@x~uaLJY4k#Uw3T%=^JX6)D`kuGP{ zRXR__7{O|dk2mI7Nd~m{Qudq5&EhDl)S6NM(XT$zipSw}(ADaRpr|@s;MD$sIYP8m z&iW>aS-Wr4h~F12`f^;6rq}5Gi6}@b5xZU%G(KdBa(x$i1v^lWge<|XHU4(yG8GZQ*L3S*X?rPgm9p>yNmlx4-`2D=aj9b3svn1Sf^Wts$TjZN#S z&F^oT6&5r`N)L%t1*E$+z12#`vt`3^D9B&;xc5dLfE}EF-2L|XeLGH%FAWA}iK ztEzYRhFjp9qiM_I)Zt=C4|b`Zt|sYmtSg4zkbx5i)4&I0iCOIE;8$D?IW3|*QcDpKZ+XYZK~8HpR1uKPVv=6T zfo^K_-x3x5yKq$nuIY4-iON>*x#$YTKr7yz!-eBGib>)Qu=e+9KVl%Q0bb%U@kU+=j~n1 zZ~emva;dPNCx!TFjwEu~VfHuKYfk$JkCeVh zTF33TF12~~s1aztDaCvqlfhP(c^JzLY|?g7kEqvP+~Ac5a7NS!B~{W6g|oa|@%elFwl?l%P>AedTowq@65~$=?3IfPeq`lA!rc)oXF!&XkMI(UllrjIg*hL`sK`z(=4I z;01ZV+iNTOf;*N6&6DxkzfvDTQ;(p!w91;T*|Nt5>$i(9t0D;2cw*;K36yR%~M znZ#{{JYWY9+9o`7_wk~jC2)oiCM_)B-_4k*-}y4QuvEC8Mi136eXh^^pG=$U+b>vE z?pZ}hiSWk){-W<^`jdxuOby^~NO}Wbrq9gK^9k(7+0YC1wi(|uS@%)o)QEwdlqL-g zyHqA!8}a%Zgl0|dxzO|3cdVuV=ncQo(lECrh~U>INfv2MMV~{h`o&V48t3yHz6)z( zh&j!_N#Oq-kjn$&Y?K+9q_o^mtb=}IG34j$X(lX0xpD)Fh zD0Wn!u}!@Iz+v)k+A9jzO<<`}fsq5SyeRzk1204GjZO88)eW-qER{qYp!Rs*BuO>} zd&``I!w=KG`({OvLn}RN7OpCUvAWt|>zz)r61;zTKJbA_QOk6)pP{!!9m9w^O@^FP zR!?@laX3T13Pn`lRfT*N^!z@MgvaEQO}`loP-9ZN;+^@z>dr+o7vP;T0pX1oW~WTkN2_PsT7MW+J_ObK)^pPv~hn<#nr zW3(u^B9-Iylxx~F482!Pd5X$rqWN}M^7WSBs(!TXvD0#c;5_*_a!G13T`L&poQHO( z3n&3l(~KHY_R}@Ir!G8#!}c`k2AQS8lbWi$hiN2v?@i*#S_z6bb!aDL2dW9@BS5P( zJ!tf(igT8`_!Pwg-%Wl{et0H{q9gs+A{=PMC20e2E{dGAm!QZ2+#5fi_$WK7yr`R$ z4_Oc-1hdu?5@)(^%z6fbAI19J{}G@zAE%US9I!NNI7g+93y!k3Wk5 z`$#F*{d{x*`(29v0IJED%#YUqH`a>ZsMiULy&QiDsAunn8xXXsEdegd3Zl)XPFWW0*7!jsaatV{f72ecyMHvAan%LO)Vi9F z58O1hj;Q7YVbjozfCN^bdn3<|B1J4+cGQr^Z`^jA*GI3&s*lK>9Q61cwIHr74YR~_ zj2&zvXWWi@c2^JpyI$+K(;tY$hMD*pZ1qRebxfu^=%y5>A1yWzUPo^B2sUpDjWz?;sh}`oWR$-E$em%IXduGw!AOsVL*dvZwZ1=pR z-Q3hi_;Edm&D9wQ`!R-(VyJ7Iq97gWK0rZVmcqJb2IdtZKZr)0A;$ zXV9}qQa_>9mxKw?Bf=Kp9q8{5RYAMV-wFpR=<9SjGhH*+hz4xh3xv zBwQvw-i>vDpk#x9>67HJxpv>&67{T>_n&=9w)gV()>kLzUF1 zomL3xYyXoHEy*q7y-qFifJ@qPB)ns~ZN^zjO>Aj+g+`Qm{lILB{O*jaw>5V7UG8)g z#K|!E{P3P9Go?zW+nlruB;-Mjk_r3kF#I+4hT5%B`pi z8>V44nUh7#{$QR(ExS=W&pZ+Yw`j!WTjU_Zr+2DCb04rU@yw%~uX!AOf%2O3u&diR zcV0sMg2c#lH6uc2x*ZRpce*QdAjRnw(pX%$3zW3& zlGX*y^pJSt>%-?N%>X$r5S|Q~Z{zz&?b8TbrF;dHl$V)5od;^w>%jY7J3X{XM1QpCP72sc)bL+Zex9UxQp4|Cm#^Y#tzI6V5zG^Y zl!V<}3Nqxx!bcuS@oClSgxl)sf2g7y7mKsC*Orr@RLAyM=a9<@p8Vhiu`~h=3Hc+_ zpUxvDeKGjmI~P_-ub#c!jD6<#QP(kuM@X9Y;PGj$$V*2?^)a1|H?