diff --git a/bin/contentctl_project/contentctl_infrastructure/adapter/templates/doc_detections.j2 b/bin/contentctl_project/contentctl_infrastructure/adapter/templates/doc_detections.j2
index 15184cd52c..60b2f1482c 100644
--- a/bin/contentctl_project/contentctl_infrastructure/adapter/templates/doc_detections.j2
+++ b/bin/contentctl_project/contentctl_infrastructure/adapter/templates/doc_detections.j2
@@ -38,7 +38,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
{% endif %}
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/detections/cloud/gsuite_drive_share_in_external_email.yml b/detections/cloud/gsuite_drive_share_in_external_email.yml
index bf726ba740..9c4bb29926 100644
--- a/detections/cloud/gsuite_drive_share_in_external_email.yml
+++ b/detections/cloud/gsuite_drive_share_in_external_email.yml
@@ -29,6 +29,7 @@ references:
tags:
analytic_story:
- Dev Sec Ops
+ - Insider Threat
asset_type: GSuite
confidence: 90
context:
diff --git a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml
index efdae5828e..e32abec18a 100644
--- a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml
+++ b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml
@@ -28,6 +28,7 @@ references:
tags:
analytic_story:
- Dev Sec Ops
+ - Insider Threat
asset_type: GSuite
confidence: 30
context:
diff --git a/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml b/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml
index 607986968d..ddac60620c 100644
--- a/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml
+++ b/detections/endpoint/high_frequency_copy_of_files_in_network_share.yml
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Information Sabotage
+ - Insider Threat
confidence: 30
context:
- Source:Endpoint
diff --git a/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml b/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml
index e706f75255..c4ab63de4b 100644
--- a/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml
+++ b/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml
@@ -48,6 +48,7 @@ references:
tags:
analytic_story:
- Active Directory Password Spraying
+ - Insider Threat
confidence: 70
context:
- Source:Endpoint
diff --git a/detections/endpoint/ssa___sdelete_application_execution.yml b/detections/endpoint/ssa___sdelete_application_execution.yml
index 5f37c2665a..d3e2f0ab6f 100644
--- a/detections/endpoint/ssa___sdelete_application_execution.yml
+++ b/detections/endpoint/ssa___sdelete_application_execution.yml
@@ -45,6 +45,7 @@ references:
tags:
analytic_story:
- Information Sabotage
+ - Insider Threat
cis20: []
confidence: 70
context:
diff --git a/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml b/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml
index cb8c3e8d19..6e67a50199 100644
--- a/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml
+++ b/detections/endpoint/windows_users_authenticate_using_explicit_credentials.yml
@@ -49,6 +49,7 @@ references:
tags:
analytic_story:
- Active Directory Password Spraying
+ - Insider Threat
confidence: 70
context:
- Source:Endpoint
diff --git a/detections/experimental/endpoint/ssa___excessive_number_of_office_files_copied.yml b/detections/experimental/endpoint/ssa___excessive_number_of_office_files_copied.yml
index 8f1980901c..a6889f6abe 100644
--- a/detections/experimental/endpoint/ssa___excessive_number_of_office_files_copied.yml
+++ b/detections/experimental/endpoint/ssa___excessive_number_of_office_files_copied.yml
@@ -25,7 +25,8 @@ how_to_implement: To successfully implement this search you need to be ingesting
known_false_positives: user may copy a lot of office fies from one folder to another
references: []
tags:
- analytic_story: []
+ analytic_story:
+ - Insider Threat
confidence: 80
context:
- Source:Endpoint
diff --git a/detections/experimental/endpoint/ssa___high_file_deletion_frequency.yml b/detections/experimental/endpoint/ssa___high_file_deletion_frequency.yml
index 4c80844d43..b34dd03ff3 100644
--- a/detections/experimental/endpoint/ssa___high_file_deletion_frequency.yml
+++ b/detections/experimental/endpoint/ssa___high_file_deletion_frequency.yml
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Clop Ransomware
+ - Insider Threat
confidence: 80
context:
- Source:Endpoint
diff --git a/docs/Gemfile.lock b/docs/Gemfile.lock
index fe8e8133c2..11c0c4f1fe 100644
--- a/docs/Gemfile.lock
+++ b/docs/Gemfile.lock
@@ -322,4 +322,4 @@ DEPENDENCIES
webrick (~> 1.7)
BUNDLED WITH
- 2.3.6
\ No newline at end of file
+ 2.3.6
diff --git a/docs/_pages/detections.md b/docs/_pages/detections.md
index 92363917b3..b3b7e96bc5 100644
--- a/docs/_pages/detections.md
+++ b/docs/_pages/detections.md
@@ -312,6 +312,7 @@ sidebar:
| [Execution of File with Multiple Extensions](/endpoint/execution_of_file_with_multiple_extensions/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Extended Period Without Successful Netbackup Backups]() | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
+| [F5 BIG-IP iControl REST Vulnerability CVE-2022-1388](/network/f5_big-ip_icontrol_rest_vulnerability_cve-2022-1388/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [File with Samsam Extension]() | None | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Firewall Allowed Program Enable](/endpoint/firewall_allowed_program_enable/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [First Time Seen Child Process of Zoom](/endpoint/first_time_seen_child_process_of_zoom/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
@@ -468,7 +469,7 @@ sidebar:
| [Linux Sudoers Tmp File Creation](/endpoint/linux_sudoers_tmp_file_creation/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Linux System Network Discovery](/endpoint/linux_system_network_discovery/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Linux Visudo Utility Execution](/endpoint/linux_visudo_utility_execution/) | [Sudo and Sudo Caching](/tags/#sudo-and-sudo-caching), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
-| [Linux deletion Of SSH Key](/endpoint/linux_deletion_of_ssh_key/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
+| [Linux deletion Of SSH Hash Conf](/endpoint/linux_deletion_of_ssh_hash_conf/) | [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | [Anomaly](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Linux pkexec Privilege Escalation](/endpoint/linux_pkexec_privilege_escalation/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Loading Of Dynwrapx Module](/endpoint/loading_of_dynwrapx_module/) | [Process Injection](/tags/#process-injection), [Dynamic-link Library Injection](/tags/#dynamic-link-library-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Local Account Discovery With Wmic](/endpoint/local_account_discovery_with_wmic/) | [Account Discovery](/tags/#account-discovery), [Local Account](/tags/#local-account) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
@@ -580,7 +581,7 @@ sidebar:
| [Powershell Processing Stream Of Data](/endpoint/powershell_processing_stream_of_data/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Powershell Remote Thread To Known Windows Process](/endpoint/powershell_remote_thread_to_known_windows_process/) | [Process Injection](/tags/#process-injection) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Powershell Remove Windows Defender Directory](/endpoint/powershell_remove_windows_defender_directory/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
-| [Powershell Using memory As Backing Store](/endpoint/powershell_using_memory_as_backing_store/) | [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
+| [Powershell Using memory As Backing Store](/endpoint/powershell_using_memory_as_backing_store/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Powershell Windows Defender Exclusion Commands](/endpoint/powershell_windows_defender_exclusion_commands/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Prevent Automatic Repair Mode using Bcdedit](/endpoint/prevent_automatic_repair_mode_using_bcdedit/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
@@ -758,7 +759,7 @@ sidebar:
| [Uninstall App Using MsiExec](/endpoint/uninstall_app_using_msiexec/) | [Msiexec](/tags/#msiexec), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Unknown Process Using The Kerberos Protocol](/endpoint/unknown_process_using_the_kerberos_protocol/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Unload Sysmon Filter Driver](/endpoint/unload_sysmon_filter_driver/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
-| [Unloading AMSI via Reflection](/endpoint/unloading_amsi_via_reflection/) | [Impair Defenses](/tags/#impair-defenses) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
+| [Unloading AMSI via Reflection](/endpoint/unloading_amsi_via_reflection/) | [Impair Defenses](/tags/#impair-defenses), [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Unsigned Image Loaded by LSASS](/deprecated/unsigned_image_loaded_by_lsass/) | [LSASS Memory](/tags/#lsass-memory) | [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Unsuccessful Netbackup backups]() | None | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
| [Unusual Number of Computer Service Tickets Requested](/endpoint/unusual_number_of_computer_service_tickets_requested/) | [Valid Accounts](/tags/#valid-accounts) | [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types) |
diff --git a/docs/_pages/stories.md b/docs/_pages/stories.md
index 1002857a7a..53901689eb 100644
--- a/docs/_pages/stories.md
+++ b/docs/_pages/stories.md
@@ -39,7 +39,7 @@ sidebar:
| [Common Phishing Frameworks](common_phishing_frameworks) | [Spearphishing via Service](/tags/#spearphishing-via-service) | [Initial Access](/tags/#initial-access) |
| [Container Implantation Monitoring and Investigation](container_implantation_monitoring_and_investigation) | [Implant Internal Image](/tags/#implant-internal-image) | [Persistence](/tags/#persistence) |
| [Credential Dumping](credential_dumping) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping), [Security Account Manager](/tags/#security-account-manager), [NTDS](/tags/#ntds), [Modify Registry](/tags/#modify-registry), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution) |
-| [CyclopsBLink]() | None | None |
+| [CyclopsBLink](cyclopsblink) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses), [Masquerade Task or Service](/tags/#masquerade-task-or-service), [Masquerading](/tags/#masquerading) | [Defense Evasion](/tags/#defense-evasion) |
| [DHS Report TA18-074A](dhs_report_ta18-074a) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job), [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file), [Modify Registry](/tags/#modify-registry), [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
| [DNS Amplification Attacks](dns_amplification_attacks) | [Network Denial of Service](/tags/#network-denial-of-service), [Reflection Amplification](/tags/#reflection-amplification) | [Impact](/tags/#impact) |
| [DNS Hijacking](dns_hijacking) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [DNS](/tags/#dns), [Drive-by Compromise](/tags/#drive-by-compromise) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) |
@@ -55,17 +55,19 @@ sidebar:
| [Double Zero Destructor](double_zero_destructor) | [Masquerading](/tags/#masquerading), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Modify Registry](/tags/#modify-registry), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
| [Dynamic DNS](dynamic_dns) | [Web Protocols](/tags/#web-protocols), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Drive-by Compromise](/tags/#drive-by-compromise) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration), [Initial Access](/tags/#initial-access) |
| [Emotet Malware DHS Report TA18-201A ](emotet_malware__dhs_report_ta18-201a_) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing), [Software Deployment Tools](/tags/#software-deployment-tools), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Remote Services](/tags/#remote-services) | [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
+| [F5 BIG-IP Vulnerability CVE-2022-1388](f5_big-ip_vulnerability_cve-2022-1388) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) |
| [F5 TMUI RCE CVE-2020-5902](f5_tmui_rce_cve-2020-5902) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) |
| [FIN7](fin7) | [System Owner/User Discovery](/tags/#system-owner/user-discovery), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Credentials from Web Browsers](/tags/#credentials-from-web-browsers), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Visual Basic](/tags/#visual-basic), [Process Injection](/tags/#process-injection), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Parent PID Spoofing](/tags/#parent-pid-spoofing), [Access Token Manipulation](/tags/#access-token-manipulation), [XSL Script Processing](/tags/#xsl-script-processing) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
| [GCP Cross Account Activity](gcp_cross_account_activity) | [Valid Accounts](/tags/#valid-accounts) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
| [HAFNIUM Group](hafnium_group) | [LSASS Memory](/tags/#lsass-memory), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Local Account](/tags/#local-account), [Create Account](/tags/#create-account), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution), [OS Credential Dumping](/tags/#os-credential-dumping), [NTDS](/tags/#ntds), [Email Collection](/tags/#email-collection), [Remote Email Collection](/tags/#remote-email-collection) | [Collection](/tags/#collection), [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence) |
-| [Hermetic Wiper](hermetic_wiper) | [PowerShell](/tags/#powershell), [Malicious File](/tags/#malicious-file), [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution), [Windows Command Shell](/tags/#windows-command-shell), [OS Credential Dumping](/tags/#os-credential-dumping), [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Masquerading](/tags/#masquerading), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Accessibility Features](/tags/#accessibility-features), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Process Injection](/tags/#process-injection), [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32), [Access Token Manipulation](/tags/#access-token-manipulation), [Token Impersonation/Theft](/tags/#token-impersonation/theft), [Screensaver](/tags/#screensaver), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Time Providers](/tags/#time-providers), [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Data Destruction](/tags/#data-destruction), [Modify Registry](/tags/#modify-registry), [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Print Processors](/tags/#print-processors) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) |
+| [Hermetic Wiper](hermetic_wiper) | [PowerShell](/tags/#powershell), [Malicious File](/tags/#malicious-file), [Active Setup](/tags/#active-setup), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution), [Windows Command Shell](/tags/#windows-command-shell), [OS Credential Dumping](/tags/#os-credential-dumping), [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Masquerading](/tags/#masquerading), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Kerberoasting](/tags/#kerberoasting), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application), [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [DLL Side-Loading](/tags/#dll-side-loading), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Accessibility Features](/tags/#accessibility-features), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Process Injection](/tags/#process-injection), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvr32](/tags/#regsvr32), [Access Token Manipulation](/tags/#access-token-manipulation), [Token Impersonation/Theft](/tags/#token-impersonation/theft), [Screensaver](/tags/#screensaver), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Time Providers](/tags/#time-providers), [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell), [Data Destruction](/tags/#data-destruction), [Modify Registry](/tags/#modify-registry), [Disk Structure Wipe](/tags/#disk-structure-wipe), [Disk Wipe](/tags/#disk-wipe), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Phishing](/tags/#phishing), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Print Processors](/tags/#print-processors) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Impact](/tags/#impact), [Initial Access](/tags/#initial-access), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) |
| [Hidden Cobra Malware](hidden_cobra_malware) | [PowerShell](/tags/#powershell), [Windows Command Shell](/tags/#windows-command-shell), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Network Share Connection Removal](/tags/#network-share-connection-removal), [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services), [File Transfer Protocols](/tags/#file-transfer-protocols), [Application Layer Protocol](/tags/#application-layer-protocol), [DNS](/tags/#dns), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Exfiltration](/tags/#exfiltration), [Lateral Movement](/tags/#lateral-movement) |
| [Host Redirection](host_redirection) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [DNS](/tags/#dns) | [Command And Control](/tags/#command-and-control), [Exfiltration](/tags/#exfiltration) |
| [IcedID](icedid) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Windows Command Shell](/tags/#windows-command-shell), [Process Injection](/tags/#process-injection), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Modify Registry](/tags/#modify-registry), [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Mshta](/tags/#mshta), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Regsvr32](/tags/#regsvr32), [Rundll32](/tags/#rundll32), [Scheduled Task/Job](/tags/#scheduled-task/job), [Data from Local System](/tags/#data-from-local-system), [Scheduled Task](/tags/#scheduled-task) | [Collection](/tags/#collection), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
| [Industroyer2](industroyer2) | [Domain Account](/tags/#domain-account), [Account Discovery](/tags/#account-discovery), [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping), [LSASS Memory](/tags/#lsass-memory), [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Masquerading](/tags/#masquerading), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service), [Data Destruction](/tags/#data-destruction), [System Network Configuration Discovery](/tags/#system-network-configuration-discovery), [Scheduled Task/Job](/tags/#scheduled-task/job), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Scheduled Task](/tags/#scheduled-task), [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Discovery](/tags/#discovery), [Execution](/tags/#execution), [Impact](/tags/#impact), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
| [Information Sabotage](information_sabotage) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | [Exfiltration](/tags/#exfiltration) |
| [Ingress Tool Transfer](ingress_tool_transfer) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [BITS Jobs](/tags/#bits-jobs) | [Command And Control](/tags/#command-and-control), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Persistence](/tags/#persistence) |
+| [Insider Threat](insider_threat) | [Exfiltration to Cloud Storage](/tags/#exfiltration-to-cloud-storage), [Exfiltration Over Web Service](/tags/#exfiltration-over-web-service), [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol), [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account), [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Credential Access](/tags/#credential-access), [Exfiltration](/tags/#exfiltration) |
| [JBoss Vulnerability](jboss_vulnerability) | [System Information Discovery](/tags/#system-information-discovery) | [Discovery](/tags/#discovery) |
| [Kubernetes Scanning Activity](kubernetes_scanning_activity) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) |
| [Kubernetes Sensitive Object Access Activity]() | None | None |
@@ -76,7 +78,7 @@ sidebar:
| [Living Off The Land](living_off_the_land) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information), [Windows Command Shell](/tags/#windows-command-shell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Control Panel](/tags/#control-panel), [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping), [Compiled HTML File](/tags/#compiled-html-file), [Mshta](/tags/#mshta), [Regsvcs/Regasm](/tags/#regsvcs/regasm), [Regsvr32](/tags/#regsvr32), [Rundll32](/tags/#rundll32), [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses), [LSASS Memory](/tags/#lsass-memory), [Security Account Manager](/tags/#security-account-manager), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Unix Shell](/tags/#unix-shell), [Plist Modification](/tags/#plist-modification), [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Process Injection](/tags/#process-injection), [Modify Registry](/tags/#modify-registry), [Scheduled Task/Job](/tags/#scheduled-task/job), [At (Windows)](/tags/#at-(windows)), [Scheduled Task](/tags/#scheduled-task), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service), [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild), [Indirect Command Execution](/tags/#indirect-command-execution), [InstallUtil](/tags/#installutil) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
| [Local Privilege Escalation With KrbRelayUp](local_privilege_escalation_with_krbrelayup) | [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets), [Windows Service](/tags/#windows-service) | [Credential Access](/tags/#credential-access), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation) |
| [Log4Shell CVE-2021-44228](log4shell_cve-2021-44228) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [Windows Command Shell](/tags/#windows-command-shell), [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Command And Control](/tags/#command-and-control), [Execution](/tags/#execution), [Initial Access](/tags/#initial-access) |
-| [Malicious PowerShell](malicious_powershell) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [OS Credential Dumping](/tags/#os-credential-dumping), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution), [Process Injection](/tags/#process-injection), [Deobfuscate/Decode Files or Information](/tags/#deobfuscate/decode-files-or-information), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Impair Defenses](/tags/#impair-defenses) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) |
+| [Malicious PowerShell](malicious_powershell) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Ingress Tool Transfer](/tags/#ingress-tool-transfer), [OS Credential Dumping](/tags/#os-credential-dumping), [Obfuscated Files or Information](/tags/#obfuscated-files-or-information), [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [Indicator Removal from Tools](/tags/#indicator-removal-from-tools), [Component Object Model Hijacking](/tags/#component-object-model-hijacking), [Event Triggered Execution](/tags/#event-triggered-execution), [Process Injection](/tags/#process-injection), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Impair Defenses](/tags/#impair-defenses) | [Command And Control](/tags/#command-and-control), [Credential Access](/tags/#credential-access), [Defense Evasion](/tags/#defense-evasion), [Execution](/tags/#execution), [Lateral Movement](/tags/#lateral-movement), [Persistence](/tags/#persistence), [Privilege Escalation](/tags/#privilege-escalation), [Reconnaissance](/tags/#reconnaissance) |
| [Masquerading - Rename System Utilities](masquerading_-_rename_system_utilities) | [Rename System Utilities](/tags/#rename-system-utilities), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Masquerading](/tags/#masquerading), [Rundll32](/tags/#rundll32), [Data Destruction](/tags/#data-destruction), [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [MSBuild](/tags/#msbuild), [InstallUtil](/tags/#installutil) | [Defense Evasion](/tags/#defense-evasion), [Impact](/tags/#impact) |
| [Meterpreter](meterpreter) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Discovery](/tags/#discovery), [Execution](/tags/#execution) |
| [Microsoft MSHTML Remote Code Execution CVE-2021-40444](microsoft_mshtml_remote_code_execution_cve-2021-40444) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Control Panel](/tags/#control-panel), [Phishing](/tags/#phishing), [Spearphishing Attachment](/tags/#spearphishing-attachment), [Rundll32](/tags/#rundll32) | [Defense Evasion](/tags/#defense-evasion), [Initial Access](/tags/#initial-access) |
diff --git a/docs/_posts/2017-01-07-spectre_and_meltdown_vulnerable_systems.md b/docs/_posts/2017-01-07-spectre_and_meltdown_vulnerable_systems.md
index 20abefa5c9..e363bc4125 100644
--- a/docs/_posts/2017-01-07-spectre_and_meltdown_vulnerable_systems.md
+++ b/docs/_posts/2017-01-07-spectre_and_meltdown_vulnerable_systems.md
@@ -16,7 +16,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md
index 0917a3d674..c1c9615a9e 100644
--- a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md
+++ b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md b/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md
index 5f3ace6721..1cc78f121b 100644
--- a/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md
+++ b/docs/_posts/2017-09-12-extended_period_without_successful_netbackup_backups.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -99,8 +99,8 @@ This search returns a list of hosts that have not successfully completed a backu
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [netbackup](https://github.com/splunk/security_content/blob/develop/macros/netbackup.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **extended_period_without_successful_netbackup_backups_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2017-09-12-identify_new_user_accounts.md b/docs/_posts/2017-09-12-identify_new_user_accounts.md
index 4cd639a7ed..4eee978935 100644
--- a/docs/_posts/2017-09-12-identify_new_user_accounts.md
+++ b/docs/_posts/2017-09-12-identify_new_user_accounts.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md b/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md
index 7be962bec3..8a7f854bc4 100644
--- a/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md
+++ b/docs/_posts/2017-09-12-unsuccessful_netbackup_backups.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -98,8 +98,8 @@ This search gives you the hosts where a backup was attempted and then failed.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [netbackup](https://github.com/splunk/security_content/blob/develop/macros/netbackup.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **unsuccessful_netbackup_backups_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md
index 11d626a206..e0a9cd30c1 100644
--- a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md
+++ b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md
index e5c9ae0f7f..aaf5e6faa8 100644
--- a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md
+++ b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md
index 72915c0dd2..2750d925cb 100644
--- a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md
+++ b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-19-open_redirect_in_splunk_web.md b/docs/_posts/2017-09-19-open_redirect_in_splunk_web.md
index 42b0015a29..85c9f4f16e 100644
--- a/docs/_posts/2017-09-19-open_redirect_in_splunk_web.md
+++ b/docs/_posts/2017-09-19-open_redirect_in_splunk_web.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md
index cff978ec0b..4ac78ce5c2 100644
--- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md
+++ b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md
index 4598b7b4fb..cccd781b91 100644
--- a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md
+++ b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md
index c015834cab..8dd65eac43 100644
--- a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md
+++ b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md
index ad9eb36d8d..f0d2e5ed9b 100644
--- a/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md
+++ b/docs/_posts/2017-09-23-monitor_dns_for_brand_abuse.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -96,8 +96,8 @@ This search looks for DNS requests for faux domains similar to the domains that
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [brand_abuse_dns](https://github.com/splunk/security_content/blob/develop/macros/brand_abuse_dns.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **monitor_dns_for_brand_abuse_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
@@ -106,7 +106,7 @@ Note that **monitor_dns_for_brand_abuse_filter** is a empty macro by default. It
#### How To Implement
-You need to ingest data from your DNS logs. Specifically you must ingest the domain that is being queried and the IP of the host originating the request. Ideally, you should also be ingesting the answer to the query and the query type. This approach allows you to also create your own localized passive DNS capability which can aid you in future investigations. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for.
+You need to ingest data from your DNS logs. Specifically you must ingest the domain that is being queried and the IP of the host originating the request. Ideally, you should also be ingesting the answer to the query and the query type. This approach allows you to also create your own localized passive DNS capability which can aid you in future investigations. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. You also need the [`dnstwist`](https://gist.github.com/d1vious/c4c2aae7fa7d5cbb1f24adc5f6303) custom command.
