mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -13,7 +13,7 @@ jobs:
|
||||
with:
|
||||
ref: develop
|
||||
|
||||
- uses: actions/setup-python@v4
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: '3.11' #Available versions here - https://github.com/actions/python-versions/releases easy to change/make a matrix/use pypy
|
||||
architecture: 'x64' # optional x64 or x86. Defaults to x64 if not specified
|
||||
|
||||
@@ -11,14 +11,11 @@ jobs:
|
||||
steps:
|
||||
- name: Check out the repository code
|
||||
uses: actions/checkout@v3
|
||||
with:
|
||||
node-version: '20'
|
||||
|
||||
- uses: actions/setup-python@v4
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: '3.11' #Available versions here - https://github.com/actions/python-versions/releases easy to change/make a matrix/use pypy
|
||||
architecture: 'x64' # optional x64 or x86. Defaults to x64 if not specified
|
||||
node-version: '20'
|
||||
|
||||
- name: Install System Packages
|
||||
run: |
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Access LSASS Memory for Dump Creation
|
||||
id: fb4c31b0-13e8-4155-8aa5-24de4b8d6717
|
||||
version: 4
|
||||
version: 3
|
||||
date: '2024-05-13'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Account Discovery With Net App
|
||||
id: 339805ce-ac30-11eb-b87d-acde48001122
|
||||
version: 6
|
||||
version: 5
|
||||
date: '2024-05-22'
|
||||
author: Teoderick Contreras, Splunk, TheLawsOfChaos, Github Community
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Access to Vulnerable Ivanti Connect Secure Bookmark Endpoint
|
||||
id: 15838756-f425-43fa-9d88-a7f88063e81a
|
||||
version: 3
|
||||
version: 2
|
||||
date: '2024-05-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
|
||||
@@ -15,7 +15,7 @@ description: The following analytic detects potential exploitation attempts agai
|
||||
unauthorized access to ColdFusion administration endpoints. If confirmed malicious,
|
||||
this could result in data theft, brute force attacks, or further exploitation of
|
||||
other vulnerabilities, posing a serious security risk to the environment.
|
||||
search: 'x| tstats count min(_time) as firstTime max(_time) as lastTime from datamodel=Web
|
||||
search: '| tstats count min(_time) as firstTime max(_time) as lastTime from datamodel=Web
|
||||
where Web.url IN ("//restplay*", "//CFIDE/restplay*", "//CFIDE/administrator*",
|
||||
"//CFIDE/adminapi*", "//CFIDE/main*", "//CFIDE/componentutils*", "//CFIDE/wizards*",
|
||||
"//CFIDE/servermanager*","/restplay*", "/CFIDE/restplay*", "/CFIDE/administrator*",
|
||||
|
||||
Reference in New Issue
Block a user