&n@bGhq**B{C> z0r(&4-^I;(w06i+c(x7pzU1CN}^N-6aYE$a2@=lL-;o zZ+bbC6c$yy!W`!t$(lzq=eMs8Rc!`7Sea>drLZi$)wpY767Q(yDD~)(7jn9(*jKHw z$9|9%RQ4Beu}fg}-hx7T-HlU<^pRX4fLTfXUj6Yb8>!Rr?!4wj?(pXh$pCxS{qPUs z-_z}uhJV)HxP+{KFaB%^ zST6yJfadXMfSnkci0@7DYd@~t-+I+7b~bA0u>2)px8TRoDU^qB=}m5!9(`KjJDHZ_ zo2gyL{p*NbS5kFCry0v_g`ZwS?^4u!j&M5MN>2T@4~~3C@Ner1 z^ztX3o~RrNo-C1)f2TJ7ba=Ejeh{9##6n01q!~&6mrZLrY&sG7_k}{K^zWB;VL$Uu zT*++lm3?pp+GO|M9gj3Y(-HK6+1}V1K%#9>BnXu%59Okl~e)(N2pG6r1t`e7|@VswSOqxU=Op>_?9 zQkt{e0|XLeA)6Pd{-nj@l>r5huDcV(I)zPamWqh;X`v1Tc2v|`RY1z!Wm-$o$$hG+ zh^0B?aQ_z~n_2XI-nwm1?c-4*T6p{-$%nT*lJY*!x;(+pE8^WJI^leD59%{;ujlj=Fw2DD&zb35vexu@a zPa<~;@e3AlESZ1d%leqi0S|BV>F6i4hYz?NajiYMjTFAl9=h|qOEq*wP|?wZjqKEA zSfpA0H^XQQwn>Cxto+#${`Y9RHst9KW}6s1GWhyL5DRn2aZmjWWBQ1+qLEcM&^2;E zhAS-@iP%<;7iO7d9}b;0dx9{cq%^n%BL&qYnss%1+wJLK?`@LOr$-$_2Q0O{UVfZ%9Aru?m;Hm(^7%7)h&kcyP&tE zH=W$E(eG-`Uq4sAGL2dFGRm@5H3E#>!s|{LaigG)X7Nnib-VGZ`>awv$;Gh!F4nA+ z=$Kc0I}ZfZ_4fTK@|PfuO9nzHU!Tu>a;U}|tJRL?M0k|OcsP3|JsTVb_ss~GSEJZJ z7W5DQB%Cl@EShQ0o<7sopV>8cQOx^*t$XttcfJ8)G=mhd>)Zc0qLi*pVve5Ce6_yz z;tlQcyJ~3Oa=2OE!dI#}!ZC*jwjMejrsjkL7iVtKh;T2%z#gffoYz{I3<9~oq%rhL z!@OzQtv6VtecZh^9%rn~&B=mIF2*w^`zIj<(H?6&nF^Vo9~nxloo0+-$mwwbVEFI0 z?`;8N5yqmh&{Q1O;bt)6eD&4qX(>e3MFneywyzZEXn z-wU?YB1IS6jub0-xxM&wb|V^ck|S8bl2EeE(B>Ugx}lrJX2RYsf-0)F^A=%Cz>@u3 z=$0iA!nr=-d)Pb94aZ&k9L#XNx9r#C%o}+3JSR+V%GLlyV89mOVzBIUP`7np-@Lgl zRv2HNdK@9#BBtTktQssXXXGfo&fbfOV%U&ho}TvEs&je+7~res$F-77%&W(Py#AnT zA}n8(wS2*Qsz5d5*mW$F3}7g|Y2@m>`dCM1C#RsYtf)`k{=&ASJZo8|y1irb+y-Np{dm zkK!)Zs)A#WmhO<1S`?ES5gT*Xk0=O(JM27?;s)t}d6HMIS^{b_##q^DWw{BGUWc$_ z&d?P`iP|$HXU}k#0wmQs)t*eT-bdAx`9Q1pF!@t6@B`WJW_+1og3l0h#z&cVgBdz* zCHXA}r0jh$Oy4E2N*R+4BSD0rD~UFdgapmn46dZ@| zZH4CDNvZW?AlPr(o=>Z0QBJUnm3kz#aC@cJ- znF{zron{n7SjF3f3ofU#TnGYb;h0iG8j#eB4dT#~&62ItqKDFTM~ zE%W0qJXi_`0uQ{FerWcZO5WcX`OJO5aVy1H=>a0wo`&HjLtE7pf~{tr>e2x`UZl(T zY23|xmx)Cx=y=HyCB1u$U2Xin+E@y3TFJe|=IFoCj*S+cB&zyS+o8Jh`n+gm=tm@k zhzyo~{c`qCp>9gdYjFpxV2Tu%348FGg2foVRf(%XNAzU`l(Q$6Fo-DFMt4Gl+@5~{ zgB#@EN)Yq7GL2#COsq^zpo^}ynHI{XLdJ2)W4nz24}Xk2$*zczbzHXsNV(DNCGoe{ zuX}LbA+#FQ#Jre32+ta<)AN6rs@_~1Y66FVtrfD$`H+2?64TTe*X`FsoL(vP+?ErL zNt{!Ohu&UZnSyp}ChqG@A3h!ZYF$G)c-^~rZ=!TieVH1%>drhXap0knfrc}~aW}$K z17G>XMchAg)zMt`1Re1^KPy@ChTm2z>6!||80;AQ{3*hI&n^u+pA>!QC@YX^mj6n) z_wK?NQ<*sQ@Yu6Sv8fyUDI5pcyQiv{VRsvIC#O^5A?BTfr@%qzc~*@=I~=A4Y+aIm z9k;7qbR)8M(Eb_R`I%@nf?Zd}D(Q`E@8KJxX7|vH)emC0xbzfc zA(l_c;G_#~Z3N3}L)0aga^YAHdFoTo`@q}i0kH#bYuYEW}_t<3)(ikt)^PQq;2U)mZ2B88JJz$Vi3<#58?