#### Known False Positives
None at this time
diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md
index 162aec362e..3398b68b82 100644
--- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md
+++ b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This search looks for Web requests to faux domains similar to the one that you w
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [brand_abuse_web](https://github.com/splunk/security_content/blob/develop/macros/brand_abuse_web.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **monitor_web_traffic_for_brand_abuse_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2017-10-13-unusually_long_content-type_length.md b/docs/_posts/2017-10-13-unusually_long_content-type_length.md
index c08dc1b515..0cef4d96df 100644
--- a/docs/_posts/2017-10-13-unusually_long_content-type_length.md
+++ b/docs/_posts/2017-10-13-unusually_long_content-type_length.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2017-11-27-detect_usb_device_insertion.md b/docs/_posts/2017-11-27-detect_usb_device_insertion.md
index d16ce4afab..eb78121ae8 100644
--- a/docs/_posts/2017-11-27-detect_usb_device_insertion.md
+++ b/docs/_posts/2017-11-27-detect_usb_device_insertion.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md
index 10efb31fcf..5a2607f8af 100644
--- a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md
+++ b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-02-23-ec2_instance_started_in_previously_unseen_region.md b/docs/_posts/2018-02-23-ec2_instance_started_in_previously_unseen_region.md
index 9ab3027499..e6207ec15f 100644
--- a/docs/_posts/2018-02-23-ec2_instance_started_in_previously_unseen_region.md
+++ b/docs/_posts/2018-02-23-ec2_instance_started_in_previously_unseen_region.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ This search looks for AWS CloudTrail events where an instance is started in a pa
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **ec2_instance_started_in_previously_unseen_region_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2018-03-12-ec2_instance_started_with_previously_unseen_ami.md b/docs/_posts/2018-03-12-ec2_instance_started_with_previously_unseen_ami.md
index f94d3d2d96..b3fb8ef05e 100644
--- a/docs/_posts/2018-03-12-ec2_instance_started_with_previously_unseen_ami.md
+++ b/docs/_posts/2018-03-12-ec2_instance_started_with_previously_unseen_ami.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search looks for EC2 instances being created with previously unseen AMIs.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **ec2_instance_started_with_previously_unseen_ami_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_city.md b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_city.md
index da281b271a..1dbd1197c1 100644
--- a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_city.md
+++ b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_city.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_country.md b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_country.md
index 6079115060..61fc3c3c1e 100644
--- a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_country.md
+++ b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_country.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_ip_address.md b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_ip_address.md
index 216a5218a3..4609b44e68 100644
--- a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_ip_address.md
+++ b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_ip_address.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_region.md b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_region.md
index 8b859f1f81..d9339dc043 100644
--- a/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_region.md
+++ b/docs/_posts/2018-03-16-aws_cloud_provisioning_from_previously_unseen_region.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-04-16-detect_new_api_calls_from_user_roles.md b/docs/_posts/2018-04-16-detect_new_api_calls_from_user_roles.md
index f1af016a55..fac9233726 100644
--- a/docs/_posts/2018-04-16-detect_new_api_calls_from_user_roles.md
+++ b/docs/_posts/2018-04-16-detect_new_api_calls_from_user_roles.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ This search detects new API calls that have either never been seen before or tha
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_new_api_calls_from_user_roles_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2018-04-18-detect_spike_in_security_group_activity.md b/docs/_posts/2018-04-18-detect_spike_in_security_group_activity.md
index d095fbfb1e..3c59905486 100644
--- a/docs/_posts/2018-04-18-detect_spike_in_security_group_activity.md
+++ b/docs/_posts/2018-04-18-detect_spike_in_security_group_activity.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md
index 8e50157999..290c3c38aa 100644
--- a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md
+++ b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-05-17-detect_api_activity_from_users_without_mfa.md b/docs/_posts/2018-05-17-detect_api_activity_from_users_without_mfa.md
index a0c5914d7d..413b27dc86 100644
--- a/docs/_posts/2018-05-17-detect_api_activity_from_users_without_mfa.md
+++ b/docs/_posts/2018-05-17-detect_api_activity_from_users_without_mfa.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This search looks for AWS CloudTrail events where a user logged into the AWS acc
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_api_activity_from_users_without_mfa_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2018-05-21-detect_spike_in_network_acl_activity.md b/docs/_posts/2018-05-21-detect_spike_in_network_acl_activity.md
index b21dabfa94..d8ac0b5de4 100644
--- a/docs/_posts/2018-05-21-detect_spike_in_network_acl_activity.md
+++ b/docs/_posts/2018-05-21-detect_spike_in_network_acl_activity.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -122,8 +122,8 @@ This search will detect users creating spikes in API activity related to network
#### Macros
The SPL above uses the following Macros:
-* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
* [network_acl_events](https://github.com/splunk/security_content/blob/develop/macros/network_acl_events.yml)
+* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
Note that **detect_spike_in_network_acl_activity_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md
index 4d59c747a4..b914aee483 100644
--- a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md
+++ b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-06-14-splunk_enterprise_information_disclosure.md b/docs/_posts/2018-06-14-splunk_enterprise_information_disclosure.md
index 58353c61ff..36f19ecc5c 100644
--- a/docs/_posts/2018-06-14-splunk_enterprise_information_disclosure.md
+++ b/docs/_posts/2018-06-14-splunk_enterprise_information_disclosure.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md
index 7d801f8b3a..85cf046d01 100644
--- a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md
+++ b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-10-08-web_fraud_-_account_harvesting.md b/docs/_posts/2018-10-08-web_fraud_-_account_harvesting.md
index bf988f4c65..9cb23524f7 100644
--- a/docs/_posts/2018-10-08-web_fraud_-_account_harvesting.md
+++ b/docs/_posts/2018-10-08-web_fraud_-_account_harvesting.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-10-08-web_fraud_-_anomalous_user_clickspeed.md b/docs/_posts/2018-10-08-web_fraud_-_anomalous_user_clickspeed.md
index dfcd3ec940..a3b84444c3 100644
--- a/docs/_posts/2018-10-08-web_fraud_-_anomalous_user_clickspeed.md
+++ b/docs/_posts/2018-10-08-web_fraud_-_anomalous_user_clickspeed.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-10-08-web_fraud_-_password_sharing_across_accounts.md b/docs/_posts/2018-10-08-web_fraud_-_password_sharing_across_accounts.md
index 271f9f3ede..4ab7beca0e 100644
--- a/docs/_posts/2018-10-08-web_fraud_-_password_sharing_across_accounts.md
+++ b/docs/_posts/2018-10-08-web_fraud_-_password_sharing_across_accounts.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md b/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md
index 9eeb18973e..8df41e8ffc 100644
--- a/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md
+++ b/docs/_posts/2018-10-12-cloud_compute_instance_created_with_previously_unseen_image.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md
index fb2f3b310d..39e2f861ca 100644
--- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md
+++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ This search looks for the creation of WMI permanent event subscriptions.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **wmi_permanent_event_subscription_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md
index f7858e136a..52bc98267a 100644
--- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md
+++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for the creation of WMI temporary event subscriptions.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wmi](https://github.com/splunk/security_content/blob/develop/macros/wmi.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **wmi_temporary_event_subscription_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2018-11-02-windows_hosts_file_modification.md b/docs/_posts/2018-11-02-windows_hosts_file_modification.md
index 4bde8d2248..5c2d49598e 100644
--- a/docs/_posts/2018-11-02-windows_hosts_file_modification.md
+++ b/docs/_posts/2018-11-02-windows_hosts_file_modification.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md
index de15d459ff..698f897b2e 100644
--- a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md
+++ b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md
index 8e94f85b40..4ccb8bccea 100644
--- a/docs/_posts/2018-12-03-remote_wmi_command_attempt.md
+++ b/docs/_posts/2018-12-03-remote_wmi_command_attempt.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-12-03-usn_journal_deletion.md b/docs/_posts/2018-12-03-usn_journal_deletion.md
index 4edf3cf3c7..6308c7c13e 100644
--- a/docs/_posts/2018-12-03-usn_journal_deletion.md
+++ b/docs/_posts/2018-12-03-usn_journal_deletion.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md
index d60dff7d38..f62efb68cb 100644
--- a/docs/_posts/2018-12-06-suspicious_java_classes.md
+++ b/docs/_posts/2018-12-06-suspicious_java_classes.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ This search looks for suspicious Java classes that are often used to exploit rem
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_java_classes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2018-12-14-file_with_samsam_extension.md b/docs/_posts/2018-12-14-file_with_samsam_extension.md
index 56efa8a693..661a939bae 100644
--- a/docs/_posts/2018-12-14-file_with_samsam_extension.md
+++ b/docs/_posts/2018-12-14-file_with_samsam_extension.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2018-12-14-samsam_test_file_write.md b/docs/_posts/2018-12-14-samsam_test_file_write.md
index 2a52f177ee..fb9528455c 100644
--- a/docs/_posts/2018-12-14-samsam_test_file_write.md
+++ b/docs/_posts/2018-12-14-samsam_test_file_write.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md
index bf708c145b..e7d3ef011d 100644
--- a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md
+++ b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2019-01-29-osquery_pack_-_coldroot_detection.md b/docs/_posts/2019-01-29-osquery_pack_-_coldroot_detection.md
index 7209452618..6daf98c953 100644
--- a/docs/_posts/2019-01-29-osquery_pack_-_coldroot_detection.md
+++ b/docs/_posts/2019-01-29-osquery_pack_-_coldroot_detection.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md b/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md
index 113a9aa642..29dff9f294 100644
--- a/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md
+++ b/docs/_posts/2019-02-27-detect_mimikatz_via_powershell_and_eventcode_4703.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ This search looks for PowerShell requesting privileges consistent with credentia
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_mimikatz_via_powershell_and_eventcode_4703_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2019-02-27-reg_exe_used_to_hide_files_directories_via_registry_keys.md b/docs/_posts/2019-02-27-reg_exe_used_to_hide_files_directories_via_registry_keys.md
index 327f63ad93..d9761492b1 100644
--- a/docs/_posts/2019-02-27-reg_exe_used_to_hide_files_directories_via_registry_keys.md
+++ b/docs/_posts/2019-02-27-reg_exe_used_to_hide_files_directories_via_registry_keys.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md
index 26bd210d99..12e9940a6c 100644
--- a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md
+++ b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2019-04-25-suspicious_file_write.md b/docs/_posts/2019-04-25-suspicious_file_write.md
index d16049b585..f7aa017d48 100644
--- a/docs/_posts/2019-04-25-suspicious_file_write.md
+++ b/docs/_posts/2019-04-25-suspicious_file_write.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -100,8 +100,8 @@ The search looks for files created with names that have been linked to malicious
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [suspicious_writes](https://github.com/splunk/security_content/blob/develop/macros/suspicious_writes.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_file_write_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md
index 8a79ce87bb..ccbf750308 100644
--- a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md
+++ b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2019-10-11-prohibited_software_on_endpoint.md b/docs/_posts/2019-10-11-prohibited_software_on_endpoint.md
index 9b6c71e976..fa53fa7bd5 100644
--- a/docs/_posts/2019-10-11-prohibited_software_on_endpoint.md
+++ b/docs/_posts/2019-10-11-prohibited_software_on_endpoint.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This search looks for applications on the endpoint that you have marked as prohi
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [prohibited_softwares](https://github.com/splunk/security_content/blob/develop/macros/prohibited_softwares.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **prohibited_software_on_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md
index 2ddfc74d8d..76a833a155 100644
--- a/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md
+++ b/docs/_posts/2019-12-03-detect_credential_dumping_through_lsass_access.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ This search looks for reading lsass memory consistent with credential dumping.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_credential_dumping_through_lsass_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md
index 69d4ec50a4..d944b2bc4c 100644
--- a/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md
+++ b/docs/_posts/2019-12-03-detect_mimikatz_using_loaded_images.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for reading loaded Images unique to credential dumping with Mi
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_mimikatz_using_loaded_images_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md
index fc550147a8..3e4012da61 100644
--- a/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md
+++ b/docs/_posts/2019-12-06-access_lsass_memory_for_dump_creation.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ Detect memory dumping of the LSASS process.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **access_lsass_memory_for_dump_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md
index 8aa14d73c6..5e46b1ae13 100644
--- a/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md
+++ b/docs/_posts/2019-12-06-create_remote_thread_into_lsass.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ Detect remote thread creation into LSASS consistent with credential dumping.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **create_remote_thread_into_lsass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2019-12-06-unsigned_image_loaded_by_lsass.md b/docs/_posts/2019-12-06-unsigned_image_loaded_by_lsass.md
index 19cc20b9a4..52bf80c709 100644
--- a/docs/_posts/2019-12-06-unsigned_image_loaded_by_lsass.md
+++ b/docs/_posts/2019-12-06-unsigned_image_loaded_by_lsass.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search detects loading of unsigned images by LSASS. Deprecated because too
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **unsigned_image_loaded_by_lsass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2019-12-10-creation_of_shadow_copy.md b/docs/_posts/2019-12-10-creation_of_shadow_copy.md
index 5470d7ae6e..bf4e19c39a 100644
--- a/docs/_posts/2019-12-10-creation_of_shadow_copy.md
+++ b/docs/_posts/2019-12-10-creation_of_shadow_copy.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md
index 554642a12e..ea2792f6b2 100644
--- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md
+++ b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md b/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md
index d5ba084fcd..2d35a4e8a9 100644
--- a/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md
+++ b/docs/_posts/2020-01-28-auto_admin_logon_registry_entry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md b/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md
index c6a2bd1218..f74ab75362 100644
--- a/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md
+++ b/docs/_posts/2020-01-28-monitor_registry_keys_for_print_monitors.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md b/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md
index f6c0d803c5..8616c8c08b 100644
--- a/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md
+++ b/docs/_posts/2020-01-28-registry_keys_for_creating_shim_databases.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-01-28-sdclt_uac_bypass.md b/docs/_posts/2020-01-28-sdclt_uac_bypass.md
index e2e5b13d9d..a9c1b96c7f 100644
--- a/docs/_posts/2020-01-28-sdclt_uac_bypass.md
+++ b/docs/_posts/2020-01-28-sdclt_uac_bypass.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md b/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md
index a1314eee79..7adaa244f8 100644
--- a/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md
+++ b/docs/_posts/2020-01-28-silentcleanup_uac_bypass.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-01-28-wsreset_uac_bypass.md b/docs/_posts/2020-01-28-wsreset_uac_bypass.md
index f5426d63ad..f7ddb6e77c 100644
--- a/docs/_posts/2020-01-28-wsreset_uac_bypass.md
+++ b/docs/_posts/2020-01-28-wsreset_uac_bypass.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md
index 443884aedb..ffa057990c 100644
--- a/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md
+++ b/docs/_posts/2020-02-03-creation_of_lsass_dump_with_taskmgr.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ Detect the hands on keyboard behavior of Windows Task Manager creating a process
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **creation_of_lsass_dump_with_taskmgr_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-02-07-ec2_instance_started_with_previously_unseen_instance_type.md b/docs/_posts/2020-02-07-ec2_instance_started_with_previously_unseen_instance_type.md
index 43dc1ecf84..8a27a38e21 100644
--- a/docs/_posts/2020-02-07-ec2_instance_started_with_previously_unseen_instance_type.md
+++ b/docs/_posts/2020-02-07-ec2_instance_started_with_previously_unseen_instance_type.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This search looks for EC2 instances being created with previously unseen instanc
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **ec2_instance_started_with_previously_unseen_instance_type_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md
index 0cc68086ed..001b7384aa 100644
--- a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md
+++ b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-02-20-gcp_gcr_container_uploaded.md b/docs/_posts/2020-02-20-gcp_gcr_container_uploaded.md
index d251cde26f..5170d9732c 100644
--- a/docs/_posts/2020-02-20-gcp_gcr_container_uploaded.md
+++ b/docs/_posts/2020-02-20-gcp_gcr_container_uploaded.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md
index 95bc2d5e79..dcce7c2a47 100644
--- a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md
+++ b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md
index b9fbb8dd03..d9264f19b3 100644
--- a/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md
+++ b/docs/_posts/2020-02-21-dump_lsass_via_comsvcs_dll.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-03-02-remote_registry_key_modifications.md b/docs/_posts/2020-03-02-remote_registry_key_modifications.md
index 015266cda9..0addf6bdba 100644
--- a/docs/_posts/2020-03-02-remote_registry_key_modifications.md
+++ b/docs/_posts/2020-03-02-remote_registry_key_modifications.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md
index 3b9cb91aa7..93cdc89692 100644
--- a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md
+++ b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md
@@ -21,7 +21,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-03-16-detect_rare_executables.md b/docs/_posts/2020-03-16-detect_rare_executables.md
index f401a7c0e8..d1be1c2df9 100644
--- a/docs/_posts/2020-03-16-detect_rare_executables.md
+++ b/docs/_posts/2020-03-16-detect_rare_executables.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ This search will return a table of rare processes, the names of the systems runn
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [filter_rare_process_allow_list](https://github.com/splunk/security_content/blob/develop/macros/filter_rare_process_allow_list.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_rare_executables_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-03-16-process_execution_via_wmi.md b/docs/_posts/2020-03-16-process_execution_via_wmi.md
index 61227044bb..dc7ac51648 100644
--- a/docs/_posts/2020-03-16-process_execution_via_wmi.md
+++ b/docs/_posts/2020-03-16-process_execution_via_wmi.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-03-16-script_execution_via_wmi.md b/docs/_posts/2020-03-16-script_execution_via_wmi.md
index 4e454d0e2d..32db576c64 100644
--- a/docs/_posts/2020-03-16-script_execution_via_wmi.md
+++ b/docs/_posts/2020-03-16-script_execution_via_wmi.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-03-16-spike_in_file_writes.md b/docs/_posts/2020-03-16-spike_in_file_writes.md
index 7ccb65d60b..419e63d1db 100644
--- a/docs/_posts/2020-03-16-spike_in_file_writes.md
+++ b/docs/_posts/2020-03-16-spike_in_file_writes.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md
index e8ad51aaa3..b4a7fa53a5 100644
--- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md
+++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This search provides information of unauthenticated requests via user agent, and
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **amazon_eks_kubernetes_cluster_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md
index 801ecb2e37..15b4c886d9 100644
--- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md
+++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This search provides detection information on unauthenticated requests against K
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [aws_cloudwatchlogs_eks](https://github.com/splunk/security_content/blob/develop/macros/aws_cloudwatchlogs_eks.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **amazon_eks_kubernetes_pod_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md
index 4203ca40fa..c758a7adc3 100644
--- a/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md
+++ b/docs/_posts/2020-04-15-gcp_kubernetes_cluster_scan_detection.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ This search provides information of unauthenticated requests via user agent, and
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [google_gcp_pubsub_message](https://github.com/splunk/security_content/blob/develop/macros/google_gcp_pubsub_message.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **gcp_kubernetes_cluster_scan_detection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-05-19-kubernetes_azure_scan_fingerprint.md b/docs/_posts/2020-05-19-kubernetes_azure_scan_fingerprint.md
index 0b963258b0..85ddc035a9 100644
--- a/docs/_posts/2020-05-19-kubernetes_azure_scan_fingerprint.md
+++ b/docs/_posts/2020-05-19-kubernetes_azure_scan_fingerprint.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md
index 902db37bb6..43d450f72a 100644
--- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md
+++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_object_access.md b/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_object_access.md
index 38bdffcdc7..efec8bdfac 100644
--- a/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_object_access.md
+++ b/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_object_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_role_access.md b/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_role_access.md
index acbec18ca6..205b8587bc 100644
--- a/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_role_access.md
+++ b/docs/_posts/2020-05-20-kubernetes_azure_detect_sensitive_role_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-20-kubernetes_azure_detect_service_accounts_forbidden_failure_access.md b/docs/_posts/2020-05-20-kubernetes_azure_detect_service_accounts_forbidden_failure_access.md
index 7216acca1c..51793bf49d 100644
--- a/docs/_posts/2020-05-20-kubernetes_azure_detect_service_accounts_forbidden_failure_access.md
+++ b/docs/_posts/2020-05-20-kubernetes_azure_detect_service_accounts_forbidden_failure_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-20-kubernetes_azure_pod_scan_fingerprint.md b/docs/_posts/2020-05-20-kubernetes_azure_pod_scan_fingerprint.md
index d5ba1131e2..e6b077a9a1 100644
--- a/docs/_posts/2020-05-20-kubernetes_azure_pod_scan_fingerprint.md
+++ b/docs/_posts/2020-05-20-kubernetes_azure_pod_scan_fingerprint.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-26-kubernetes_azure_active_service_accounts_by_pod_namespace.md b/docs/_posts/2020-05-26-kubernetes_azure_active_service_accounts_by_pod_namespace.md
index dd121a91cf..6d0fd77c18 100644
--- a/docs/_posts/2020-05-26-kubernetes_azure_active_service_accounts_by_pod_namespace.md
+++ b/docs/_posts/2020-05-26-kubernetes_azure_active_service_accounts_by_pod_namespace.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-26-kubernetes_azure_detect_rbac_authorization_by_account.md b/docs/_posts/2020-05-26-kubernetes_azure_detect_rbac_authorization_by_account.md
index 3a8806a65a..f9bad36585 100644
--- a/docs/_posts/2020-05-26-kubernetes_azure_detect_rbac_authorization_by_account.md
+++ b/docs/_posts/2020-05-26-kubernetes_azure_detect_rbac_authorization_by_account.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-26-kubernetes_azure_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-05-26-kubernetes_azure_detect_suspicious_kubectl_calls.md
index c251aa428b..df0cc357c2 100644
--- a/docs/_posts/2020-05-26-kubernetes_azure_detect_suspicious_kubectl_calls.md
+++ b/docs/_posts/2020-05-26-kubernetes_azure_detect_suspicious_kubectl_calls.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md b/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md
index 7c7c74b4bb..5dae9a4aba 100644
--- a/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md
+++ b/docs/_posts/2020-05-28-aws_cross_account_activity_from_previously_unseen_account.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-06-23-aws_eks_kubernetes_cluster_sensitive_object_access.md b/docs/_posts/2020-06-23-aws_eks_kubernetes_cluster_sensitive_object_access.md
index b1337093ea..80b1792a03 100644
--- a/docs/_posts/2020-06-23-aws_eks_kubernetes_cluster_sensitive_object_access.md
+++ b/docs/_posts/2020-06-23-aws_eks_kubernetes_cluster_sensitive_object_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_most_active_service_accounts_by_pod.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_most_active_service_accounts_by_pod.md
index 55ea636b39..c66f2fea57 100644
--- a/docs/_posts/2020-06-23-kubernetes_aws_detect_most_active_service_accounts_by_pod.md
+++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_most_active_service_accounts_by_pod.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_rbac_authorization_by_account.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_rbac_authorization_by_account.md
index 04dc1e5921..832f4df40f 100644
--- a/docs/_posts/2020-06-23-kubernetes_aws_detect_rbac_authorization_by_account.md
+++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_rbac_authorization_by_account.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_sensitive_role_access.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_sensitive_role_access.md
index 69f30eb677..ea69275131 100644
--- a/docs/_posts/2020-06-23-kubernetes_aws_detect_sensitive_role_access.md
+++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_sensitive_role_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_service_accounts_forbidden_failure_access.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_service_accounts_forbidden_failure_access.md
index f25271fbc8..b6092e7c34 100644
--- a/docs/_posts/2020-06-23-kubernetes_aws_detect_service_accounts_forbidden_failure_access.md
+++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_service_accounts_forbidden_failure_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md
index cc32b964f1..f3e02c754b 100644
--- a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md
+++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-06-23-kubernetes_gcp_detect_service_accounts_forbidden_failure_access.md b/docs/_posts/2020-06-23-kubernetes_gcp_detect_service_accounts_forbidden_failure_access.md
index 788220f545..8338bae07a 100644
--- a/docs/_posts/2020-06-23-kubernetes_gcp_detect_service_accounts_forbidden_failure_access.md
+++ b/docs/_posts/2020-06-23-kubernetes_gcp_detect_service_accounts_forbidden_failure_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md
index c6f67e1323..5f782f89a3 100644
--- a/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md
+++ b/docs/_posts/2020-07-03-detect_path_interception_by_creation_of_program_exe.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-06-short_lived_windows_accounts.md b/docs/_posts/2020-07-06-short_lived_windows_accounts.md
index c53a4ec86a..d6925d4bda 100644
--- a/docs/_posts/2020-07-06-short_lived_windows_accounts.md
+++ b/docs/_posts/2020-07-06-short_lived_windows_accounts.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-06-windows_event_log_cleared.md b/docs/_posts/2020-07-06-windows_event_log_cleared.md
index b8c7760064..b714105b37 100644
--- a/docs/_posts/2020-07-06-windows_event_log_cleared.md
+++ b/docs/_posts/2020-07-06-windows_event_log_cleared.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,9 +115,9 @@ The following analytic utilizes Windows Security Event ID 1102 or System log eve
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
-* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml)
+* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_event_log_cleared_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md
index 2eb14ff048..800de82fbe 100644
--- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md
+++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-08-detect_new_local_admin_account.md b/docs/_posts/2020-07-08-detect_new_local_admin_account.md
index 788f5d7e61..13b59c4b4a 100644
--- a/docs/_posts/2020-07-08-detect_new_local_admin_account.md
+++ b/docs/_posts/2020-07-08-detect_new_local_admin_account.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for newly created accounts that have been elevated to local ad
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_new_local_admin_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-10-kubernetes_gcp_detect_most_active_service_accounts_by_pod.md b/docs/_posts/2020-07-10-kubernetes_gcp_detect_most_active_service_accounts_by_pod.md
index 67e134b92b..724092a746 100644
--- a/docs/_posts/2020-07-10-kubernetes_gcp_detect_most_active_service_accounts_by_pod.md
+++ b/docs/_posts/2020-07-10-kubernetes_gcp_detect_most_active_service_accounts_by_pod.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-11-kubernetes_gcp_detect_rbac_authorizations_by_account.md b/docs/_posts/2020-07-11-kubernetes_gcp_detect_rbac_authorizations_by_account.md
index 6082cd709b..fd255cc900 100644
--- a/docs/_posts/2020-07-11-kubernetes_gcp_detect_rbac_authorizations_by_account.md
+++ b/docs/_posts/2020-07-11-kubernetes_gcp_detect_rbac_authorizations_by_account.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_object_access.md b/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_object_access.md
index 5103eaf88e..c1aa580a0a 100644
--- a/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_object_access.md
+++ b/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_object_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_role_access.md b/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_role_access.md
index 28918e2e81..b347ee6f4e 100644
--- a/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_role_access.md
+++ b/docs/_posts/2020-07-11-kubernetes_gcp_detect_sensitive_role_access.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-11-kubernetes_gcp_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-07-11-kubernetes_gcp_detect_suspicious_kubectl_calls.md
index b56454d131..c29465b6be 100644
--- a/docs/_posts/2020-07-11-kubernetes_gcp_detect_suspicious_kubectl_calls.md
+++ b/docs/_posts/2020-07-11-kubernetes_gcp_detect_suspicious_kubectl_calls.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md
index 41ae84659d..bd38511440 100644
--- a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md
+++ b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user.md b/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user.md
index 1509071b4b..7654631f46 100644
--- a/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user.md
+++ b/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user_-_mltk.md b/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user_-_mltk.md
index d0aaad6c29..2acdda0b83 100644
--- a/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user_-_mltk.md
+++ b/docs/_posts/2020-07-21-abnormally_high_aws_instances_launched_by_user_-_mltk.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user.md b/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user.md
index bf95af286e..06ccefd5c9 100644
--- a/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user.md
+++ b/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user_-_mltk.md b/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user_-_mltk.md
index 4de3c9f318..a221308503 100644
--- a/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user_-_mltk.md
+++ b/docs/_posts/2020-07-21-abnormally_high_aws_instances_terminated_by_user_-_mltk.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md
index 7ce611ae4c..bd3240f431 100644
--- a/docs/_posts/2020-07-21-attempt_to_stop_security_service.md
+++ b/docs/_posts/2020-07-21-attempt_to_stop_security_service.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -119,8 +119,8 @@ This search looks for attempts to stop security-related services on the endpoint
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **attempt_to_stop_security_service_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-clients_connecting_to_multiple_dns_servers.md b/docs/_posts/2020-07-21-clients_connecting_to_multiple_dns_servers.md
index 3658556087..786950d581 100644
--- a/docs/_posts/2020-07-21-clients_connecting_to_multiple_dns_servers.md
+++ b/docs/_posts/2020-07-21-clients_connecting_to_multiple_dns_servers.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-detect_aws_api_activities_from_unapproved_accounts.md b/docs/_posts/2020-07-21-detect_aws_api_activities_from_unapproved_accounts.md
index 8577bf1e0b..d7e5cf5360 100644
--- a/docs/_posts/2020-07-21-detect_aws_api_activities_from_unapproved_accounts.md
+++ b/docs/_posts/2020-07-21-detect_aws_api_activities_from_unapproved_accounts.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -118,8 +118,8 @@ This search looks for successful AWS CloudTrail activity by user accounts that a
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_aws_api_activities_from_unapproved_accounts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md b/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md
index 0046ebb8b2..5f666920d4 100644
--- a/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md
+++ b/docs/_posts/2020-07-21-detect_dns_requests_to_phishing_sites_leveraging_evilginx2.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -124,13 +124,13 @@ This search looks for DNS requests for phishing domains that are leveraging Evil
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
+* [evilginx_phishlets_facebook](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_facebook.yml)
* [evilginx_phishlets_aws](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_aws.yml)
* [evilginx_phishlets_outlook](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_outlook.yml)
-* [evilginx_phishlets_github](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_github.yml)
-* [evilginx_phishlets_0365](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_0365.yml)
-* [evilginx_phishlets_facebook](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_facebook.yml)
-* [evilginx_phishlets_google](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_google.yml)
* [evilginx_phishlets_amazon](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_amazon.yml)
+* [evilginx_phishlets_0365](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_0365.yml)
+* [evilginx_phishlets_github](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_github.yml)
+* [evilginx_phishlets_google](https://github.com/splunk/security_content/blob/develop/macros/evilginx_phishlets_google.yml)
Note that **detect_dns_requests_to_phishing_sites_leveraging_evilginx2_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md
index b18dc909c4..071e60fd9f 100644
--- a/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md
+++ b/docs/_posts/2020-07-21-detect_excessive_user_account_lockouts.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-detect_long_dns_txt_record_response.md b/docs/_posts/2020-07-21-detect_long_dns_txt_record_response.md
index 6e06cf8484..a3dcbcbb38 100644
--- a/docs/_posts/2020-07-21-detect_long_dns_txt_record_response.md
+++ b/docs/_posts/2020-07-21-detect_long_dns_txt_record_response.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-detect_new_user_aws_console_login.md b/docs/_posts/2020-07-21-detect_new_user_aws_console_login.md
index 273ce7537d..7d8105e616 100644
--- a/docs/_posts/2020-07-21-detect_new_user_aws_console_login.md
+++ b/docs/_posts/2020-07-21-detect_new_user_aws_console_login.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for AWS CloudTrail events wherein a console login event by a u
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_new_user_aws_console_login_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md
index 912387e432..8512f6d967 100644
--- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md
+++ b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md
index 8dc1096616..f52bfff6c9 100644
--- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md
+++ b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-detect_spike_in_aws_api_activity.md b/docs/_posts/2020-07-21-detect_spike_in_aws_api_activity.md
index 85a7a482f1..2ad7cfff1c 100644
--- a/docs/_posts/2020-07-21-detect_spike_in_aws_api_activity.md
+++ b/docs/_posts/2020-07-21-detect_spike_in_aws_api_activity.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md
index f8f3d5e76a..35a5a686ad 100644
--- a/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md
+++ b/docs/_posts/2020-07-21-detect_use_of_cmd_exe_to_launch_script_interpreters.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-detect_web_traffic_to_dynamic_domain_providers.md b/docs/_posts/2020-07-21-detect_web_traffic_to_dynamic_domain_providers.md
index 0b615e08f2..83c6c5bce0 100644
--- a/docs/_posts/2020-07-21-detect_web_traffic_to_dynamic_domain_providers.md
+++ b/docs/_posts/2020-07-21-detect_web_traffic_to_dynamic_domain_providers.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ This search looks for web connections to dynamic DNS providers.
