From 1e731ee7af915debab12d844e3e69cab5f086ac2 Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 3 Jan 2022 12:03:34 -0500 Subject: [PATCH 1/4] modify experimental detections to say not supported --- bin/jinja2_templates/doc_detections.j2 | 2 +- docs/_data/navigation.yml | 2 + docs/_pages/detections.md | 5 +- docs/_pages/privilege_escalation.md | 10 +- docs/_pages/stories.md | 3 +- docs/_playbooks/delete_detected_files.md | 3 + docs/_playbooks/log4j_investigate.md | 27 ++++ docs/_playbooks/log4j_respond.md | 27 ++++ .../ransomware_investigate_and_contain.md | 3 + ...12-detect_new_login_attempts_to_routers.md | 2 +- ...tect_unauthorized_assets_by_mac_address.md | 2 +- ...9-15-no_windows_updates_in_a_time_frame.md | 2 +- ...9-email_attachments_with_lots_of_spaces.md | 2 +- ...7-09-20-large_volume_of_dns_any_queries.md | 2 +- ...s_scanning_for_vulnerable_jboss_servers.md | 2 +- ...cious_requests_to_exploit_jboss_servers.md | 2 +- ...-23-monitor_web_traffic_for_brand_abuse.md | 2 +- ...0-13-unusually_long_content-type_length.md | 2 +- ...018-01-05-monitor_email_for_brand_abuse.md | 2 +- ..._blocked_outbound_traffic_from_your_aws.md | 2 +- ...6-01-detect_large_outbound_icmp_packets.md | 2 +- ...18-06-28-detect_s3_access_from_a_new_ip.md | 2 +- ...-10-23-wmi_permanent_event_subscription.md | 2 +- ...-10-23-wmi_temporary_event_subscription.md | 2 +- ...1-27-detect_spike_in_s3_bucket_deletion.md | 2 +- .../2018-12-06-suspicious_java_classes.md | 2 +- ...01-25-processes_tapping_keyboard_events.md | 2 +- ..._servers_executing_suspicious_processes.md | 2 +- ...5-08-unusually_long_command_line_-_mltk.md | 2 +- ...-01-22-dns_query_length_outliers_-_mltk.md | 2 +- ...20-02-07-macos_-_re-opened_applications.md | 2 +- ...02-20-new_container_uploaded_to_aws_ecr.md | 2 +- ...20-03-16-child_processes_of_spoolsv_exe.md | 2 +- .../2020-03-16-detect_rare_executables.md | 2 +- .../_posts/2020-03-16-spike_in_file_writes.md | 2 +- ...n_eks_kubernetes_cluster_scan_detection.md | 2 +- ...mazon_eks_kubernetes_pod_scan_detection.md | 2 +- ...0-first_time_seen_child_process_of_zoom.md | 2 +- ...tes_aws_detect_suspicious_kubectl_calls.md | 2 +- ...20-07-07-remote_desktop_network_traffic.md | 2 +- ...p_kubernetes_cluster_pod_scan_detection.md | 2 +- .../2020-07-21-detect_outbound_smb_traffic.md | 2 +- ...1-detect_outlook_exe_writing_a_zip_file.md | 2 +- ...-21-detection_of_tools_built_by_nirsoft.md | 2 +- ...ritten_outside_of_the_outlook_directory.md | 2 +- ...rs_sending_high_volume_traffic_to_hosts.md | 2 +- .../2020-07-21-excessive_dns_failures.md | 2 +- ...first_time_seen_running_windows_service.md | 2 +- ...me_of_network_traffic_from_email_server.md | 2 +- ...th_invalid_credentials_from_the_same_ip.md | 2 +- .../2020-07-21-okta_account_lockout_events.md | 2 +- .../2020-07-21-okta_failed_sso_attempts.md | 2 +- ...1-okta_user_logins_from_multiple_cities.md | 2 +- ...7-21-prohibited_network_traffic_allowed.md | 2 +- .../2020-07-21-protocol_or_port_mismatch.md | 2 +- ...07-21-remote_desktop_network_bruteforce.md | 2 +- ...emote_desktop_process_running_on_system.md | 2 +- ...2020-07-21-sql_injection_with_long_urls.md | 2 +- docs/_posts/2020-07-22-smb_traffic_spike.md | 2 +- .../2020-07-22-smb_traffic_spike_-_mltk.md | 2 +- ...-suspicious_email_attachment_extensions.md | 2 +- docs/_posts/2020-07-22-tor_traffic.md | 2 +- ...-07-27-aws_detect_attach_to_role_policy.md | 2 +- ...07-27-aws_detect_permanent_key_creation.md | 2 +- .../2020-07-27-aws_detect_role_creation.md | 2 +- ...-07-27-aws_detect_sts_assume_role_abuse.md | 2 +- ...-aws_detect_sts_get_session_token_abuse.md | 2 +- ...ct_windows_dns_sigred_via_splunk_stream.md | 2 +- ...7-28-detect_windows_dns_sigred_via_zeek.md | 2 +- ...-08-02-detect_f5_tmui_rce_cve-2020-5902.md | 2 +- ...-05-detect_new_open_gcp_storage_buckets.md | 2 +- ...detect_gcp_storage_access_from_a_new_ip.md | 2 +- .../_posts/2020-08-11-detect_arp_poisoning.md | 2 +- .../2020-08-11-detect_rogue_dhcp_server.md | 2 +- ...igh_number_of_cloud_instances_destroyed.md | 2 +- ...high_number_of_cloud_instances_launched.md | 2 +- ...ection_by_machine_learning_method_-_ssa.md | 2 +- .../2020-09-15-detect_zerologon_via_zeek.md | 2 +- ...computer_changed_with_anonymous_account.md | 2 +- ...2020-10-08-gcp_detect_gcploit_framework.md | 2 +- ...20-10-21-detect_snicat_sni_exfiltration.md | 2 +- ...ect_ipv6_network_infrastructure_threats.md | 2 +- ...20-10-28-detect_port_security_violation.md | 2 +- ...ect_software_download_to_network_device.md | 2 +- .../2020-10-28-detect_traffic_mirroring.md | 2 +- ...burst_correlation_dll_and_network_event.md | 2 +- ..._of_login_failures_from_a_single_source.md | 2 +- docs/_posts/2021-01-06-supernova_webshell.md | 2 +- ...ike_in_aws_security_hub_alerts_for_user.md | 2 +- ...1-27-detect_baron_samedit_cve-2021-3156.md | 2 +- ...baron_samedit_cve-2021-3156_via_osquery.md | 2 +- ...ct_baron_samedit_cve-2021-3156_segfault.md | 2 +- ...2-22-suspicious_curl_network_connection.md | 2 +- .../2021-02-22-suspicious_plistbuddy_usage.md | 2 +- ...suspicious_plistbuddy_usage_via_osquery.md | 2 +- ...uspicious_sqlite3_lsquarantine_behavior.md | 2 +- .../2021-03-01-any_powershell_downloadfile.md | 2 +- .../2021-05-21-winrm_spawning_a_process.md | 2 +- ...ols_passing_authentication_in_cleartext.md | 2 +- ...8-27-exchange_powershell_abuse_via_ssrf.md | 2 +- ...-08-27-exchange_powershell_module_usage.md | 2 +- ...9-28-print_processor_registry_autostart.md | 2 +- ..._connect_to_internet_with_hidden_window.md | 2 +- ...21-10-24-gdrive_suspicious_file_sharing.md | 2 +- ...10-24-gsuite_suspicious_calendar_invite.md | 2 +- ...-randomly_generated_scheduled_task_name.md | 2 +- ...randomly_generated_windows_service_name.md | 2 +- ...r_of_computer_service_tickets_requested.md | 2 +- ...f_remote_endpoint_authentication_events.md | 2 +- ...-12-10-curl_download_and_bash_execution.md | 2 +- ...-12-11-wget_download_and_bash_execution.md | 2 +- ...-cmd_carry_out_string_command_parameter.md | 2 +- ...2021-12-13-detect_outbound_ldap_traffic.md | 2 +- ..._class_file_download_by_java_user_agent.md | 2 +- .../2021-12-13-linux_java_spawning_shell.md | 4 +- ...og4shell_jndi_payload_injection_attempt.md | 2 +- ...load_injection_with_outbound_connection.md | 2 +- ...onnection_from_java_using_default_ports.md | 31 +++-- ...2021-12-13-windows_java_spawning_shells.md | 4 +- .../2021-12-14-hunting_for_log4shell.md | 2 +- ...suspicious_computer_account_name_change.md | 117 +++++++++++++++++ ...picious_kerberos_service_ticket_request.md | 120 ++++++++++++++++++ ...spicious_ticket_granting_ticket_request.md | 111 ++++++++++++++++ docs/_stories/credential_dumping.md | 2 +- ...ing_and_domain_controller_impersonation.md | 45 +++++++ docs/index.markdown | 6 +- 126 files changed, 605 insertions(+), 133 deletions(-) create mode 100644 docs/_posts/2021-12-20-suspicious_computer_account_name_change.md create mode 100644 docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md create mode 100644 docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md create mode 100644 docs/_stories/samaccountname_spoofing_and_domain_controller_impersonation.md diff --git a/bin/jinja2_templates/doc_detections.j2 b/bin/jinja2_templates/doc_detections.j2 index 6f81151276..99bfc103b0 100644 --- a/bin/jinja2_templates/doc_detections.j2 +++ b/bin/jinja2_templates/doc_detections.j2 @@ -31,7 +31,7 @@ tags: {% if detection.experimental is sameas true -%} ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! {% endif %} [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_data/navigation.yml b/docs/_data/navigation.yml index 0fe74c1bec..7808f8c6c0 100644 --- a/docs/_data/navigation.yml +++ b/docs/_data/navigation.yml @@ -85,6 +85,8 @@ stories: url: /stories/cloud_security/ - title: Malware url: /stories/malware/ + - title: Privilege Escalation + url: /stories/privilege_escalation/ - title: Vulnerability url: /stories/vulnerability/ playbooks: diff --git a/docs/_pages/detections.md b/docs/_pages/detections.md index 49496d4d0a..f4eb63a047 100644 --- a/docs/_pages/detections.md +++ b/docs/_pages/detections.md @@ -60,8 +60,8 @@ sidebar: | [Attempt To Delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | | [Attempt To Disable Services](/endpoint/attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | TTP | | [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Security Account Manager](/tags/#security-account-manager) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | TTP | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | @@ -589,6 +589,7 @@ sidebar: | [Start Up During Safe Mode Boot](/endpoint/start_up_during_safe_mode_boot/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Sunburst Correlation DLL and Network Event](/endpoint/sunburst_correlation_dll_and_network_event/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | TTP | | [Supernova Webshell](/web/supernova_webshell/) | [Web Shell](/tags/#web-shell) | TTP | +| [Suspicious Computer Account Name Change](/endpoint/suspicious_computer_account_name_change/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | TTP | | [Suspicious Copy on System32](/endpoint/suspicious_copy_on_system32/) | [Rename System Utilities](/tags/#rename-system-utilities), [Masquerading](/tags/#masquerading) | TTP | | [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Suspicious DLLHost no Command Line Arguments](/endpoint/suspicious_dllhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | TTP | @@ -599,6 +600,7 @@ sidebar: | [Suspicious IcedID Rundll32 Cmdline](/endpoint/suspicious_icedid_rundll32_cmdline/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | | [Suspicious Image Creation In Appdata Folder](/endpoint/suspicious_image_creation_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture) | TTP | | [Suspicious Java Classes]() | None | Anomaly | +| [Suspicious Kerberos Service Ticket Request](/endpoint/suspicious_kerberos_service_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | TTP | | [Suspicious MSBuild Rename](/endpoint/suspicious_msbuild_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | TTP | | [Suspicious MSBuild Spawn](/endpoint/suspicious_msbuild_spawn/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [MSBuild](/tags/#msbuild) | TTP | | [Suspicious PlistBuddy Usage](/endpoint/suspicious_plistbuddy_usage/) | [Launch Agent](/tags/#launch-agent), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | @@ -615,6 +617,7 @@ sidebar: | [Suspicious SQLite3 LSQuarantine Behavior](/endpoint/suspicious_sqlite3_lsquarantine_behavior/) | [Data Staged](/tags/#data-staged) | TTP | | [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | | [Suspicious SearchProtocolHost no Command Line Arguments](/endpoint/suspicious_searchprotocolhost_no_command_line_arguments/) | [Process Injection](/tags/#process-injection) | TTP | +| [Suspicious Ticket Granting Ticket Request](/endpoint/suspicious_ticket_granting_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | Hunting | | [Suspicious WAV file in Appdata Folder](/endpoint/suspicious_wav_file_in_appdata_folder/) | [Screen Capture](/tags/#screen-capture) | TTP | | [Suspicious microsoft workflow compiler rename](/endpoint/suspicious_microsoft_workflow_compiler_rename/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities) | Hunting | | [Suspicious microsoft workflow compiler usage](/endpoint/suspicious_microsoft_workflow_compiler_usage/) | [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution) | TTP | diff --git a/docs/_pages/privilege_escalation.md b/docs/_pages/privilege_escalation.md index 60bde4562d..234c9e8c36 100644 --- a/docs/_pages/privilege_escalation.md +++ b/docs/_pages/privilege_escalation.md @@ -3,7 +3,11 @@ title: Privilege Escalation layout: tag author_profile: false taxonomy: Privilege Escalation -permalink: /detections/privilege_escalation/ +permalink: /stories/privilege_escalation/ sidebar: - nav: "detections" ---- \ No newline at end of file + nav: "stories" +--- + +| Name | Technique | Tactic | +| ----------- | ----------- |--------------| +| [sAMAccountName Spoofing and Domain Controller Impersonation](/stories/samaccountname_spoofing_and_domain_controller_impersonation/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | [Defense Evasion](/tags/#defense-evasion) | \ No newline at end of file diff --git a/docs/_pages/stories.md b/docs/_pages/stories.md index 118f12121b..b3dfe3c717 100644 --- a/docs/_pages/stories.md +++ b/docs/_pages/stories.md @@ -116,4 +116,5 @@ sidebar: | [Windows Persistence Techniques](windows_persistence_techniques) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | | [Windows Privilege Escalation](windows_privilege_escalation) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Persistence](/tags/#persistence) | | [Windows Service Abuse](windows_service_abuse) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | -| [XMRig](xmrig) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | \ No newline at end of file +| [XMRig](xmrig) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | [Persistence](/tags/#persistence) | +| [sAMAccountName Spoofing and Domain Controller Impersonation](samaccountname_spoofing_and_domain_controller_impersonation) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | [Defense Evasion](/tags/#defense-evasion) | \ No newline at end of file diff --git a/docs/_playbooks/delete_detected_files.md b/docs/_playbooks/delete_detected_files.md index 8cfcdde7fa..cdfc5924d6 100644 --- a/docs/_playbooks/delete_detected_files.md +++ b/docs/_playbooks/delete_detected_files.md @@ -719,6 +719,9 @@ This playbook acts upon events where a file has been determined to be malicious + + + diff --git a/docs/_playbooks/log4j_investigate.md