@oYh?BJDi5W35;c;@a zaiL-PemCH_3pP+^qQ#0#}TQv6|2^I6ES|YiyHI zLG(B%2Ly;u@W^$JJ$?xmJcd?p`HxcmCKG6XS03*iGeR=29=p&3+bhuIT;;3Fi@9@W zal@$8-=Z%@l+379YCOmqQ@~LZOwfD9E1X=7y_Id&xzstG9_1#V~ zIw>9W0+^TgQ#O~XeYz{gc+DuMmDsu88=@OwevN=@A6YnL|6R4f#)7}AN`p|ehpV#t zG-awb+Ah21^4Z*B;53??&k*Caksqb4J=^KxvH`K&T$8Do;ORx}+6jHpw05yC zrWRxQga%Zq&;&yb5wZXM_FbqdGcK`ejL-z0Ef?rq@G}Q7wF(f)=MA;Pv&xEG3Npq? zgP89Fpi}70zG{L&At?>TC z6D&X3Fb0k`KKpoIxrQzoD2(v5o3HEdPIAj#!nkY z+~V!&_rWDV1-}>?TE-4Yzn*V6r%~+39)B$$E}vj5Cz3DUh*}#A$#~PsJ*_bPK|kFN zm;dGTnoZYBh#Xaw!hYv#?oOT%qTW}q(ph{1V}SIqEkJS&l6{YNOSy`1XUW#;_Oh3n zrK@?sHP2%ZxfD&u(*4(dA=bef1RPWy3RiT{GZVj%70t|%&zj}mlMNzoA?|DMl_>hC z_j!TymzLYR_}82cMhx!zwQusnk2_!PJ3gAI_6uF1%po{2 z`{xwDFj@!j&OOFD-+tV@v)*%?iI?KTkyj~xngH7=V$WyE*2es7msoLVr3qAtO9;rU z_e9#S4}vBs5yqlm3X$1~15$?Ss!s@$=eqaJ=bY+7{aaBKjwHqj2Or%846X=Ik7vA8 z{8`3sQZq0_g%kV%pCOE)>tz=gYy|Np1Rme!-DYje7iBdhnhN@^)TQEUcetG@Z?mh+ za#~N1`pYq6huA2DAOpg0?>~82@w~^XPWz)P=|uq;j79X`UL~((RJryrO265iP>p#w z8VCM}V*LkteN;d~Q>hCyz11@DtEeCcuO|;Reaf$Rm%zaMG0r9rzZn=gk*zzGf8M!VT(;5ZYEsht=cI$}l0A9z`y8npQ<-L&n2(4)L;Z#HIfqLvwN1FM*5+Vl_K*)q#f=gdw?%e%{;@>+v327GAr#Q zX>YTx`uV~n&4#XOD?iG!ieF=u)MszEK2UpYWY}+m8YfCd^jmAM!*x;A!JHPm&%r=w zW3S0l?7Oxw|M1IH7gnnoWO_v{5@~B0ioEh>z};PJ(XHaVpML3urV64JwdpkaIbeP? zuQ&d*=?P!KLpo@fijDmXkych?lAG=ADXcF*=9pTC>GO16?zGre6BuAs<$Z{ zNhr~~Xom%xFY%qbAC%7vEz^|P9$EG+IG$$-U4z74fs#G^?)m6g%T18e*wFB5boPa- zbaetc^v_!;CIh=JeEK#J~MEzrw+I`=!%(Uc3=VDB+(*!ArQiyjXj+p*jECAk) zAG}>b)UyR9zGb+L%r-$Ue+Z)K&4d)Jy>1*k>}=UejP8~M0(RlOip1jKIvw} zKb{?fE!BdY7z4Yc;0zxntFqHLg=95xQ%7M2JwuDb(Vnr&^WpR6cS1=;Zz)(VaNZR}Q`c`4NGY%7z`i}?M5x<|c?w^A zdbj5yrB25%ym0e5isv_@{_*Nxu}-fTPZVe8iSa^m@sVHmB#$ibCYFq3@bUAPKuZJD zjf?GP4HUO&W4W+;djzMku0WLrE@HA2jT>MLmRZmTjT}B^7pv`HBn<3dV8Y#F z2)LPZhU2gBKhLj7?_aohzCi>eBe$Stc_tX#;o@MR`vI`3EnLsh#Z#rAp)Cx>7^o-k z^q;|w2nFoT-E+J(-Yu?k5K#9xhE;wv;Yw3tGh9S?g=HpuT`%mE>G zI~=c_+cNg*ezDE!HX-JUQiDox1mt2<&8~Et52s<3hGw3Wl~ffFX5V279G0hJz<_4cWM4~ZgISGh-O^_Pc;#EKsM%b z_Q^}u-G0BaV7Wl!>fDKPN$WpXm>H?^_73-m|LB34k`Ip*`$ob z%gU!2@l_&>i>f<0aMjy?zBk(~*xv_!)(CE|d9ljZyR&q4{;i(MKnzzH*Gspd7*Q1* zV*IdAVR}l^>@=u739^NbVax!_mQeSzt zZctfJQ+Vtd|F~ds-{&mvIL+^g)Iu8cY~y6%WkihIlgF%gn`4g71afbARY`6EV~0s; z$=*_?%n>#Y4#Q;<{3r+q#{j|H*KJKswAJHLn9sFDDwJQaA4j7`mEG$+X~qIxSVY9F zS2ZfZ@X&||_fn6?