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [dynamic_dns_web_traffic](https://github.com/splunk/security_content/blob/develop/macros/dynamic_dns_web_traffic.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_web_traffic_to_dynamic_domain_providers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md
index f57c3c016a..419668a345 100644
--- a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md
+++ b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md
@@ -21,7 +21,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-dns_query_requests_resolved_by_unauthorized_dns_servers.md b/docs/_posts/2020-07-21-dns_query_requests_resolved_by_unauthorized_dns_servers.md
index fc3e11fff9..65361d4eee 100644
--- a/docs/_posts/2020-07-21-dns_query_requests_resolved_by_unauthorized_dns_servers.md
+++ b/docs/_posts/2020-07-21-dns_query_requests_resolved_by_unauthorized_dns_servers.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-dns_record_changed.md b/docs/_posts/2020-07-21-dns_record_changed.md
index cd248af252..8cee4ea6da 100644
--- a/docs/_posts/2020-07-21-dns_record_changed.md
+++ b/docs/_posts/2020-07-21-dns_record_changed.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md b/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md
index 2a3183ad30..ad9fe8d1d6 100644
--- a/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md
+++ b/docs/_posts/2020-07-21-ec2_instance_modified_with_previously_unseen_user.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -118,9 +118,9 @@ This search looks for EC2 instances being modified by users who have not previou
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
-* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
* [ec2_modification_api_calls](https://github.com/splunk/security_content/blob/develop/macros/ec2_modification_api_calls.yml)
+* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **ec2_instance_modified_with_previously_unseen_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-ec2_instance_started_with_previously_unseen_user.md b/docs/_posts/2020-07-21-ec2_instance_started_with_previously_unseen_user.md
index 7e2df37260..813d6abad0 100644
--- a/docs/_posts/2020-07-21-ec2_instance_started_with_previously_unseen_user.md
+++ b/docs/_posts/2020-07-21-ec2_instance_started_with_previously_unseen_user.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ This search looks for EC2 instances being created by users who have not created
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **ec2_instance_started_with_previously_unseen_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md
index c20cd71e8f..87522b53a1 100644
--- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md
+++ b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md
index b645d108aa..0f49f83cd6 100644
--- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md
+++ b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md
index 33ea7afb51..cafbda87e0 100644
--- a/docs/_posts/2020-07-21-excessive_dns_failures.md
+++ b/docs/_posts/2020-07-21-excessive_dns_failures.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-first_time_seen_command_line_argument.md b/docs/_posts/2020-07-21-first_time_seen_command_line_argument.md
index c73e0ff14c..e0437eb7b1 100644
--- a/docs/_posts/2020-07-21-first_time_seen_command_line_argument.md
+++ b/docs/_posts/2020-07-21-first_time_seen_command_line_argument.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md
index b37c976fbc..13c49da2d5 100644
--- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md
+++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md
index 74ca087556..c6878f278c 100644
--- a/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md
+++ b/docs/_posts/2020-07-21-hiding_files_and_directories_with_attrib_exe.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md
index 332dbc6015..ab8a2539a5 100644
--- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md
+++ b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md
index 6bc1c31bc9..33fc00d5b9 100644
--- a/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md
+++ b/docs/_posts/2020-07-21-malicious_powershell_process_-_execution_policy_bypass.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ This search looks for PowerShell processes started with parameters used to bypas
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **malicious_powershell_process_-_execution_policy_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md
index 326187b09a..167413fe5b 100644
--- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md
+++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md
@@ -28,7 +28,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -119,8 +119,8 @@ This search detects Okta login failures due to bad credentials for multiple user
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md
index 122cef7fb1..fa8a72054e 100644
--- a/docs/_posts/2020-07-21-okta_account_lockout_events.md
+++ b/docs/_posts/2020-07-21-okta_account_lockout_events.md
@@ -28,7 +28,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md
index cc03763381..ab0163d9ae 100644
--- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md
+++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md
@@ -28,7 +28,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ Detect failed Okta SSO events
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **okta_failed_sso_attempts_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md
index 0cd59c7473..78e8cdb22a 100644
--- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md
+++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md
@@ -28,7 +28,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -118,8 +118,8 @@ This search detects logins from the same user from different cities in a 24 hour
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [okta](https://github.com/splunk/security_content/blob/develop/macros/okta.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **okta_user_logins_from_multiple_cities_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md
index 18c0aeecdb..cfa1725ca5 100644
--- a/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md
+++ b/docs/_posts/2020-07-21-overwriting_accessibility_binaries.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md
index e62f64d154..85c6ab8700 100644
--- a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md
+++ b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md
index 4c55abfac6..820f017292 100644
--- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md
+++ b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md
index 0f334bd42e..37f58662c4 100644
--- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md
+++ b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md
index 7309b95c4d..cccfeefb94 100644
--- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md
+++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md
index 063f6913a4..db22951e7f 100644
--- a/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md
+++ b/docs/_posts/2020-07-21-sc_exe_manipulating_windows_services.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-21-scheduled_tasks_used_in_badrabbit_ransomware.md b/docs/_posts/2020-07-21-scheduled_tasks_used_in_badrabbit_ransomware.md
index 0adc1b3fc5..9d86e5c94f 100644
--- a/docs/_posts/2020-07-21-scheduled_tasks_used_in_badrabbit_ransomware.md
+++ b/docs/_posts/2020-07-21-scheduled_tasks_used_in_badrabbit_ransomware.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md
index 4da164dcf2..3afb3f2a9f 100644
--- a/docs/_posts/2020-07-22-smb_traffic_spike.md
+++ b/docs/_posts/2020-07-22-smb_traffic_spike.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md
index c038526c69..ddfc7a6356 100644
--- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md
+++ b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-22-suspicious_changes_to_file_associations.md b/docs/_posts/2020-07-22-suspicious_changes_to_file_associations.md
index e48b2a88bd..931be0b686 100644
--- a/docs/_posts/2020-07-22-suspicious_changes_to_file_associations.md
+++ b/docs/_posts/2020-07-22-suspicious_changes_to_file_associations.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-22-suspicious_email_-_uba_anomaly.md b/docs/_posts/2020-07-22-suspicious_email_-_uba_anomaly.md
index d74b9d5a7b..4deba7d294 100644
--- a/docs/_posts/2020-07-22-suspicious_email_-_uba_anomaly.md
+++ b/docs/_posts/2020-07-22-suspicious_email_-_uba_anomaly.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md
index fa4f49af87..de9c477dd3 100644
--- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md
+++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -118,8 +118,8 @@ This search looks for emails that have attachments with suspicious file extensio
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [suspicious_email_attachments](https://github.com/splunk/security_content/blob/develop/macros/suspicious_email_attachments.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_email_attachment_extensions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-22-suspicious_reg_exe_process.md b/docs/_posts/2020-07-22-suspicious_reg_exe_process.md
index 9c8f73d6e0..775074cfcd 100644
--- a/docs/_posts/2020-07-22-suspicious_reg_exe_process.md
+++ b/docs/_posts/2020-07-22-suspicious_reg_exe_process.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-22-suspicious_writes_to_system_volume_information.md b/docs/_posts/2020-07-22-suspicious_writes_to_system_volume_information.md
index 47ebc94eed..9982204540 100644
--- a/docs/_posts/2020-07-22-suspicious_writes_to_system_volume_information.md
+++ b/docs/_posts/2020-07-22-suspicious_writes_to_system_volume_information.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -104,8 +104,8 @@ This search detects writes to the 'System Volume Information' folder by somethin
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_writes_to_system_volume_information_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md b/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md
index 9681c6beed..5987a21ca1 100644
--- a/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md
+++ b/docs/_posts/2020-07-22-suspicious_writes_to_windows_recycle_bin.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md
index 8001dd1e4e..effb94d77a 100644
--- a/docs/_posts/2020-07-22-tor_traffic.md
+++ b/docs/_posts/2020-07-22-tor_traffic.md
@@ -23,7 +23,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-22-uncommon_processes_on_endpoint.md b/docs/_posts/2020-07-22-uncommon_processes_on_endpoint.md
index 25adedf5d9..5302c71118 100644
--- a/docs/_posts/2020-07-22-uncommon_processes_on_endpoint.md
+++ b/docs/_posts/2020-07-22-uncommon_processes_on_endpoint.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -109,8 +109,8 @@ This search looks for applications on the endpoint that you have marked as uncom
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [uncommon_processes](https://github.com/splunk/security_content/blob/develop/macros/uncommon_processes.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **uncommon_processes_on_endpoint_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md
index 67c9dc6275..492ad31786 100644
--- a/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md
+++ b/docs/_posts/2020-07-22-unload_sysmon_filter_driver.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md
index 70cb37dd9b..c85897c02a 100644
--- a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md
+++ b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md
index f6cf61a2b8..7717630ad3 100644
--- a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md
+++ b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-27-aws_detect_role_creation.md b/docs/_posts/2020-07-27-aws_detect_role_creation.md
index a3bd6b5f6b..9ca37b3f95 100644
--- a/docs/_posts/2020-07-27-aws_detect_role_creation.md
+++ b/docs/_posts/2020-07-27-aws_detect_role_creation.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md
index d0ebbd3224..dc24e80d99 100644
--- a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md
+++ b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md
index a5eeabea8a..d2953dfdc9 100644
--- a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md
+++ b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md
index 139a7c944f..81e876c4db 100644
--- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md
+++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md
index 4034326e39..48546e0906 100644
--- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md
+++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md
@@ -21,7 +21,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md
index 64b17deb2a..e84a91f46b 100644
--- a/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md
+++ b/docs/_posts/2020-07-29-cloud_instance_modified_by_previously_unseen_user.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md
index e828ed3178..82d3d82913 100644
--- a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md
+++ b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md
index f1946af888..a03af31549 100644
--- a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md
+++ b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md
index 065db4f9c3..4c1431e70c 100644
--- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md
+++ b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md
index adcada45d6..0e698b953f 100644
--- a/docs/_posts/2020-08-11-detect_arp_poisoning.md
+++ b/docs/_posts/2020-08-11-detect_arp_poisoning.md
@@ -30,7 +30,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -128,8 +128,8 @@ By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organiza
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_arp_poisoning_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md
index e2d06d01f7..ba0697643f 100644
--- a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md
+++ b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md
@@ -26,7 +26,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -121,8 +121,8 @@ By enabling DHCP Snooping as a Layer 2 Security measure on the organization's ne
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_rogue_dhcp_server_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md
index c62e53acfe..ba2d1a00a6 100644
--- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md
+++ b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_ip_address.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md
index 50ec849700..16a8eda801 100644
--- a/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md
+++ b/docs/_posts/2020-08-16-cloud_provisioning_activity_from_previously_unseen_region.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md
index 725d122879..d4e391bfb8 100644
--- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md
+++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md
@@ -29,7 +29,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md
index 87429d2be7..a99c78fd84 100644
--- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md
+++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md
@@ -29,7 +29,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-09-01-gcp_detect_oauth_token_abuse.md b/docs/_posts/2020-09-01-gcp_detect_oauth_token_abuse.md
index d58665dbcd..e0d866b8ac 100644
--- a/docs/_posts/2020-09-01-gcp_detect_oauth_token_abuse.md
+++ b/docs/_posts/2020-09-01-gcp_detect_oauth_token_abuse.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md b/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md
index 05ae4bc9ff..b644f8f7e5 100644
--- a/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md
+++ b/docs/_posts/2020-09-02-cloud_compute_instance_created_in_previously_unused_region.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md b/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md
index e4fe7f07d7..da2d8c00e3 100644
--- a/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md
+++ b/docs/_posts/2020-09-04-cloud_api_calls_from_previously_unseen_user_roles.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md
index 0a35691f4e..2200390ded 100644
--- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md
+++ b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_infrastructure_api_calls.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md
index 62e821ae4d..1b0d25e9a1 100644
--- a/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md
+++ b/docs/_posts/2020-09-07-abnormally_high_number_of_cloud_security_group_api_calls.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-09-08-cloud_network_access_control_list_deleted.md b/docs/_posts/2020-09-08-cloud_network_access_control_list_deleted.md
index ff803f6754..a259825f33 100644
--- a/docs/_posts/2020-09-08-cloud_network_access_control_list_deleted.md
+++ b/docs/_posts/2020-09-08-cloud_network_access_control_list_deleted.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -98,8 +98,8 @@ Enforcing network-access controls is one of the defensive mechanisms used by clo
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **cloud_network_access_control_list_deleted_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md b/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md
index ff6f217d9e..801a2c8044 100644
--- a/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md
+++ b/docs/_posts/2020-09-12-cloud_compute_instance_created_with_previously_unseen_instance_type.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md
index bf1121c205..46324de957 100644
--- a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md
+++ b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md
index 6a2102f69b..c5668f5375 100644
--- a/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md
+++ b/docs/_posts/2020-09-16-create_or_delete_windows_shares_using_net_exe.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ This search looks for the creation or deletion of hidden shares using net.exe.
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **create_or_delete_windows_shares_using_net_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md
index 27746874e4..19bdc2592b 100644
--- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md
+++ b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md
index 2661650d56..b9d0037aca 100644
--- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md
+++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_city.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md
index 7fca14f159..6ee99dd331 100644
--- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md
+++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_country.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md
index 3c23e9ebd4..a0e2d6dd2c 100644
--- a/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md
+++ b/docs/_posts/2020-10-07-detect_aws_console_login_by_user_from_new_region.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md
index e95210d731..3bf0522a69 100644
--- a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md
+++ b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md
index 93ae6e9aa2..007611a514 100644
--- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md
+++ b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_city.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md
index 6021c70aa9..3f3aa6c7f5 100644
--- a/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md
+++ b/docs/_posts/2020-10-09-cloud_provisioning_activity_from_previously_unseen_country.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-09-gcp_detect_accounts_with_high_risk_roles_by_project.md b/docs/_posts/2020-10-09-gcp_detect_accounts_with_high_risk_roles_by_project.md
index fb787ff0ca..e0a94ebbf9 100644
--- a/docs/_posts/2020-10-09-gcp_detect_accounts_with_high_risk_roles_by_project.md
+++ b/docs/_posts/2020-10-09-gcp_detect_accounts_with_high_risk_roles_by_project.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-09-gcp_detect_high_risk_permissions_by_resource_and_account.md b/docs/_posts/2020-10-09-gcp_detect_high_risk_permissions_by_resource_and_account.md
index 07fc7148c8..7c806051f4 100644
--- a/docs/_posts/2020-10-09-gcp_detect_high_risk_permissions_by_resource_and_account.md
+++ b/docs/_posts/2020-10-09-gcp_detect_high_risk_permissions_by_resource_and_account.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md
index 2eabd5a4ff..6bdaedeebb 100644
--- a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md
+++ b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ This search looks for specific authentication events from the Windows Security E
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_activity_related_to_pass_the_hash_attacks_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md
index c66ed418e7..c1c882fb2f 100644
--- a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md
+++ b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md
index 76955aa4d3..eea3a5f835 100644
--- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md
+++ b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md
@@ -30,7 +30,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -130,8 +130,8 @@ By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organiz
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_ipv6_network_infrastructure_threats_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md
index 27c6c5bc51..48f9cb455e 100644
--- a/docs/_posts/2020-10-28-detect_port_security_violation.md
+++ b/docs/_posts/2020-10-28-detect_port_security_violation.md
@@ -30,7 +30,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -129,8 +129,8 @@ By enabling Port Security on a Cisco switch you can restrict input to an interfa
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_port_security_violation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md
index 37506021e4..fc1a1717dd 100644
--- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md
+++ b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md
@@ -25,7 +25,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md
index 0ff385644e..98cb6fb60c 100644
--- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md
+++ b/docs/_posts/2020-10-28-detect_traffic_mirroring.md
@@ -28,7 +28,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -124,8 +124,8 @@ Adversaries may leverage traffic mirroring in order to automate data exfiltratio
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cisco_networks](https://github.com/splunk/security_content/blob/develop/macros/cisco_networks.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_traffic_mirroring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-11-06-ryuk_test_files_detected.md b/docs/_posts/2020-11-06-ryuk_test_files_detected.md
index 9523f43cb4..9911ea1c8c 100644
--- a/docs/_posts/2020-11-06-ryuk_test_files_detected.md
+++ b/docs/_posts/2020-11-06-ryuk_test_files_detected.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-06-windows_connhost_exe_started_forcefully.md b/docs/_posts/2020-11-06-windows_connhost_exe_started_forcefully.md
index ffa3d2b441..259b218d89 100644
--- a/docs/_posts/2020-11-06-windows_connhost_exe_started_forcefully.md
+++ b/docs/_posts/2020-11-06-windows_connhost_exe_started_forcefully.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md b/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md
index 36c61ed7ff..1582a7902e 100644
--- a/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md
+++ b/docs/_posts/2020-11-06-windows_security_account_manager_stopped.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-09-common_ransomware_extensions.md b/docs/_posts/2020-11-09-common_ransomware_extensions.md
index b65451dee5..9c7657c5d8 100644
--- a/docs/_posts/2020-11-09-common_ransomware_extensions.md
+++ b/docs/_posts/2020-11-09-common_ransomware_extensions.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ The search looks for file modifications with extensions commonly used by Ransomw
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [ransomware_extensions](https://github.com/splunk/security_content/blob/develop/macros/ransomware_extensions.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **common_ransomware_extensions_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-11-09-common_ransomware_notes.md b/docs/_posts/2020-11-09-common_ransomware_notes.md
index 97d3c5f84d..5e7b9a8a99 100644
--- a/docs/_posts/2020-11-09-common_ransomware_notes.md
+++ b/docs/_posts/2020-11-09-common_ransomware_notes.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -109,8 +109,8 @@ The search looks for files created with names matching those typically used in r
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [ransomware_notes](https://github.com/splunk/security_content/blob/develop/macros/ransomware_notes.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **common_ransomware_notes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-11-09-deleting_shadow_copies.md b/docs/_posts/2020-11-09-deleting_shadow_copies.md
index fa8862e06e..4491116390 100644
--- a/docs/_posts/2020-11-09-deleting_shadow_copies.md
+++ b/docs/_posts/2020-11-09-deleting_shadow_copies.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md
index e75d7d4931..2aa625dd0f 100644
--- a/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md
+++ b/docs/_posts/2020-11-09-detect_excessive_account_lockouts_from_endpoint.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md
index 55c8ff2d4e..c00120321f 100644
--- a/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md
+++ b/docs/_posts/2020-11-10-detect_processes_used_for_system_network_configuration_discovery.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ This search looks for fast execution of processes used for system network config
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [system_network_configuration_discovery_tools](https://github.com/splunk/security_content/blob/develop/macros/system_network_configuration_discovery_tools.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_processes_used_for_system_network_configuration_discovery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md
index 0e0621b0ae..9b5614b0b5 100644
--- a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md
+++ b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ This search looks for executions of cmd.exe spawned by a process that is often a
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
-* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml)
* [prohibited_apps_launching_cmd](https://github.com/splunk/security_content/blob/develop/macros/prohibited_apps_launching_cmd.yml)
+* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml)
Note that **detect_prohibited_applications_spawning_cmd_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md
index 134244855f..6098a953f6 100644
--- a/docs/_posts/2020-11-18-disabling_remote_user_account_control.md
+++ b/docs/_posts/2020-11-18-disabling_remote_user_account_control.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md
index 7c6c0f01f0..d018808b59 100644
--- a/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md
+++ b/docs/_posts/2020-11-18-execution_of_file_with_multiple_extensions.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-19-execution_of_file_with_spaces_before_extension.md b/docs/_posts/2020-11-19-execution_of_file_with_spaces_before_extension.md
index 87ee25c640..36de07d88f 100644
--- a/docs/_posts/2020-11-19-execution_of_file_with_spaces_before_extension.md
+++ b/docs/_posts/2020-11-19-execution_of_file_with_spaces_before_extension.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-23-processes_created_by_netsh.md b/docs/_posts/2020-11-23-processes_created_by_netsh.md
index 18a23c62e3..f6f8f87b86 100644
--- a/docs/_posts/2020-11-23-processes_created_by_netsh.md
+++ b/docs/_posts/2020-11-23-processes_created_by_netsh.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md
index 6bd8aaf93b..79a8231a89 100644
--- a/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md
+++ b/docs/_posts/2020-11-23-shim_database_installation_with_suspicious_parameters.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md
index bc69dca97c..3ab3b1e4e3 100644
--- a/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md
+++ b/docs/_posts/2020-11-26-reg_exe_manipulating_windows_services_registry_keys.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md
index 28e8dc1375..7478fda0ee 100644
--- a/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md
+++ b/docs/_posts/2020-12-07-schtasks_used_for_forcing_a_reboot.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-08-shim_database_file_creation.md b/docs/_posts/2020-12-08-shim_database_file_creation.md
index ad652b1afd..b0ff0c00ec 100644
--- a/docs/_posts/2020-12-08-shim_database_file_creation.md
+++ b/docs/_posts/2020-12-08-shim_database_file_creation.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md
index b5ea8e9863..55c2200690 100644
--- a/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md
+++ b/docs/_posts/2020-12-08-single_letter_process_on_endpoint.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md
index 42d7edeef6..6ad3971cfe 100644
--- a/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md
+++ b/docs/_posts/2020-12-08-system_processes_run_from_unexpected_locations.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -116,8 +116,8 @@ During triage, review the parallel processes - what process moved the native Win
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [is_windows_system_file](https://github.com/splunk/security_content/blob/develop/macros/is_windows_system_file.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **system_processes_run_from_unexpected_locations_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-12-08-unusually_long_command_line.md b/docs/_posts/2020-12-08-unusually_long_command_line.md
index fb85f45b4f..a71cf9522e 100644
--- a/docs/_posts/2020-12-08-unusually_long_command_line.md
+++ b/docs/_posts/2020-12-08-unusually_long_command_line.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md
index 0b5044b9fc..7eb1110305 100644
--- a/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md
+++ b/docs/_posts/2020-12-08-wmi_permanent_event_subscription_-_sysmon.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md
index 58d9b858c1..07bd8c32fe 100644
--- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md
+++ b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **sunburst_correlation_dll_and_network_event_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md
index fc881e7ca1..4389816a8d 100644
--- a/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md
+++ b/docs/_posts/2020-12-15-o365_suspicious_rights_delegation.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md
index 6695f32192..e5ddbf3202 100644
--- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md
+++ b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-16-o365_pst_export_alert.md b/docs/_posts/2020-12-16-o365_pst_export_alert.md
index a7bc06c011..ebd0b27b67 100644
--- a/docs/_posts/2020-12-16-o365_pst_export_alert.md
+++ b/docs/_posts/2020-12-16-o365_pst_export_alert.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md
index b3a5e29bb6..1c916f64f4 100644
--- a/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md
+++ b/docs/_posts/2020-12-16-o365_suspicious_admin_email_forwarding.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md
index 86a3931e47..56fe380a87 100644
--- a/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md
+++ b/docs/_posts/2020-12-16-o365_suspicious_user_email_forwarding.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md b/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md
index 447549f4e1..f789df6bf9 100644
--- a/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md
+++ b/docs/_posts/2020-12-21-bcdedit_failure_recovery_modification.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-06-supernova_webshell.md b/docs/_posts/2021-01-06-supernova_webshell.md
index 3b00b01d2b..eb14e131c0 100644
--- a/docs/_posts/2021-01-06-supernova_webshell.md
+++ b/docs/_posts/2021-01-06-supernova_webshell.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md b/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md
index 0e2c303a9a..de007cba35 100644
--- a/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md
+++ b/docs/_posts/2021-01-11-aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -107,8 +107,8 @@ This search provides detection of KMS keys where action kms:Encrypt is accessibl
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md b/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md
index ea27ea6f41..b8ad609ac6 100644
--- a/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md
+++ b/docs/_posts/2021-01-11-aws_detect_users_with_kms_keys_performing_encryption_s3.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This search provides detection of users with KMS keys performing encryption spec
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_detect_users_with_kms_keys_performing_encryption_s3_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md
index a20843401c..cafbd2abc8 100644
--- a/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md
+++ b/docs/_posts/2021-01-11-aws_network_access_control_list_created_with_all_open_ports.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ The search looks for AWS CloudTrail events to detect if any network ACLs were cr
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_network_access_control_list_created_with_all_open_ports_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md
index 74562f94e1..7f06af1025 100644
--- a/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md
+++ b/docs/_posts/2021-01-12-aws_network_access_control_list_deleted.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ Enforcing network-access controls is one of the defensive mechanisms used by clo
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_network_access_control_list_deleted_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md
index 8ee90b72b9..abd6664045 100644
--- a/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md
+++ b/docs/_posts/2021-01-12-suspicious_microsoft_workflow_compiler_usage.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following analytic identifies microsoft.workflow.compiler.exe usage. microso
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_microsoftworkflowcompiler](https://github.com/splunk/security_content/blob/develop/macros/process_microsoftworkflowcompiler.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_microsoft_workflow_compiler_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md
index 0e3806ea76..5d96425130 100644
--- a/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md
+++ b/docs/_posts/2021-01-12-suspicious_msbuild_spawn.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavi
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_msbuild](https://github.com/splunk/security_content/blob/develop/macros/process_msbuild.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_msbuild_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md
index b9fcb706d2..2d4000fc81 100644
--- a/docs/_posts/2021-01-12-suspicious_mshta_child_process.md
+++ b/docs/_posts/2021-01-12-suspicious_mshta_child_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md
index 2a316b7906..bbd7ee2658 100644
--- a/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md
+++ b/docs/_posts/2021-01-14-detect_hosts_connecting_to_dynamic_domain_providers.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ Malicious actors often abuse legitimate Dynamic DNS services to host malicious p
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [dynamic_dns_providers](https://github.com/splunk/security_content/blob/develop/macros/dynamic_dns_providers.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_hosts_connecting_to_dynamic_domain_providers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md
index 8f27aa6c43..9bbe4597cb 100644
--- a/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md
+++ b/docs/_posts/2021-01-19-malicious_powershell_process_with_obfuscation_techniques.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -119,8 +119,8 @@ This search looks for PowerShell processes launched with arguments that have cha
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **malicious_powershell_process_with_obfuscation_techniques_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-19-suspicious_powershell_command-line_arguments.md b/docs/_posts/2021-01-19-suspicious_powershell_command-line_arguments.md
index 7fad9174ed..25123ce00b 100644
--- a/docs/_posts/2021-01-19-suspicious_powershell_command-line_arguments.md
+++ b/docs/_posts/2021-01-19-suspicious_powershell_command-line_arguments.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md
index 53eb941af2..b5e9238218 100644
--- a/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md
+++ b/docs/_posts/2021-01-20-detect_rundll32_inline_hta_execution.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md
index a0e541b2ca..f80c516381 100644
--- a/docs/_posts/2021-01-20-suspicious_mshta_spawn.md
+++ b/docs/_posts/2021-01-20-suspicious_mshta_spawn.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_mshta_spawn_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md b/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md
index cc81f64a4c..da29d68bc8 100644
--- a/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md
+++ b/docs/_posts/2021-01-22-wbadmin_delete_system_backups.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md b/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md
index a33efb5185..837308bdf9 100644
--- a/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md
+++ b/docs/_posts/2021-01-26-aws_saml_access_by_provider_user_and_principal.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This search provides specific SAML access from specific Service Provider, user a
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_saml_access_by_provider_user_and_principal_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md b/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md
index 12b3589f24..e33bebfe86 100644
--- a/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md
+++ b/docs/_posts/2021-01-26-aws_saml_update_identity_provider.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This search provides detection of updates to SAML provider in AWS. Updates to SA
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_saml_update_identity_provider_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md b/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md
index 36145ee1f4..beef988c15 100644
--- a/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md
+++ b/docs/_posts/2021-01-26-certutil_exe_certificate_extraction.md
@@ -15,7 +15,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md
index ae1faef83a..471fe73ca8 100644
--- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md
+++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_ec2_instance.md
@@ -14,7 +14,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md
index d1721aae97..33fe7b4b24 100644
--- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md
+++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md
@@ -16,7 +16,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md
index ecf695a712..aca8baaa06 100644
--- a/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md
+++ b/docs/_posts/2021-01-26-o365_add_app_role_assignment_grant_user.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md
index a225ee8e1e..7b3a7560c9 100644
--- a/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md
+++ b/docs/_posts/2021-01-26-o365_excessive_sso_logon_errors.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md
index 8dd8f7ba2b..9c5d8a821b 100644
--- a/docs/_posts/2021-01-26-o365_new_federated_domain_added.md
+++ b/docs/_posts/2021-01-26-o365_new_federated_domain_added.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-26-revil_registry_entry.md b/docs/_posts/2021-01-26-revil_registry_entry.md
index 374282cda4..a1f5ec5cb7 100644
--- a/docs/_posts/2021-01-26-revil_registry_entry.md
+++ b/docs/_posts/2021-01-26-revil_registry_entry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md
index e35de0fc20..b6d7196f47 100644
--- a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md
+++ b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md
index 91ddf2a76c..23f23aa231 100644
--- a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md
+++ b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md
index 1159471776..44aadcdcd5 100644
--- a/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md
+++ b/docs/_posts/2021-01-28-detect_regsvr32_application_control_bypass.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ Upon investigating, look for network connections to remote destinations (interna
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_regsvr32_application_control_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md
index c6f240a0d1..5fe7848c2a 100644
--- a/docs/_posts/2021-01-28-ntdsutil_export_ntds.md
+++ b/docs/_posts/2021-01-28-ntdsutil_export_ntds.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md
index d383a80f4d..bc7f06d9e2 100644
--- a/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md
+++ b/docs/_posts/2021-01-28-suspicious_regsvr32_register_suspicious_path.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_regsvr32_register_suspicious_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md
index ccb3f80946..b9e2165474 100644
--- a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md
+++ b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-01-dump_lsass_via_procdump_rename.md b/docs/_posts/2021-02-01-dump_lsass_via_procdump_rename.md