b/docs/_playbooks/log4j_investigate.md index dfffa5f799..a6b8404eb9 100644 --- a/docs/_playbooks/log4j_investigate.md +++ b/docs/_playbooks/log4j_investigate.md @@ -1369,6 +1369,12 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + + + + @@ -3162,6 +3168,12 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + + + + @@ -3952,6 +3964,9 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + @@ -4574,6 +4589,9 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + @@ -5273,6 +5291,9 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + @@ -5753,6 +5774,9 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + @@ -6301,6 +6325,9 @@ Published in response to CVE-2021-44228, this playbook and its sub-playbooks can + + + diff --git a/docs/_playbooks/log4j_respond.md b/docs/_playbooks/log4j_respond.md index d54e6d630a..e481f99c95 100644 --- a/docs/_playbooks/log4j_respond.md +++ b/docs/_playbooks/log4j_respond.md @@ -1369,6 +1369,12 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + + + + @@ -3162,6 +3168,12 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + + + + @@ -3952,6 +3964,9 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + @@ -4574,6 +4589,9 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + @@ -5273,6 +5291,9 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + @@ -5753,6 +5774,9 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + @@ -6301,6 +6325,9 @@ Published in response to CVE-2021-44228, this playbook is meant to be launched a + + + diff --git a/docs/_playbooks/ransomware_investigate_and_contain.md b/docs/_playbooks/ransomware_investigate_and_contain.md index 0299c811e8..bdea3a0823 100644 --- a/docs/_playbooks/ransomware_investigate_and_contain.md +++ b/docs/_playbooks/ransomware_investigate_and_contain.md @@ -723,6 +723,9 @@ This playbook investigates and contains ransomware detected on endpoints. + + + diff --git a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md index fdf9fa20c5..455b9a95ef 100644 --- a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md +++ b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md index 546b572f60..c3a9b214df 100644 --- a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md +++ b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md index e12d68de5b..b2e53eb9a5 100644 --- a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md +++ b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md index ab0ecc5637..b86e580526 100644 --- a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md +++ b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md index bcf8aaaa8c..5375c0dc11 100644 --- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md +++ b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md index 8fad54eb25..7eef32f339 100644 --- a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md index 4ad2e5b52c..1db007281a 100644 --- a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md index 84e6a6e56c..afd439206b 100644 --- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md +++ b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-10-13-unusually_long_content-type_length.md b/docs/_posts/2017-10-13-unusually_long_content-type_length.md index 656f58f772..7b784a60aa 100644 --- a/docs/_posts/2017-10-13-unusually_long_content-type_length.md +++ b/docs/_posts/2017-10-13-unusually_long_content-type_length.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md index 27c4ea999a..f8d7a0dcb4 100644 --- a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md +++ b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md index 16f6591cd9..2a75de252b 100644 --- a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md +++ b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md index 74be8d82f7..3a35522a01 100644 --- a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md +++ b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md index 3c89f71481..7d27c75c68 100644 --- a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md +++ b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md index abe9c62ba4..89f26464ad 100644 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md index c04d5022e3..01de59e01b 100644 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md index 305b0d96c0..13e25a88c2 100644 --- a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md +++ b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md index 57e387f1b3..7ab8e16864 100644 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ b/docs/_posts/2018-12-06-suspicious_java_classes.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md index 8eb6dcb7b4..371ae39b20 100644 --- a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md +++ b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md index a3a7ff4fe0..ff364d2b70 100644 --- a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md +++ b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md index 93b66ac79b..80bf394297 100644 --- a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md +++ b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md index e45ef8fd13..e3e0e07c56 100644 --- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md +++ b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md index 2324a3c081..a4693c8e2f 100644 --- a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md +++ b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md index c3a899224e..7bbcda1b38 100644 --- a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md +++ b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md index 5497d10313..67c87e61c3 100644 --- a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md +++ b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-detect_rare_executables.md b/docs/_posts/2020-03-16-detect_rare_executables.md index 52e81731e8..4acc79024a 100644 --- a/docs/_posts/2020-03-16-detect_rare_executables.md +++ b/docs/_posts/2020-03-16-detect_rare_executables.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-spike_in_file_writes.md b/docs/_posts/2020-03-16-spike_in_file_writes.md index b2b1612b06..097d2b4319 100644 --- a/docs/_posts/2020-03-16-spike_in_file_writes.md +++ b/docs/_posts/2020-03-16-spike_in_file_writes.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md index 648c5ac70a..e7c964633d 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md index 342fdf976a..dcc2ade5d0 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index e9f3b6a2de..1273a9a86e 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md index 21755982a6..494f9069b4 100644 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md +++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md index c47e24c064..461b3e2071 100644 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md index aea0b66924..b3bc479faf 100644 --- a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md +++ b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md index 34dfdef967..f4161d48d6 100644 --- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md +++ b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md index fad1b4da69..04e419a0d6 100644 --- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md +++ b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md index 6cec018769..567d895104 100644 --- a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md +++ b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md index efe6426756..811b95d6f6 100644 --- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md +++ b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md index 587c321922..8a54943096 100644 --- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md +++ b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md index a3971be906..fee7273c83 100644 --- a/docs/_posts/2020-07-21-excessive_dns_failures.md +++ b/docs/_posts/2020-07-21-excessive_dns_failures.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md index f59439128a..8d4503f02b 100644 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md index 0df2e3e9a4..56ceda832f 100644 --- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md +++ b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index 125925f8ea..820c32e491 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md index 76df51567f..16907b98e2 100644 --- a/docs/_posts/2020-07-21-okta_account_lockout_events.md +++ b/docs/_posts/2020-07-21-okta_account_lockout_events.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index f86000429d..54bd047e59 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index b398487cf2..0430827d4e 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md index 59b32e13bd..37da58a903 100644 --- a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md +++ b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md index 011f47bf11..7812840cfe 100644 --- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md +++ b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md index adc98ba3e1..055e3d35b6 100644 --- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md +++ b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md index 6d7527892e..7bdf6aca45 100644 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md index 05f075aa32..87d7018f47 100644 --- a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md +++ b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md index 46c91e5864..d1d6b9e306 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md index abb6589d8a..11ebfa0686 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index 657c0693e1..c3eb8c9414 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md index 4bde5a0a93..aba20ca45b 100644 --- a/docs/_posts/2020-07-22-tor_traffic.md +++ b/docs/_posts/2020-07-22-tor_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md index ac098cfc58..a8dee9f816 100644 --- a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md +++ b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md index de3b6f6ff7..e632104e28 100644 --- a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_role_creation.md b/docs/_posts/2020-07-27-aws_detect_role_creation.md index ec5164abee..53f807dd2c 100644 --- a/docs/_posts/2020-07-27-aws_detect_role_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_role_creation.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md index 251c22c45c..84b3076718 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md index e725754cc4..917c891929 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md index 6b5f9a566d..219d929334 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md index 88ae2f4a2f..991c26fa6b 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md index 66e0cb61d7..f472e72c33 100644 --- a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md +++ b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md index f0740c07c0..4795e1ad08 100644 --- a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md +++ b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md index 09b0d44813..2c935da8b4 100644 --- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md +++ b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md index 6ca47d8477..fe40472655 100644 --- a/docs/_posts/2020-08-11-detect_arp_poisoning.md +++ b/docs/_posts/2020-08-11-detect_arp_poisoning.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md index 898b1cb5bc..c5acae3bcb 100644 --- a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md +++ b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md index 0cf62cb13a..c250d88d78 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md @@ -25,7 +25,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md index 00e0f786ad..38f522e95e 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md @@ -25,7 +25,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md index cd75dc755b..086775892e 100644 --- a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md +++ b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md index c69b147120..39bd9bd064 100644 --- a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md +++ b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md index 17ff1b5612..5a197c1286 100644 --- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md +++ b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md index 0c0afb318c..d3b484cdb4 100644 --- a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md +++ b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md index fb54f9013b..9adb7bee09 100644 --- a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md +++ b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md index 0cf36a0a0d..ae6ab24373 100644 --- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md +++ b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md index 6486c00bc7..1d3a6924a4 100644 --- a/docs/_posts/2020-10-28-detect_port_security_violation.md +++ b/docs/_posts/2020-10-28-detect_port_security_violation.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md index 2cc469a351..218c429e0f 100644 --- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md +++ b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md index 4dd1b87f8a..e15d9742fb 100644 --- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md +++ b/docs/_posts/2020-10-28-detect_traffic_mirroring.md @@ -21,7 +21,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md index 84fc83f605..abd525a001 100644 --- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md +++ b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md index 72570dc4fa..daf9a8dd47 100644 --- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md +++ b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-06-supernova_webshell.md b/docs/_posts/2021-01-06-supernova_webshell.md index dbadb9f1d6..81bb04cc19 100644 --- a/docs/_posts/2021-01-06-supernova_webshell.md +++ b/docs/_posts/2021-01-06-supernova_webshell.