=l8W&&tYrDzs$)+Yx?%839IP0{6hW0{T}+Lqm|Xv3ck~l&_LDH zvibQX*Ur8xe7t--rQ?@xZ>IBr_UhwDE9E|;0RciT&MxsTB?21)6mX2Xj-PkiA^(~1 zXDdRT!E#q9G~0N9LUs%Hf+A&y$r{8~e~rT5sQ&_{DXFwB0S5jIi8( z6y{Vnx-PO#ydG;~)7OSV{{EJF{vvc=_Q;vFZq6Wf*y=1`j=$veL$1B)v--0ytP;ib zJ8A7H4j;D%Ln-9WPL?rhxi>8`l`dZXXg2Ko*>-^8v969^vHgkmcUPUU3VYJjin~{? zYClRPHTY>{Usi50D(qA}+JLD7V@Jg*(?Ma3;FT#P%{QkNjoy)fF<5%;7YV_JEFJ38 zH>$hemlaUZE~WlGh}zLvDSL;xr)JCUt>R7$u@!ex^VTT%LqTg_`3B3gv->|1`^0rp zzpPsvX(4uh3_VDDXA`An_8M!MuUe-8B9Ys6q*I%1-`H0kc;_8?O0Hn9dTOrIV7vVa zriU#W66n!8kaXU#toA4+cNbx7>EEH-(cT_Vc4VE{FkP?r%sVeCBI0W@ZAyjJ;0=e- zES=-We5(C{$uc}Y2FsO2Mt@WMbChpj@>*n{Mz978kNU)&a`z7D8^;)+P=t!r8-+Uh zWy%dRD)8&7KEZv*MHd!voxxm$oJIi!-BNVT?!$@bh=_<7sVGQFE~IFa>4Snvw$SoW zs)rB<2Z!h^FYHkYti0VV`{KRw&76no!N2Z|5OarP?5qw#+imFuoS3RM^kd&mR(K(% zo zMC&@f^_*>st@l#Q7IB_DX&K zA#FdB{Id@Z>uyigW{>Q(xIN)}&)K=(P^M_2Mr`gsDF_zZVbiIa)h`9yZ6@TtI_ukF<#-7iB>w+Xp&D@~VO41~@ zzdg$Oy-V%M<^@ABy(fNn;P-xD^Y!|*1Z!SAv>AO4}WxM=#<&K3qRH;1bWM_7&?AQFPd6!%F=lIx?+S7JB z#*W6*uN?0j&T@3M6}0oL(80d*HQ;|!_ZF9C&?U{^Dvt}t$yhcK@uG{K(y~#@6~j4L;*S3<#_!ye19AJE@r`P{{nq-Jl2bgLI5B~{6u^bpU%FRmY%85%vA z*+IdumCzrRH@a=tL+~v4tC9j#^i;IP+d?->MhG5Zy7*QhD(a3d??zQ?mml7-n_ai_ zK5gHGTKe{Kw)#d*uB~g)udzpqoUvtygXD}@ z7f>^p@o3N6zdt>8v4Wi5xp=zBT=9LpTP{*DThl9A<%WV4mM~`f%uSWBCc?+01R-8- zo{H@Wpv#W7KD4`MNorP}F9|euEQ`#XRh7`kD^VMs4IT_tnxD2Mjfp<3{qS7v-+o_K zfHelLf&Rb@_Q>+^`85AKF7x>ga{in)zTZQ|^F7X%0ec27xq1lDTBWieSfMv$axiyKdiFX2TQ8`|K9o0KvJt5ht!v^7W z2FLk%blrz4*ooQ~9Dp`@|OR018G2mERw_LF8`y2zyvM%e=ayK{MI?U97| z{Ilr5EJnVfC&oX9*HTGA?h0adOxvnd=d*s?r>k%Yn95nbviJ#i9VUnlTHx#WK2i6= z#*+4$a1^1j-Wo|haD4D(3_{FT*T0c0rf|@fb-c0oe1=!>3Ny{2%@r^x5hT3v`2B9C zZ(#2u?uNWLfe)4gblaDFL7X7gJS4C|trHFiwfP9^5@IR+*>PX5h`4fsu zn)f;FmeBphqFJmSOKOPrDCS9?H_7t)^w|&7%^o$t1zRNbI7dNlT+X!AA9>{_9r|1_ zC3slW7+DkXkf5GPqk8rXpMIxE3pF2AhxMFQ?D$gB{RcU;Uy-x(?v=B7O3ekcVmK&) znqQL`NwoZ4HJZA*5!P^s<{UTAoK3@?3RGLx6ep}Bj8 z%#{=4JQT%L)%0VGZ^vvaG<=;HOngh)M#sw2^Qv6uRmQPssUsdX_Z}+TQGc7oFcX;q zSDf+n0unx0er`}>PR7tNbHQs2^gkDtJ(zlnulYo16lY3i=SsvdsjF$_S*sx){?QN8 zLs`;-50RU<5|W3Cd`01RO-d|8p&rHM{8TXtOls7L=Lh6F%VqhLHWX+t&P*Yxlty5^ zOx#t6$B(L!pG8)IqzGsSfq^2KMQgzH9a`8q01KZJu~_+;$Q2oOd1@WjOeceM(d1G) zk`;}2LNO#v9PID;LFD@Wc*aYkfl>wYb9cgA5njJqU&QAzm+5iXQL10xI~iQWEWx-f? zL@^9mJ%}eVb+$%|Hy=bx^2AUzg=YHs)w3=mb?g^KCI*vPZ)V+{D=|Qw=Y_VwAs$>6zavf_|+1%)p3t>@+T8gyR!q84P#CcYf&# zr*`B5Q<`+hrc(-y;q|FC`+HbkzKeDj``lRU)VE2uJ_9iQ>U+3058IWYBJ+mwDN6*( zD?dh$P5lX984bXep&Q%4E%XvG-j>SnD3oY{3)<FRT*rEJs-u4D+O@`#QrL87Rre|!y8V%yf;e|-}CBKipv>^ zmtJxCXGbnN&W&vbdc0&4P~ExT81 z8z#&oawoAT&j?R2{qO1vtMybO7u{NW=6k~ui2Cj~>&hjD&UUlD8C_olb=_R+r9oo% z3Y04tG@Z?37~m$8;ui;dN-qc)IwT|geC?ZY!z|!Gig_f6Q-&5}^YZsjeLf?7iI1UW zhWf40KorB_Gk#yx)%TTY*U!uaJS1EIf=gKNt>nD;?>PN%qo9r-N{@t~rO5E~=^?S= zfKn~{W6GT$735cJ;SAx|1n6>V52vXUueN$S>mCzy5tAeR$y#~cnYF8(MVs6%!sJF{ zS6{DKn>AFl+-H{MFkULO`XR@;X{K&pc$K&(AD(ae>H?i-=m(wwW=GYl?>QyuL${Am z44#(V5%w3&8)cnp7&n-QNwyF&O9T5vE#Al(dB7IpwVMhT$Z@69B1I6wx3!U9{{@p>%el6 zqCT*|j1qUIn1TwmI{od=U(4H7PA1Q{0FJ&x06RX`wb{4DBkK;orDC54)P6~hq|>7i z?^}rXgwvuN>7&HLgWWWqQQ^g=%f zf^1P5Go9yn(NC!I6}TC1IivYqBQX6fALjNY%0m@kd%tX{2~tdfMQnOaCk zzvIqJ%a&M2mf~jK(dw*UO1Fi_@+h^2ryky=8M-0x(czCez3Egy%8QWpq`e#ls*)^* zN6TP)$#xV)Q@%b`V*VvQcqVcQ+$x7g?x=2Q%{VdA&K01b+8=4(D7E>8NABH<6(5mR zw&Cb3*9}hxg`=|O1>%1U5S+-cL}#P_tki#6r~x1#p2`1&?jSXvkSfGBGeSgK|7KUO3M>{OmaFFMzG-`&(IAcCmA}s| zBq{PQsCKHV-p4S=xYv9Squy#Y}#5%CJy*&TsuKN>hMh9WH5O_Ee)T0gXGDa0|mLSF@dO zfjmWdr%zRhVbGOBpMtcYmrh#SANcyS+>U%1{%XI!jjr1#(&VqA4q}E>fbShz3=sg` z`4jiwm!m&i0xKOfb4zno9ld$^O=(Mw813Iczy_Ht_4gdP5r;LA)i~=Tg8TECUvq=` zyF;1eqWEWVi(6y%4Sk8lzoasGe?`UU04#`f>u)=W)IjVlZ8l86j{kh&IQ8iQW>_jb zVqL)rW82m7hd4J@w70s2;!MS0+9FgG@R{RX%ZDpZnNL=?jG24(wCTl9i#^K3{Wb!j zHh$~-Qc}XP#$Reau~^sab5Unkfd$f<@^7?Zj$&AK89CA&Evd1)D2I;vzO?LB-Y=CTPzKyNN}ZoyR|KuuEMntyZ?ZH$RA>dBkl%#5Gk7)&nc1K87986 z``rgt8o_2jzp>a+KHrezVGCi}|Cz-O zC#ZZp%DD)Ox_96D>*vjb=(&2?gdT-mf6m2bkN1L|n-TBohYXKD8OFcMJiM>z=k`02 z%^;ICZS?+TcgwVb?7M{;@r8xiyr4S%jK!0V{)rW>k_RY;bhp~~pBwwN5h%G8=%Jk? z_QT`;H*W<;*d0rX!2;REqnXzwtrq@mOXh=i>TV~p+bmqCO^%5DG2TaTOSh8i!>t^w z364P8NCSt!e{PY>Z zl5X8Mvu)*D{*f+>PyjI3l~IMwwV_yPzMF$KfK8m7>J?9NMCC0vzzJ;|aVawW$Q89%yePD}Z#Eb^2qJT9(S;CQLd z6h!hF(RA~zXM1|_03+ibL<|m$hbSj}a}O-gYM6?lY3nR&KD@#KK*zQ!P#CNffF#fi z64vf0=4SB#%x?W#O#2&HcT}-|R{koCaVW$dzu&K4Q;ywaJdoCd&5ffz z{k+o6T95S==4z*Fz8rTMmt5}yd~fW!^iq+<>VOZBT<)d2=~ocAimTjkL_-OkB?L8i z=al)>_mm|=l-pM1xnZI)y~liL>#AIUOZviZbi7rZ3Qq0!+LMB5WOw;x9{1i|3CNi|@P}YmHG~-; z6mPjTtfyw}`ZUxria{QreKv^Vt7XLcm)=9e4-W$v$9D7E zb3-#}@UN<`k0XzZT7#IyJZAKL@Uon#sD@AA)ZdJ_TOnTg}OIS>Exhs z!