index 98eeed668c..90823c0b23 100644
--- a/docs/_posts/2021-02-01-dump_lsass_via_procdump_rename.md
+++ b/docs/_posts/2021-02-01-dump_lsass_via_procdump_rename.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ During triage, confirm this is procdump.exe executing. If it is the first time a
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **dump_lsass_via_procdump_rename_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md
index 8390feaf8e..f23fb92693 100644
--- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md
+++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_advpack.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md
index c69a80a8cb..ce0649ac9e 100644
--- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md
+++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_setupapi.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md
index 59735fc482..03a4324b24 100644
--- a/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md
+++ b/docs/_posts/2021-02-04-detect_rundll32_application_control_bypass_-_syssetup.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md
index 946ab0e4ed..362e55f907 100644
--- a/docs/_posts/2021-02-04-suspicious_rundll32_startw.md
+++ b/docs/_posts/2021-02-04-suspicious_rundll32_startw.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md
index 3780f815a6..5fb954fd14 100644
--- a/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md
+++ b/docs/_posts/2021-02-09-suspicious_rundll32_dllregisterserver.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md
index 7389ff250a..4176718d5b 100644
--- a/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md
+++ b/docs/_posts/2021-02-11-detect_html_help_spawn_child_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md
index 0ed0bf6012..90c6d32acb 100644
--- a/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md
+++ b/docs/_posts/2021-02-12-detect_regasm_spawning_a_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md
index b21be132e1..bf456604ba 100644
--- a/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md
+++ b/docs/_posts/2021-02-12-detect_regsvcs_spawning_a_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md
index 0e70fa2818..21edce5031 100644
--- a/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md
+++ b/docs/_posts/2021-02-22-cobalt_strike_named_pipes.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ Upon triage, review the process performing the named pipe. If it is explorer.exe
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **cobalt_strike_named_pipes_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md
index 51d6763076..16744b51c8 100644
--- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md
+++ b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md
index 3a1aa8c4af..7aced0d6ee 100644
--- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md
+++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md
@@ -25,7 +25,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md
index 6684c596ef..fc34668e91 100644
--- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md
+++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md
@@ -24,7 +24,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md
index b5069a51cb..e4c5b06925 100644
--- a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md
+++ b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md
@@ -20,7 +20,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md
index 337c7b7e45..4cdd869a2b 100644
--- a/docs/_posts/2021-03-01-fodhelper_uac_bypass.md
+++ b/docs/_posts/2021-03-01-fodhelper_uac_bypass.md
@@ -26,7 +26,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md
index ad6d500487..c759b86f75 100644
--- a/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md
+++ b/docs/_posts/2021-03-01-ryuk_wake_on_lan_command.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md
index 58ebb99a88..15c3cb3b99 100644
--- a/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md
+++ b/docs/_posts/2021-03-01-suspicious_scheduled_task_from_public_directory.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md
index 64a41e2444..018eef699e 100644
--- a/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md
+++ b/docs/_posts/2021-03-02-aws_setdefaultpolicyversion.md
@@ -26,7 +26,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ This search looks for AWS CloudTrail events where a user has set a default polic
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_setdefaultpolicyversion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md b/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md
index 0528d9497c..bb5bd29bc3 100644
--- a/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md
+++ b/docs/_posts/2021-03-02-unified_messaging_service_spawning_a_process.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md
index 5305e0d427..3f49fb69d7 100644
--- a/docs/_posts/2021-03-02-windows_disableantispyware_registry.md
+++ b/docs/_posts/2021-03-02-windows_disableantispyware_registry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md
index 58162b0639..45ed630e84 100644
--- a/docs/_posts/2021-03-03-nishang_powershelltcponeline.md
+++ b/docs/_posts/2021-03-03-nishang_powershelltcponeline.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **nishang_powershelltcponeline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-03-w3wp_spawning_shell.md b/docs/_posts/2021-03-03-w3wp_spawning_shell.md
index e5f91cd411..0481d59293 100644
--- a/docs/_posts/2021-03-03-w3wp_spawning_shell.md
+++ b/docs/_posts/2021-03-03-w3wp_spawning_shell.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,9 +117,9 @@ This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
+* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml)
-* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
Note that **w3wp_spawning_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md
index 13b8c77cf1..c7df8c82e1 100644
--- a/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md
+++ b/docs/_posts/2021-03-12-ransomware_notes_bulk_creation.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ The following analytics identifies a big number of instance of ransomware notes
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **ransomware_notes_bulk_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-12-resize_shadowstorage_volume.md b/docs/_posts/2021-03-12-resize_shadowstorage_volume.md
index 188fc9f4a8..dc8ba4ca74 100644
--- a/docs/_posts/2021-03-12-resize_shadowstorage_volume.md
+++ b/docs/_posts/2021-03-12-resize_shadowstorage_volume.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-03-16-high_process_termination_frequency.md b/docs/_posts/2021-03-16-high_process_termination_frequency.md
index 895cad31c1..f51c9026be 100644
--- a/docs/_posts/2021-03-16-high_process_termination_frequency.md
+++ b/docs/_posts/2021-03-16-high_process_termination_frequency.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This analytics are designed to indentify a high frequency of process termination
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **high_process_termination_frequency_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md b/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md
index 15fab392c7..0560a55d6b 100644
--- a/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md
+++ b/docs/_posts/2021-03-16-windows_high_file_deletion_frequency.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ This search looks for high frequency of file deletion relative to process name a
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_high_file_deletion_frequency_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-17-clop_common_exec_parameter.md b/docs/_posts/2021-03-17-clop_common_exec_parameter.md
index dc7696c984..7096a23a35 100644
--- a/docs/_posts/2021-03-17-clop_common_exec_parameter.md
+++ b/docs/_posts/2021-03-17-clop_common_exec_parameter.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md
index a0c77a5d05..aa748035da 100644
--- a/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md
+++ b/docs/_posts/2021-03-17-clop_ransomware_known_service_name.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ This detection is to identify the common service name created by the CLOP ransom
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **clop_ransomware_known_service_name_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-23-certutil_with_decode_argument.md b/docs/_posts/2021-03-23-certutil_with_decode_argument.md
index 535b08bf8c..eb93a257d8 100644
--- a/docs/_posts/2021-03-23-certutil_with_decode_argument.md
+++ b/docs/_posts/2021-03-23-certutil_with_decode_argument.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ CertUtil.exe may be used to `encode` and `decode` a file, including PE and scrip
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **certutil_with_decode_argument_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md
index e19498b493..627c984874 100644
--- a/docs/_posts/2021-03-29-powershell_start-bitstransfer.md
+++ b/docs/_posts/2021-03-29-powershell_start-bitstransfer.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -104,8 +104,8 @@ Start-BitsTransfer is the PowerShell "version" of BitsAdmin.exe. Similar functio
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **powershell_start-bitstransfer_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md
index 4c3a3cbd67..f53668c9f7 100644
--- a/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md
+++ b/docs/_posts/2021-03-31-aws_iam_successful_group_deletion.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ The following query uses IAM events to track the success of a group being delete
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_iam_successful_group_deletion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md
index 50b3f4da68..f0a64230be 100644
--- a/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md
+++ b/docs/_posts/2021-03-31-disabling_firewall_with_netsh.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This search is to identifies suspicious firewall disabling using netsh applicati
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **disabling_firewall_with_netsh_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-03-31-dsquery_domain_discovery.md b/docs/_posts/2021-03-31-dsquery_domain_discovery.md
index 206d347377..01acd8f8c0 100644
--- a/docs/_posts/2021-03-31-dsquery_domain_discovery.md
+++ b/docs/_posts/2021-03-31-dsquery_domain_discovery.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md b/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md
index 15947dcf4d..9474d4f5f4 100644
--- a/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md
+++ b/docs/_posts/2021-04-01-aws_iam_assume_role_policy_brute_force.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ The following detection identifies any malformed policy document exceptions with
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_iam_assume_role_policy_brute_force_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-01-aws_iam_delete_policy.md b/docs/_posts/2021-04-01-aws_iam_delete_policy.md
index 1575dfd36a..1b54fb783f 100644
--- a/docs/_posts/2021-04-01-aws_iam_delete_policy.md
+++ b/docs/_posts/2021-04-01-aws_iam_delete_policy.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -100,8 +100,8 @@ The following detection identifes when a policy is deleted on AWS. This does not
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_iam_delete_policy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md b/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md
index b793b9283d..bf24384fb4 100644
--- a/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md
+++ b/docs/_posts/2021-04-01-aws_iam_failure_group_deletion.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -100,8 +100,8 @@ This detection identifies failure attempts to delete groups. We want to identify
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_iam_failure_group_deletion_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md
index d2943a0edb..bd730c681b 100644
--- a/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md
+++ b/docs/_posts/2021-04-07-malicious_powershell_executed_as_a_service.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ This detection is to identify the abuse the Windows SC.exe to execute malicious
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **malicious_powershell_executed_as_a_service_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md
index e3ae03f1b1..28e354d369 100644
--- a/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md
+++ b/docs/_posts/2021-04-08-multiple_users_failing_to_authenticate_from_host_using_kerberos.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md
index a25c3b8fc1..b1e9e453eb 100644
--- a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md
+++ b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or was it v
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **winevent_scheduled_task_created_within_public_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-12-excel_spawning_powershell.md b/docs/_posts/2021-04-12-excel_spawning_powershell.md
index 18fceec683..02e0cd1de2 100644
--- a/docs/_posts/2021-04-12-excel_spawning_powershell.md
+++ b/docs/_posts/2021-04-12-excel_spawning_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following detection identifies Microsoft Excel spawning PowerShell. Typicall
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **excel_spawning_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md
index 7ad41cf22b..a5b9ca2779 100644
--- a/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md
+++ b/docs/_posts/2021-04-12-excel_spawning_windows_script_host.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md
index 3d06f1ae2c..81a1afef38 100644
--- a/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md
+++ b/docs/_posts/2021-04-12-winevent_scheduled_task_created_to_spawn_shell.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or via Task
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **winevent_scheduled_task_created_to_spawn_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-12-winword_spawning_powershell.md b/docs/_posts/2021-04-12-winword_spawning_powershell.md
index 7435c278a9..678824acda 100644
--- a/docs/_posts/2021-04-12-winword_spawning_powershell.md
+++ b/docs/_posts/2021-04-12-winword_spawning_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following detection identifies Microsoft Word spawning PowerShell. Typically
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **winword_spawning_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md
index f1f4f8875e..5cfd894eab 100644
--- a/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md
+++ b/docs/_posts/2021-04-12-winword_spawning_windows_script_host.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-13-aws_excessive_security_scanning.md b/docs/_posts/2021-04-13-aws_excessive_security_scanning.md
index d6de864826..5ac4cb9a25 100644
--- a/docs/_posts/2021-04-13-aws_excessive_security_scanning.md
+++ b/docs/_posts/2021-04-13-aws_excessive_security_scanning.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -107,8 +107,8 @@ This search looks for AWS CloudTrail events and analyse the amount of eventNames
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_excessive_security_scanning_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md
index 8637512555..46976b9a16 100644
--- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md
+++ b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_host_using_ntlm.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md
index 6999e763dd..24bc3a3b15 100644
--- a/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md
+++ b/docs/_posts/2021-04-13-multiple_users_failing_to_authenticate_from_process.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -135,6 +135,7 @@ A process failing to authenticate with multiple users is not a common behavior f
#### Associated Analytic story
* [Active Directory Password Spraying](/stories/active_directory_password_spraying)
+* [Insider Threat](/stories/insider_threat)
diff --git a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md
index fbe1690b51..ce669d8449 100644
--- a/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md
+++ b/docs/_posts/2021-04-13-multiple_users_remotely_failing_to_authenticate_from_host.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md
index f9539f7ce3..f9e6cc7e67 100644
--- a/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md
+++ b/docs/_posts/2021-04-13-office_application_spawn_rundll32_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-13-windows_users_authenticate_using_explicit_credentials.md b/docs/_posts/2021-04-13-windows_users_authenticate_using_explicit_credentials.md
index 52c3907f07..9f274afe25 100644
--- a/docs/_posts/2021-04-13-windows_users_authenticate_using_explicit_credentials.md
+++ b/docs/_posts/2021-04-13-windows_users_authenticate_using_explicit_credentials.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -134,6 +134,7 @@ A source user failing attempting to authenticate multiple users on a host is not
#### Associated Analytic story
* [Active Directory Password Spraying](/stories/active_directory_password_spraying)
+* [Insider Threat](/stories/insider_threat)
diff --git a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md
index 2df2c08b22..88fee77549 100644
--- a/docs/_posts/2021-04-14-office_document_creating_schedule_task.md
+++ b/docs/_posts/2021-04-14-office_document_creating_schedule_task.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ this search detects a potential malicious office document that create schedule t
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **office_document_creating_schedule_task_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-14-office_document_executing_macro_code.md b/docs/_posts/2021-04-14-office_document_executing_macro_code.md
index 4b21420204..5f0a270f86 100644
--- a/docs/_posts/2021-04-14-office_document_executing_macro_code.md
+++ b/docs/_posts/2021-04-14-office_document_executing_macro_code.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ this detection was designed to identifies suspicious office documents that using
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **office_document_executing_macro_code_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-14-windows_disabled_users_failing_to_authenticate_kerberos.md b/docs/_posts/2021-04-14-windows_disabled_users_failing_to_authenticate_kerberos.md
index 753a1faabf..2c7a532c78 100644
--- a/docs/_posts/2021-04-14-windows_disabled_users_failing_to_authenticate_kerberos.md
+++ b/docs/_posts/2021-04-14-windows_disabled_users_failing_to_authenticate_kerberos.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-14-windows_invalid_users_failed_authentication_via_kerberos.md b/docs/_posts/2021-04-14-windows_invalid_users_failed_authentication_via_kerberos.md
index 07181f8a47..7a5d4a4773 100644
--- a/docs/_posts/2021-04-14-windows_invalid_users_failed_authentication_via_kerberos.md
+++ b/docs/_posts/2021-04-14-windows_invalid_users_failed_authentication_via_kerberos.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md b/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md
index ed23e6ccca..16a2536be9 100644
--- a/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md
+++ b/docs/_posts/2021-04-15-dns_exfiltration_using_nslookup_app.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md
index 3254d7e5dc..b87ff4e494 100644
--- a/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md
+++ b/docs/_posts/2021-04-15-multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md
index c43e81b053..81fcfe56b7 100644
--- a/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md
+++ b/docs/_posts/2021-04-19-powershell_remote_thread_to_known_windows_process.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ this search is designed to detect suspicious powershell process that tries to in
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **powershell_remote_thread_to_known_windows_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md
index ecd709a0e6..6562dd05d1 100644
--- a/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md
+++ b/docs/_posts/2021-04-19-schedule_task_with_http_command_arguments.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -105,8 +105,8 @@ The following query utilizes Windows Security EventCode 4698, `A scheduled task
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **schedule_task_with_http_command_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md
index ef713b2e06..e2752b6b07 100644
--- a/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md
+++ b/docs/_posts/2021-04-19-schedule_task_with_rundll32_command_trigger.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -105,8 +105,8 @@ The following query utilizes Windows Security EventCode 4698, `A scheduled task
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **schedule_task_with_rundll32_command_trigger_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md
index 73bc6c0ec9..0f6ecbc0b4 100644
--- a/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md
+++ b/docs/_posts/2021-04-19-wermgr_process_connecting_to_ip_check_web_services.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ this search is designed to detect suspicious wermgr.exe process that tries to co
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **wermgr_process_connecting_to_ip_check_web_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md
index cd138f7ea3..9b1a30b5d4 100644
--- a/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md
+++ b/docs/_posts/2021-04-19-wermgr_process_create_executable_file.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ this search is designed to detect potential malicious wermgr.exe process that dr
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **wermgr_process_create_executable_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md
index 94528e236a..25d42829d4 100644
--- a/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md
+++ b/docs/_posts/2021-04-19-wermgr_process_spawned_cmd_or_powershell_process.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,9 +103,9 @@ This search is designed to detect suspicious cmd and powershell process spawned
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
+* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml)
-* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
Note that **wermgr_process_spawned_cmd_or_powershell_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md
index ed31a7793f..201d862190 100644
--- a/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md
+++ b/docs/_posts/2021-04-21-excessive_usage_of_nslookup_app.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect potential DNS exfiltration using nslookup application.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **excessive_usage_of_nslookup_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md
index 1da816b5f4..1d9cdde512 100644
--- a/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md
+++ b/docs/_posts/2021-04-21-multiple_archive_files_http_post_traffic.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -109,8 +109,8 @@ This search is designed to detect high frequency of archive files data exfiltrat
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **multiple_archive_files_http_post_traffic_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md
index e9cc22551c..43e32f4f6f 100644
--- a/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md
+++ b/docs/_posts/2021-04-22-anomalous_usage_of_7zip.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md
index 8a78a3bf34..33e0a32a4e 100644
--- a/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md
+++ b/docs/_posts/2021-04-22-office_product_spawning_rundll32_with_no_dll.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md
index b554f66150..4bf5f81e8f 100644
--- a/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md
+++ b/docs/_posts/2021-04-22-plain_http_post_exfiltrated_data.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect potential plain HTTP POST method data exfiltration. Thi
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [stream_http](https://github.com/splunk/security_content/blob/develop/macros/stream_http.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **plain_http_post_exfiltrated_data_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-22-winword_spawning_cmd.md b/docs/_posts/2021-04-22-winword_spawning_cmd.md
index f4e48abf0d..6e9d61dd23 100644
--- a/docs/_posts/2021-04-22-winword_spawning_cmd.md
+++ b/docs/_posts/2021-04-22-winword_spawning_cmd.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md
index 8022fbfc39..626f6ec2c3 100644
--- a/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md
+++ b/docs/_posts/2021-04-26-office_product_spawning_bitsadmin.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following detection identifies the latest behavior utilized by different mal
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **office_product_spawning_bitsadmin_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-26-office_product_spawning_certutil.md b/docs/_posts/2021-04-26-office_product_spawning_certutil.md
index f8f6a61372..d611202a2d 100644
--- a/docs/_posts/2021-04-26-office_product_spawning_certutil.md
+++ b/docs/_posts/2021-04-26-office_product_spawning_certutil.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following detection identifies the latest behavior utilized by different mal
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **office_product_spawning_certutil_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-26-office_product_spawning_mshta.md b/docs/_posts/2021-04-26-office_product_spawning_mshta.md
index 3533abb60a..a1673f3155 100644
--- a/docs/_posts/2021-04-26-office_product_spawning_mshta.md
+++ b/docs/_posts/2021-04-26-office_product_spawning_mshta.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following detection identifies the latest behavior utilized by different mal
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **office_product_spawning_mshta_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-26-trickbot_named_pipe.md b/docs/_posts/2021-04-26-trickbot_named_pipe.md
index 1158b6cf9a..306eef602d 100644
--- a/docs/_posts/2021-04-26-trickbot_named_pipe.md
+++ b/docs/_posts/2021-04-26-trickbot_named_pipe.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ this search is to detect potential trickbot infection through the create/connect
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **trickbot_named_pipe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-29-icacls_deny_command.md b/docs/_posts/2021-04-29-icacls_deny_command.md
index 1a44f88cfd..876d74abce 100644
--- a/docs/_posts/2021-04-29-icacls_deny_command.md
+++ b/docs/_posts/2021-04-29-icacls_deny_command.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md
index 7db21c16a7..4b5f304a02 100644
--- a/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md
+++ b/docs/_posts/2021-04-29-suspicious_driver_loaded_path.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic will detect suspicious driver loaded paths. This technique is comm
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_driver_loaded_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-04-29-xmrig_driver_loaded.md b/docs/_posts/2021-04-29-xmrig_driver_loaded.md
index 0b79a8782f..0ffd07de20 100644
--- a/docs/_posts/2021-04-29-xmrig_driver_loaded.md
+++ b/docs/_posts/2021-04-29-xmrig_driver_loaded.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic identifies XMRIG coinminer driver installation on the system. The
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **xmrig_driver_loaded_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-05-04-deleting_of_net_users.md b/docs/_posts/2021-05-04-deleting_of_net_users.md
index 63888d2cb9..817bee63db 100644
--- a/docs/_posts/2021-05-04-deleting_of_net_users.md
+++ b/docs/_posts/2021-05-04-deleting_of_net_users.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This analytic will detect a suspicious net.exe/net1.exe command-line to delete a
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **deleting_of_net_users_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-05-04-disabling_net_user_account.md b/docs/_posts/2021-05-04-disabling_net_user_account.md
index bdb1491c51..107db93290 100644
--- a/docs/_posts/2021-05-04-disabling_net_user_account.md
+++ b/docs/_posts/2021-05-04-disabling_net_user_account.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This analytic will identify a suspicious command-line that disables a user accou
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **disabling_net_user_account_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md b/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md
index 5ed2cfa27c..36c22d74c1 100644
--- a/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md
+++ b/docs/_posts/2021-05-04-excessive_attempt_to_disable_services.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-04-excessive_service_stop_attempt.md b/docs/_posts/2021-05-04-excessive_service_stop_attempt.md
index 2510142ab6..11a5c85330 100644
--- a/docs/_posts/2021-05-04-excessive_service_stop_attempt.md
+++ b/docs/_posts/2021-05-04-excessive_service_stop_attempt.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -104,8 +104,8 @@ This analytic identifies suspicious series of attempt to kill multiple services
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **excessive_service_stop_attempt_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md
index bff59e613c..24c2ed96d5 100644
--- a/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md
+++ b/docs/_posts/2021-05-04-excessive_usage_of_taskkill.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-04-icacls_grant_command.md b/docs/_posts/2021-05-04-icacls_grant_command.md
index 79dbc6a308..9bd44013ea 100644
--- a/docs/_posts/2021-05-04-icacls_grant_command.md
+++ b/docs/_posts/2021-05-04-icacls_grant_command.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md
index a6f0eadd62..8b4b653a50 100644
--- a/docs/_posts/2021-05-04-process_kill_base_on_file_path.md
+++ b/docs/_posts/2021-05-04-process_kill_base_on_file_path.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-05-suspicious_process_file_path.md b/docs/_posts/2021-05-05-suspicious_process_file_path.md
index 7f8d2015e5..d8e2e848c9 100644
--- a/docs/_posts/2021-05-05-suspicious_process_file_path.md
+++ b/docs/_posts/2021-05-05-suspicious_process_file_path.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-06-download_files_using_telegram.md b/docs/_posts/2021-05-06-download_files_using_telegram.md
index a854bfb692..61901c3eb8 100644
--- a/docs/_posts/2021-05-06-download_files_using_telegram.md
+++ b/docs/_posts/2021-05-06-download_files_using_telegram.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ The following analytic will identify a suspicious download by the Telegram appli
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **download_files_using_telegram_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md
index bf23163ed6..5e3dabdc4a 100644
--- a/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md
+++ b/docs/_posts/2021-05-06-enumerate_users_local_group_using_telegram.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This analytic will detect a suspicious Telegram process enumerating all network
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **enumerate_users_local_group_using_telegram_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-05-06-excessive_usage_of_net_app.md b/docs/_posts/2021-05-06-excessive_usage_of_net_app.md
index ce6ef5b4e5..d25f9d4152 100644
--- a/docs/_posts/2021-05-06-excessive_usage_of_net_app.md
+++ b/docs/_posts/2021-05-06-excessive_usage_of_net_app.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -104,8 +104,8 @@ This analytic identifies excessive usage of `net.exe` or `net1.exe` within a buc
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **excessive_usage_of_net_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md
index e7d138d8f2..a9a0bb6527 100644
--- a/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md
+++ b/docs/_posts/2021-05-06-executables_or_script_creation_in_suspicious_path.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md b/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md
index 172b4f0ac3..aceca87902 100644
--- a/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md
+++ b/docs/_posts/2021-05-07-excessive_usage_of_cacls_app.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md b/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md
index 4d68f999ad..61be924e09 100644
--- a/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md
+++ b/docs/_posts/2021-05-07-schtasks_run_task_on_demand.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md b/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md
index cbfc56943f..8e9966a470 100644
--- a/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md
+++ b/docs/_posts/2021-05-12-delete_shadowcopy_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md
index b0016a85a6..01d4953eaf 100644
--- a/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md
+++ b/docs/_posts/2021-05-13-cmlua_or_cmstplua_uac_bypass.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This analytic detects a potential process using COM Object like CMLUA or CMSTPLU
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **cmlua_or_cmstplua_uac_bypass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-05-13-slui_runas_elevated.md b/docs/_posts/2021-05-13-slui_runas_elevated.md
index ad740ff550..2f279a4ca0 100644
--- a/docs/_posts/2021-05-13-slui_runas_elevated.md
+++ b/docs/_posts/2021-05-13-slui_runas_elevated.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-13-slui_spawning_a_process.md b/docs/_posts/2021-05-13-slui_spawning_a_process.md
index 37ae2ee3f5..ecc2a94b63 100644
--- a/docs/_posts/2021-05-13-slui_spawning_a_process.md
+++ b/docs/_posts/2021-05-13-slui_spawning_a_process.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-18-services_escalate_exe.md b/docs/_posts/2021-05-18-services_escalate_exe.md
index 054ab7177a..b73e5e7c23 100644
--- a/docs/_posts/2021-05-18-services_escalate_exe.md
+++ b/docs/_posts/2021-05-18-services_escalate_exe.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md
index f7c266b411..d3b5e586a7 100644
--- a/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md
+++ b/docs/_posts/2021-05-19-allow_inbound_traffic_in_firewall_rule.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md
index 901e844500..7499b742c8 100644
--- a/docs/_posts/2021-05-19-mailsniper_invoke_functions.md
+++ b/docs/_posts/2021-05-19-mailsniper_invoke_functions.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md
index b648276bce..b2f8a6b247 100644
--- a/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md
+++ b/docs/_posts/2021-05-20-cmd_echo_pipe_-_escalation.md
@@ -29,7 +29,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-21-winrm_spawning_a_process.md b/docs/_posts/2021-05-21-winrm_spawning_a_process.md
index 6c50a0ad1c..d73fcadf44 100644
--- a/docs/_posts/2021-05-21-winrm_spawning_a_process.md
+++ b/docs/_posts/2021-05-21-winrm_spawning_a_process.md
@@ -21,7 +21,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md
index 5ede6720a5..f87f6dd552 100644
--- a/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md
+++ b/docs/_posts/2021-05-26-secretdumps_offline_ntds_dumping_tool.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md
index a65e888144..ce320f7007 100644
--- a/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md
+++ b/docs/_posts/2021-05-27-detect_sharphound_file_modifications.md
@@ -36,7 +36,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-05-27-detect_sharphound_usage.md b/docs/_posts/2021-05-27-detect_sharphound_usage.md
index 3f19325d68..3279482058 100644
--- a/docs/_posts/2021-05-27-detect_sharphound_usage.md
+++ b/docs/_posts/2021-05-27-detect_sharphound_usage.md
@@ -36,7 +36,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md
index 7a763954c0..d12501f2a0 100644
--- a/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md
+++ b/docs/_posts/2021-06-01-detect_azurehound_command-line_arguments.md
@@ -36,7 +36,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md
index 7037ea35b7..3f89942edb 100644
--- a/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md
+++ b/docs/_posts/2021-06-01-detect_azurehound_file_modifications.md
@@ -36,7 +36,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md
index d5b1551e14..42588dabc5 100644
--- a/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md
+++ b/docs/_posts/2021-06-01-detect_sharphound_command-line_arguments.md
@@ -36,7 +36,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-02-conti_common_exec_parameter.md b/docs/_posts/2021-06-02-conti_common_exec_parameter.md
index d6723b7f04..b9569cb6e2 100644
--- a/docs/_posts/2021-06-02-conti_common_exec_parameter.md
+++ b/docs/_posts/2021-06-02-conti_common_exec_parameter.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-02-modification_of_wallpaper.md b/docs/_posts/2021-06-02-modification_of_wallpaper.md
index a296abe1a9..e8f877225c 100644
--- a/docs/_posts/2021-06-02-modification_of_wallpaper.md
+++ b/docs/_posts/2021-06-02-modification_of_wallpaper.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This analytic identifies suspicious modification of registry to deface or change
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **modification_of_wallpaper_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-06-02-revil_common_exec_parameter.md b/docs/_posts/2021-06-02-revil_common_exec_parameter.md
index 26fa5f1342..9725af2020 100644
--- a/docs/_posts/2021-06-02-revil_common_exec_parameter.md
+++ b/docs/_posts/2021-06-02-revil_common_exec_parameter.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md
index 1e9dc12127..7ae39f7e5d 100644
--- a/docs/_posts/2021-06-02-wbemprox_com_object_execution.md
+++ b/docs/_posts/2021-06-02-wbemprox_com_object_execution.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ this search is designed to detect potential malicious process loading COM object
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **wbemprox_com_object_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md
index e03accc979..f7499762cd 100644
--- a/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md
+++ b/docs/_posts/2021-06-04-known_services_killed_by_ransomware.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This search detects a suspicioous termination of known services killed by ransom
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **known_services_killed_by_ransomware_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md b/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md
index 170d22adf3..929c3bc8cf 100644
--- a/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md
+++ b/docs/_posts/2021-06-07-excessive_number_of_taskhost_processes.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md
index 99a2c0b97f..36b6da54e1 100644
--- a/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md
+++ b/docs/_posts/2021-06-08-powershell_fileless_process_injection_via_getprocaddress.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md
index 90d9809de5..14c0a3a393 100644
--- a/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md
+++ b/docs/_posts/2021-06-08-powershell_fileless_script_contains_base64_encoded_content.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md
index 5e23bdcc4b..d5235a3a57 100644
--- a/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md
+++ b/docs/_posts/2021-06-09-detect_empire_with_powershell_script_block_logging.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md b/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md
index 32a4ee8d2d..f2d74c4654 100644
--- a/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md
+++ b/docs/_posts/2021-06-09-detect_mimikatz_with_powershell_script_block_logging.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md
index 719003cc88..1cf0defddf 100644
--- a/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md
+++ b/docs/_posts/2021-06-09-unloading_amsi_via_reflection.md
@@ -1,6 +1,8 @@
---
title: "Unloading AMSI via Reflection"
excerpt: "Impair Defenses
+, PowerShell
+, Command and Scripting Interpreter
"
categories:
- Endpoint
@@ -9,7 +11,11 @@ toc: true
toc_label: ""
tags:
- Impair Defenses
+ - PowerShell
+ - Command and Scripting Interpreter
- Defense Evasion
+ - Execution
+ - Execution
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
@@ -17,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -45,6 +51,10 @@ During triage, review parallel processes using an EDR product or 4688 events. It
| -------------- | ---------------- |-------------------- |
| [T1562](https://attack.mitre.org/techniques/T1562/) | Impair Defenses | Defense Evasion |
+| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution |
+
+| [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution |
+
@@ -93,8 +103,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It
#### Search
```
-`powershell` EventCode=4104 Message=*system.management.automation.amsi*
-| stats count min(_time) as firstTime max(_time) as lastTime by OpCode ComputerName User EventCode Message
+`powershell` EventCode=4104 ScriptBlockText = *system.management.automation.amsi*
+| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `unloading_amsi_via_reflection_filter`
@@ -150,7 +160,7 @@ Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.
Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server)
-* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell.log)
+* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/windows-powershell-xml.log)
diff --git a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md
index f0d527ce43..d17e2a4dcd 100644
--- a/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md
+++ b/docs/_posts/2021-06-10-clear_unallocated_sector_using_cipher_app.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md
index 6f2b1af284..32020a650d 100644
--- a/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md
+++ b/docs/_posts/2021-06-10-disable_logs_using_wevtutil.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md b/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md
index dbc2ab8cb9..36ee7429d3 100644
--- a/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md
+++ b/docs/_posts/2021-06-10-permission_modification_using_takeown_app.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md
index 6115340021..178a4c5b4e 100644
--- a/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md
+++ b/docs/_posts/2021-06-10-powershell_creating_thread_mutex.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-10-powershell_domain_enumeration.md b/docs/_posts/2021-06-10-powershell_domain_enumeration.md
index c779915afa..fa73c67748 100644
--- a/docs/_posts/2021-06-10-powershell_domain_enumeration.md
+++ b/docs/_posts/2021-06-10-powershell_domain_enumeration.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_reflection.md b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_reflection.md
index 34207dc574..3f2f4fd322 100644
--- a/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_reflection.md
+++ b/docs/_posts/2021-06-10-powershell_loading_dotnet_into_memory_via_reflection.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md
index eff542efff..90a10cedfb 100644
--- a/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md
+++ b/docs/_posts/2021-06-10-powershell_processing_stream_of_data.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md b/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md
index 5ba60d93de..67a4fa8cc3 100644
--- a/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md
+++ b/docs/_posts/2021-06-10-prevent_automatic_repair_mode_using_bcdedit.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-10-recon_using_wmi_class.md b/docs/_posts/2021-06-10-recon_using_wmi_class.md
index c4ef2b0fe4..07d237d77d 100644
--- a/docs/_posts/2021-06-10-recon_using_wmi_class.md
+++ b/docs/_posts/2021-06-10-recon_using_wmi_class.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md b/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md
index 05a0825272..272f26e93c 100644
--- a/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md
+++ b/docs/_posts/2021-06-14-wmi_recon_running_process_or_services.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md
index fa06692d54..f7c1d774c5 100644
--- a/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md
+++ b/docs/_posts/2021-06-16-detect_wmi_event_subscription_persistence.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ Monitor for the creation of new WMI EventFilter, EventConsumer, and FilterToCons
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_wmi_event_subscription_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md
index 62f0415a0f..ff08bba7e0 100644
--- a/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md
+++ b/docs/_posts/2021-06-17-suspicious_event_log_service_behavior.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ The following analytic utilizes Windows Event ID 1100 to identify when Windows e
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_event_log_service_behavior_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md
index 93f0cb6512..2d4cab57ea 100644
--- a/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md
+++ b/docs/_posts/2021-06-22-execute_javascript_with_jscript_com_clsid.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md
index 701dd293f9..da5d61f998 100644
--- a/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md
+++ b/docs/_posts/2021-06-22-powershell_enable_smb1protocol_feature.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md
index cad4230f8c..a7016662cf 100644
--- a/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md
+++ b/docs/_posts/2021-06-22-recursive_delete_of_directory_in_batch_cmd.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md
index 205add643a..57de0d6b64 100644
--- a/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md
+++ b/docs/_posts/2021-06-23-allow_file_and_printing_sharing_in_firewall.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This search is to detect a suspicious modification of firewall to allow file and
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **allow_file_and_printing_sharing_in_firewall_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md
index 36ae60980d..3dc1d1e90d 100644
--- a/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md
+++ b/docs/_posts/2021-06-23-allow_network_discovery_in_firewall.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This search is to detect a suspicious modification to the firewall to allow netw
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **allow_network_discovery_in_firewall_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md
index 4750ec2ea0..f001969b6d 100644
--- a/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md
+++ b/docs/_posts/2021-06-24-excessive_usage_of_sc_service_utility.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ This search is to detect a suspicious excessive usage of sc.exe in a host machin
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **excessive_usage_of_sc_service_utility_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md
index 6671a1b142..c4549c62a8 100644
--- a/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md
+++ b/docs/_posts/2021-06-25-excessive_number_of_service_control_start_as_disabled.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md
index 385e312b70..59ecfb001e 100644
--- a/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md
+++ b/docs/_posts/2021-07-01-print_spooler_adding_a_printer_driver.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ During triage, isolate the endpoint and review for source of exploitation. Captu
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [printservice](https://github.com/splunk/security_content/blob/develop/macros/printservice.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **print_spooler_adding_a_printer_driver_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md
index 2eb3ddd701..bee1ca3516 100644
--- a/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md
+++ b/docs/_posts/2021-07-01-print_spooler_failed_to_load_a_plug-in.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -118,8 +118,8 @@ During triage, isolate the endpoint and review for source of exploitation. Captu
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [printservice](https://github.com/splunk/security_content/blob/develop/macros/printservice.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **print_spooler_failed_to_load_a_plug-in_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md
index bf0426e577..d6b3d4efe2 100644
--- a/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md
+++ b/docs/_posts/2021-07-01-spoolsv_spawning_rundll32.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md
index dbce47b9c7..cf63b73335 100644
--- a/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md
+++ b/docs/_posts/2021-07-01-spoolsv_suspicious_loaded_modules.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ This search is to detect suspicious loading of dll in specific path relative to
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **spoolsv_suspicious_loaded_modules_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md
index e28f396237..b1c9c00e93 100644
--- a/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md
+++ b/docs/_posts/2021-07-01-spoolsv_suspicious_process_access.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This analytic identifies a suspicious behavior related to PrintNightmare, or CVE
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **spoolsv_suspicious_process_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md
index 644dbc96bc..62ecbeca9d 100644
--- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md
+++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md
index 52f30c1349..1958550e28 100644
--- a/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md
+++ b/docs/_posts/2021-07-01-spoolsv_writing_a_dll_-_sysmon.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ The following analytic identifies a `.dll` being written by `spoolsv.exe`. This
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **spoolsv_writing_a_dll_-_sysmon_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md
index 421a6bb7bf..0bea15ccc2 100644
--- a/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md
+++ b/docs/_posts/2021-07-05-msmpeng_application_dll_side_loading.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md
index fc6a32f7ff..c20db73b1a 100644
--- a/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md
+++ b/docs/_posts/2021-07-05-powershell_disable_security_monitoring.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This search is to identifies a modification in registry to disable the windows d
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **powershell_disable_security_monitoring_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md
index 8c1957878b..ac99225112 100644
--- a/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md
+++ b/docs/_posts/2021-07-12-uac_bypass_mmc_load_unsigned_dll.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This search is to detect a suspicious loaded unsigned dll by MMC.exe application
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **uac_bypass_mmc_load_unsigned_dll_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md
index 8c47f9ca87..dee2144b49 100644
--- a/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md
+++ b/docs/_posts/2021-07-13-cloud_compute_instance_created_by_previously_unseen_user.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-19-aws_createloginprofile.md b/docs/_posts/2021-07-19-aws_createloginprofile.md
index d00adf12c1..d1434f91c2 100644
--- a/docs/_posts/2021-07-19-aws_createloginprofile.md
+++ b/docs/_posts/2021-07-19-aws_createloginprofile.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -116,8 +116,8 @@ This search looks for AWS CloudTrail events where a user A(victim A) creates a l
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_createloginprofile_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md b/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md
index a31e892d5a..6be6fa7578 100644
--- a/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md
+++ b/docs/_posts/2021-07-19-detect_new_open_s3_buckets.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ This search looks for AWS CloudTrail events where a user has created an open/pub
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_new_open_s3_buckets_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md b/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md
index 4ae443a594..442913a397 100644
--- a/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md
+++ b/docs/_posts/2021-07-19-detect_new_open_s3_buckets_over_aws_cli.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This search looks for AWS CloudTrail events where a user has created an open/pub
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_new_open_s3_buckets_over_aws_cli_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md
index ca29ba5912..e0df1506dc 100644
--- a/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md
+++ b/docs/_posts/2021-07-19-mshta_spawning_rundll32_or_regsvr32_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,9 +108,9 @@ This search is to detect a suspicious mshta.exe process that spawn rundll32 or r
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
+* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml)
* [process_rundll32](https://github.com/splunk/security_content/blob/develop/macros/process_rundll32.yml)
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
-* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml)
Note that **mshta_spawning_rundll32_or_regsvr32_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md
index 0cc6bbe956..7f8b1df18e 100644
--- a/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md
+++ b/docs/_posts/2021-07-19-office_product_spawn_cmd_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md b/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md
index a7b9c87d6f..3db74744e6 100644
--- a/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md
+++ b/docs/_posts/2021-07-20-detect_shared_ec2_snapshot.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md
index 593f93e968..96e3856208 100644
--- a/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md
+++ b/docs/_posts/2021-07-21-detect_copy_of_shadowcopy_with_script_block_logging.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md
index c157819162..92e4be7498 100644
--- a/docs/_posts/2021-07-23-sam_database_file_access_attempt.md
+++ b/docs/_posts/2021-07-23-sam_database_file_access_attempt.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md
index 9fbc6d0603..92e154dd20 100644
--- a/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md
+++ b/docs/_posts/2021-07-26-rundll32_createremotethread_in_browser.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ This analytic identifies the suspicious Remote Thread execution of rundll32.exe
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **rundll32_createremotethread_in_browser_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md
index f3edc8694b..5589ee3d62 100644
--- a/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md
+++ b/docs/_posts/2021-07-26-rundll32_process_creating_exe_dll_files.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect a suspicious rundll32 process that drops executable (.e
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **rundll32_process_creating_exe_dll_files_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md
index 49192440ea..b29002a9f8 100644
--- a/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md
+++ b/docs/_posts/2021-07-26-suspicious_icedid_rundll32_cmdline.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md
index c2fe18f32b..d8e94cc7d6 100644
--- a/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md
+++ b/docs/_posts/2021-07-26-suspicious_rundll32_plugininit.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-27-chcp_command_execution.md b/docs/_posts/2021-07-27-chcp_command_execution.md
index fced024e03..e40ac495db 100644
--- a/docs/_posts/2021-07-27-chcp_command_execution.md
+++ b/docs/_posts/2021-07-27-chcp_command_execution.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md b/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md
index 838c62d3d8..2d0876983f 100644
--- a/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md
+++ b/docs/_posts/2021-07-27-regsvr32_with_known_silent_switch_cmdline.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ The following analytic identifies Regsvr32.exe utilizing the silent switch to lo
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **regsvr32_with_known_silent_switch_cmdline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md
index e3d3f392d6..b947870fb1 100644
--- a/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md
+++ b/docs/_posts/2021-07-29-rundll32_create_remote_thread_to_a_process.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ This analytic identifies the suspicious Remote Thread execution of rundll32.exe
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **rundll32_create_remote_thread_to_a_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-30-drop_icedid_license_dat.md b/docs/_posts/2021-07-30-drop_icedid_license_dat.md
index 1642ea8715..783f700993 100644
--- a/docs/_posts/2021-07-30-drop_icedid_license_dat.md
+++ b/docs/_posts/2021-07-30-drop_icedid_license_dat.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect dropping a suspicious file named as "license.dat" in %a
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **drop_icedid_license_dat_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md
index 6edf12b83c..d2aebe361e 100644
--- a/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md
+++ b/docs/_posts/2021-07-30-icedid_exfiltrated_archived_file_creation.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect a suspicious file creation namely passff.tar and cookie
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **icedid_exfiltrated_archived_file_creation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md
index cf01b22b99..05a79d426a 100644
--- a/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md
+++ b/docs/_posts/2021-07-30-office_application_spawn_regsvr32_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ this detection was designed to identifies suspicious spawned process of known MS
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **office_application_spawn_regsvr32_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md
index 3d6d7f91e5..ed549f1f25 100644
--- a/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md
+++ b/docs/_posts/2021-08-03-sqlite_module_in_temp_folder.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This search is to detect a suspicious file creation of sqlite3.dll in %temp% fol
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **sqlite_module_in_temp_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md
index 63c7d6be6e..60c4c19f29 100644
--- a/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md
+++ b/docs/_posts/2021-08-04-create_remote_thread_in_shell_application.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ This search is to detect suspicious process injection in command shell. This tec
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **create_remote_thread_in_shell_application_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md
index 7d70e2753c..5f5b758c30 100644
--- a/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md
+++ b/docs/_posts/2021-08-09-uninstall_app_using_msiexec.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-11-fsutil_zeroing_file.md b/docs/_posts/2021-08-11-fsutil_zeroing_file.md
index f4d554b272..593f394f63 100644
--- a/docs/_posts/2021-08-11-fsutil_zeroing_file.md
+++ b/docs/_posts/2021-08-11-fsutil_zeroing_file.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md
index 0de21d0535..3410a03cc5 100644
--- a/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md
+++ b/docs/_posts/2021-08-13-uac_bypass_with_colorui_com_object.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect a possible uac bypass using the colorui.dll COM Object.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **uac_bypass_with_colorui_com_object_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md
index f718a90ab5..abd129ea17 100644
--- a/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md
+++ b/docs/_posts/2021-08-16-gsuite_drive_share_in_external_email.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ This search is to detect suspicious google drive or google docs files shared out
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [gsuite_drive](https://github.com/splunk/security_content/blob/develop/macros/gsuite_drive.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **gsuite_drive_share_in_external_email_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
@@ -135,6 +135,7 @@ network admin or normal user may share files to customer and external team.
#### Associated Analytic story
* [Dev Sec Ops](/stories/dev_sec_ops)
+* [Insider Threat](/stories/insider_threat)
diff --git a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md
index b9dacba00e..d43eea28f6 100644
--- a/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md
+++ b/docs/_posts/2021-08-16-gsuite_email_suspicious_attachment.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -107,8 +107,8 @@ This search is to detect a suspicious attachment file extension in Gsuite email
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **gsuite_email_suspicious_attachment_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md
index d609a050de..d398b66b8c 100644
--- a/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md
+++ b/docs/_posts/2021-08-17-7zip_commandline_to_smb_share_path.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md
index 053ef6340c..99671dd5d5 100644
--- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md
+++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_high.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -119,8 +119,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service (
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_ecr_container_scanning_findings_high_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md
index 70c74390d1..2d1998e85b 100644
--- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md
+++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_low_informational_unknown.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -119,8 +119,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service (
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_ecr_container_scanning_findings_low_informational_unknown_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md
index 847ba4d0b9..de76147256 100644
--- a/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md
+++ b/docs/_posts/2021-08-17-aws_ecr_container_scanning_findings_medium.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -119,8 +119,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service (
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_ecr_container_scanning_findings_medium_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md
index 65e14a484f..e55752595b 100644
--- a/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md
+++ b/docs/_posts/2021-08-17-gsuite_outbound_email_with_attachment_to_external_domain.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ This search is to detect a suspicious outbound e-mail from internal email to ext
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **gsuite_outbound_email_with_attachment_to_external_domain_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
@@ -129,6 +129,7 @@ network admin and normal user may send this file attachment as part of their day
#### Associated Analytic story
* [Dev Sec Ops](/stories/dev_sec_ops)
+* [Insider Threat](/stories/insider_threat)
diff --git a/docs/_posts/2021-08-18-esentutl_sam_copy.md b/docs/_posts/2021-08-18-esentutl_sam_copy.md
index 179470a163..be7d0ea0ac 100644
--- a/docs/_posts/2021-08-18-esentutl_sam_copy.md
+++ b/docs/_posts/2021-08-18-esentutl_sam_copy.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following analytic identifies the process - `esentutl.exe` - being used to c
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_esentutl](https://github.com/splunk/security_content/blob/develop/macros/process_esentutl.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **esentutl_sam_copy_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-18-powershell_4104_hunting.md b/docs/_posts/2021-08-18-powershell_4104_hunting.md
index 52a0b1d3ae..1351608297 100644
--- a/docs/_posts/2021-08-18-powershell_4104_hunting.md
+++ b/docs/_posts/2021-08-18-powershell_4104_hunting.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md
index 2e87df2551..527313a176 100644
--- a/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md
+++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_outside_business_hours.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service (
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_ecr_container_upload_outside_business_hours_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md
index 8bf711341c..82fc892395 100644
--- a/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md
+++ b/docs/_posts/2021-08-19-aws_ecr_container_upload_unknown_user.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,9 +115,9 @@ This search looks for AWS CloudTrail events from AWS Elastic Container Service (
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
-* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
* [aws_ecr_users](https://github.com/splunk/security_content/blob/develop/macros/aws_ecr_users.yml)
+* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_ecr_container_upload_unknown_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md
index 8cb486ef45..ae40c76c12 100644
--- a/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md
+++ b/docs/_posts/2021-08-19-gsuite_email_suspicious_subject_with_attachment.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ This search is to detect a gsuite email contains suspicious subject having known
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **gsuite_email_suspicious_subject_with_attachment_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md
index 792c4cde1e..676c320054 100644
--- a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md
+++ b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md
@@ -17,7 +17,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-20-github_commit_changes_in_master.md b/docs/_posts/2021-08-20-github_commit_changes_in_master.md
index 8cb069125a..d7d3d70b15 100644
--- a/docs/_posts/2021-08-20-github_commit_changes_in_master.md
+++ b/docs/_posts/2021-08-20-github_commit_changes_in_master.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This search is to detect a pushed or commit to master or main branch. This is to
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **github_commit_changes_in_master_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md b/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md
index e4bff95cbe..3b2578bb54 100644
--- a/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md
+++ b/docs/_posts/2021-08-20-kubernetes_nginx_ingress_lfi.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md
index 619162a960..1fdc4a6f05 100644
--- a/docs/_posts/2021-08-23-getlocaluser_with_powershell.md
+++ b/docs/_posts/2021-08-23-getlocaluser_with_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md
index 371d9b9057..4e28542135 100644
--- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md
+++ b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md
index 523e28b3c3..3299483619 100644
--- a/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md
+++ b/docs/_posts/2021-08-23-getwmiobject_user_account_with_powershell_script_block.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md
index 987ffab910..5ab03de085 100644
--- a/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md
+++ b/docs/_posts/2021-08-23-gsuite_email_with_known_abuse_web_service_link.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ This analytics is to detect a gmail containing a link that are known to be abuse
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [gsuite_gmail](https://github.com/splunk/security_content/blob/develop/macros/gsuite_gmail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **gsuite_email_with_known_abuse_web_service_link_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md
index 8cae71b6f8..69e85932a2 100644
--- a/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md
+++ b/docs/_posts/2021-08-23-gsuite_suspicious_shared_file_name.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ This search is to detect a shared file in google drive with suspicious file name
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [gsuite_drive](https://github.com/splunk/security_content/blob/develop/macros/gsuite_drive.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **gsuite_suspicious_shared_file_name_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md b/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md
index e60f72e3ca..2c43db94e5 100644
--- a/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md
+++ b/docs/_posts/2021-08-23-kubernetes_nginx_ingress_rfi.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md
index 718cf3c1f8..29da9115fb 100644
--- a/docs/_posts/2021-08-24-adsisearcher_account_discovery.md
+++ b/docs/_posts/2021-08-24-adsisearcher_account_discovery.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md
index c45d9dd9fb..fe7c05fb8f 100644
--- a/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md
+++ b/docs/_posts/2021-08-24-domain_account_discovery_with_dsquery.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md
index 5bd9295153..f8b212a37d 100644
--- a/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md
+++ b/docs/_posts/2021-08-24-domain_account_discovery_with_net_app.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **domain_account_discovery_with_net_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md
index 1ee95e1903..9344028a3c 100644
--- a/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md
+++ b/docs/_posts/2021-08-24-domain_account_discovery_with_wmic.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md b/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md
index e56cf8622f..40df4695b8 100644
--- a/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md
+++ b/docs/_posts/2021-08-24-get-domaintrust_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md b/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md
index 2517fc3fd2..680d6c6740 100644
--- a/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md
+++ b/docs/_posts/2021-08-24-get-domaintrust_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell.md b/docs/_posts/2021-08-24-get_aduser_with_powershell.md
index 9a408350ad..47bbe3d77a 100644
--- a/docs/_posts/2021-08-24-get_aduser_with_powershell.md
+++ b/docs/_posts/2021-08-24-get_aduser_with_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md
index 558f516974..4300497b95 100644
--- a/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md
+++ b/docs/_posts/2021-08-24-get_aduser_with_powershell_script_block.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md
index 8d25b236cb..a281179358 100644
--- a/docs/_posts/2021-08-24-get_domainuser_with_powershell.md
+++ b/docs/_posts/2021-08-24-get_domainuser_with_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md
index bbc1f91c9a..72be01f466 100644
--- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md
+++ b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md
index 1d7ad2997a..209e6fc97c 100644
--- a/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md
+++ b/docs/_posts/2021-08-24-getwmiobject_ds_user_with_powershell_script_block.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md b/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md
index 9dd84e7f6a..3731ae0ed6 100644
--- a/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md
+++ b/docs/_posts/2021-08-24-kubernetes_scanner_image_pulling.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md
index bd72a25c37..7e6c5a6d40 100644
--- a/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md
+++ b/docs/_posts/2021-08-25-domain_group_discovery_with_adsisearcher.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md
index 4700b5ffc0..533f6a5d41 100644
--- a/docs/_posts/2021-08-25-domain_group_discovery_with_net.md
+++ b/docs/_posts/2021-08-25-domain_group_discovery_with_net.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md
index ed160f58cb..1962d58d0c 100644
--- a/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md
+++ b/docs/_posts/2021-08-25-domain_group_discovery_with_wmic.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md
index 1f91ecbd22..772fd9b084 100644
--- a/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md
+++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_net.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md
index cbfd8b9b6d..fb42a72bad 100644
--- a/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md
+++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_powerview.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md
index 4b3a54b22c..8c2f9a1830 100644
--- a/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md
+++ b/docs/_posts/2021-08-25-elevated_group_discovery_with_wmic.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-getadgroup_with_powershell.md b/docs/_posts/2021-08-25-getadgroup_with_powershell.md
index 15a5c8f89c..f090faab40 100644
--- a/docs/_posts/2021-08-25-getadgroup_with_powershell.md
+++ b/docs/_posts/2021-08-25-getadgroup_with_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md
index f4167d61f3..24c6547c83 100644
--- a/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md
+++ b/docs/_posts/2021-08-25-getdomaingroup_with_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md b/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md
index f10e734570..c94843f7c4 100644
--- a/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md
+++ b/docs/_posts/2021-08-25-getnettcpconnection_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md
index 40b9bcec09..b5261b2918 100644
--- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md
+++ b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md
index 5e4319e7de..f93750f437 100644
--- a/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md
+++ b/docs/_posts/2021-08-25-getwmiobject_ds_group_with_powershell_script_block.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md
index 1e5abf7b0c..d53bf8a488 100644
--- a/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md
+++ b/docs/_posts/2021-08-26-get_addefaultdomainpasswordpolicy_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md
index 7181ea5035..32895ba17f 100644
--- a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md
+++ b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md
index 9a2c8c73c8..d14cb2b3d1 100644
--- a/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md
+++ b/docs/_posts/2021-08-26-get_aduserresultantpasswordpolicy_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md
index 59a92beff2..65a9bcd58d 100644
--- a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md
+++ b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md
index 7fc5d84c27..6aa9d42441 100644
--- a/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md
+++ b/docs/_posts/2021-08-26-get_domainpolicy_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md
index 669cc8eec9..d01d478628 100644
--- a/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md
+++ b/docs/_posts/2021-08-26-getdomaingroup_with_powershell_script_block.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-26-password_policy_discovery_with_net.md b/docs/_posts/2021-08-26-password_policy_discovery_with_net.md
index 074ac6c176..bd3b253c16 100644
--- a/docs/_posts/2021-08-26-password_policy_discovery_with_net.md
+++ b/docs/_posts/2021-08-26-password_policy_discovery_with_net.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md
index e2c3fb2e82..db0628bbb9 100644
--- a/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md
+++ b/docs/_posts/2021-08-26-process_creating_lnk_file_in_suspicious_location.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md
index 26b2b7d18c..73d2183b2e 100644
--- a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md
+++ b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -107,8 +107,8 @@ Review the source attempting to perform this activity against your environment.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [exchange](https://github.com/splunk/security_content/blob/develop/macros/exchange.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **exchange_powershell_abuse_via_ssrf_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md
index c15a96ad84..ebad7e3524 100644
--- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md
+++ b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md b/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md
index f2902e7957..89c7afc925 100644
--- a/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md
+++ b/docs/_posts/2021-08-30-domain_controller_discovery_with_nltest.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-30-remote_system_discovery_with_net.md b/docs/_posts/2021-08-30-remote_system_discovery_with_net.md
index e29a587403..58a5497db9 100644
--- a/docs/_posts/2021-08-30-remote_system_discovery_with_net.md
+++ b/docs/_posts/2021-08-30-remote_system_discovery_with_net.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md
index 80b87bd7d6..e0563e1381 100644
--- a/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md
+++ b/docs/_posts/2021-08-31-petitpotam_network_share_access_request.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ During triage, review parallel security events to identify further suspicious ac
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **petitpotam_network_share_access_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md
index ace1d3011d..7a201fa852 100644
--- a/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md
+++ b/docs/_posts/2021-08-31-petitpotam_suspicious_kerberos_tgt_request.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -105,8 +105,8 @@ The following analytic identifes Event Code 4768, A `Kerberos authentication tic
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **petitpotam_suspicious_kerberos_tgt_request_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md b/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md
index 2257445617..a8eab02ed5 100644
--- a/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md
+++ b/docs/_posts/2021-08-31-remote_system_discovery_with_dsquery.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md
index 413d248d1b..16f9fdc1a0 100644
--- a/docs/_posts/2021-09-01-circle_ci_disable_security_step.md
+++ b/docs/_posts/2021-09-01-circle_ci_disable_security_step.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ This search looks for disable security step in CircleCI pipeline.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **circle_ci_disable_security_step_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md b/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md
index 08187b3666..0ccb0de37d 100644
--- a/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md
+++ b/docs/_posts/2021-09-01-domain_controller_discovery_with_wmic.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md
index ded28ae614..560928d1f3 100644
--- a/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md
+++ b/docs/_posts/2021-09-01-domain_group_discovery_with_dsquery.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md b/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md
index 06ef4b38a0..2031b300d0 100644
--- a/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md
+++ b/docs/_posts/2021-09-01-getadcomputer_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md b/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md
index e5e3068d65..a4144ca572 100644
--- a/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md
+++ b/docs/_posts/2021-09-01-getwmiobject_ds_computer_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-01-github_commit_in_develop.md b/docs/_posts/2021-09-01-github_commit_in_develop.md
index 25c3927186..14146fe091 100644
--- a/docs/_posts/2021-09-01-github_commit_in_develop.md
+++ b/docs/_posts/2021-09-01-github_commit_in_develop.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -101,8 +101,8 @@ This search is to detect a pushed or commit to develop branch. This is to avoid
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **github_commit_in_develop_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-01-github_dependabot_alert.md b/docs/_posts/2021-09-01-github_dependabot_alert.md
index 9498c4e6a2..df2fa9e22b 100644
--- a/docs/_posts/2021-09-01-github_dependabot_alert.md
+++ b/docs/_posts/2021-09-01-github_dependabot_alert.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for Dependabot Alerts in Github logs.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **github_dependabot_alert_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md
index 3d1baf9a67..21f6a5b788 100644
--- a/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md
+++ b/docs/_posts/2021-09-01-github_pull_request_from_unknown_user.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,9 +114,9 @@ This search looks for Pull Request from unknown user.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
-* [github_known_users](https://github.com/splunk/security_content/blob/develop/macros/github_known_users.yml)
* [github](https://github.com/splunk/security_content/blob/develop/macros/github.yml)
+* [github_known_users](https://github.com/splunk/security_content/blob/develop/macros/github_known_users.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **github_pull_request_from_unknown_user_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md b/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md
index 59c88fc53a..4fb1e803cc 100644
--- a/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md
+++ b/docs/_posts/2021-09-01-remote_system_discovery_with_adsisearcher.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md b/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md
index c2020345d4..f21cf569e5 100644
--- a/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md
+++ b/docs/_posts/2021-09-01-remote_system_discovery_with_wmic.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md
index 4eb3d0488b..0594577878 100644
--- a/docs/_posts/2021-09-02-circle_ci_disable_security_job.md
+++ b/docs/_posts/2021-09-02-circle_ci_disable_security_job.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for disable security job in CircleCI pipeline.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [circleci](https://github.com/splunk/security_content/blob/develop/macros/circleci.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **circle_ci_disable_security_job_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md b/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md
index 88e79f9fd2..1050aa1e78 100644
--- a/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md
+++ b/docs/_posts/2021-09-02-get-foresttrust_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md b/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md
index f02f0cf197..fdeef8b8f2 100644
--- a/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md
+++ b/docs/_posts/2021-09-02-get-foresttrust_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -93,8 +93,8 @@ During triage, review parallel processes using an EDR product or 4688 events. It
#### Search
```
-`powershell` EventCode=4104 Message = "*get-foresttrust*"
-| stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode
+`powershell` EventCode=4104 ScriptBlockText = "*get-foresttrust*"
+| stats count min(_time) as firstTime max(_time) as lastTime by EventCode ScriptBlockText Computer user_id
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `get_foresttrust_with_powershell_script_block_filter`
@@ -121,7 +121,7 @@ Note that **get-foresttrust_with_powershell_script_block_filter** is a empty mac
To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
#### Known False Positives
-UPDATE_KNOWN_FALSE_POSITIVES
+False positives may be present. Tune as needed.