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md index 112b57d434..fc27afff0a 100644 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md +++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md index b447f0ff1b..5924638bad 100644 --- a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md +++ b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md index b91ddbe8de..27e54e9976 100644 --- a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md +++ b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md index 332ddfc58c..ba7caeb0f7 100644 --- a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md +++ b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md index ed5ee31894..45bcba9e21 100644 --- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md +++ b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md index 2c97d73e16..3a204513e6 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md index 4a5e3f7198..d57afb5686 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md index 22dfe0d5f6..bbf3c5c62c 100644 --- a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md +++ b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-03-01-any_powershell_downloadfile.md b/docs/_posts/2021-03-01-any_powershell_downloadfile.md index 5af1e40a1a..612df1337e 100644 --- a/docs/_posts/2021-03-01-any_powershell_downloadfile.md +++ b/docs/_posts/2021-03-01-any_powershell_downloadfile.md @@ -97,7 +97,7 @@ False positives may be present and filtering will need to occur by parent proces | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-05-21-winrm_spawning_a_process.md b/docs/_posts/2021-05-21-winrm_spawning_a_process.md index 50038aa3aa..fd2d98382e 100644 --- a/docs/_posts/2021-05-21-winrm_spawning_a_process.md +++ b/docs/_posts/2021-05-21-winrm_spawning_a_process.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md index 1f3b635fde..b0024e160e 100644 --- a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md +++ b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md index 1eb10f9491..86c7b85291 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md +++ b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md index 2ce86bfe2a..961022da49 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md +++ b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md index 714b87b24c..f838a899a7 100644 --- a/docs/_posts/2021-09-28-print_processor_registry_autostart.md +++ b/docs/_posts/2021-09-28-print_processor_registry_autostart.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md b/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md index 277f4092b4..058e672ada 100644 --- a/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md +++ b/docs/_posts/2021-10-05-malicious_powershell_process_-_connect_to_internet_with_hidden_window.md @@ -98,7 +98,7 @@ Legitimate process can have this combination of command-line options, but it' | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md index 96af2320bc..9bfc5124e9 100644 --- a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md +++ b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md index d6165d454a..63db98ac26 100644 --- a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md +++ b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md index 220322b755..0749aefe13 100644 --- a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md @@ -22,7 +22,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md index 5979cf17df..a3345e7f46 100644 --- a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md index e5ad7cad7b..363b4387a5 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md +++ b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md index 68d8b11af7..b117314a6f 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md +++ b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md index 2428fde8c9..977af1e228 100644 --- a/docs/_posts/2021-12-10-curl_download_and_bash_execution.md +++ b/docs/_posts/2021-12-10-curl_download_and_bash_execution.md @@ -92,7 +92,7 @@ False positives should be limited, however filtering may be required. | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-11-wget_download_and_bash_execution.md b/docs/_posts/2021-12-11-wget_download_and_bash_execution.md index 76f3fe49d6..a32955e614 100644 --- a/docs/_posts/2021-12-11-wget_download_and_bash_execution.md +++ b/docs/_posts/2021-12-11-wget_download_and_bash_execution.md @@ -92,7 +92,7 @@ False positives should be limited, however filtering may be required. | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-13-cmd_carry_out_string_command_parameter.md b/docs/_posts/2021-12-13-cmd_carry_out_string_command_parameter.md index 38a0bc3e33..29f3d586dd 100644 --- a/docs/_posts/2021-12-13-cmd_carry_out_string_command_parameter.md +++ b/docs/_posts/2021-12-13-cmd_carry_out_string_command_parameter.md @@ -94,7 +94,7 @@ False positives may be high based on legitimate scripted code in any environment | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md b/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md index 90dc422735..345cff8038 100644 --- a/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md +++ b/docs/_posts/2021-12-13-detect_outbound_ldap_traffic.md @@ -89,7 +89,7 @@ Unknown at this moment. Outbound LDAP traffic should not be allowed outbound thr | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md b/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md index 817a87316a..d567c1cb8b 100644 --- a/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md +++ b/docs/_posts/2021-12-13-java_class_file_download_by_java_user_agent.md @@ -86,7 +86,7 @@ Filtering may be required in some instances, filter as needed. | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-13-linux_java_spawning_shell.md b/docs/_posts/2021-12-13-linux_java_spawning_shell.md index 671785d68d..c7539368b0 100644 --- a/docs/_posts/2021-12-13-linux_java_spawning_shell.md +++ b/docs/_posts/2021-12-13-linux_java_spawning_shell.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -93,7 +93,7 @@ Filtering may be required on internal developer build systems or classify assets | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md index 7e4615d7d1..a5c516bf66 100644 --- a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md +++ b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_attempt.md @@ -97,7 +97,7 @@ If there is a vulnerablility scannner looking for log4shells this will trigger, | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md index 1f9dadbed2..3e585f0ac3 100644 --- a/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md +++ b/docs/_posts/2021-12-13-log4shell_jndi_payload_injection_with_outbound_connection.md @@ -103,7 +103,7 @@ If there is a vulnerablility scannner looking for log4shells this will trigger, | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md b/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md index 34e66801b5..a4da3cde5b 100644 --- a/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md +++ b/docs/_posts/2021-12-13-outbound_network_connection_from_java_using_default_ports.md @@ -40,10 +40,16 @@ A required step while exploiting the CVE-2021-44228-Log4j vulnerability is that #### Search ``` - `sysmon` EventCode=3 (process_name=java OR process_name=java.exe) (DestinationPort=389 OR DestinationPort=1389 OR DestinationPort = 1099 ) -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, process_name, DestinationPort + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where (Processes.process_name="java.exe" OR Processes.process_name=javaw.exe OR Processes.process_name=javaw.exe) by _time Processes.process_guid Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| join process_guid [ +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Ports where (Ports.dest_port= 389 OR Ports.dest_port= 636 OR Ports.dest_port = 1389 OR Ports.dest_port = 1099 ) by Ports.process_guid Ports.dest Ports.dest_port +| `drop_dm_object_name(Ports)` +| rename dest as connection_to_CNC] +| table _time dest parent_process_name process_name process_path process connection_to_CNC dest_port | `outbound_network_connection_from_java_using_default_ports_filter` ``` @@ -56,12 +62,15 @@ To successfully implement this search you need to be ingesting information on pr #### Required field * _time -* process_name -* EventID -* CommandLine -* Computer -* DestinationPort -* DestinationIp +* Processes.process_guid +* Processes.process_name +* Processes.dest +* Processes.process_path +* Processes.process +* Processes.parent_process_name +* Ports.process_guid +* Ports.dest +* Ports.dest_port #### Kill Chain Phase @@ -84,7 +93,7 @@ Legitimate Java applications may use perform outbound connections to these ports | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | @@ -99,7 +108,7 @@ Legitimate Java applications may use perform outbound connections to these ports Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/linux-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/linux-sysmon.log) +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/outbound_java/windows-sysmon.log) diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md index 5a5e26df94..4142b5d2bd 100644 --- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md +++ b/docs/_posts/2021-12-13-windows_java_spawning_shells.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -93,7 +93,7 @@ Filtering may be required on internal developer build systems or classify assets | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-14-hunting_for_log4shell.md b/docs/_posts/2021-12-14-hunting_for_log4shell.md index 01c4e9145c..b51cfa3f8c 100644 --- a/docs/_posts/2021-12-14-hunting_for_log4shell.md +++ b/docs/_posts/2021-12-14-hunting_for_log4shell.md @@ -201,7 +201,7 @@ It is highly possible you will find false positives, however, the base score is | ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | | ----------- | ----------- | -------------- | -| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class). | None | +| [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) | Apache Log4j2 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0, this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. | 9.3 | diff --git a/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md b/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md new file mode 100644 index 0000000000..c50ba0c257 --- /dev/null +++ b/docs/_posts/2021-12-20-suspicious_computer_account_name_change.md @@ -0,0 +1,117 @@ +--- +title: "Suspicious Computer Account Name Change" +excerpt: "Valid Accounts, Domain Accounts" +categories: + - Endpoint +last_modified_at: 2021-12-20 +toc: true +toc_label: "" +tags: + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Domain Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - CVE-2021-42287 + - CVE-2021-42278 + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries need to create a new computer account name and rename it to match the name of a domain controller account without the ending '$'. In Windows Active Directory environments, computer account names always end with `$`. This analytic leverages Event Id 4781, `The name of an account was changed`, to identify a computer account rename event with a suspicious name that does not terminate with `$`. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-12-20 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 35a61ed8-61c4-11ec-bc1e-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +#### Search + +``` +`wineventlog_security` EventCode=4781 Old_Account_Name="*$" New_Account_Name!="*$" +| table _time, ComputerName, Account_Name, Old_Account_Name, New_Account_Name +| `suspicious_computer_account_name_change_filter` +``` + +#### Associated Analytic Story +* [sAMAccountName Spoofing and Domain Controller Impersonation](/stories/samaccountname_spoofing_and_domain_controller_impersonation) + + +#### How To Implement +To successfully implement this search, you need to be ingesting Windows event logs from your hosts. In addition, the Splunk Windows TA is needed. + +#### Required field +* _time +* EventCode +* ComputerName +* Account_Name +* Old_Account_Name +* New_Account_Name + + +#### Kill Chain Phase +* Privilege Escalation + + +#### Known False Positives +Renaming a computer account name to a name that not end with '$' is highly unsual and may not have any legitimate scenarios. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 70.0 | 100 | 70 | A computer account $Old_Account_Name$ was renamed with a suspicious computer name | + + + +#### CVE + +| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | +| ----------- | ----------- | -------------- | +| [CVE-2021-42287](https://nvd.nist.gov/vuln/detail/CVE-2021-42287) | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291. | 6.5 | +| [CVE-2021-42278](https://nvd.nist.gov/vuln/detail/CVE-2021-42278) | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291. | 6.5 | + + + +#### Reference + +* [https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) +* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278) +* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_computer_account_name_change.