@$k$m$Yg}UYu225~+fAl)gJ7u7<=@0q654UZ2%V$6$BhmbVtCA-5psiy-We9rxcw zx-j0Dh|P{{bH95c`=9)eP^419|v>{6ezJpVSn(TeULKgZlAw+#A zIv?a4k32|?xRjy^5gs{7X=5B+Haz6EqwKaX#NQBHo^#>i)W?12XGjdor-jsi7OnrX z44KanWa@@?q8NVhGWoCg8Q2eH?6_!mx|W^i^ZZm&JyX11yOq{(&=Py07a%@uU^nZx z=_h!8uq5fN+(*4}|3~I?tu$N~aG{xanT89YVVx)NyTXKk^a|b^OGI5T!U(QX8b?sc zm{Gq>SOw^!6>KH3Vzis)vf<@JW zy;_EKRz2V$J9g?+@h3+ST`PYSyE?D=10i<_T zLtn`mt^w!J6Lp5|pg@Nwr{J){W)8%oh}H%;zFtGINY6B7yhxW}~6Cahp5z8r@9{;Ty>d)$U7FaNET9@a!AI5+643Wwqm znzi?0bxO0ZVFOAS#RFTMVT#Hi-aE&&5Kl{)MfFs@J%5e?;0m-C%2QF1?XA?^(X}$x ziV|G{agSNEg!dYRfUE|xCkwubQTa?8;?JVw9u~(dzEG_4{7&W;ntPGYpeUR=Q05^vBbiZa0qc(GFEAx0pVx(}zqVA?lF107W}W z#WmjtGFV>jUBF~*_Y>Pdw0#}{sVBiFpD$f2i{C=|s33eMhPe@)>h4HoJ9RF{VE&hz z(OzgxSCFHsn3Cfo42q%4Q^i639s>0^w$u{Qh#G_uXF4xn&yrZaErsR)iebV{UD;zG z^+g!aZXPY0+b9NJjqq6@7@t-poN~x_v~tOk_BMUed&cSt`snD|for5zD81t8_C&10 zTQOEJn_D9Hn?D!$%u_nEpZtaJYi;jg&)keOE-b$*vBeJ@$-LX1PIuq7ybdK<5W`U3 zBmy0+A)>`2$KgtRS3#x~!+v-^zwpJt{$B~tATDfieh5WvhercN$|WJE^LdwSHDRr? zptA8*|CEBxqgC1YquVfKoPN*C?-cXfj;|Gy$-|oH-X}_a{``UFz+28Hb{?!Fl@hsG z>NXOUEP$G@H3raFxRWc^c_{(ne^bVBVjzDEv0Y8yJhuD0KLB;E~d3jC~rui z3p?=&iLRE-H=g^H?g?}1{tzL zm~Ct}#9;+R1lsIP;0 zc^LI36PzoHx&6``;T?bjMN!qwkptN14Ie7eA3Ir7Eu`+pZ(Gt7Yj)*{8v~$2GTi>< zuOXoz*YNV2qP2A?d#{i1V^oL24%W}($h=jIAMyGL&o7-$^b2bF?NJ}r7C8`_SG6)_ z3f~bLJuYPFn7z{neXr#`e4u%}nR~hmn1$e_X2z=2;UO#%5EA9P3FUeQoE3rEHq*v( z$l~-cOHB{{&Xt{q1WZ7fShe9ohnA{a(;3&=L!$Tzh*$<#O_x zp&i<~Nb!o1>Q>7I0(PNyb~dD2!gFL4tPZ)ASyOu&R2THa+5~+PT5`__%JVPk@SvNCt@MD^Ast#6lPlEnet8j^_nbbUM!*XtT%EJB_ zh?n4g@8kJz2ZOBmY`NyDN9A9$7}LGYGx{mBmk_MDtKuWqH}8u(Q7=ojd=U@w4*zp; zN86uBlK*_b$wFi|3d{#&>A$oVGrQLRjpF>PQGu|4{agPf1rtL);(P(7usHNzViZoD zfW=}lvtAsh;R`NZ-+`^jRnjlgsf_$P2nB_r=d!oANBRP;)X6_;`LMZT;d2qW0fpKN0PUzcx`C7k1XvDSviFvxxneH+$Dh0=d9=u z`h2wbz@_*gY3^iHpn%T%K~$CKsWd$Ooco7Z08*9NIr|@wbNZ9(zu5?&%|E{UcddbG zyZqnCCg8mNZSVmN$tk(qfOeu@L( zAE|@1qJi+WtiNcf5vB4+;7hqvbjZwH5W;N)jGv6Z0oy<$(+%J`dZ!U=aQGA8aqSP+ z-bhc40l`Wzfz#nB1zeHX^nPLTaoSEBnD0ICFjN!?t^56ez%oi52 zo7MhsO7RA88}QIvI5p+!?Zl>Lea!l3zF77(9~t4IY^9)P4Pr$o|0*-orPm#SZuhNvX(qHYNcX?4CXj;cWd)KL zfvm0(JBp=Ur3kvTohSXrB42G58{9|knb*sl9a$&;Y5`tZY<#0$@7+CPUqz({R=p86 zh!Ooy(Va2u6%Dg7=0e1dg3aNy(G%TS`7Kv$6Y7ggfBhS|#rdA}=ZNGIoBR5+JNoxb zyUx_+!3L9lT?t$xn*?zSOFb$8tPi!7JJ&f^WfFA#C?Pkn%31Sc8SC^$?h!2MY>Pkt zrsN}H?vZp7>FenW0l~WRd3FK8hej@n-9cQ5jrh6Oh-&VI7>1L~4*Q+5SiDz*Cy%s2 z+Y1xZE%hHeia)#FBLZ58=%+nE)#ZR3g%xDYf zb*6tR(bgH6Nk+PjAe~3Az)Q+{@OLm(WF|tIKBxK*F4wRhK`1Q#&B~jLE=*ep+K(MjQ(csuu61J+~HG zJWGmb7YR=bHt^{VshN{)tIw_vc4AmYdwq1pq;~{T18O`4liq!2{s-0e;Y7u`U<_-#5Ym$V95v5HS^xaoxr*(7F89xA8!