#### Associated Analytic story
* [Active Directory Discovery](/stories/active_directory_discovery)
@@ -147,7 +147,7 @@ Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.
Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server)
-* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell.log)
+* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell-xml.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-powershell-xml.log)
diff --git a/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md b/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md
index bab9ea64b1..5f39a66ce2 100644
--- a/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md
+++ b/docs/_posts/2021-09-02-getdomaincomputer_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md b/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md
index 8587fa0d68..6083fabcb4 100644
--- a/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md
+++ b/docs/_posts/2021-09-02-getdomaincontroller_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md b/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md
index f95cb82a9b..56f4b628cf 100644
--- a/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md
+++ b/docs/_posts/2021-09-06-bcdedit_command_back_to_normal_mode_boot.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md b/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md
index 9e88e01d9d..03cce0a089 100644
--- a/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md
+++ b/docs/_posts/2021-09-06-change_to_safe_mode_with_network_config.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md
index 1686072b64..00deb4123c 100644
--- a/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md
+++ b/docs/_posts/2021-09-06-correlation_by_repository_and_risk.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md
index 3909edb3f4..485c22af9b 100644
--- a/docs/_posts/2021-09-06-correlation_by_user_and_risk.md
+++ b/docs/_posts/2021-09-06-correlation_by_user_and_risk.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-07-getadcomputer_with_powershell.md b/docs/_posts/2021-09-07-getadcomputer_with_powershell.md
index af3985fa64..9a3ba5ec1d 100644
--- a/docs/_posts/2021-09-07-getadcomputer_with_powershell.md
+++ b/docs/_posts/2021-09-07-getadcomputer_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md b/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md
index 652c2bbf63..69ccb89dd4 100644
--- a/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md
+++ b/docs/_posts/2021-09-07-getdomaincomputer_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md b/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md
index 70c9b0df61..7f19e00592 100644
--- a/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md
+++ b/docs/_posts/2021-09-07-getdomaincontroller_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md b/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md
index 1db32dc7a8..370f0ba828 100644
--- a/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md
+++ b/docs/_posts/2021-09-07-getwmiobject_ds_computer_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md
index 5679158b61..163fc02b39 100644
--- a/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md
+++ b/docs/_posts/2021-09-07-schcache_change_by_app_connect_and_create_adsi_object.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This analytic is to detect an application try to connect and create ADSI Object
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **schcache_change_by_app_connect_and_create_adsi_object_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-07-system_information_discovery_detection.md b/docs/_posts/2021-09-07-system_information_discovery_detection.md
index a2c924e506..db747cb5eb 100644
--- a/docs/_posts/2021-09-07-system_information_discovery_detection.md
+++ b/docs/_posts/2021-09-07-system_information_discovery_detection.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md
index 3578087dc0..d93eb07694 100644
--- a/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md
+++ b/docs/_posts/2021-09-08-control_loading_from_world_writable_directory.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md
index 89b17543f7..7e88592aca 100644
--- a/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md
+++ b/docs/_posts/2021-09-08-create_local_admin_accounts_using_net_exe.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-08-office_spawning_control.md b/docs/_posts/2021-09-08-office_spawning_control.md
index 551671112f..b7a12fd9f2 100644
--- a/docs/_posts/2021-09-08-office_spawning_control.md
+++ b/docs/_posts/2021-09-08-office_spawning_control.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md
index 10acc58dff..2e96fe6ec3 100644
--- a/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md
+++ b/docs/_posts/2021-09-08-rundll32_control_rundll_hunt.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md
index 8dcec90e94..c863d92a32 100644
--- a/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md
+++ b/docs/_posts/2021-09-08-rundll32_control_rundll_world_writable_directory.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-09-extraction_of_registry_hives.md b/docs/_posts/2021-09-09-extraction_of_registry_hives.md
index 4bb0409bac..e4eaaab27e 100644
--- a/docs/_posts/2021-09-09-extraction_of_registry_hives.md
+++ b/docs/_posts/2021-09-09-extraction_of_registry_hives.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md
index e9d852091f..61af759d4b 100644
--- a/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md
+++ b/docs/_posts/2021-09-09-mshtml_module_load_in_office_product.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ The following detection identifies the module load of mshtml.dll into an Office
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **mshtml_module_load_in_office_product_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md b/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md
index 6379015a2f..bde39c4fb2 100644
--- a/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md
+++ b/docs/_posts/2021-09-10-getnettcpconnection_with_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md b/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md
index 15e62a9286..c470efdb9b 100644
--- a/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md
+++ b/docs/_posts/2021-09-10-network_connection_discovery_with_arp.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_net.md b/docs/_posts/2021-09-10-network_connection_discovery_with_net.md
index 2dcd1588cd..530c8c7be3 100644
--- a/docs/_posts/2021-09-10-network_connection_discovery_with_net.md
+++ b/docs/_posts/2021-09-10-network_connection_discovery_with_net.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md b/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md
index 137f00e536..caa32c5cbc 100644
--- a/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md
+++ b/docs/_posts/2021-09-10-network_connection_discovery_with_netstat.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md
index 2aa8e80891..d1353cef0a 100644
--- a/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md
+++ b/docs/_posts/2021-09-10-office_product_writing_cab_or_inf.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md b/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md
index e138e64cf9..fcde3d51ae 100644
--- a/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md
+++ b/docs/_posts/2021-09-13-getcurrent_user_with_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md
index 3b7b2966f0..3a9b0a61a7 100644
--- a/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md
+++ b/docs/_posts/2021-09-13-jscript_execution_using_cscript_app.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md
index 48a0b4de9a..001414c750 100644
--- a/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md
+++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_ldap_module.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **ms_scripting_process_loading_ldap_module_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md
index b9c551bed9..43351b858d 100644
--- a/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md
+++ b/docs/_posts/2021-09-13-ms_scripting_process_loading_wmi_module.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect a suspicious MS scripting process such as wscript.exe o
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **ms_scripting_process_loading_wmi_module_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-13-office_application_drop_executable.md b/docs/_posts/2021-09-13-office_application_drop_executable.md
index 0be5e7f52a..1df8b93a59 100644
--- a/docs/_posts/2021-09-13-office_application_drop_executable.md
+++ b/docs/_posts/2021-09-13-office_application_drop_executable.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-13-system_user_discovery_with_query.md b/docs/_posts/2021-09-13-system_user_discovery_with_query.md
index 2ad7dbf583..b97b92a8fa 100644
--- a/docs/_posts/2021-09-13-system_user_discovery_with_query.md
+++ b/docs/_posts/2021-09-13-system_user_discovery_with_query.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md b/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md
index 00563ff01e..aa3ef077ae 100644
--- a/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md
+++ b/docs/_posts/2021-09-13-system_user_discovery_with_whoami.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md
index b2b7f846f6..da8d0bcba2 100644
--- a/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md
+++ b/docs/_posts/2021-09-13-user_discovery_with_env_vars_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md
index 8197cdb8f8..e973a5464c 100644
--- a/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md
+++ b/docs/_posts/2021-09-13-xsl_script_execution_with_wmic.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md
index 4bf3e11d30..484a8bb37c 100644
--- a/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md
+++ b/docs/_posts/2021-09-14-cmdline_tool_not_executed_in_cmd_shell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md
index 6195a6221a..e43c9324ff 100644
--- a/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md
+++ b/docs/_posts/2021-09-14-get_wmiobject_group_discovery.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-14-net_localgroup_discovery.md b/docs/_posts/2021-09-14-net_localgroup_discovery.md
index c227813936..09c7ade0c7 100644
--- a/docs/_posts/2021-09-14-net_localgroup_discovery.md
+++ b/docs/_posts/2021-09-14-net_localgroup_discovery.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md
index 9a1ea5802b..4ef8ff8a53 100644
--- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md
+++ b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md
index a5eb79605f..2732f129ff 100644
--- a/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md
+++ b/docs/_posts/2021-09-14-powershell_get_localgroup_discovery_with_script_block_logging.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-14-wmic_group_discovery.md b/docs/_posts/2021-09-14-wmic_group_discovery.md
index 899fc48279..fd5ba2d674 100644
--- a/docs/_posts/2021-09-14-wmic_group_discovery.md
+++ b/docs/_posts/2021-09-14-wmic_group_discovery.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md b/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md
index cfede24e2d..8511b276a2 100644
--- a/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md
+++ b/docs/_posts/2021-09-15-check_elevated_cmd_using_whoami.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md
index c19b4e40ec..a8512fe65a 100644
--- a/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md
+++ b/docs/_posts/2021-09-15-non_chrome_process_accessing_chrome_default_dir.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect an anomaly event of non-chrome process accessing the fi
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **non_chrome_process_accessing_chrome_default_dir_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md
index 0e2aea7d72..7d77ef65e4 100644
--- a/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md
+++ b/docs/_posts/2021-09-15-non_firefox_process_access_firefox_profile_dir.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect an anomaly event of non-firefox process accessing the f
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **non_firefox_process_access_firefox_profile_dir_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-account_discovery_with_net_app.md b/docs/_posts/2021-09-16-account_discovery_with_net_app.md
index d2d47cd2e7..8689793b66 100644
--- a/docs/_posts/2021-09-16-account_discovery_with_net_app.md
+++ b/docs/_posts/2021-09-16-account_discovery_with_net_app.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -109,8 +109,8 @@ this search is to detect a potential account discovery series of command used by
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **account_discovery_with_net_app_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md
index 985920736d..d1ac8a3852 100644
--- a/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md
+++ b/docs/_posts/2021-09-16-attempt_to_add_certificate_to_untrusted_store.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ Attempt To Add Certificate To Untrusted Store
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **attempt_to_add_certificate_to_untrusted_store_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md
index d129d794bd..7fb61fc52a 100644
--- a/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md
+++ b/docs/_posts/2021-09-16-attempted_credential_dump_from_registry_via_reg_exe.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_cmd](https://github.com/splunk/security_content/blob/develop/macros/process_cmd.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_reg](https://github.com/splunk/security_content/blob/develop/macros/process_reg.yml)
Note that **attempted_credential_dump_from_registry_via_reg_exe_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-batch_file_write_to_system32.md b/docs/_posts/2021-09-16-batch_file_write_to_system32.md
index 9f525a1942..7573c5f585 100644
--- a/docs/_posts/2021-09-16-batch_file_write_to_system32.md
+++ b/docs/_posts/2021-09-16-batch_file_write_to_system32.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-16-bits_job_persistence.md b/docs/_posts/2021-09-16-bits_job_persistence.md
index 9d4c04f468..fdacda3ddd 100644
--- a/docs/_posts/2021-09-16-bits_job_persistence.md
+++ b/docs/_posts/2021-09-16-bits_job_persistence.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -104,8 +104,8 @@ The following query identifies Microsoft Background Intelligent Transfer Service
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **bits_job_persistence_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-bitsadmin_download_file.md b/docs/_posts/2021-09-16-bitsadmin_download_file.md
index 6b18c8083f..83b218db99 100644
--- a/docs/_posts/2021-09-16-bitsadmin_download_file.md
+++ b/docs/_posts/2021-09-16-bitsadmin_download_file.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -109,8 +109,8 @@ The following query identifies Microsoft Background Intelligent Transfer Service
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_bitsadmin](https://github.com/splunk/security_content/blob/develop/macros/process_bitsadmin.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **bitsadmin_download_file_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md
index db65257052..9faf96a248 100644
--- a/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md
+++ b/docs/_posts/2021-09-16-creation_of_shadow_copy_with_wmic_and_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,9 +113,9 @@ This search detects the use of wmic and Powershell to create a shadow copy.
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
+* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
* [process_wmic](https://github.com/splunk/security_content/blob/develop/macros/process_wmic.yml)
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
-* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
Note that **creation_of_shadow_copy_with_wmic_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md
index eae86f8ae3..57db84f496 100644
--- a/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md
+++ b/docs/_posts/2021-09-16-credential_dumping_via_copy_command_from_shadow_copy.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md
index 5b8f250241..212f87fed7 100644
--- a/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md
+++ b/docs/_posts/2021-09-16-credential_dumping_via_symlink_to_shadow_copy.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md
index 1238faa275..81c1a79387 100644
--- a/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md
+++ b/docs/_posts/2021-09-16-detect_html_help_url_in_command_line.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_html_help_url_in_command_line_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md
index 5fa2523bbd..9e4050d8ec 100644
--- a/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md
+++ b/docs/_posts/2021-09-16-detect_html_help_using_infotech_storage_handlers.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_hh](https://github.com/splunk/security_content/blob/develop/macros/process_hh.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_html_help_using_infotech_storage_handlers_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md
index 74e79b0469..1c02569aa9 100644
--- a/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md
+++ b/docs/_posts/2021-09-16-detect_mshta_inline_hta_execution.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ The following analytic identifies "mshta.exe" execution with inline protocol han
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_mshta_inline_hta_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md
index 43c9c44af6..f1bea5df87 100644
--- a/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md
+++ b/docs/_posts/2021-09-16-detect_mshta_url_in_command_line.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This analytic identifies when Microsoft HTML Application Host (mshta.exe) utilit
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_mshta](https://github.com/splunk/security_content/blob/develop/macros/process_mshta.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_mshta_url_in_command_line_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md
index 7135d6a736..e84a36cabe 100644
--- a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md
+++ b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [process_psexec](https://github.com/splunk/security_content/blob/develop/macros/process_psexec.yml)
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
+* [process_psexec](https://github.com/splunk/security_content/blob/develop/macros/process_psexec.yml)
Note that **detect_psexec_with_accepteula_flag_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-detect_renamed_7-zip.md b/docs/_posts/2021-09-16-detect_renamed_7-zip.md
index 98f422f76e..5825a0d34f 100644
--- a/docs/_posts/2021-09-16-detect_renamed_7-zip.md
+++ b/docs/_posts/2021-09-16-detect_renamed_7-zip.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-16-detect_renamed_rclone.md b/docs/_posts/2021-09-16-detect_renamed_rclone.md
index 08d288f6b1..86e2ed5f64 100644
--- a/docs/_posts/2021-09-16-detect_renamed_rclone.md
+++ b/docs/_posts/2021-09-16-detect_renamed_rclone.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-16-detect_renamed_winrar.md b/docs/_posts/2021-09-16-detect_renamed_winrar.md
index b7382fef74..70e3eeee35 100644
--- a/docs/_posts/2021-09-16-detect_renamed_winrar.md
+++ b/docs/_posts/2021-09-16-detect_renamed_winrar.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md
index 5120ca5611..68b311bd0a 100644
--- a/docs/_posts/2021-09-16-dump_lsass_via_procdump.md
+++ b/docs/_posts/2021-09-16-dump_lsass_via_procdump.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ During triage, confirm this is procdump.exe executing. If it is the first time a
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_procdump](https://github.com/splunk/security_content/blob/develop/macros/process_procdump.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **dump_lsass_via_procdump_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_net.md b/docs/_posts/2021-09-16-local_account_discovery_with_net.md
index 24a77cb66a..8493477b81 100644
--- a/docs/_posts/2021-09-16-local_account_discovery_with_net.md
+++ b/docs/_posts/2021-09-16-local_account_discovery_with_net.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic looks for the execution of `net.exe` or `net1.exe` with command-li
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_net](https://github.com/splunk/security_content/blob/develop/macros/process_net.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **local_account_discovery_with_net_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md
index 1c9cea77b2..214b8d7f54 100644
--- a/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md
+++ b/docs/_posts/2021-09-16-local_account_discovery_with_wmic.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-16-office_product_spawning_wmic.md b/docs/_posts/2021-09-16-office_product_spawning_wmic.md
index c376bc2512..93a8bf90d4 100644
--- a/docs/_posts/2021-09-16-office_product_spawning_wmic.md
+++ b/docs/_posts/2021-09-16-office_product_spawning_wmic.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-16-processes_launching_netsh.md b/docs/_posts/2021-09-16-processes_launching_netsh.md
index a6fa63324a..fd986d298a 100644
--- a/docs/_posts/2021-09-16-processes_launching_netsh.md
+++ b/docs/_posts/2021-09-16-processes_launching_netsh.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for processes launching netsh.exe. Netsh is a command-line scr
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_netsh](https://github.com/splunk/security_content/blob/develop/macros/process_netsh.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **processes_launching_netsh_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md
index 2101d93e7b..e65899557d 100644
--- a/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md
+++ b/docs/_posts/2021-09-20-office_document_spawned_child_process_to_download.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md b/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md
index c2bdeb5212..be19b45068 100644
--- a/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md
+++ b/docs/_posts/2021-09-21-remcos_rat_file_creation_in_remcos_folder.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md b/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md
index 809181e1fe..8571c61c67 100644
--- a/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md
+++ b/docs/_posts/2021-09-21-suspicious_image_creation_in_appdata_folder.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md b/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md
index 18f133b3ce..e6be7312e3 100644
--- a/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md
+++ b/docs/_posts/2021-09-21-suspicious_wav_file_in_appdata_folder.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-27-change_default_file_association.md b/docs/_posts/2021-09-27-change_default_file_association.md
index d575013b93..6268273a12 100644
--- a/docs/_posts/2021-09-27-change_default_file_association.md
+++ b/docs/_posts/2021-09-27-change_default_file_association.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md
index 1031804d60..fc1825c50b 100644
--- a/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md
+++ b/docs/_posts/2021-09-27-logon_script_event_trigger_execution.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md
index 95863ff7c3..bb5bb915f2 100644
--- a/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md
+++ b/docs/_posts/2021-09-27-screensaver_event_trigger_execution.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md
index eecad70e0d..235f92531a 100644
--- a/docs/_posts/2021-09-28-print_processor_registry_autostart.md
+++ b/docs/_posts/2021-09-28-print_processor_registry_autostart.md
@@ -25,7 +25,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-09-29-verclsid_clsid_execution.md b/docs/_posts/2021-09-29-verclsid_clsid_execution.md
index df46277db6..d4ca20a6f7 100644
--- a/docs/_posts/2021-09-29-verclsid_clsid_execution.md
+++ b/docs/_posts/2021-09-29-verclsid_clsid_execution.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic is to detect a possible abuse of verclsid to execute malicious fil
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_verclsid](https://github.com/splunk/security_content/blob/develop/macros/process_verclsid.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **verclsid_clsid_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md
index 7c3c0c36bf..0998e90d5a 100644
--- a/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md
+++ b/docs/_posts/2021-10-01-vbscript_execution_using_wscript_app.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md
index 20d2c25a79..7c91580c16 100644
--- a/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md
+++ b/docs/_posts/2021-10-04-msbuild_suspicious_spawned_by_script_process.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic is to detect a suspicious child process of MSBuild spawned by Wind
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_msbuild](https://github.com/splunk/security_content/blob/develop/macros/process_msbuild.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **msbuild_suspicious_spawned_by_script_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md b/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md
index 60cc951119..06706ff195 100644
--- a/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md
+++ b/docs/_posts/2021-10-04-regsvr32_silent_and_install_param_dll_loading.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ This analytic is to detect a loading of dll using regsvr32 application with sile
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_regsvr32](https://github.com/splunk/security_content/blob/develop/macros/process_regsvr32.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **regsvr32_silent_and_install_param_dll_loading_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-10-05-detect_exchange_web_shell.md b/docs/_posts/2021-10-05-detect_exchange_web_shell.md
index a0bb42b16f..787e32638e 100644
--- a/docs/_posts/2021-10-05-detect_exchange_web_shell.md
+++ b/docs/_posts/2021-10-05-detect_exchange_web_shell.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md
index 5d213c80d5..49a8fdf020 100644
--- a/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md
+++ b/docs/_posts/2021-10-05-malicious_inprocserver32_modification.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md
index a466d1f6bb..0a6b9d4d34 100644
--- a/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md
+++ b/docs/_posts/2021-10-05-process_writing_dynamicwrapperx.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md
index 4850cea3fa..5f2369b0c2 100644
--- a/docs/_posts/2021-10-05-rundll32_shimcache_flush.md
+++ b/docs/_posts/2021-10-05-rundll32_shimcache_flush.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md
index 1601238844..db1721c8c8 100644
--- a/docs/_posts/2021-10-05-suspicious_copy_on_system32.md
+++ b/docs/_posts/2021-10-05-suspicious_copy_on_system32.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic is to detect a suspicious copy of file from systemroot folder of t
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_copy](https://github.com/splunk/security_content/blob/develop/macros/process_copy.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_copy_on_system32_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md
index ba25a484ff..591e986c87 100644
--- a/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md
+++ b/docs/_posts/2021-10-05-winhlp32_spawning_a_process.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md
index 2c694027ef..bde26d3d18 100644
--- a/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md
+++ b/docs/_posts/2021-10-06-dns_query_length_with_high_standard_deviation.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-06-sdelete_application_execution.md b/docs/_posts/2021-10-06-sdelete_application_execution.md
index feeb557e2b..818be6bcea 100644
--- a/docs/_posts/2021-10-06-sdelete_application_execution.md
+++ b/docs/_posts/2021-10-06-sdelete_application_execution.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This analytic is to detect the execution of sdelete.exe application sysinternal
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_sdelete](https://github.com/splunk/security_content/blob/develop/macros/process_sdelete.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **sdelete_application_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md
index ba70937134..008e0d97d2 100644
--- a/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md
+++ b/docs/_posts/2021-10-06-wscript_or_cscript_suspicious_child_process.md
@@ -31,7 +31,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md
index caf2f1a03f..21b8b25ac0 100644
--- a/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md
+++ b/docs/_posts/2021-10-11-suspicious_wevtutil_usage.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md
index cb3dcd3623..1d3a2e11a7 100644
--- a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md
+++ b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_powershell.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md
index 3a534bdd2f..8d6c833cdb 100644
--- a/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md
+++ b/docs/_posts/2021-10-14-serviceprincipalnames_discovery_with_setspn.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-18-disable_schedule_task.md b/docs/_posts/2021-10-18-disable_schedule_task.md
index 2943b0a04b..c876b6ce23 100644
--- a/docs/_posts/2021-10-18-disable_schedule_task.md
+++ b/docs/_posts/2021-10-18-disable_schedule_task.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md b/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md
index 72411603de..1b5aa53ab2 100644
--- a/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md
+++ b/docs/_posts/2021-10-19-windows_curl_download_to_suspicious_path.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md
index db42484d58..2fe4868155 100644
--- a/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md
+++ b/docs/_posts/2021-10-19-winevent_windows_task_scheduler_event_action_started.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -104,8 +104,8 @@ The following hunting analytic assists with identifying suspicious tasks that ha
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_task_scheduler](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_task_scheduler.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **winevent_windows_task_scheduler_event_action_started_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md b/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md
index 19d164fe8a..d01b847fcf 100644
--- a/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md
+++ b/docs/_posts/2021-10-20-wmic_noninteractive_app_uninstallation.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md
index b866a2bf67..13ccb03567 100644
--- a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md
+++ b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md
index 7f9cbaa0e5..f39f15d3f2 100644
--- a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md
+++ b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md
@@ -19,7 +19,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-03-windows_adfind_exe.md b/docs/_posts/2021-11-03-windows_adfind_exe.md
index 2d33a7e038..f3e94e30af 100644
--- a/docs/_posts/2021-11-03-windows_adfind_exe.md
+++ b/docs/_posts/2021-11-03-windows_adfind_exe.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md b/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md
index 66f2db97da..c3427f8585 100644
--- a/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md
+++ b/docs/_posts/2021-11-04-attacker_tools_on_endpoint.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md b/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md
index 8a54d2656a..7b3a6af5b2 100644
--- a/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md
+++ b/docs/_posts/2021-11-10-windows_curl_upload_to_remote_destination.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md b/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md
index 2ce2d86564..3f1b9e7373 100644
--- a/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md
+++ b/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md b/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md
index d50220cb14..74c1095898 100644
--- a/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md
+++ b/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md b/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md
index 7c2b9a8602..a064ad9158 100644
--- a/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md
+++ b/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md b/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md
index f13678a0ac..b5ca9e2c09 100644
--- a/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md
+++ b/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md b/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md
index 1d9253db6d..c9b2572f78 100644
--- a/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md
+++ b/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md b/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md
index 1cfa95eeef..c32eeff0b0 100644
--- a/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md
+++ b/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md b/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md
index c207aec5b7..241067a47c 100644
--- a/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md
+++ b/docs/_posts/2021-11-11-wmic_xsl_execution_via_url.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md b/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md
index 601af0aab9..a0e67cae8d 100644
--- a/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md
+++ b/docs/_posts/2021-11-12-aws_iam_accessdenied_discovery_events.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -102,8 +102,8 @@ The following detection identifies excessive AccessDenied events within an hour
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_iam_accessdenied_discovery_events_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md b/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md
index c2f25f35dc..dc82c5a904 100644
--- a/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md
+++ b/docs/_posts/2021-11-12-csc_net_on_the_fly_compilation.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ this analytic is to detect a suspicious compile before delivery approach of .net
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_csc](https://github.com/splunk/security_content/blob/develop/macros/process_csc.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **csc_net_on_the_fly_compilation_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-12-firewall_allowed_program_enable.md b/docs/_posts/2021-11-12-firewall_allowed_program_enable.md
index 4b5f89536f..9f89254057 100644
--- a/docs/_posts/2021-11-12-firewall_allowed_program_enable.md
+++ b/docs/_posts/2021-11-12-firewall_allowed_program_enable.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md b/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md
index c6afd3bf3b..7877ac2a92 100644
--- a/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md
+++ b/docs/_posts/2021-11-12-network_discovery_using_route_windows_app.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md
index c463f21025..9baac4aa81 100644
--- a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md
+++ b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-12-runas_execution_in_commandline.md b/docs/_posts/2021-11-12-runas_execution_in_commandline.md
index 446258a518..1320fc8ca1 100644
--- a/docs/_posts/2021-11-12-runas_execution_in_commandline.md
+++ b/docs/_posts/2021-11-12-runas_execution_in_commandline.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ This analytic look for a spawned runas.exe process with a administrator user opt
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_runas](https://github.com/splunk/security_content/blob/develop/macros/process_runas.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **runas_execution_in_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-12-windows_installutil_credential_theft.md b/docs/_posts/2021-11-12-windows_installutil_credential_theft.md
index 4dcc0262e3..7f40445573 100644
--- a/docs/_posts/2021-11-12-windows_installutil_credential_theft.md
+++ b/docs/_posts/2021-11-12-windows_installutil_credential_theft.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ During triage review resulting network connections, file modifications, and para
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_installutil_credential_theft_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md b/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md
index c885bca329..680a007db7 100644
--- a/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md
+++ b/docs/_posts/2021-11-12-windows_installutil_uninstall_option.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ During triage review resulting network connections, file modifications, and para
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_installutil_uninstall_option_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md b/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md
index b4cbf4d03a..1efccc1685 100644
--- a/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md
+++ b/docs/_posts/2021-11-12-windows_installutil_url_in_command_line.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ During triage review resulting network connections, file modifications, and para
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_installutil_url_in_command_line_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md
index 83e3571dd1..bf9d884a5d 100644
--- a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md
+++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic looks for the execution of `powershell.exe` with arguments utilize
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **remote_process_instantiation_via_dcom_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md
index d8ae1a2601..5d297c98c1 100644
--- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md
+++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This analytic looks for the execution of `powershell.exe` leveraging the `Invoke
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **remote_process_instantiation_via_wmi_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md
index 2ee027b6a5..24bb7ca483 100644
--- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md
+++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-15-windows_diskcryptor_usage.md b/docs/_posts/2021-11-15-windows_diskcryptor_usage.md
index 749164711c..c102c46a7f 100644
--- a/docs/_posts/2021-11-15-windows_diskcryptor_usage.md
+++ b/docs/_posts/2021-11-15-windows_diskcryptor_usage.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md b/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md
index 5f53f8d528..42e6991bd8 100644
--- a/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md
+++ b/docs/_posts/2021-11-16-high_frequency_copy_of_files_in_network_share.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -128,6 +128,7 @@ this behavior may seen in normal transfer of file within network if network shar
#### Associated Analytic story
* [Information Sabotage](/stories/information_sabotage)
+* [Insider Threat](/stories/insider_threat)
diff --git a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md
index 441455f218..adbf129fb2 100644
--- a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md
+++ b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic looks for the execution of `powershell.exe` with arguments utilize
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **remote_process_instantiation_via_winrm_and_powershell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-17-windows_dism_remove_defender.md b/docs/_posts/2021-11-17-windows_dism_remove_defender.md
index a9d65d562c..62a962c521 100644
--- a/docs/_posts/2021-11-17-windows_dism_remove_defender.md
+++ b/docs/_posts/2021-11-17-windows_dism_remove_defender.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md
index 22a63d1076..76ddaa8e26 100644
--- a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md
+++ b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -105,8 +105,8 @@ The following analytic identifies executable files (.exe or .dll) being written
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **executable_file_written_in_administrative_smb_share_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md b/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md
index 5dd955aa03..13136b8bd8 100644
--- a/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md
+++ b/docs/_posts/2021-11-18-loading_of_dynwrapx_module.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ DynamicWrapperX is an ActiveX component that can be used in a script to call Win
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **loading_of_dynwrapx_module_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md
index de9d806cb6..26f1d24c96 100644
--- a/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md
+++ b/docs/_posts/2021-11-19-system_info_gathering_using_dxdiag_application.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md b/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md
index cb2f6fef65..b98b4b5bfa 100644
--- a/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md
+++ b/docs/_posts/2021-11-22-possible_browser_pass_view_parameter.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md
index 9cfdc8ebea..226bb733bc 100644
--- a/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md
+++ b/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md
index 5bd13df00c..fb167454e9 100644
--- a/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md
+++ b/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md
index 3b338d2744..90c3fbac45 100644
--- a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md
+++ b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -105,8 +105,8 @@ The following analytc uses Windows Event Id 7045, `New Service Was Installed`, t
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_service_created_with_suspicious_service_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md
index b9d4f933a3..42d8081d0e 100644
--- a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md
+++ b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -107,8 +107,8 @@ The following analytc uses Windows Event Id 7045, `New Service Was Installed`, t
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_service_created_within_public_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md
index 7ffe682eb2..d9996eed86 100644
--- a/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md
+++ b/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md
index 276d318044..3be0529034 100644
--- a/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md
+++ b/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md
index b017b11469..cafa08467b 100644
--- a/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md
+++ b/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md b/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md
index 936a9f865e..bb3c4996f7 100644
--- a/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md
+++ b/docs/_posts/2021-11-25-add_or_set_windows_defender_exclusion.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md b/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md
index 09c6ba2284..666580ebe2 100644
--- a/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md
+++ b/docs/_posts/2021-11-25-powershell_windows_defender_exclusion_commands.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md b/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md
index 3ff630a630..1eaa2cddfd 100644
--- a/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md
+++ b/docs/_posts/2021-11-25-windows_defender_exclusion_registry_entry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md b/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md
index be98c1a77d..ff159cfcdd 100644
--- a/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md
+++ b/docs/_posts/2021-11-29-detect_rclone_command-line_usage.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This analytic identifies commonly used command-line arguments used by `rclone.ex
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_rclone](https://github.com/splunk/security_content/blob/develop/macros/process_rclone.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_rclone_command-line_usage_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md b/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md
index f6a868912b..f5e24409c9 100644
--- a/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md
+++ b/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md
@@ -39,7 +39,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md
index 5c18f45018..045b3529ef 100644
--- a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md
+++ b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md
@@ -26,7 +26,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md
index b373d1d58f..1b1c3826a9 100644
--- a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md
+++ b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md
@@ -24,7 +24,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md
index 6df23d2125..930626cc08 100644
--- a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md
+++ b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md
index 4ddabc750f..ec64a1e108 100644
--- a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md
+++ b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md
@@ -22,7 +22,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-03-short_lived_scheduled_task.md b/docs/_posts/2021-12-03-short_lived_scheduled_task.md
index 2e30129165..f463a4671a 100644
--- a/docs/_posts/2021-12-03-short_lived_scheduled_task.md
+++ b/docs/_posts/2021-12-03-short_lived_scheduled_task.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-06-suspicious_linux_discovery_commands.md b/docs/_posts/2021-12-06-suspicious_linux_discovery_commands.md
index 2036a963e1..84c130af9d 100644
--- a/docs/_posts/2021-12-06-suspicious_linux_discovery_commands.md
+++ b/docs/_posts/2021-12-06-suspicious_linux_discovery_commands.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-07-ms_exchange_mailbox_replication_service_writing_active_server_pages.md b/docs/_posts/2021-12-07-ms_exchange_mailbox_replication_service_writing_active_server_pages.md
index 55b2b6652c..752bff1c36 100644
--- a/docs/_posts/2021-12-07-ms_exchange_mailbox_replication_service_writing_active_server_pages.md
+++ b/docs/_posts/2021-12-07-ms_exchange_mailbox_replication_service_writing_active_server_pages.md
@@ -26,7 +26,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md b/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md
index f299a1bfef..5d43bef40e 100644
--- a/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md
+++ b/docs/_posts/2021-12-07-windows_raccine_scheduled_task_deletion.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md b/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md
index 86ccb7816e..0872354df1 100644
--- a/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md
+++ b/docs/_posts/2021-12-08-msi_module_loaded_by_non-system_binary.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -119,8 +119,8 @@ In addition, `msi.dll` has been abused in DLL side-loading attacks by being load
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **msi_module_loaded_by_non-system_binary_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md
index 9d5565668b..be1cc636b0 100644
--- a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md
+++ b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-11-wget_download_and_bash_execution.md b/docs/_posts/2021-12-11-wget_download_and_bash_execution.md
index d1767dc18e..373429ed8b 100644
--- a/docs/_posts/2021-12-11-wget_download_and_bash_execution.md
+++ b/docs/_posts/2021-12-11-wget_download_and_bash_execution.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md b/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md
index 807b21055f..5a5d2074d3 100644
--- a/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md
+++ b/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md b/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md
index 967b055754..95c15ec2c8 100644
--- a/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md
+++ b/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-13-linux_java_spawning_shell.md b/docs/_posts/2021-12-13-linux_java_spawning_shell.md
index 30b6f0bc30..97dd38854b 100644
--- a/docs/_posts/2021-12-13-linux_java_spawning_shell.md
+++ b/docs/_posts/2021-12-13-linux_java_spawning_shell.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following analytic identifies the process name of Java, Apache, or Tomcat sp
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [linux_shells](https://github.com/splunk/security_content/blob/develop/macros/linux_shells.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **linux_java_spawning_shell_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md
index a73fcd86c1..394e00a8b0 100644
--- a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md
+++ b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md
index f7896912d1..c72d8c498f 100644
--- a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md
+++ b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md b/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md
index 898543d1d4..0d058a12f6 100644
--- a/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md
+++ b/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md
index 650a7cb569..bad02595fd 100644
--- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md
+++ b/docs/_posts/2021-12-13-windows_java_spawning_shells.md
@@ -21,7 +21,7 @@ tags:
We have not been able to test, simulate, or build datasets for this object. Use at your own risk. This analytic is **NOT** supported.