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md b/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md new file mode 100644 index 0000000000..c67b4e4ab7 --- /dev/null +++ b/docs/_posts/2021-12-20-suspicious_kerberos_service_ticket_request.md @@ -0,0 +1,120 @@ +--- +title: "Suspicious Kerberos Service Ticket Request" +excerpt: "Valid Accounts, Domain Accounts" +categories: + - Endpoint +last_modified_at: 2021-12-20 +toc: true +toc_label: "" +tags: + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Domain Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - CVE-2021-42287 + - CVE-2021-42278 + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries will request and obtain a Kerberos Service Ticket (TGS) with a domain controller computer account as the Service Name. This Service Ticket can be then used to take control of the domain controller on the final part of the attack. This analytic leverages Event Id 4769, `A Kerberos service ticket was requested`, to identify an unusual TGS request where the Account_Name requesting the ticket matches the Service_Name field. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-12-20 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 8b1297bc-6204-11ec-b7c4-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +#### Search + +``` + `wineventlog_security` EventCode=4769 +| eval isSuspicious = if(lower(Service_Name) = lower(mvindex(split(Account_Name,"@"),0)+"$"),1,0) +| where isSuspicious = 1 +| table _time, Client_Address, Account_Name, Service_Name, Failure_Code, isSuspicious +| `suspicious_kerberos_service_ticket_request_filter` +``` + +#### Associated Analytic Story +* [sAMAccountName Spoofing and Domain Controller Impersonation](/stories/samaccountname_spoofing_and_domain_controller_impersonation) + + +#### How To Implement +To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. + +#### Required field +* _time +* EventCode +* Service_Name +* Account_Name +* Client_Address +* Failure_Code + + +#### Kill Chain Phase +* Privilege Escalation + + +#### Known False Positives +We have tested this detection logic with ~2 million 4769 events and did not identify false positives. However, they may be possible in certain environments. Filter as needed. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 60.0 | 100 | 60 | A suspicious Kerberos Service Ticket was requested by $Account_Name$ | + + + +#### CVE + +| ID | Summary | [CVSS](https://nvd.nist.gov/vuln-metrics/cvss) | +| ----------- | ----------- | -------------- | +| [CVE-2021-42287](https://nvd.nist.gov/vuln/detail/CVE-2021-42287) | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291. | 6.5 | +| [CVE-2021-42278](https://nvd.nist.gov/vuln/detail/CVE-2021-42278) | Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291. | 6.5 | + + + +#### Reference + +* [https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) +* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278) +* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287) +* [https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-sfu/02636893-7a1f-4357-af9a-b672e3e3de13](https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-sfu/02636893-7a1f-4357-af9a-b672e3e3de13) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_kerberos_service_ticket_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md b/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md new file mode 100644 index 0000000000..d6d6c3df82 --- /dev/null +++ b/docs/_posts/2021-12-21-suspicious_ticket_granting_ticket_request.md @@ -0,0 +1,111 @@ +--- +title: "Suspicious Ticket Granting Ticket Request" +excerpt: "Valid Accounts, Domain Accounts" +categories: + - Endpoint +last_modified_at: 2021-12-21 +toc: true +toc_label: "" +tags: + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Domain Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +As part of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) exploitation chain, adversaries will need to request a Kerberos Ticket Granting Ticket (TGT) on behalf of the newly created and renamed computer account. The TGT request will be preceded by a computer account name event. This analytic leverages Event Id 4781, `The name of an account was changed` and event Id 4768 `A Kerberos authentication ticket (TGT) was requested` to correlate a sequence of events where the new computer account on event id 4781 matches the request account on event id 4768. This behavior could represent an exploitation attempt of CVE-2021-42278 and CVE-2021-42287 for privilege escalation. + +- **Type**: Hunting +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-12-21 +- **Author**: Mauricio Velazco, Splunk +- **ID**: d77d349e-6269-11ec-9cfe-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +| [T1078.002](https://attack.mitre.org/techniques/T1078/002/) | Domain Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +#### Search + +``` + `wineventlog_security` (EventCode=4781 Old_Account_Name="*$" New_Account_Name!="*$") OR (EventCode=4768 Account_Name!="*$") +| eval RenamedComputerAccount = coalesce(New_Account_Name, mvindex(Account_Name,0)) +| transaction RenamedComputerAccount startswith=(EventCode=4781) endswith=(EventCode=4768) +| eval short_lived=case((duration<2),"TRUE") +| search short_lived = TRUE +| table _time, ComputerName, EventCode, Account_Name,RenamedComputerAccount, short_lived +|`suspicious_ticket_granting_ticket_request_filter` +``` + +#### Associated Analytic Story +* [sAMAccountName Spoofing and Domain Controller Impersonation](/stories/samaccountname_spoofing_and_domain_controller_impersonation) + + +#### How To Implement +To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. + +#### Required field +* _time +* EventCode +* Old_Account_Name +* New_Account_Name +* Account_Name +* ComputerName + + +#### Kill Chain Phase +* Privilege Escalation + + +#### Known False Positives +A computer account name change event inmediately followed by a kerberos TGT request with matching fields is unsual. However, legitimate behavior may trigger it. Filter as needed. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 60.0 | 100 | 60 | A suspicious TGT was requested was requested | + + + + +#### Reference + +* [https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) +* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278) +* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.002/samaccountname_spoofing/windows-security.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/suspicious_ticket_granting_ticket_request.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/credential_dumping.md b/docs/_stories/credential_dumping.md index 1bae69e6b5..dc36fe0040 100644 --- a/docs/_stories/credential_dumping.md +++ b/docs/_stories/credential_dumping.md @@ -35,8 +35,8 @@ The detection searches in this Analytic Story monitor access to the Local Securi | Name | Technique | Type | | ----------- | ----------- |--------------| | [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Security Account Manager](/tags/#security-account-manager) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | diff --git a/docs/_stories/samaccountname_spoofing_and_domain_controller_impersonation.md b/docs/_stories/samaccountname_spoofing_and_domain_controller_impersonation.md new file mode 100644 index 0000000000..f0f76e3896 --- /dev/null +++ b/docs/_stories/samaccountname_spoofing_and_domain_controller_impersonation.md @@ -0,0 +1,45 @@ +--- +title: "sAMAccountName Spoofing and Domain Controller Impersonation" +last_modified_at: 2021-12-20 +toc: true +toc_label: "" +tags: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +Monitor for activities and techniques associated with the exploitation of the sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287) vulnerabilities. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-12-20 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 0244fdee-61be-11ec-900e-acde48001122 + +#### Narrative + +On November 9, 2021, Microsoft released patches to address two vulnerabilities that affect Windows Active Directory networks, sAMAccountName Spoofing (CVE-2021-42278) and Domain Controller Impersonation (CVE-2021-42287). On December 10, 2021, security researchers Charlie Clark and Andrew Schwartz released a blog post where they shared how to weaponise these vulnerabilities in a target network an the initial detection opportunities. When successfully exploited, CVE-2021-42278 and CVE-2021-42287 allow an adversary, who has stolen the credentials of a low priviled domain user, to obtain a Kerberos Service ticket for a Domain Controller computer account. The only requirement is to have network connectivity to a domain controller. This attack vector effectivelly allows attackers to escalate their privileges in an Active Directory from a regular domain user account and take control of a domain controller. While patches have been released to address these vulnerabilities, deploying detection controls for this attack may help help defenders identify attackers attempting exploitation. + +#### Detections + +| Name | Technique | Type | +| ----------- | ----------- |--------------| +| [Suspicious Computer Account Name Change](/endpoint/suspicious_computer_account_name_change/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | TTP | +| [Suspicious Kerberos Service Ticket Request](/endpoint/suspicious_kerberos_service_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | TTP | +| [Suspicious Ticket Granting Ticket Request](/endpoint/suspicious_ticket_granting_ticket_request/) | [Valid Accounts](/tags/#valid-accounts), [Domain Accounts](/tags/#domain-accounts) | Hunting | + +#### Reference + +* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278) +* [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287) +* [https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/stories/samaccountname_spoofing_and_domain_controller_impersonation.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/index.markdown b/docs/index.markdown index 94ea7dcdae..60f02392ab 100644 --- a/docs/index.markdown +++ b/docs/index.markdown @@ -9,19 +9,19 @@ header: actions: - label: "Download" url: "https://splunkbase.splunk.com/app/3449/" -excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **696** detections for Splunk." +excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **699** detections for Splunk." feature_row: - image_path: /static/feature_detection.png alt: "customizable" title: "Detections" - excerpt: "See all **696** Splunk Analytics built to find evil 😈." + excerpt: "See all **699** Splunk Analytics built to find evil 😈." url: "/detections" btn_class: "btn--primary" btn_label: "Explore" - image_path: /static/feature_stories.png alt: "fully responsive" title: "Analytic Stories" - excerpt: "See all **107** use cases, 📦 of detections built to address a threat." + excerpt: "See all **108** use cases, 📦 of detections built to address a threat." url: "/stories" btn_class: "btn--primary" btn_label: "Explore" From 50ba79335884b5e6ae93cfff74725be0c7907e9b Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 3 Jan 2022 12:20:42 -0500 Subject: [PATCH 2/4] fixing formatting --- bin/jinja2_templates/doc_detections.j2 | 2 +- docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md | 2 +- .../2017-09-13-detect_unauthorized_assets_by_mac_address.md | 2 +- docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md | 2 +- docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md | 2 +- docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md | 2 +- ...23-detect_attackers_scanning_for_vulnerable_jboss_servers.md | 2 +- ...-09-23-detect_malicious_requests_to_exploit_jboss_servers.md | 2 +- docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md | 2 +- docs/_posts/2017-10-13-unusually_long_content-type_length.md | 2 +- docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md | 2 +- ...07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md | 2 +- docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md | 2 +- docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md | 2 +- docs/_posts/2018-10-23-wmi_permanent_event_subscription.md | 2 +- docs/_posts/2018-10-23-wmi_temporary_event_subscription.md | 2 +- docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md | 2 +- docs/_posts/2018-12-06-suspicious_java_classes.md | 2 +- docs/_posts/2019-01-25-processes_tapping_keyboard_events.md | 2 +- .../2019-04-01-web_servers_executing_suspicious_processes.md | 2 +- docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md | 2 +- docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md | 2 +- docs/_posts/2020-02-07-macos_-_re-opened_applications.md | 2 +- docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md | 2 +- docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md | 2 +- docs/_posts/2020-03-16-detect_rare_executables.md | 2 +- docs/_posts/2020-03-16-spike_in_file_writes.md | 2 +- .../2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md | 2 +- .../2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md | 2 +- docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md | 2 +- ...2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md | 2 +- docs/_posts/2020-07-07-remote_desktop_network_traffic.md | 2 +- .../2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md | 2 +- docs/_posts/2020-07-21-detect_outbound_smb_traffic.md | 2 +- docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md | 2 +- docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md | 2 +- ...7-21-email_files_written_outside_of_the_outlook_directory.md | 2 +- ...