_4qz@5W*NQCCDv!yF*es+QEr)U|TI#ip0pL8Z*}o zh*cijq0W@L3*lc9Jq|Vck4wKEe=az(55Sv5roUd5N#9vE(a?YOu2g$ceaiiTbGZGn zcoH{%aIk8S^}@tmN7;6~rrt_pizbuZcNt?}x2^q+US)Pb2f~DAWUpywD`2{lnPuB? zwdWxi$u9w}$$3K1HB~t5@I>dgvfEQ2h+-||yQfFvr$arVMVW<_F_Uf@l{&9+WNL>i znWBrAX$p7pv#g47K%G`|C{MCH^I4Wd(9gT8=^V@clc|q}mELvu&DdAjc%X*`8f;F~ zU4A#4#D6$O79c1aGCFLv%S|DB!FPJ9+`^Sltc6BfkouPnB1DXbBMGd#0w?@iXShe; z`n}dw6G-KxQAr)(B{|h%S|l{AE#X1unC2Vo^(3-Kl`L{DjXZjP1o>n{?vgnj2_p?; zO6Gf;?ll)s=`!0ClHi~8{D&Mwfhww}qVEKl%-ZFW3osyIHN+$tfAn2$A$gx@-I0+E z2-_^k=;k4jZA^KhbP{B2`I-ZYhBvyE6FKiSQ8x+>>OeknH@5!?m0>6aCOG8 zt#0#-UxDq6fsu&Ng4_ryPkURNC#%NQbjVA4QndkCA;+7=hF{2w}Zh{DFlrSt3}y34bMCQzb}= zW93I*eNqP#RR!Ik{%l3S!*c=o9)$sH=bQsRuJ0I^Sk6@y_MYGGAck>)xEX&*6dS+cSvIv}q$5t%%*u zoe_`81g7e-&tuwezWx>hYS36KpVUjebxi3Rav=V~=G<)QI5{#2R5!b zB*pAswwGrP423vJhe3HVubyi-P8+@CK$fe(u}0<^@wy3~9;P>sHU=eK zFY`tO(7kfiH#tML#B7Ps(CjErz+F7;2+79^*70 z%#)m)f2*X>8B(ghpW%{)db0}c=*@bC`|}QN2Epk+C~kH$Vb6RkPokN&wCU(uLFCMm zQRoq00tE&0`#W$|6Td7p?TdA5Vj#Sp)rhP}WswuD7e5RF|A~8O5uOgC9=g)|x@=p7 ze#b6(q!Mu4-5>3hHLXATwrXOkqY8@;XeXij?<#+N%@|-w99S!B^}L4Wz~^1y{je1F zPX5^?aB_Lyo=QO||GHq&N%RFCZbjB9THIhkK$HGlX$0YCrw5x-lEBHW7*3Mr(PyEmDaM4#cAt2R0>He)|1xlsnz5LjOyOaE>3=fkD)k zz|=$P0rjodq(k#3tk~0K_ea^$^(4LZXS7&eRwRXC$W~6$v&r%9Q3|~+N1}@$ZHRk< zaFGzS1;0~m{vg;mZY}bsioPPg<<6A7LZc@!sGUFilknYH3AHNPX>!P$b6Zc!(8~H} zo3ZAsy=>SXuQso@J#U$EqDjWVIQ?xn&@_ zVX8_o=>uE4mvuDW|A3K3DVdTFsZ~;c@U6+8%X0->aAfM`qsjLm9LF?KN5Zw8&mub1DI=iD?Uq+cVbm=7`zWp zqy3>l8v;y_ip3v)C(9+M51i!|34rh*N_DK!GbAH&Q^oVNG!S^tKrYV_u5;)q3T^$qnR*v{#>sW+Dhu;v6(+WAb*nR^J<|d! z6&}0rrzVRmL>znX^-2B>y5XlPK4QL7z~B0`5h9mraQ|8h^~yWQh*x>#f_EFU z9p~;N#=4*_y*`TsaW=(Z*iF@Yh(=j~p8kSO*qBWr&hV_?ftiMZYS%X&?+bpv&E9q_ zZ)EDw(nQ!(l74LP5@iKwqhhg>paTUb1w7Rl4kpT)Bl+}v;+tC2uY*xueLrsa+XxMD z4nOE_r7ph7e0@ybS24oV#>gp{vaPPC-luzt?V|6+y1aj{5cJrP7Zk2%vjaEWh-o66 zJ;U8V%7H4@P@KiQQ)M!1?#3|>gW)?~8OAAyn7hRMt=$#*+^74!Nbkrafph> zK4sEY!KBhm&{U8L+e7Y#WP!-#K>4Je*WXe8Wb#6cNd+>Cg@=l{CFc=*=+c-Y*0?^gVP7h@#oEa3{a6@9v4A5MJWN zmp@o#SdzWQ_XJ+*$;WGbk9;MuAxtunNR!xo+R`W44LQye#-TTRlPk(7GJPgb3ih20s#4ixX zcQ^Xy5vW@nO)RO1oBiHGt@QIdj^>5;i7oRdU3Vo$`A|~`o#*VVG+FA2q0r_8{K zT~e!i_C>66p1@2gM`{Xdi?QahZ9&hUO=I@t8Al^XsLLUpxo z(@8qfx!k$f+w#ST!B5}7!M3Tw=rwd8VQ+mfXV2>Eo#3daoORx3Jz6pWL$n;K}s~i!