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ The following analytic identifies the process name of java.exe and w3wp.exe spaw
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_java_spawning_shells_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2021-12-14-hunting_for_log4shell.md b/docs/_posts/2021-12-14-hunting_for_log4shell.md
index d60970e27e..105f8f4794 100644
--- a/docs/_posts/2021-12-14-hunting_for_log4shell.md
+++ b/docs/_posts/2021-12-14-hunting_for_log4shell.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md b/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md
index 3ad2b9f0a3..44db15448a 100644
--- a/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md
+++ b/docs/_posts/2021-12-17-linux_add_files_in_known_crontab_directories.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md b/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md
index 1988954c6e..8b40120102 100644
--- a/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md
+++ b/docs/_posts/2021-12-17-linux_at_allow_config_file_creation.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-17-linux_at_application_execution.md b/docs/_posts/2021-12-17-linux_at_application_execution.md
index 15399f7704..a6c78fc0bc 100644
--- a/docs/_posts/2021-12-17-linux_at_application_execution.md
+++ b/docs/_posts/2021-12-17-linux_at_application_execution.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md b/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md
index 5dcf88553e..7e1cc034af 100644
--- a/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md
+++ b/docs/_posts/2021-12-17-linux_edit_cron_table_parameter.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md b/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md
index 302ab92b97..03fe7fd507 100644
--- a/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md
+++ b/docs/_posts/2021-12-17-linux_possible_append_command_to_at_allow_config_file.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md b/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md
index 473119e53b..ebb8598947 100644
--- a/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md
+++ b/docs/_posts/2021-12-17-linux_possible_append_cronjob_entry_on_existing_cronjob_file.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md b/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md
index c5a8a034a7..10e1bf4910 100644
--- a/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md
+++ b/docs/_posts/2021-12-17-linux_possible_cronjob_modification_with_editor.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md b/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md
index ddc781bd15..5c6edc4ffd 100644
--- a/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md
+++ b/docs/_posts/2021-12-20-linux_file_creation_in_init_boot_directory.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md b/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md
index a1e453bfe1..4cff71d540 100644
--- a/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md
+++ b/docs/_posts/2021-12-20-linux_file_creation_in_profile_directory.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md b/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md
index 2d585b9989..5dd8677ab6 100644
--- a/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md
+++ b/docs/_posts/2021-12-20-linux_possible_append_command_to_profile_config_file.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md b/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md
index c8d4e2ed1e..da16daa7b1 100644
--- a/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md
+++ b/docs/_posts/2021-12-20-linux_service_file_created_in_systemd_directory.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-20-linux_service_restarted.md b/docs/_posts/2021-12-20-linux_service_restarted.md
index 29b47b0992..b7396498e1 100644
--- a/docs/_posts/2021-12-20-linux_service_restarted.md
+++ b/docs/_posts/2021-12-20-linux_service_restarted.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-20-linux_service_started_or_enabled.md b/docs/_posts/2021-12-20-linux_service_started_or_enabled.md
index d7dac183bd..675b6a6c1e 100644
--- a/docs/_posts/2021-12-20-linux_service_started_or_enabled.md
+++ b/docs/_posts/2021-12-20-linux_service_started_or_enabled.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md b/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md
index 10d905a387..d82770f5c5 100644
--- a/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md
+++ b/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md
@@ -29,7 +29,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md b/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md
index 9288cc7567..8628490bf4 100644
--- a/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md
+++ b/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md
@@ -29,7 +29,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-21-linux_add_user_account.md b/docs/_posts/2021-12-21-linux_add_user_account.md
index 215aaa0b06..2ef4c647f5 100644
--- a/docs/_posts/2021-12-21-linux_add_user_account.md
+++ b/docs/_posts/2021-12-21-linux_add_user_account.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md b/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md
index 787bf9cf07..a377133dad 100644
--- a/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md
+++ b/docs/_posts/2021-12-21-linux_change_file_owner_to_root.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md b/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md
index 1435ec4b25..2781cd043e 100644
--- a/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md
+++ b/docs/_posts/2021-12-21-linux_nopasswd_entry_in_sudoers_file.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md b/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md
index 0a1f0db1f2..e5e15614e5 100644
--- a/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md
+++ b/docs/_posts/2021-12-21-linux_setuid_using_chmod_utility.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md b/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md
index 68d970d4fc..ce5b8d29c3 100644
--- a/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md
+++ b/docs/_posts/2021-12-21-linux_setuid_using_setcap_utility.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-21-linux_visudo_utility_execution.md b/docs/_posts/2021-12-21-linux_visudo_utility_execution.md
index d4b1ebd892..65d1e645ea 100644
--- a/docs/_posts/2021-12-21-linux_visudo_utility_execution.md
+++ b/docs/_posts/2021-12-21-linux_visudo_utility_execution.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md b/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md
index 190e88f27d..d9e5aea24e 100644
--- a/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md
+++ b/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md b/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md
index e03f211383..1dba2aa74f 100644
--- a/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md
+++ b/docs/_posts/2021-12-22-linux_file_created_in_kernel_driver_directory.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md b/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md
index 93b650fe0a..349d02b9a5 100644
--- a/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md
+++ b/docs/_posts/2021-12-22-linux_insert_kernel_module_using_insmod_utility.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md b/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md
index 2c8bf702b9..dc34a4c2a7 100644
--- a/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md
+++ b/docs/_posts/2021-12-22-linux_install_kernel_module_using_modprobe_utility.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md b/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md
index b2ab9b1edc..ea421b9a93 100644
--- a/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md
+++ b/docs/_posts/2021-12-22-linux_preload_hijack_library_calls.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md b/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md
index 630260d649..11a0298f78 100644
--- a/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md
+++ b/docs/_posts/2021-12-23-linux_common_process_for_elevation_control.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md b/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md
index 5ecd7ddeb9..0320145254 100644
--- a/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md
+++ b/docs/_posts/2021-12-23-linux_sudoers_tmp_file_creation.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md b/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md
index a4091d5bd5..3c9cdd3ad4 100644
--- a/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md
+++ b/docs/_posts/2022-01-04-linux_sudo_or_su_execution.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md b/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md
index fed38517b7..237b38f894 100644
--- a/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md
+++ b/docs/_posts/2022-01-05-linux_doas_conf_file_creation.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-05-linux_doas_tool_execution.md b/docs/_posts/2022-01-05-linux_doas_tool_execution.md
index 1599d008a8..b994f31e98 100644
--- a/docs/_posts/2022-01-05-linux_doas_tool_execution.md
+++ b/docs/_posts/2022-01-05-linux_doas_tool_execution.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md b/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md
index 8abacad923..ddecfbd480 100644
--- a/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md
+++ b/docs/_posts/2022-01-10-linux_possible_access_to_credential_files.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md b/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md
index d32def4018..12b27e4de3 100644
--- a/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md
+++ b/docs/_posts/2022-01-10-linux_possible_access_to_sudoers_file.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md b/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md
index 646b74e3e7..c60f84abd5 100644
--- a/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md
+++ b/docs/_posts/2022-01-11-linux_possible_access_or_modification_of_sshd_config_file.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md b/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md
index 44b67839f1..a0af17c2ed 100644
--- a/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md
+++ b/docs/_posts/2022-01-11-linux_possible_ssh_key_file_creation.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md b/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md
index 7bd661d040..2c0f7d9773 100644
--- a/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md
+++ b/docs/_posts/2022-01-12-powershell_-_connect_to_internet_with_hidden_window.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -127,8 +127,8 @@ The following hunting analytic identifies PowerShell commands utilizing the Wind
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **powershell_-_connect_to_internet_with_hidden_window_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md b/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md
index de5dd6c1d4..f400fa518a 100644
--- a/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md
+++ b/docs/_posts/2022-01-12-windows_hunting_system_account_targeting_lsass.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -109,8 +109,8 @@ The following hunting analytic identifies all processes requesting access into L
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_hunting_system_account_targeting_lsass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md b/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md
index 1aaff1ac13..4fa4899d2f 100644
--- a/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md
+++ b/docs/_posts/2022-01-12-windows_non-system_account_targeting_lsass.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -109,8 +109,8 @@ The following analytic identifies non SYSTEM accounts requesting access to lsass
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_non-system_account_targeting_lsass_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md b/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md
index 13e4d8f295..d296ecad78 100644
--- a/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md
+++ b/docs/_posts/2022-01-14-potentially_malicious_code_on_commandline.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -109,8 +109,8 @@ The following analytic uses a pretrained machine learning text classifier to det
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [potentially_malicious_code_on_cmdline_tokenize_score](https://github.com/splunk/security_content/blob/develop/macros/potentially_malicious_code_on_cmdline_tokenize_score.yml)
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
+* [potentially_malicious_code_on_cmdline_tokenize_score](https://github.com/splunk/security_content/blob/develop/macros/potentially_malicious_code_on_cmdline_tokenize_score.yml)
Note that **potentially_malicious_code_on_commandline_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md b/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md
index 61b7d865ab..526a60298a 100644
--- a/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md
+++ b/docs/_posts/2022-01-18-cmd_carry_out_string_command_parameter.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md b/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md
index b0d8b9a34a..6f95d3bfb2 100644
--- a/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md
+++ b/docs/_posts/2022-01-18-impacket_lateral_movement_commandline_parameters.md
@@ -31,7 +31,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md b/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md
index 6d076a994e..52a40ef484 100644
--- a/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md
+++ b/docs/_posts/2022-01-18-malicious_powershell_process_-_encoded_command.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -120,8 +120,8 @@ Alternatively, may use regex per matching here https://regexr.com/662ov.
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_powershell](https://github.com/splunk/security_content/blob/develop/macros/process_powershell.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **malicious_powershell_process_-_encoded_command_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-18-powershell_remove_windows_defender_directory.md b/docs/_posts/2022-01-18-powershell_remove_windows_defender_directory.md
index e3619c665e..6a375ef4e3 100644
--- a/docs/_posts/2022-01-18-powershell_remove_windows_defender_directory.md
+++ b/docs/_posts/2022-01-18-powershell_remove_windows_defender_directory.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md b/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md
index 625116b089..afaae2673d 100644
--- a/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md
+++ b/docs/_posts/2022-01-18-suspicious_process_dns_query_known_abuse_web_services.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This analytic detects a suspicious process making a DNS query via known, abused
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_process_dns_query_known_abuse_web_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md b/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md
index 790b96d787..caa1974bb8 100644
--- a/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md
+++ b/docs/_posts/2022-01-19-suspicious_process_with_discord_dns_query.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ This analytic identifies a process making a DNS query to Discord, a well known i
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_process_with_discord_dns_query_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md b/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md
index c4fbc9c057..9e4a421ecb 100644
--- a/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md
+++ b/docs/_posts/2022-01-19-windows_dotnet_binary_in_non_standard_path.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -119,8 +119,8 @@ The following analytic identifies native .net binaries within the Windows operat
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [is_net_windows_file](https://github.com/splunk/security_content/blob/develop/macros/is_net_windows_file.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_dotnet_binary_in_non_standard_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md b/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md
index d8f29439d6..7bfce8b123 100644
--- a/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md
+++ b/docs/_posts/2022-01-19-windows_installutil_in_non_standard_path.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -118,8 +118,8 @@ The following analytic identifies the Windows binary InstallUtil.exe running fro
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_installutil_in_non_standard_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md b/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md
index 8c544b007e..56506da21b 100644
--- a/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md
+++ b/docs/_posts/2022-01-20-excessive_file_deletion_in_windefender_folder.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ This analytic will identify excessive file deletion events in the Windows Defend
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **excessive_file_deletion_in_windefender_folder_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-20-ping_sleep_batch_command.md b/docs/_posts/2022-01-20-ping_sleep_batch_command.md
index 0c8dcdca5f..10e0ff60ec 100644
--- a/docs/_posts/2022-01-20-ping_sleep_batch_command.md
+++ b/docs/_posts/2022-01-20-ping_sleep_batch_command.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md b/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md
index 2e355530e0..98faf35dd4 100644
--- a/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md
+++ b/docs/_posts/2022-01-21-windows_nirsoft_advancedrun.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-24-windows_nirsoft_utilities.md b/docs/_posts/2022-01-24-windows_nirsoft_utilities.md
index 6a018a961f..603ea7f79f 100644
--- a/docs/_posts/2022-01-24-windows_nirsoft_utilities.md
+++ b/docs/_posts/2022-01-24-windows_nirsoft_utilities.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -104,8 +104,8 @@ The following hunting analytic assists with identifying the proces execution of
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [is_nirsoft_software](https://github.com/splunk/security_content/blob/develop/macros/is_nirsoft_software.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_nirsoft_utilities_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-26-active_setup_registry_autostart.md b/docs/_posts/2022-01-26-active_setup_registry_autostart.md
index 361c32c9f9..085e69db10 100644
--- a/docs/_posts/2022-01-26-active_setup_registry_autostart.md
+++ b/docs/_posts/2022-01-26-active_setup_registry_autostart.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md b/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md
index e3b95c3a2e..f7022c398d 100644
--- a/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md
+++ b/docs/_posts/2022-01-26-add_defaultuser_and_password_in_registry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md b/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md
index 399c21f3de..89888e22c8 100644
--- a/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md
+++ b/docs/_posts/2022-01-26-allow_inbound_traffic_by_firewall_rule_registry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md b/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md
index b8a47a358d..e042dba54b 100644
--- a/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md
+++ b/docs/_posts/2022-01-26-allow_operation_with_consent_admin.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-disable_amsi_through_registry.md b/docs/_posts/2022-01-26-disable_amsi_through_registry.md
index f6cdfc655c..b558160c14 100644
--- a/docs/_posts/2022-01-26-disable_amsi_through_registry.md
+++ b/docs/_posts/2022-01-26-disable_amsi_through_registry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md b/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md
index 7e1001b8c8..0d86c6e480 100644
--- a/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md
+++ b/docs/_posts/2022-01-26-disable_defender_antivirus_registry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md b/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md
index b0bd369bf8..b59e41f180 100644
--- a/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md
+++ b/docs/_posts/2022-01-26-disable_defender_blockatfirstseen_feature.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md b/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md
index 5ced3b3e0f..46065e094b 100644
--- a/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md
+++ b/docs/_posts/2022-01-26-disable_defender_enhanced_notification.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md b/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md
index 6f2a54b953..5df3caff98 100644
--- a/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md
+++ b/docs/_posts/2022-01-26-disable_defender_mpengine_registry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md b/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md
index 1bac9efd0a..834fe3d956 100644
--- a/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md
+++ b/docs/_posts/2022-01-26-disable_defender_spynet_reporting.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md b/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md
index 83e2346ca1..2b0d4b1005 100644
--- a/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md
+++ b/docs/_posts/2022-01-26-disable_defender_submit_samples_consent_feature.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-log4shell_cve-2021-44228_exploitation.md b/docs/_posts/2022-01-26-log4shell_cve-2021-44228_exploitation.md
index bbb3d2e272..0079523c95 100644
--- a/docs/_posts/2022-01-26-log4shell_cve-2021-44228_exploitation.md
+++ b/docs/_posts/2022-01-26-log4shell_cve-2021-44228_exploitation.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md b/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md
index bd27363836..6163b0bc46 100644
--- a/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md
+++ b/docs/_posts/2022-01-26-registry_keys_used_for_persistence.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md b/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md
index 9343633c68..7682995088 100644
--- a/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md
+++ b/docs/_posts/2022-01-26-registry_keys_used_for_privilege_escalation.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md b/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md
index 34b3e28dd9..9a9e5e33db 100644
--- a/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md
+++ b/docs/_posts/2022-01-26-remcos_client_registry_install_entry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-26-time_provider_persistence_registry.md b/docs/_posts/2022-01-26-time_provider_persistence_registry.md
index 49ce735d75..c2220555d0 100644
--- a/docs/_posts/2022-01-26-time_provider_persistence_registry.md
+++ b/docs/_posts/2022-01-26-time_provider_persistence_registry.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disable_etw_through_registry.md b/docs/_posts/2022-01-27-disable_etw_through_registry.md
index 0002168ccf..9504be6285 100644
--- a/docs/_posts/2022-01-27-disable_etw_through_registry.md
+++ b/docs/_posts/2022-01-27-disable_etw_through_registry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disable_registry_tool.md b/docs/_posts/2022-01-27-disable_registry_tool.md
index a6e8497827..f449526c81 100644
--- a/docs/_posts/2022-01-27-disable_registry_tool.md
+++ b/docs/_posts/2022-01-27-disable_registry_tool.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md b/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md
index cbc4235332..a0bc800d10 100644
--- a/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md
+++ b/docs/_posts/2022-01-27-disable_security_logs_using_minint_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disable_show_hidden_files.md b/docs/_posts/2022-01-27-disable_show_hidden_files.md
index 06738053ba..7579caf3c2 100644
--- a/docs/_posts/2022-01-27-disable_show_hidden_files.md
+++ b/docs/_posts/2022-01-27-disable_show_hidden_files.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disable_uac_remote_restriction.md b/docs/_posts/2022-01-27-disable_uac_remote_restriction.md
index d871e4c89a..7667377593 100644
--- a/docs/_posts/2022-01-27-disable_uac_remote_restriction.md
+++ b/docs/_posts/2022-01-27-disable_uac_remote_restriction.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md b/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md
index 25d865b2a0..c02bf71d6e 100644
--- a/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md
+++ b/docs/_posts/2022-01-27-disable_windows_app_hotkeys.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md b/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md
index 4b32b8cc63..eb8929d41e 100644
--- a/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md
+++ b/docs/_posts/2022-01-27-disable_windows_behavior_monitoring.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md b/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md
index d4671e7d58..20ec21c26d 100644
--- a/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md
+++ b/docs/_posts/2022-01-27-disable_windows_smartscreen_protection.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disabling_cmd_application.md b/docs/_posts/2022-01-27-disabling_cmd_application.md
index 863cf0d13a..3fd64e752c 100644
--- a/docs/_posts/2022-01-27-disabling_cmd_application.md
+++ b/docs/_posts/2022-01-27-disabling_cmd_application.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-disabling_controlpanel.md b/docs/_posts/2022-01-27-disabling_controlpanel.md
index 7b8e305e79..d30eb9216a 100644
--- a/docs/_posts/2022-01-27-disabling_controlpanel.md
+++ b/docs/_posts/2022-01-27-disabling_controlpanel.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-27-windows_possible_credential_dumping.md b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md
index 4ec0f102de..f48e7104de 100644
--- a/docs/_posts/2022-01-27-windows_possible_credential_dumping.md
+++ b/docs/_posts/2022-01-27-windows_possible_credential_dumping.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ The idea behind using ntdll.dll is to blend in by using native api of ntdll.dll.