-07-21-email_servers_sending_high_volume_traffic_to_hosts.md | 2 +- docs/_posts/2020-07-21-excessive_dns_failures.md | 2 +- .../2020-07-21-first_time_seen_running_windows_service.md | 2 +- ...eceiving_high_volume_of_network_traffic_from_email_server.md | 2 +- ...iple_okta_users_with_invalid_credentials_from_the_same_ip.md | 2 +- docs/_posts/2020-07-21-okta_account_lockout_events.md | 2 +- docs/_posts/2020-07-21-okta_failed_sso_attempts.md | 2 +- docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md | 2 +- docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md | 2 +- docs/_posts/2020-07-21-protocol_or_port_mismatch.md | 2 +- docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md | 2 +- .../2020-07-21-remote_desktop_process_running_on_system.md | 2 +- docs/_posts/2020-07-21-sql_injection_with_long_urls.md | 2 +- docs/_posts/2020-07-22-smb_traffic_spike.md | 2 +- docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md | 2 +- .../_posts/2020-07-22-suspicious_email_attachment_extensions.md | 2 +- docs/_posts/2020-07-22-tor_traffic.md | 2 +- docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md | 2 +- docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md | 2 +- docs/_posts/2020-07-27-aws_detect_role_creation.md | 2 +- docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md | 2 +- .../_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md | 2 +- .../2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md | 2 +- docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md | 2 +- docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md | 2 +- docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md | 2 +- .../2020-08-10-detect_gcp_storage_access_from_a_new_ip.md | 2 +- docs/_posts/2020-08-11-detect_arp_poisoning.md | 2 +- docs/_posts/2020-08-11-detect_rogue_dhcp_server.md | 2 +- ...08-21-abnormally_high_number_of_cloud_instances_destroyed.md | 2 +- ...-08-21-abnormally_high_number_of_cloud_instances_launched.md | 2 +- ...phishing_email_detection_by_machine_learning_method_-_ssa.md | 2 +- docs/_posts/2020-09-15-detect_zerologon_via_zeek.md | 2 +- ...2020-09-18-detect_computer_changed_with_anonymous_account.md | 2 +- docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md | 2 +- docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md | 2 +- .../2020-10-28-detect_ipv6_network_infrastructure_threats.md | 2 +- docs/_posts/2020-10-28-detect_port_security_violation.md | 2 +- .../2020-10-28-detect_software_download_to_network_device.md | 2 +- docs/_posts/2020-10-28-detect_traffic_mirroring.md | 2 +- .../2020-12-14-sunburst_correlation_dll_and_network_event.md | 2 +- ...-12-16-high_number_of_login_failures_from_a_single_source.md | 2 +- docs/_posts/2021-01-06-supernova_webshell.md | 2 +- ...21-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md | 2 +- docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md | 2 +- ...2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md | 2 +- .../2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md | 2 +- docs/_posts/2021-02-22-suspicious_curl_network_connection.md | 2 +- docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md | 2 +- .../2021-02-22-suspicious_plistbuddy_usage_via_osquery.md | 2 +- .../2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md | 2 +- docs/_posts/2021-05-21-winrm_spawning_a_process.md | 2 +- .../2021-08-19-protocols_passing_authentication_in_cleartext.md | 2 +- docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md | 2 +- docs/_posts/2021-08-27-exchange_powershell_module_usage.md | 2 +- docs/_posts/2021-09-28-print_processor_registry_autostart.md | 2 +- docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md | 2 +- docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md | 2 +- .../_posts/2021-11-29-randomly_generated_scheduled_task_name.md | 2 +- .../2021-11-29-randomly_generated_windows_service_name.md | 2 +- ...2-01-unusual_number_of_computer_service_tickets_requested.md | 2 +- ...1-unusual_number_of_remote_endpoint_authentication_events.md | 2 +- docs/_posts/2021-12-13-linux_java_spawning_shell.md | 2 +- docs/_posts/2021-12-13-windows_java_spawning_shells.md | 2 +- 101 files changed, 101 insertions(+), 101 deletions(-) diff --git a/bin/jinja2_templates/doc_detections.j2 b/bin/jinja2_templates/doc_detections.j2 index 99bfc103b0..c570a7238b 100644 --- a/bin/jinja2_templates/doc_detections.j2 +++ b/bin/jinja2_templates/doc_detections.j2 @@ -31,7 +31,7 @@ tags: {% if detection.experimental is sameas true -%} ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! {% endif %} [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md index 455b9a95ef..4b3af82123 100644 --- a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md +++ b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md index c3a9b214df..8a1cb3ee04 100644 --- a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md +++ b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md index b2e53eb9a5..994c664299 100644 --- a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md +++ b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md index b86e580526..cdd6fe62ed 100644 --- a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md +++ b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md index 5375c0dc11..ef476b6f1c 100644 --- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md +++ b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md index 7eef32f339..944f62ab7b 100644 --- a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md index 1db007281a..add54c77c8 100644 --- a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md index afd439206b..e1f2fb67c9 100644 --- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md +++ b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-10-13-unusually_long_content-type_length.md b/docs/_posts/2017-10-13-unusually_long_content-type_length.md index 7b784a60aa..4594fb7478 100644 --- a/docs/_posts/2017-10-13-unusually_long_content-type_length.md +++ b/docs/_posts/2017-10-13-unusually_long_content-type_length.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md index f8d7a0dcb4..06a77b0ac9 100644 --- a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md +++ b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md index 2a75de252b..a052304bdc 100644 --- a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md +++ b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md index 3a35522a01..27a1c6a08e 100644 --- a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md +++ b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md index 7d27c75c68..9b18393ec9 100644 --- a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md +++ b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md index 89f26464ad..4df111eeb5 100644 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md index 01de59e01b..7cfed94862 100644 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md index 13e25a88c2..ab5bdbbc6e 100644 --- a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md +++ b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md index 7ab8e16864..98faa510fa 100644 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ b/docs/_posts/2018-12-06-suspicious_java_classes.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md index 371ae39b20..f04e836c7d 100644 --- a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md +++ b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md index ff364d2b70..8670eddf75 100644 --- a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md +++ b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md index 80bf394297..c90dbc6641 100644 --- a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md +++ b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md index e3e0e07c56..05ed2d701b 100644 --- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md +++ b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md index a4693c8e2f..b26bdea73f 100644 --- a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md +++ b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md index 7bbcda1b38..34b3fb6140 100644 --- a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md +++ b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md index 67c87e61c3..fd87407d7e 100644 --- a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md +++ b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-detect_rare_executables.md b/docs/_posts/2020-03-16-detect_rare_executables.md index 4acc79024a..03b9ba9906 100644 --- a/docs/_posts/2020-03-16-detect_rare_executables.md +++ b/docs/_posts/2020-03-16-detect_rare_executables.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-spike_in_file_writes.md b/docs/_posts/2020-03-16-spike_in_file_writes.md index 097d2b4319..d1f4d53943 100644 --- a/docs/_posts/2020-03-16-spike_in_file_writes.md +++ b/docs/_posts/2020-03-16-spike_in_file_writes.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md index e7c964633d..e4136ac0cb 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md index dcc2ade5d0..0774efabd0 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index 1273a9a86e..d0fb5ae155 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md index 494f9069b4..56da1a0fd2 100644 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md +++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md index 461b3e2071..e30de987fc 100644 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md index b3bc479faf..eafb4b351e 100644 --- a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md +++ b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md index f4161d48d6..feda7694ba 100644 --- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md +++ b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md index 04e419a0d6..b90360493d 100644 --- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md +++ b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md index 567d895104..54cbe330b9 100644 --- a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md +++ b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md index 811b95d6f6..886cce9564 100644 --- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md +++ b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md index 8a54943096..f6b8e3d247 100644 --- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md +++ b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md index fee7273c83..77111d0d16 100644 --- a/docs/_posts/2020-07-21-excessive_dns_failures.md +++ b/docs/_posts/2020-07-21-excessive_dns_failures.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md index 8d4503f02b..e45d4a4794 100644 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md index 56ceda832f..b37b845b8f 100644 --- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md +++ b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index 820c32e491..5c87c7325e 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md index 16907b98e2..c3066252ed 100644 --- a/docs/_posts/2020-07-21-okta_account_lockout_events.md +++ b/docs/_posts/2020-07-21-okta_account_lockout_events.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index 54bd047e59..5e464b9e82 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index 0430827d4e..8cee8a7ed1 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md index 37da58a903..a5c9a21725 100644 --- a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md +++ b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md index 7812840cfe..b26c0dc59c 100644 --- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md +++ b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md index 055e3d35b6..69eda237e9 100644 --- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md +++ b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md index 7bdf6aca45..cdc5b5aa42 100644 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md index 87d7018f47..969f09985f 100644 --- a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md +++ b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md index d1d6b9e306..61d5628b70 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md index 11ebfa0686..04fdfa0d23 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index c3eb8c9414..f3e1c859a1 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md index aba20ca45b..92553d5fba 100644 --- a/docs/_posts/2020-07-22-tor_traffic.md +++ b/docs/_posts/2020-07-22-tor_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md index a8dee9f816..2c64d8bf1a 100644 --- a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md +++ b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md index e632104e28..9e6f680cb0 100644 --- a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_role_creation.md b/docs/_posts/2020-07-27-aws_detect_role_creation.md index 53f807dd2c..f01c3f38ab 100644 --- a/docs/_posts/2020-07-27-aws_detect_role_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_role_creation.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md index 84b3076718..da1c3dd75c 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md index 917c891929..3ccd85eae8 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md index 219d929334..f08230f3e4 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md index 991c26fa6b..09a634c815 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md index f472e72c33..a9e9e523cf 100644 --- a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md +++ b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md index 4795e1ad08..5f5c6f1dd7 100644 --- a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md +++ b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md index 2c935da8b4..8a2310859e 100644 --- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md +++ b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md index fe40472655..166e5b1ad0 100644 --- a/docs/_posts/2020-08-11-detect_arp_poisoning.md +++ b/docs/_posts/2020-08-11-detect_arp_poisoning.