&)do zlTDFZ9~KqReh%gr5WXE|r>+Y~0tn;ArHu(X^p%Z(x~~vB%3gKZcjbNd1Qjt*GAd}A zavv?tJEKa=0+e8@>P;TUFX=0gD6Oj_7e{xWzJ3UFkj^zIJaztj@x=pLLxJQQUTf?3 zM_x-yn2W%zBa>8Mg1hmgl*tW~;#gV!Pl*hu#On7y#r&bmgC=s&U;Z_M{Rm{|wJ#=Z z)^?OUYRtTmv{qOAP-d~96Ua(WY7B!c{dc0$3?QCh4a#0>I*S4*5Ccv=se;zKCDLQS z<})AzvqKeFE0aCOIvN9=VSfm@SupmuH0QC1W^yB$^V8 z-LYr>bQOqP*J=BYmySs902%mQ8T?d8sg!jrouug7n?BO%=|F#Do*e$T32#JBY{M&$ zCYCIS_o}zVV!U}(Cf|QSM+IrD&a9h1P;sDOzUZMQgzJ8hYG$Rf_q1e_Uf>dt_2z?T zmnSIH5-|xYWXj`1Wxh*s5CxRN1++{j{kN1DAiA1XHh_M;X>Y=KUS(E1Gnq(Yyt+1p z_lQ+E0cM$nC?A`F#}kx2(w%KbT4K=d`R1K_=gMzGsCU@adHkXo;OvQ9@ji^*os~xH zy`|#YZVB`sY^{`{A!?RmVJb{YzMppG71BCv&!7-!CdJR?NoXJHXN&jfS#l(MfWvsj zMUL?n=Sbn+OLVAuJ9bY|6{;5B!cdjOAx~hyo!qNW?l?&B3R^%k!0#GF-NQ07@9y@6 zvxW9+y)}ZfpYuHFJ5ap#PY(h^8Fn=ZNIs{xylMoo4M#yTb6`VK%wQk)pT(c-T-fsf0th=9K^l{+DkIosh}XS z;S^C<|FoLeQF3zwDlPNRk8q&FDI=LKL-O~2PAX)h1GIoOjKVMSj=ZS$BJ~hW)Cu~A zFyHM^l96vQB<#awSy;+en>gAIf1hJ$KGkH7lnwg>)Lk&ubydGkS;gPzOCXc9)OGMK z_cDi5guhFt$vCT}CWLnfPvibm8$q#gBAn#K)Kba?S149KdzE`}EPcyw+JUqTgCLgH z?#qGVk4OczHsAG2ZiHUr9;0PyJn{nY*ZQyf96b=fnG^LikP$5JT7g2Fc~QBWFi;0z zf_wii@z0r+SdSXe-5d5RwX2yOuGOab>I-L`Fi?!Le7;zw@65F_3gB#!$5~JM;bY1o z=@s&OA!s-Z=etoD_R?6kErawJ_828IW058>=RC>Y9H{N?@=>>geq`b)UO3592zv%( z_x+80i&#b9IHsfGYmg9$bFw}?nxG<0(b@H@F_5+^r|}!bx=$G@83k8EWWPMSd{|<9 z13pQiZiSu7C_sFMTLfHB!UMD5?k$q;u&-EKU8H!MR8+Z4WgkoK(`JW`mV<9L*fVZ- z9j%LLdc@w_&x#rOLiku8rkm8$$hrl1dAOfcnz#Y63LdMQag$cmbVg(bb#q|w=4&rZ zr#nxxS&G$b!!!bJ{z&;pc167VajW3)r;~E^y4_rB1`xSN0ilP}4Q@8a2X1_TFe?Al zz9YxYudI{99~$Q8e^YVw%!%Gj2L1;W9)*8Y`51b6Ax`LLR1p+Wv{4wQv+?S_9@51> zHlEo74YKDmMGRwVizq6$1T4nEL(k(AOvzXF-8J(}z+uy)<~E19{o?9IgTivl_Np%A zEBATo)HHpaCB9LBiM|avi8eT&cX=N;XV4hW1S=f!887ZqJK!>VWLEJaXJ>uHwp;|_ z0?B?Ti9JJ_N-wbNsnbd)B3sTXwS;{(8jf^sP}Xs@hM&m_Ysb(TOnKNMXkeGN@?UFw zyFfx)Ybe!HW{N<tf}D z>*(2lJgVq1&0 z`+;&l-O!r@hqzWVF{?c_n>(KR#uMMU8QDNSs(|S#Bs2rS!#@aUDpB28-x$pybZ2fpoG_8QxwW@6 zbe9NW$=kuKsVPj>cIzxR*mUE$v#1i!ZS8<0dS8kd4SU^5)ze?r3ly7HcpCK?ET1Pi z5jwchRPcqAnaRPY0aJ1`BUDrfFHR4T`^`}7A2r>LWoT2a#-e7=>XZUQ;Lka46|tMk zA-4RZUrR*)+_xr(cr)S%JV{fZ^FHp_w5PlV%$M@c%d+0j(frMdrxfv*<-3P2PfzOt`23fq+W#ppH0NWZ*FJL zF3${@?2KXF3AkrBjT9WzHA~zPe2~|1ToABhurk)$VcVcUE` zPn{zMgr6P8dA&Y-n|ko|Lh~aT&tNCcUAnqng~}|`@{aKWVal_u=bbk)ml>awH_S$w z3-P;pdoDndO|QWV4t>8XqF%KfMez3=eHGWGy{KYgj+Vo`q-Fcqzw*>)V%<^$?l93C zHo;_(_w<;jMWs8B$G z?i@4yy;4+U6{vYd_TTcK0 literal 0 HcmV?d00001