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_possible_credential_dumping_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-01-28-disabling_defender_services.md b/docs/_posts/2022-01-28-disabling_defender_services.md
index b60a8f6a1b..49c35fb5b6 100644
--- a/docs/_posts/2022-01-28-disabling_defender_services.md
+++ b/docs/_posts/2022-01-28-disabling_defender_services.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md b/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md
index 6f73478f25..9919bc4270 100644
--- a/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md
+++ b/docs/_posts/2022-01-28-disabling_folderoptions_windows_feature.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-disabling_norun_windows_app.md b/docs/_posts/2022-01-28-disabling_norun_windows_app.md
index 293755b2a6..7e81c9f40f 100644
--- a/docs/_posts/2022-01-28-disabling_norun_windows_app.md
+++ b/docs/_posts/2022-01-28-disabling_norun_windows_app.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md b/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md
index 3a637bb7e9..57694d0f6d 100644
--- a/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md
+++ b/docs/_posts/2022-01-28-disabling_systemrestore_in_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-disabling_task_manager.md b/docs/_posts/2022-01-28-disabling_task_manager.md
index 8170c723e6..5fd539e8ba 100644
--- a/docs/_posts/2022-01-28-disabling_task_manager.md
+++ b/docs/_posts/2022-01-28-disabling_task_manager.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md b/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md
index 2bec02667e..31897cbc00 100644
--- a/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md
+++ b/docs/_posts/2022-01-28-enable_rdp_in_other_port_number.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md b/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md
index e1c52338a0..c48814e40b 100644
--- a/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md
+++ b/docs/_posts/2022-01-28-enable_wdigest_uselogoncredential_registry.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-etw_registry_disabled.md b/docs/_posts/2022-01-28-etw_registry_disabled.md
index 75e5d6e139..a39de54409 100644
--- a/docs/_posts/2022-01-28-etw_registry_disabled.md
+++ b/docs/_posts/2022-01-28-etw_registry_disabled.md
@@ -24,7 +24,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-eventvwr_uac_bypass.md b/docs/_posts/2022-01-28-eventvwr_uac_bypass.md
index 428433df49..331bf13b04 100644
--- a/docs/_posts/2022-01-28-eventvwr_uac_bypass.md
+++ b/docs/_posts/2022-01-28-eventvwr_uac_bypass.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md b/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md
index 8ac918d4e1..bea9919622 100644
--- a/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md
+++ b/docs/_posts/2022-01-28-hide_user_account_from_sign-in_screen.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md b/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md
index 98c5d90bf3..181fb842f0 100644
--- a/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md
+++ b/docs/_posts/2022-01-28-linux_pkexec_privilege_escalation.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-01-mimikatz_passtheticket_commandline_parameters.md b/docs/_posts/2022-02-01-mimikatz_passtheticket_commandline_parameters.md
index 9c374923f6..3fdbb761d4 100644
--- a/docs/_posts/2022-02-01-mimikatz_passtheticket_commandline_parameters.md
+++ b/docs/_posts/2022-02-01-mimikatz_passtheticket_commandline_parameters.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-01-rubeus_command_line_parameters.md b/docs/_posts/2022-02-01-rubeus_command_line_parameters.md
index 01896d56f2..de738321f0 100644
--- a/docs/_posts/2022-02-01-rubeus_command_line_parameters.md
+++ b/docs/_posts/2022-02-01-rubeus_command_line_parameters.md
@@ -32,7 +32,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-03-certutil_download_with_urlcache_and_split_arguments.md b/docs/_posts/2022-02-03-certutil_download_with_urlcache_and_split_arguments.md
index 7b5f317c98..73496028b7 100644
--- a/docs/_posts/2022-02-03-certutil_download_with_urlcache_and_split_arguments.md
+++ b/docs/_posts/2022-02-03-certutil_download_with_urlcache_and_split_arguments.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ Certutil.exe may download a file from a remote destination using `-urlcache`. Th
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **certutil_download_with_urlcache_and_split_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-03-certutil_download_with_verifyctl_and_split_arguments.md b/docs/_posts/2022-02-03-certutil_download_with_verifyctl_and_split_arguments.md
index a1a15a29b4..d6acfc58bc 100644
--- a/docs/_posts/2022-02-03-certutil_download_with_verifyctl_and_split_arguments.md
+++ b/docs/_posts/2022-02-03-certutil_download_with_verifyctl_and_split_arguments.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ Certutil.exe may download a file from a remote destination using `-VerifyCtl`. T
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_certutil](https://github.com/splunk/security_content/blob/develop/macros/process_certutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **certutil_download_with_verifyctl_and_split_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-03-o365_added_service_principal.md b/docs/_posts/2022-02-03-o365_added_service_principal.md
index aa4f03c7bd..c5e4b8f377 100644
--- a/docs/_posts/2022-02-03-o365_added_service_principal.md
+++ b/docs/_posts/2022-02-03-o365_added_service_principal.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md b/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md
index 56227cb9c5..9cc65015a4 100644
--- a/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md
+++ b/docs/_posts/2022-02-03-o365_bypass_mfa_via_trusted_ip.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-03-o365_disable_mfa.md b/docs/_posts/2022-02-03-o365_disable_mfa.md
index 12662ec347..81e7c1d7c0 100644
--- a/docs/_posts/2022-02-03-o365_disable_mfa.md
+++ b/docs/_posts/2022-02-03-o365_disable_mfa.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-07-rubeus_kerberos_ticket_exports_through_winlogon_access.md b/docs/_posts/2022-02-07-rubeus_kerberos_ticket_exports_through_winlogon_access.md
index b3a2bd7c5d..44b079c245 100644
--- a/docs/_posts/2022-02-07-rubeus_kerberos_ticket_exports_through_winlogon_access.md
+++ b/docs/_posts/2022-02-07-rubeus_kerberos_ticket_exports_through_winlogon_access.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -108,8 +108,8 @@ The following analytic looks for a process accessing the winlogon.exe system pro
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **rubeus_kerberos_ticket_exports_through_winlogon_access_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md b/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md
index 55b00b0056..470b3aae17 100644
--- a/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md
+++ b/docs/_posts/2022-02-07-windows_remote_assistance_spawning_process.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -104,8 +104,8 @@ The following analytic identifies the use of Microsoft Remote Assistance, msra.e
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [windows_shells](https://github.com/splunk/security_content/blob/develop/macros/windows_shells.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_remote_assistance_spawning_process_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-07-windows_schtasks_create_run_as_system.md b/docs/_posts/2022-02-07-windows_schtasks_create_run_as_system.md
index 35d63e9024..fcdeb70d72 100644
--- a/docs/_posts/2022-02-07-windows_schtasks_create_run_as_system.md
+++ b/docs/_posts/2022-02-07-windows_schtasks_create_run_as_system.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ The following analytic identifies Schtasks.exe creating a new task to start and
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_schtasks](https://github.com/splunk/security_content/blob/develop/macros/process_schtasks.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_schtasks_create_run_as_system_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md b/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md
index e0bbec1969..9e23ba0160 100644
--- a/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md
+++ b/docs/_posts/2022-02-08-rundll_loading_dll_by_ordinal.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-08-unusual_number_of_kerberos_service_tickets_requested.md b/docs/_posts/2022-02-08-unusual_number_of_kerberos_service_tickets_requested.md
index d7cc33cf1c..1926e35390 100644
--- a/docs/_posts/2022-02-08-unusual_number_of_kerberos_service_tickets_requested.md
+++ b/docs/_posts/2022-02-08-unusual_number_of_kerberos_service_tickets_requested.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md b/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md
index 75b0670ea5..10b9488ba4 100644
--- a/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md
+++ b/docs/_posts/2022-02-09-kerberoasting_spn_request_with_rc4_encryption.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -110,8 +110,8 @@ The following analytic leverages Kerberos Event 4769, A Kerberos service ticket
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **kerberoasting_spn_request_with_rc4_encryption_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-11-linux_system_network_discovery.md b/docs/_posts/2022-02-11-linux_system_network_discovery.md
index 97accff133..95d73bf6b5 100644
--- a/docs/_posts/2022-02-11-linux_system_network_discovery.md
+++ b/docs/_posts/2022-02-11-linux_system_network_discovery.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-14-linux_dd_file_overwrite.md b/docs/_posts/2022-02-14-linux_dd_file_overwrite.md
index 86a1977809..1d111a0535 100644
--- a/docs/_posts/2022-02-14-linux_dd_file_overwrite.md
+++ b/docs/_posts/2022-02-14-linux_dd_file_overwrite.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-15-detection_of_dns_tunnels.md b/docs/_posts/2022-02-15-detection_of_dns_tunnels.md
index e95f131154..436c7b933c 100644
--- a/docs/_posts/2022-02-15-detection_of_dns_tunnels.md
+++ b/docs/_posts/2022-02-15-detection_of_dns_tunnels.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md b/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md
index 538857c064..c66cdc5d23 100644
--- a/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md
+++ b/docs/_posts/2022-02-15-windows_diskshadow_proxy_execution.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -107,8 +107,8 @@ DiskShadow.exe is a Microsoft Signed binary present on Windows Server. It has a
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_diskshadow](https://github.com/splunk/security_content/blob/develop/macros/process_diskshadow.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_diskshadow_proxy_execution_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-15-windows_rasautou_dll_execution.md b/docs/_posts/2022-02-15-windows_rasautou_dll_execution.md
index 9bec2a26f5..d9e2d0d298 100644
--- a/docs/_posts/2022-02-15-windows_rasautou_dll_execution.md
+++ b/docs/_posts/2022-02-15-windows_rasautou_dll_execution.md
@@ -26,7 +26,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-17-windows_disable_notification_center.md b/docs/_posts/2022-02-17-windows_disable_notification_center.md
index e2bc0969bd..e1d92a1968 100644
--- a/docs/_posts/2022-02-17-windows_disable_notification_center.md
+++ b/docs/_posts/2022-02-17-windows_disable_notification_center.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-17-windows_raw_access_to_master_boot_record_drive.md b/docs/_posts/2022-02-17-windows_raw_access_to_master_boot_record_drive.md
index 27f66158ab..f0ec619bf8 100644
--- a/docs/_posts/2022-02-17-windows_raw_access_to_master_boot_record_drive.md
+++ b/docs/_posts/2022-02-17-windows_raw_access_to_master_boot_record_drive.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ This analytic is to look for suspicious raw access read to drive where the maste
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_raw_access_to_master_boot_record_drive_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-18-detect_regasm_with_network_connection.md b/docs/_posts/2022-02-18-detect_regasm_with_network_connection.md
index 33ed55e6c3..f17f3886d1 100644
--- a/docs/_posts/2022-02-18-detect_regasm_with_network_connection.md
+++ b/docs/_posts/2022-02-18-detect_regasm_with_network_connection.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ The following analytic identifies regasm.exe with a network connection to a publ
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_regasm_with_network_connection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-18-detect_regsvcs_with_network_connection.md b/docs/_posts/2022-02-18-detect_regsvcs_with_network_connection.md
index 5fcf4a6cbc..da779e0306 100644
--- a/docs/_posts/2022-02-18-detect_regsvcs_with_network_connection.md
+++ b/docs/_posts/2022-02-18-detect_regsvcs_with_network_connection.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -111,8 +111,8 @@ The following analytic identifies Regsvcs.exe with a network connection to a pub
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_regsvcs_with_network_connection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-18-disabled_kerberos_pre-authentication_discovery_with_powerview.md b/docs/_posts/2022-02-18-disabled_kerberos_pre-authentication_discovery_with_powerview.md
index c8fb7b42bc..b2e4ef8f59 100644
--- a/docs/_posts/2022-02-18-disabled_kerberos_pre-authentication_discovery_with_powerview.md
+++ b/docs/_posts/2022-02-18-disabled_kerberos_pre-authentication_discovery_with_powerview.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-18-net_profiler_uac_bypass.md b/docs/_posts/2022-02-18-net_profiler_uac_bypass.md
index 5a1d767dda..fcc8e98af4 100644
--- a/docs/_posts/2022-02-18-net_profiler_uac_bypass.md
+++ b/docs/_posts/2022-02-18-net_profiler_uac_bypass.md
@@ -23,7 +23,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md b/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md
index e8f0f99335..ed83770c9f 100644
--- a/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md
+++ b/docs/_posts/2022-02-18-o365_excessive_authentication_failures_alert.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-18-process_deleting_its_process_file_path.md b/docs/_posts/2022-02-18-process_deleting_its_process_file_path.md
index 2fa3827afe..f1f675e0b9 100644
--- a/docs/_posts/2022-02-18-process_deleting_its_process_file_path.md
+++ b/docs/_posts/2022-02-18-process_deleting_its_process_file_path.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -103,8 +103,8 @@ This detection is to identify a suspicious process that tries to delete the proc
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **process_deleting_its_process_file_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-18-rundll32_dnsquery.md b/docs/_posts/2022-02-18-rundll32_dnsquery.md
index a1454b06df..ce230860ff 100644
--- a/docs/_posts/2022-02-18-rundll32_dnsquery.md
+++ b/docs/_posts/2022-02-18-rundll32_dnsquery.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -106,8 +106,8 @@ This search is to detect a suspicious rundll32.exe process having a http connect
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **rundll32_dnsquery_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-18-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md b/docs/_posts/2022-02-18-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md
index 8e78e8488b..59ca69aaad 100644
--- a/docs/_posts/2022-02-18-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md
+++ b/docs/_posts/2022-02-18-set_default_powershell_execution_policy_to_unrestricted_or_bypass.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-22-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md b/docs/_posts/2022-02-22-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md
index 71b824e3ab..22a656ff1b 100644
--- a/docs/_posts/2022-02-22-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md
+++ b/docs/_posts/2022-02-22-disabled_kerberos_pre-authentication_discovery_with_get-aduser.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-22-kerberos_pre-authentication_flag_disabled_in_useraccountcontrol.md b/docs/_posts/2022-02-22-kerberos_pre-authentication_flag_disabled_in_useraccountcontrol.md
index 3b5c7a29f2..5c90cd0cd6 100644
--- a/docs/_posts/2022-02-22-kerberos_pre-authentication_flag_disabled_in_useraccountcontrol.md
+++ b/docs/_posts/2022-02-22-kerberos_pre-authentication_flag_disabled_in_useraccountcontrol.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-22-scheduled_task_deleted_or_created_via_cmd.md b/docs/_posts/2022-02-22-scheduled_task_deleted_or_created_via_cmd.md
index f7b8fe52f7..b8dc0c3156 100644
--- a/docs/_posts/2022-02-22-scheduled_task_deleted_or_created_via_cmd.md
+++ b/docs/_posts/2022-02-22-scheduled_task_deleted_or_created_via_cmd.md
@@ -25,7 +25,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-22-windows_wmi_process_call_create.md b/docs/_posts/2022-02-22-windows_wmi_process_call_create.md
index a6e6bf3833..c7870cdfb8 100644
--- a/docs/_posts/2022-02-22-windows_wmi_process_call_create.md
+++ b/docs/_posts/2022-02-22-windows_wmi_process_call_create.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md b/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md
index f9f0572550..46bcc186e8 100644
--- a/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md
+++ b/docs/_posts/2022-02-23-windows_excessive_disabled_services_event.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This analytic will identify suspicious excessive number of system events of serv
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_system](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_system.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_excessive_disabled_services_event_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-23-windows_process_with_namedpipe_commandline.md b/docs/_posts/2022-02-23-windows_process_with_namedpipe_commandline.md
index 55982e231d..8b24eef031 100644
--- a/docs/_posts/2022-02-23-windows_process_with_namedpipe_commandline.md
+++ b/docs/_posts/2022-02-23-windows_process_with_namedpipe_commandline.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-23-windows_service_creation_using_registry_entry.md b/docs/_posts/2022-02-23-windows_service_creation_using_registry_entry.md
index d7f9ae2801..4787c272ee 100644
--- a/docs/_posts/2022-02-23-windows_service_creation_using_registry_entry.md
+++ b/docs/_posts/2022-02-23-windows_service_creation_using_registry_entry.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-24-aws_lambda_updatefunctioncode.md b/docs/_posts/2022-02-24-aws_lambda_updatefunctioncode.md
index 3b772c1128..a95a00e40d 100644
--- a/docs/_posts/2022-02-24-aws_lambda_updatefunctioncode.md
+++ b/docs/_posts/2022-02-24-aws_lambda_updatefunctioncode.md
@@ -17,7 +17,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-25-windows_disable_memory_crash_dump.md b/docs/_posts/2022-02-25-windows_disable_memory_crash_dump.md
index aad9823397..f76480af6f 100644
--- a/docs/_posts/2022-02-25-windows_disable_memory_crash_dump.md
+++ b/docs/_posts/2022-02-25-windows_disable_memory_crash_dump.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-25-windows_file_without_extension_in_critical_folder.md b/docs/_posts/2022-02-25-windows_file_without_extension_in_critical_folder.md
index 4920f10377..f733122b06 100644
--- a/docs/_posts/2022-02-25-windows_file_without_extension_in_critical_folder.md
+++ b/docs/_posts/2022-02-25-windows_file_without_extension_in_critical_folder.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-02-25-windows_raw_access_to_disk_volume_partition.md b/docs/_posts/2022-02-25-windows_raw_access_to_disk_volume_partition.md
index 819ed31cf9..59da619b08 100644
--- a/docs/_posts/2022-02-25-windows_raw_access_to_disk_volume_partition.md
+++ b/docs/_posts/2022-02-25-windows_raw_access_to_disk_volume_partition.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -112,8 +112,8 @@ This analytic is to look for suspicious raw access read to device disk partition
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [sysmon](https://github.com/splunk/security_content/blob/develop/macros/sysmon.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_raw_access_to_disk_volume_partition_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-02-28-excessive_distinct_processes_from_windows_temp.md b/docs/_posts/2022-02-28-excessive_distinct_processes_from_windows_temp.md
index b6fd1bc350..6b3dbb733d 100644
--- a/docs/_posts/2022-02-28-excessive_distinct_processes_from_windows_temp.md
+++ b/docs/_posts/2022-02-28-excessive_distinct_processes_from_windows_temp.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-02-windows_modify_show_compress_color_and_info_tip_registry.md b/docs/_posts/2022-03-02-windows_modify_show_compress_color_and_info_tip_registry.md
index 26d0f0fe7b..faa6848142 100644
--- a/docs/_posts/2022-03-02-windows_modify_show_compress_color_and_info_tip_registry.md
+++ b/docs/_posts/2022-03-02-windows_modify_show_compress_color_and_info_tip_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-03-aws_createaccesskey.md b/docs/_posts/2022-03-03-aws_createaccesskey.md
index aadceda6d0..d7f75c790b 100644
--- a/docs/_posts/2022-03-03-aws_createaccesskey.md
+++ b/docs/_posts/2022-03-03-aws_createaccesskey.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for AWS CloudTrail events where a user A who has already permi
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_createaccesskey_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-03-aws_updateloginprofile.md b/docs/_posts/2022-03-03-aws_updateloginprofile.md
index 0a3fd5cbb0..b9fe5ffb9b 100644
--- a/docs/_posts/2022-03-03-aws_updateloginprofile.md
+++ b/docs/_posts/2022-03-03-aws_updateloginprofile.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -113,8 +113,8 @@ This search looks for AWS CloudTrail events where a user A who has already permi
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [cloudtrail](https://github.com/splunk/security_content/blob/develop/macros/cloudtrail.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **aws_updateloginprofile_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-04-kerberos_tgt_request_using_rc4_encryption.md b/docs/_posts/2022-03-04-kerberos_tgt_request_using_rc4_encryption.md
index 68855019bd..bbabea9bec 100644
--- a/docs/_posts/2022-03-04-kerberos_tgt_request_using_rc4_encryption.md
+++ b/docs/_posts/2022-03-04-kerberos_tgt_request_using_rc4_encryption.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-04-macos_lolbin.md b/docs/_posts/2022-03-04-macos_lolbin.md
index 1512d4c20c..b83cbd92f7 100644
--- a/docs/_posts/2022-03-04-macos_lolbin.md
+++ b/docs/_posts/2022-03-04-macos_lolbin.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -115,8 +115,8 @@ Detect multiple executions of Living off the Land (LOLbin) binaries in a short p
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [osquery](https://github.com/splunk/security_content/blob/develop/macros/osquery.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **macos_lolbin_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-08-suspicious_msbuild_path.md b/docs/_posts/2022-03-08-suspicious_msbuild_path.md
index 4fcc581205..3600fa9d6d 100644
--- a/docs/_posts/2022-03-08-suspicious_msbuild_path.md
+++ b/docs/_posts/2022-03-08-suspicious_msbuild_path.md
@@ -27,7 +27,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -123,8 +123,8 @@ The following analytic identifies msbuild.exe executing from a non-standard path
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_msbuild](https://github.com/splunk/security_content/blob/develop/macros/process_msbuild.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_msbuild_path_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-08-windows_disable_change_password_through_registry.md b/docs/_posts/2022-03-08-windows_disable_change_password_through_registry.md
index 24e2910587..3e5427dc4d 100644
--- a/docs/_posts/2022-03-08-windows_disable_change_password_through_registry.md
+++ b/docs/_posts/2022-03-08-windows_disable_change_password_through_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-08-windows_disable_lock_workstation_feature_through_registry.md b/docs/_posts/2022-03-08-windows_disable_lock_workstation_feature_through_registry.md
index 99704a9980..cb7fce60c0 100644
--- a/docs/_posts/2022-03-08-windows_disable_lock_workstation_feature_through_registry.md
+++ b/docs/_posts/2022-03-08-windows_disable_lock_workstation_feature_through_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-08-windows_disable_logoff_button_through_registry.md b/docs/_posts/2022-03-08-windows_disable_logoff_button_through_registry.md
index d72acb6401..e772ea10d4 100644
--- a/docs/_posts/2022-03-08-windows_disable_logoff_button_through_registry.md
+++ b/docs/_posts/2022-03-08-windows_disable_logoff_button_through_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-08-windows_disable_shutdown_button_through_registry.md b/docs/_posts/2022-03-08-windows_disable_shutdown_button_through_registry.md
index 3c1e4a0bd7..f20834acd2 100644
--- a/docs/_posts/2022-03-08-windows_disable_shutdown_button_through_registry.md
+++ b/docs/_posts/2022-03-08-windows_disable_shutdown_button_through_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-08-windows_disable_windows_group_policy_features_through_registry.md b/docs/_posts/2022-03-08-windows_disable_windows_group_policy_features_through_registry.md
index b7016fb78e..f202806f35 100644
--- a/docs/_posts/2022-03-08-windows_disable_windows_group_policy_features_through_registry.md
+++ b/docs/_posts/2022-03-08-windows_disable_windows_group_policy_features_through_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-08-windows_hide_notification_features_through_registry.md b/docs/_posts/2022-03-08-windows_hide_notification_features_through_registry.md
index 3eb452f62a..a5d9b7f072 100644
--- a/docs/_posts/2022-03-08-windows_hide_notification_features_through_registry.md
+++ b/docs/_posts/2022-03-08-windows_hide_notification_features_through_registry.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-09-unknown_process_using_the_kerberos_protocol.md b/docs/_posts/2022-03-09-unknown_process_using_the_kerberos_protocol.md
index 599c0939bb..61de9a9d77 100644
--- a/docs/_posts/2022-03-09-unknown_process_using_the_kerberos_protocol.md
+++ b/docs/_posts/2022-03-09-unknown_process_using_the_kerberos_protocol.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-10-kerberos_user_enumeration.md b/docs/_posts/2022-03-10-kerberos_user_enumeration.md
index 8f9ecccaea..6e0d18c126 100644
--- a/docs/_posts/2022-03-10-kerberos_user_enumeration.md
+++ b/docs/_posts/2022-03-10-kerberos_user_enumeration.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-15-detect_regasm_with_no_command_line_arguments.md b/docs/_posts/2022-03-15-detect_regasm_with_no_command_line_arguments.md
index 8891732a67..1466788f8c 100644
--- a/docs/_posts/2022-03-15-detect_regasm_with_no_command_line_arguments.md
+++ b/docs/_posts/2022-03-15-detect_regasm_with_no_command_line_arguments.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ The following analytic identifies regasm.exe with no command line arguments. Thi
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_regasm](https://github.com/splunk/security_content/blob/develop/macros/process_regasm.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_regasm_with_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md b/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md
index 2bfea68b87..0c78930f9f 100644
--- a/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md
+++ b/docs/_posts/2022-03-15-detect_regsvcs_with_no_command_line_arguments.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -114,8 +114,8 @@ The following analytic identifies regsvcs.exe with no command line arguments. Th
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_regsvcs](https://github.com/splunk/security_content/blob/develop/macros/process_regsvcs.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **detect_regsvcs_with_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-15-dllhost_with_no_command_line_arguments_with_network.md b/docs/_posts/2022-03-15-dllhost_with_no_command_line_arguments_with_network.md
index 772ed5f046..d5efd2ceca 100644
--- a/docs/_posts/2022-03-15-dllhost_with_no_command_line_arguments_with_network.md
+++ b/docs/_posts/2022-03-15-dllhost_with_no_command_line_arguments_with_network.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-15-gpupdate_with_no_command_line_arguments_with_network.md b/docs/_posts/2022-03-15-gpupdate_with_no_command_line_arguments_with_network.md
index dac22000fe..b903b29e32 100644
--- a/docs/_posts/2022-03-15-gpupdate_with_no_command_line_arguments_with_network.md
+++ b/docs/_posts/2022-03-15-gpupdate_with_no_command_line_arguments_with_network.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md b/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md
index b76329ebcc..f81ff8e28b 100644
--- a/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md
+++ b/docs/_posts/2022-03-15-kerberos_service_ticket_request_using_rc4_encryption.md
@@ -20,7 +20,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -105,8 +105,8 @@ The following analytic leverages Kerberos Event 4769, A Kerberos service ticket
#### Macros
The SPL above uses the following Macros:
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [wineventlog_security](https://github.com/splunk/security_content/blob/develop/macros/wineventlog_security.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **kerberos_service_ticket_request_using_rc4_encryption_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md b/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md
index 6e324d3b9a..4b3856fabf 100644
--- a/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md
+++ b/docs/_posts/2022-03-15-rundll32_with_no_command_line_arguments_with_network.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-15-searchprotocolhost_with_no_command_line_with_network.md b/docs/_posts/2022-03-15-searchprotocolhost_with_no_command_line_with_network.md
index f31630945d..c9192a1a3c 100644
--- a/docs/_posts/2022-03-15-searchprotocolhost_with_no_command_line_with_network.md
+++ b/docs/_posts/2022-03-15-searchprotocolhost_with_no_command_line_with_network.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-15-suspicious_dllhost_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_dllhost_no_command_line_arguments.md
index 6dfe5e635f..786d52d479 100644
--- a/docs/_posts/2022-03-15-suspicious_dllhost_no_command_line_arguments.md
+++ b/docs/_posts/2022-03-15-suspicious_dllhost_no_command_line_arguments.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -105,8 +105,8 @@ The following analytic identifies DLLHost.exe with no command line arguments. It
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_dllhost](https://github.com/splunk/security_content/blob/develop/macros/process_dllhost.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_dllhost_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md
index 097fc09892..7f68c473c1 100644
--- a/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md
+++ b/docs/_posts/2022-03-15-suspicious_gpupdate_no_command_line_arguments.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -105,8 +105,8 @@ The following analytic identifies gpupdate.exe with no command line arguments. I
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_gpupdate](https://github.com/splunk/security_content/blob/develop/macros/process_gpupdate.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **suspicious_gpupdate_no_command_line_arguments_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md
index 9f48225e77..093db53b97 100644
--- a/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md
+++ b/docs/_posts/2022-03-15-suspicious_rundll32_no_command_line_arguments.md
@@ -22,7 +22,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-15-suspicious_searchprotocolhost_no_command_line_arguments.md b/docs/_posts/2022-03-15-suspicious_searchprotocolhost_no_command_line_arguments.md
index 986cc33ef5..fe79afa456 100644
--- a/docs/_posts/2022-03-15-suspicious_searchprotocolhost_no_command_line_arguments.md
+++ b/docs/_posts/2022-03-15-suspicious_searchprotocolhost_no_command_line_arguments.md
@@ -19,7 +19,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-16-windows_installutil_remote_network_connection.md b/docs/_posts/2022-03-16-windows_installutil_remote_network_connection.md
index 921df93a7c..a4b484fdc4 100644
--- a/docs/_posts/2022-03-16-windows_installutil_remote_network_connection.md
+++ b/docs/_posts/2022-03-16-windows_installutil_remote_network_connection.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -116,8 +116,8 @@ During triage review resulting network connections, file modifications, and para
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_installutil_remote_network_connection_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-16-windows_installutil_uninstall_option_with_network.md b/docs/_posts/2022-03-16-windows_installutil_uninstall_option_with_network.md
index e850747500..531bea3924 100644
--- a/docs/_posts/2022-03-16-windows_installutil_uninstall_option_with_network.md
+++ b/docs/_posts/2022-03-16-windows_installutil_uninstall_option_with_network.md
@@ -21,7 +21,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
@@ -117,8 +117,8 @@ During triage review resulting network connections, file modifications, and para
#### Macros
The SPL above uses the following Macros:
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
-* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
* [process_installutil](https://github.com/splunk/security_content/blob/develop/macros/process_installutil.yml)
+* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
Note that **windows_installutil_uninstall_option_with_network_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
diff --git a/docs/_posts/2022-03-17-modify_acl_permission_to_files_or_folder.md b/docs/_posts/2022-03-17-modify_acl_permission_to_files_or_folder.md
index 3b06db008c..03c96bdae4 100644
--- a/docs/_posts/2022-03-17-modify_acl_permission_to_files_or_folder.md
+++ b/docs/_posts/2022-03-17-modify_acl_permission_to_files_or_folder.md
@@ -18,7 +18,7 @@ tags:
-[Try in Splunk Security Cloud](https://www.splunk.com/en_splunk_app_enrichmentus/cyber-security.html){: .btn .btn--success}
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
diff --git a/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md b/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md
new file mode 100644
index 0000000000..9ae51e7508
--- /dev/null
+++ b/docs/_posts/2022-03-22-get_addefaultdomainpasswordpolicy_with_powershell_script_block.md
@@ -0,0 +1,152 @@
+---
+title: "Get ADDefaultDomainPasswordPolicy with Powershell Script Block"
+excerpt: "Password Policy Discovery
+"
+categories:
+ - Endpoint
+last_modified_at: 2022-03-22
+toc: true
+toc_label: ""
+tags:
+ - Password Policy Discovery
+ - Discovery
+ - Splunk Enterprise
+ - Splunk Enterprise Security
+ - Splunk Cloud
+---
+
+
+
+[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
+
+#### Description
+
+The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-ADDefaultDomainPasswordPolicy` commandlet used to obtain the password policy in a Windows domain. Red Teams and adversaries alike may use PowerShell to enumerate domain policies for situational awareness and Active Directory Discovery.
+
+- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types)
+- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
+
+- **Last Updated**: 2022-03-22
+- **Author**: Teoderick Contreras, Mauricio Velazco, Splunk
+- **ID**: 1ff7ccc8-065a-11ec-91e4-acde48001122
+
+
+#### Annotations
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+ATT&CK
+
+Kill Chain Phase
+
+NIST
+
+CIS20
+
+CVE
+
+