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md index c5acae3bcb..a7ff8cb52b 100644 --- a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md +++ b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md index c250d88d78..01236c47f8 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md @@ -25,7 +25,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md index 38f522e95e..ca3708022a 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md @@ -25,7 +25,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md index 086775892e..8f52bf663d 100644 --- a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md +++ b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md index 39bd9bd064..bca76e453e 100644 --- a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md +++ b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md index 5a197c1286..667c0d4b27 100644 --- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md +++ b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md index d3b484cdb4..b4f87bda90 100644 --- a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md +++ b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md index 9adb7bee09..51ed4a7b3c 100644 --- a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md +++ b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md index ae6ab24373..77c96f1376 100644 --- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md +++ b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md index 1d3a6924a4..937cc52bcf 100644 --- a/docs/_posts/2020-10-28-detect_port_security_violation.md +++ b/docs/_posts/2020-10-28-detect_port_security_violation.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md index 218c429e0f..33ee886742 100644 --- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md +++ b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md index e15d9742fb..4b237165dd 100644 --- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md +++ b/docs/_posts/2020-10-28-detect_traffic_mirroring.md @@ -21,7 +21,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md index abd525a001..6d28d18b77 100644 --- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md +++ b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md index daf9a8dd47..8c4c25c39b 100644 --- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md +++ b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-06-supernova_webshell.md b/docs/_posts/2021-01-06-supernova_webshell.md index 81bb04cc19..8531f0b3a2 100644 --- a/docs/_posts/2021-01-06-supernova_webshell.md +++ b/docs/_posts/2021-01-06-supernova_webshell.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md index fc27afff0a..24c34734d6 100644 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md +++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md index 5924638bad..0bc6afacef 100644 --- a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md +++ b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md index 27e54e9976..9a3084f899 100644 --- a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md +++ b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md index ba7caeb0f7..a0856f5491 100644 --- a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md +++ b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md index 45bcba9e21..69558a9a0f 100644 --- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md +++ b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md index 3a204513e6..724095d46a 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md index d57afb5686..ff0531a18b 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md index bbf3c5c62c..8e61c6c080 100644 --- a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md +++ b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-05-21-winrm_spawning_a_process.md b/docs/_posts/2021-05-21-winrm_spawning_a_process.md index fd2d98382e..c7db3ec60f 100644 --- a/docs/_posts/2021-05-21-winrm_spawning_a_process.md +++ b/docs/_posts/2021-05-21-winrm_spawning_a_process.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md index b0024e160e..b00bf77307 100644 --- a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md +++ b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md index 86c7b85291..3ec80b3747 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md +++ b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md index 961022da49..a286e2e50f 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md +++ b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md index f838a899a7..cd2d38cd92 100644 --- a/docs/_posts/2021-09-28-print_processor_registry_autostart.md +++ b/docs/_posts/2021-09-28-print_processor_registry_autostart.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md index 9bfc5124e9..ba3b0263b2 100644 --- a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md +++ b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md index 63db98ac26..e38d5dd232 100644 --- a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md +++ b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md index 0749aefe13..55536c2b73 100644 --- a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md @@ -22,7 +22,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md index a3345e7f46..c9f1572b72 100644 --- a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md index 363b4387a5..aa38ac6335 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md +++ b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md index b117314a6f..0f76d78cfc 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md +++ b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-13-linux_java_spawning_shell.md b/docs/_posts/2021-12-13-linux_java_spawning_shell.md index c7539368b0..5c2b0cbfca 100644 --- a/docs/_posts/2021-12-13-linux_java_spawning_shell.md +++ b/docs/_posts/2021-12-13-linux_java_spawning_shell.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md index 4142b5d2bd..195d5cafe2 100644 --- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md +++ b/docs/_posts/2021-12-13-windows_java_spawning_shells.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT supported**! +We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} From 7c1025425aa78ec54075c125de9953f3f4b1e61b Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 3 Jan 2022 14:35:49 -0500 Subject: [PATCH 3/4] fixed spelling --- bin/jinja2_templates/doc_detections.j2 | 2 +- docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md | 2 +- .../2017-09-13-detect_unauthorized_assets_by_mac_address.md | 2 +- docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md | 2 +- docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md | 2 +- docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md | 2 +- ...23-detect_attackers_scanning_for_vulnerable_jboss_servers.md | 2 +- ...-09-23-detect_malicious_requests_to_exploit_jboss_servers.md | 2 +- docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md | 2 +- docs/_posts/2017-10-13-unusually_long_content-type_length.md | 2 +- docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md | 2 +- ...07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md | 2 +- docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md | 2 +- docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md | 2 +- docs/_posts/2018-10-23-wmi_permanent_event_subscription.md | 2 +- docs/_posts/2018-10-23-wmi_temporary_event_subscription.md | 2 +- docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md | 2 +- docs/_posts/2018-12-06-suspicious_java_classes.md | 2 +- docs/_posts/2019-01-25-processes_tapping_keyboard_events.md | 2 +- .../2019-04-01-web_servers_executing_suspicious_processes.md | 2 +- docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md | 2 +- docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md | 2 +- docs/_posts/2020-02-07-macos_-_re-opened_applications.md | 2 +- docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md | 2 +- docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md | 2 +- docs/_posts/2020-03-16-detect_rare_executables.md | 2 +- docs/_posts/2020-03-16-spike_in_file_writes.md | 2 +- .../2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md | 2 +- .../2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md | 2 +- docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md | 2 +- ...2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md | 2 +- docs/_posts/2020-07-07-remote_desktop_network_traffic.md | 2 +- .../2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md | 2 +- docs/_posts/2020-07-21-detect_outbound_smb_traffic.md | 2 +- docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md | 2 +- docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md | 2 +- ...7-21-email_files_written_outside_of_the_outlook_directory.md | 2 +- ...-07-21-email_servers_sending_high_volume_traffic_to_hosts.md | 2 +- docs/_posts/2020-07-21-excessive_dns_failures.md | 2 +- .../2020-07-21-first_time_seen_running_windows_service.md | 2 +- ...eceiving_high_volume_of_network_traffic_from_email_server.md | 2 +- ...iple_okta_users_with_invalid_credentials_from_the_same_ip.md | 2 +- docs/_posts/2020-07-21-okta_account_lockout_events.md | 2 +- docs/_posts/2020-07-21-okta_failed_sso_attempts.md | 2 +- docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md | 2 +- docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md | 2 +- docs/_posts/2020-07-21-protocol_or_port_mismatch.md | 2 +- docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md | 2 +- .../2020-07-21-remote_desktop_process_running_on_system.md | 2 +- docs/_posts/2020-07-21-sql_injection_with_long_urls.md | 2 +- docs/_posts/2020-07-22-smb_traffic_spike.md | 2 +- docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md | 2 +- .../_posts/2020-07-22-suspicious_email_attachment_extensions.md | 2 +- docs/_posts/2020-07-22-tor_traffic.md | 2 +- docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md | 2 +- docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md | 2 +- docs/_posts/2020-07-27-aws_detect_role_creation.md | 2 +- docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md | 2 +- .../_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md | 2 +- .../2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md | 2 +- docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md | 2 +- docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md | 2 +- docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md | 2 +- .../2020-08-10-detect_gcp_storage_access_from_a_new_ip.md | 2 +- docs/_posts/2020-08-11-detect_arp_poisoning.md | 2 +- docs/_posts/2020-08-11-detect_rogue_dhcp_server.md | 2 +- ...08-21-abnormally_high_number_of_cloud_instances_destroyed.md | 2 +- ...-08-21-abnormally_high_number_of_cloud_instances_launched.md | 2 +- ...phishing_email_detection_by_machine_learning_method_-_ssa.md | 2 +- docs/_posts/2020-09-15-detect_zerologon_via_zeek.md | 2 +- ...2020-09-18-detect_computer_changed_with_anonymous_account.md | 2 +- docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md | 2 +- docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md | 2 +- .../2020-10-28-detect_ipv6_network_infrastructure_threats.md | 2 +- docs/_posts/2020-10-28-detect_port_security_violation.md | 2 +- .../2020-10-28-detect_software_download_to_network_device.md | 2 +- docs/_posts/2020-10-28-detect_traffic_mirroring.md | 2 +- .../2020-12-14-sunburst_correlation_dll_and_network_event.md | 2 +- ...-12-16-high_number_of_login_failures_from_a_single_source.md | 2 +- docs/_posts/2021-01-06-supernova_webshell.md | 2 +- ...21-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md | 2 +- docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md | 2 +- ...2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md | 2 +- .../2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md | 2 +- docs/_posts/2021-02-22-suspicious_curl_network_connection.md | 2 +- docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md | 2 +- .../2021-02-22-suspicious_plistbuddy_usage_via_osquery.md | 2 +- .../2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md | 2 +- docs/_posts/2021-05-21-winrm_spawning_a_process.md | 2 +- .../2021-08-19-protocols_passing_authentication_in_cleartext.md | 2 +- docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md | 2 +- docs/_posts/2021-08-27-exchange_powershell_module_usage.md | 2 +- docs/_posts/2021-09-28-print_processor_registry_autostart.md | 2 +- docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md | 2 +- docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md | 2 +- .../_posts/2021-11-29-randomly_generated_scheduled_task_name.md | 2 +- .../2021-11-29-randomly_generated_windows_service_name.md | 2 +- ...2-01-unusual_number_of_computer_service_tickets_requested.md | 2 +- ...1-unusual_number_of_remote_endpoint_authentication_events.md | 2 +- docs/_posts/2021-12-13-linux_java_spawning_shell.md | 2 +- docs/_posts/2021-12-13-windows_java_spawning_shells.md | 2 +- 101 files changed, 101 insertions(+), 101 deletions(-) diff --git a/bin/jinja2_templates/doc_detections.j2 b/bin/jinja2_templates/doc_detections.j2 index c570a7238b..1674d9d254 100644 --- a/bin/jinja2_templates/doc_detections.j2 +++ b/bin/jinja2_templates/doc_detections.j2 @@ -31,7 +31,7 @@ tags: {% if detection.experimental is sameas true -%} ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. {% endif %} [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md index 4b3af82123..63635e1cac 100644 --- a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md +++ b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md index 8a1cb3ee04..1ce370f054 100644 --- a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md +++ b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md index 994c664299..5337f62a6a 100644 --- a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md +++ b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md index cdd6fe62ed..7c4dc9c10c 100644 --- a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md +++ b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md index ef476b6f1c..65763038e2 100644 --- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md +++ b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md index 944f62ab7b..5c88083518 100644 --- a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md index add54c77c8..7cb062a67e 100644 --- a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md index e1f2fb67c9..9d86d10c78 100644 --- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md +++ b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-10-13-unusually_long_content-type_length.md b/docs/_posts/2017-10-13-unusually_long_content-type_length.md index 4594fb7478..1d5a1ceddd 100644 --- a/docs/_posts/2017-10-13-unusually_long_content-type_length.md +++ b/docs/_posts/2017-10-13-unusually_long_content-type_length.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md index 06a77b0ac9..b1ab0a9661 100644 --- a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md +++ b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md index a052304bdc..a4a747e994 100644 --- a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md +++ b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md index 27a1c6a08e..235fec05e1 100644 --- a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md +++ b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md index 9b18393ec9..fc46eeedd9 100644 --- a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md +++ b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md index 4df111eeb5..d71ae84c90 100644 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md index 7cfed94862..2835a4e40e 100644 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md index ab5bdbbc6e..c0bfc0d70a 100644 --- a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md +++ b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md index 98faa510fa..ba3a15d0d1 100644 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ b/docs/_posts/2018-12-06-suspicious_java_classes.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md index f04e836c7d..d8086a4b48 100644 --- a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md +++ b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md index 8670eddf75..503ea38ec0 100644 --- a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md +++ b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md index c90dbc6641..074dd9597c 100644 --- a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md +++ b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md index 05ed2d701b..8e002cabd3 100644 --- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md +++ b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md index b26bdea73f..5a972cdf0b 100644 --- a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md +++ b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md index 34b3fb6140..1b89ba0d20 100644 --- a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md +++ b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md index fd87407d7e..0e9289dfb6 100644 --- a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md +++ b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-detect_rare_executables.md b/docs/_posts/2020-03-16-detect_rare_executables.md index 03b9ba9906..e63b22f9d2 100644 --- a/docs/_posts/2020-03-16-detect_rare_executables.md +++ b/docs/_posts/2020-03-16-detect_rare_executables.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-spike_in_file_writes.md b/docs/_posts/2020-03-16-spike_in_file_writes.md index d1f4d53943..7a2b124379 100644 --- a/docs/_posts/2020-03-16-spike_in_file_writes.md +++ b/docs/_posts/2020-03-16-spike_in_file_writes.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md index e4136ac0cb..22987a3ab7 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md index 0774efabd0..a4aaf7629d 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index d0fb5ae155..aa1133c56a 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md index 56da1a0fd2..daac2680d6 100644 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md +++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md index e30de987fc..cf87f364c0 100644 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md index eafb4b351e..780e30ab19 100644 --- a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md +++ b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md index feda7694ba..79490e9115 100644 --- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md +++ b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md index b90360493d..e3bf0189b9 100644 --- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md +++ b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md index 54cbe330b9..ebefaebf7e 100644 --- a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md +++ b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md index 886cce9564..31a2c28fe1 100644 --- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md +++ b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md index f6b8e3d247..fa7612e255 100644 --- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md +++ b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md index 77111d0d16..446b6fc857 100644 --- a/docs/_posts/2020-07-21-excessive_dns_failures.md +++ b/docs/_posts/2020-07-21-excessive_dns_failures.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md index e45d4a4794..2bd70571d5 100644 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md index b37b845b8f..2b02f90b3c 100644 --- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md +++ b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index 5c87c7325e..ed581283cc 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md index c3066252ed..4f96ebd047 100644 --- a/docs/_posts/2020-07-21-okta_account_lockout_events.md +++ b/docs/_posts/2020-07-21-okta_account_lockout_events.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index 5e464b9e82..b42cee4c7d 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index 8cee8a7ed1..ce7829be86 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md index a5c9a21725..9b54527c5e 100644 --- a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md +++ b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md index b26c0dc59c..6532f871e8 100644 --- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md +++ b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md index 69eda237e9..b00c47cbb2 100644 --- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md +++ b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md index cdc5b5aa42..62d18e5229 100644 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md index 969f09985f..5304bff8ff 100644 --- a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md +++ b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md index 61d5628b70..cf9ea9b2ab 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md index 04fdfa0d23..5b48a0b52c 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index f3e1c859a1..16e5f54313 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md index 92553d5fba..824ebb7d8b 100644 --- a/docs/_posts/2020-07-22-tor_traffic.md +++ b/docs/_posts/2020-07-22-tor_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md index 2c64d8bf1a..4b7bf6cb45 100644 --- a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md +++ b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md index 9e6f680cb0..936ea6b5ad 100644 --- a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_role_creation.md b/docs/_posts/2020-07-27-aws_detect_role_creation.md index f01c3f38ab..1e4ad76c49 100644 --- a/docs/_posts/2020-07-27-aws_detect_role_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_role_creation.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md index da1c3dd75c..9cab8e632b 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md index 3ccd85eae8..8ad19dea08 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md index f08230f3e4..6c82da2d3c 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md index 09a634c815..b0665c3e08 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md index a9e9e523cf..ecd6aa9334 100644 --- a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md +++ b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md index 5f5c6f1dd7..e572cc03c0 100644 --- a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md +++ b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md index 8a2310859e..21bd4faecb 100644 --- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md +++ b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md index 166e5b1ad0..9b10f64ecc 100644 --- a/docs/_posts/2020-08-11-detect_arp_poisoning.md +++ b/docs/_posts/2020-08-11-detect_arp_poisoning.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md index a7ff8cb52b..93c3dd2be8 100644 --- a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md +++ b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md index 01236c47f8..f64991d252 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md @@ -25,7 +25,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md index ca3708022a..6433ca235b 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md @@ -25,7 +25,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md index 8f52bf663d..2d36c928d2 100644 --- a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md +++ b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md index bca76e453e..c4160634b6 100644 --- a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md +++ b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md index 667c0d4b27..9547ad2f6b 100644 --- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md +++ b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md index b4f87bda90..479e5cee98 100644 --- a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md +++ b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md index 51ed4a7b3c..5d058bd02e 100644 --- a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md +++ b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md index 77c96f1376..077649ca47 100644 --- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md +++ b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md index 937cc52bcf..4a36ceeb59 100644 --- a/docs/_posts/2020-10-28-detect_port_security_violation.md +++ b/docs/_posts/2020-10-28-detect_port_security_violation.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md index 33ee886742..06e45e9821 100644 --- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md +++ b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md index 4b237165dd..1a9fe784d5 100644 --- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md +++ b/docs/_posts/2020-10-28-detect_traffic_mirroring.md @@ -21,7 +21,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md index 6d28d18b77..91d668fb23 100644 --- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md +++ b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md index 8c4c25c39b..3e53222c6b 100644 --- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md +++ b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-06-supernova_webshell.md b/docs/_posts/2021-01-06-supernova_webshell.md index 8531f0b3a2..b5b9dc7948 100644 --- a/docs/_posts/2021-01-06-supernova_webshell.md +++ b/docs/_posts/2021-01-06-supernova_webshell.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md index 24c34734d6..13732800a2 100644 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md +++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md index 0bc6afacef..2f6499c27f 100644 --- a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md +++ b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md index 9a3084f899..9f5442976c 100644 --- a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md +++ b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md index a0856f5491..1dc823f1d3 100644 --- a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md +++ b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md index 69558a9a0f..a2e6e3c585 100644 --- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md +++ b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md index 724095d46a..6d8f482138 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md index ff0531a18b..c29cc0d9bc 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md index 8e61c6c080..67d0580c7e 100644 --- a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md +++ b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-05-21-winrm_spawning_a_process.md b/docs/_posts/2021-05-21-winrm_spawning_a_process.md index c7db3ec60f..aab8f21b03 100644 --- a/docs/_posts/2021-05-21-winrm_spawning_a_process.md +++ b/docs/_posts/2021-05-21-winrm_spawning_a_process.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md index b00bf77307..a4d85a7711 100644 --- a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md +++ b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md index 3ec80b3747..6d495797e5 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md +++ b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md index a286e2e50f..bc0e356282 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md +++ b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md index cd2d38cd92..427c90cfcf 100644 --- a/docs/_posts/2021-09-28-print_processor_registry_autostart.md +++ b/docs/_posts/2021-09-28-print_processor_registry_autostart.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md index ba3b0263b2..aa5770e84c 100644 --- a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md +++ b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md index e38d5dd232..8111844a05 100644 --- a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md +++ b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md index 55536c2b73..9cd388701b 100644 --- a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md @@ -22,7 +22,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md index c9f1572b72..c46271bfd9 100644 --- a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md index aa38ac6335..117be67220 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md +++ b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md index 0f76d78cfc..d83c8647c1 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md +++ b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-13-linux_java_spawning_shell.md b/docs/_posts/2021-12-13-linux_java_spawning_shell.md index 5c2b0cbfca..465d7feba8 100644 --- a/docs/_posts/2021-12-13-linux_java_spawning_shell.md +++ b/docs/_posts/2021-12-13-linux_java_spawning_shell.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md index 195d5cafe2..d45c272b7f 100644 --- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md +++ b/docs/_posts/2021-12-13-windows_java_spawning_shells.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been able to test, simulate or build datasets for it, use at your own risk and **NOT** supported! +We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} From 8f0518b5afc026e37bfbd5fd1522ebee16dc4bb8 Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 3 Jan 2022 14:39:48 -0500 Subject: [PATCH 4/4] spelling fix --- bin/jinja2_templates/doc_detections.j2 | 2 +- docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md | 2 +- .../2017-09-13-detect_unauthorized_assets_by_mac_address.md | 2 +- docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md | 2 +- docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md | 2 +- docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md | 2 +- ...23-detect_attackers_scanning_for_vulnerable_jboss_servers.md | 2 +- ...-09-23-detect_malicious_requests_to_exploit_jboss_servers.md | 2 +- docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md | 2 +- docs/_posts/2017-10-13-unusually_long_content-type_length.md | 2 +- docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md | 2 +- ...07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md | 2 +- docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md | 2 +- docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md | 2 +- docs/_posts/2018-10-23-wmi_permanent_event_subscription.md | 2 +- docs/_posts/2018-10-23-wmi_temporary_event_subscription.md | 2 +- docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md | 2 +- docs/_posts/2018-12-06-suspicious_java_classes.md | 2 +- docs/_posts/2019-01-25-processes_tapping_keyboard_events.md | 2 +- .../2019-04-01-web_servers_executing_suspicious_processes.md | 2 +- docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md | 2 +- docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md | 2 +- docs/_posts/2020-02-07-macos_-_re-opened_applications.md | 2 +- docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md | 2 +- docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md | 2 +- docs/_posts/2020-03-16-detect_rare_executables.md | 2 +- docs/_posts/2020-03-16-spike_in_file_writes.md | 2 +- .../2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md | 2 +- .../2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md | 2 +- docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md | 2 +- ...2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md | 2 +- docs/_posts/2020-07-07-remote_desktop_network_traffic.md | 2 +- .../2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md | 2 +- docs/_posts/2020-07-21-detect_outbound_smb_traffic.md | 2 +- docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md | 2 +- docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md | 2 +- ...7-21-email_files_written_outside_of_the_outlook_directory.md | 2 +- ...-07-21-email_servers_sending_high_volume_traffic_to_hosts.md | 2 +- docs/_posts/2020-07-21-excessive_dns_failures.md | 2 +- .../2020-07-21-first_time_seen_running_windows_service.md | 2 +- ...eceiving_high_volume_of_network_traffic_from_email_server.md | 2 +- ...iple_okta_users_with_invalid_credentials_from_the_same_ip.md | 2 +- docs/_posts/2020-07-21-okta_account_lockout_events.md | 2 +- docs/_posts/2020-07-21-okta_failed_sso_attempts.md | 2 +- docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md | 2 +- docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md | 2 +- docs/_posts/2020-07-21-protocol_or_port_mismatch.md | 2 +- docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md | 2 +- .../2020-07-21-remote_desktop_process_running_on_system.md | 2 +- docs/_posts/2020-07-21-sql_injection_with_long_urls.md | 2 +- docs/_posts/2020-07-22-smb_traffic_spike.md | 2 +- docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md | 2 +- .../_posts/2020-07-22-suspicious_email_attachment_extensions.md | 2 +- docs/_posts/2020-07-22-tor_traffic.md | 2 +- docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md | 2 +- docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md | 2 +- docs/_posts/2020-07-27-aws_detect_role_creation.md | 2 +- docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md | 2 +- .../_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md | 2 +- .../2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md | 2 +- docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md | 2 +- docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md | 2 +- docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md | 2 +- .../2020-08-10-detect_gcp_storage_access_from_a_new_ip.md | 2 +- docs/_posts/2020-08-11-detect_arp_poisoning.md | 2 +- docs/_posts/2020-08-11-detect_rogue_dhcp_server.md | 2 +- ...08-21-abnormally_high_number_of_cloud_instances_destroyed.md | 2 +- ...-08-21-abnormally_high_number_of_cloud_instances_launched.md | 2 +- ...phishing_email_detection_by_machine_learning_method_-_ssa.md | 2 +- docs/_posts/2020-09-15-detect_zerologon_via_zeek.md | 2 +- ...2020-09-18-detect_computer_changed_with_anonymous_account.md | 2 +- docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md | 2 +- docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md | 2 +- .../2020-10-28-detect_ipv6_network_infrastructure_threats.md | 2 +- docs/_posts/2020-10-28-detect_port_security_violation.md | 2 +- .../2020-10-28-detect_software_download_to_network_device.md | 2 +- docs/_posts/2020-10-28-detect_traffic_mirroring.md | 2 +- .../2020-12-14-sunburst_correlation_dll_and_network_event.md | 2 +- ...-12-16-high_number_of_login_failures_from_a_single_source.md | 2 +- docs/_posts/2021-01-06-supernova_webshell.md | 2 +- ...21-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md | 2 +- docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md | 2 +- ...2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md | 2 +- .../2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md | 2 +- docs/_posts/2021-02-22-suspicious_curl_network_connection.md | 2 +- docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md | 2 +- .../2021-02-22-suspicious_plistbuddy_usage_via_osquery.md | 2 +- .../2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md | 2 +- docs/_posts/2021-05-21-winrm_spawning_a_process.md | 2 +- .../2021-08-19-protocols_passing_authentication_in_cleartext.md | 2 +- docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md | 2 +- docs/_posts/2021-08-27-exchange_powershell_module_usage.md | 2 +- docs/_posts/2021-09-28-print_processor_registry_autostart.md | 2 +- docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md | 2 +- docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md | 2 +- .../_posts/2021-11-29-randomly_generated_scheduled_task_name.md | 2 +- .../2021-11-29-randomly_generated_windows_service_name.md | 2 +- ...2-01-unusual_number_of_computer_service_tickets_requested.md | 2 +- ...1-unusual_number_of_remote_endpoint_authentication_events.md | 2 +- docs/_posts/2021-12-13-linux_java_spawning_shell.md | 2 +- docs/_posts/2021-12-13-windows_java_spawning_shells.md | 2 +- 101 files changed, 101 insertions(+), 101 deletions(-) diff --git a/bin/jinja2_templates/doc_detections.j2 b/bin/jinja2_templates/doc_detections.j2 index 1674d9d254..c271e9b7a1 100644 --- a/bin/jinja2_templates/doc_detections.j2 +++ b/bin/jinja2_templates/doc_detections.j2 @@ -31,7 +31,7 @@ tags: {% if detection.experimental is sameas true -%} ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. {% endif %} [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md index 63635e1cac..e764528022 100644 --- a/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md +++ b/docs/_posts/2017-09-12-detect_new_login_attempts_to_routers.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md index 1ce370f054..4b1d45805d 100644 --- a/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md +++ b/docs/_posts/2017-09-13-detect_unauthorized_assets_by_mac_address.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md index 5337f62a6a..98bb689ec4 100644 --- a/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md +++ b/docs/_posts/2017-09-15-no_windows_updates_in_a_time_frame.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md index 7c4dc9c10c..a3fa6ef07a 100644 --- a/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md +++ b/docs/_posts/2017-09-19-email_attachments_with_lots_of_spaces.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md index 65763038e2..73b559cdc7 100644 --- a/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md +++ b/docs/_posts/2017-09-20-large_volume_of_dns_any_queries.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md index 5c88083518..8899aeda49 100644 --- a/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_attackers_scanning_for_vulnerable_jboss_servers.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md index 7cb062a67e..abed4f537e 100644 --- a/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md +++ b/docs/_posts/2017-09-23-detect_malicious_requests_to_exploit_jboss_servers.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md index 9d86d10c78..21106203ab 100644 --- a/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md +++ b/docs/_posts/2017-09-23-monitor_web_traffic_for_brand_abuse.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2017-10-13-unusually_long_content-type_length.md b/docs/_posts/2017-10-13-unusually_long_content-type_length.md index 1d5a1ceddd..fa905cff49 100644 --- a/docs/_posts/2017-10-13-unusually_long_content-type_length.md +++ b/docs/_posts/2017-10-13-unusually_long_content-type_length.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md index b1ab0a9661..09dc3ce7c3 100644 --- a/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md +++ b/docs/_posts/2018-01-05-monitor_email_for_brand_abuse.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md index a4a747e994..5d22e8600c 100644 --- a/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md +++ b/docs/_posts/2018-05-07-detect_spike_in_blocked_outbound_traffic_from_your_aws.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md index 235fec05e1..abed6c2a30 100644 --- a/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md +++ b/docs/_posts/2018-06-01-detect_large_outbound_icmp_packets.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md index fc46eeedd9..88fc78ffb0 100644 --- a/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md +++ b/docs/_posts/2018-06-28-detect_s3_access_from_a_new_ip.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md index d71ae84c90..2a41671e6e 100644 --- a/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_permanent_event_subscription.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md index 2835a4e40e..4a13cb8743 100644 --- a/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md +++ b/docs/_posts/2018-10-23-wmi_temporary_event_subscription.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md index c0bfc0d70a..b04d22b896 100644 --- a/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md +++ b/docs/_posts/2018-11-27-detect_spike_in_s3_bucket_deletion.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2018-12-06-suspicious_java_classes.md b/docs/_posts/2018-12-06-suspicious_java_classes.md index ba3a15d0d1..c27131ec6a 100644 --- a/docs/_posts/2018-12-06-suspicious_java_classes.md +++ b/docs/_posts/2018-12-06-suspicious_java_classes.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md index d8086a4b48..5c1c79a22a 100644 --- a/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md +++ b/docs/_posts/2019-01-25-processes_tapping_keyboard_events.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md index 503ea38ec0..d36385034a 100644 --- a/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md +++ b/docs/_posts/2019-04-01-web_servers_executing_suspicious_processes.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md index 074dd9597c..d87eabc15e 100644 --- a/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md +++ b/docs/_posts/2019-05-08-unusually_long_command_line_-_mltk.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md index 8e002cabd3..ec3d1540dd 100644 --- a/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md +++ b/docs/_posts/2020-01-22-dns_query_length_outliers_-_mltk.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md index 5a972cdf0b..aa4c2545d7 100644 --- a/docs/_posts/2020-02-07-macos_-_re-opened_applications.md +++ b/docs/_posts/2020-02-07-macos_-_re-opened_applications.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md index 1b89ba0d20..6010dd78b3 100644 --- a/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md +++ b/docs/_posts/2020-02-20-new_container_uploaded_to_aws_ecr.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md index 0e9289dfb6..293057b6dc 100644 --- a/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md +++ b/docs/_posts/2020-03-16-child_processes_of_spoolsv_exe.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-detect_rare_executables.md b/docs/_posts/2020-03-16-detect_rare_executables.md index e63b22f9d2..9f200d7288 100644 --- a/docs/_posts/2020-03-16-detect_rare_executables.md +++ b/docs/_posts/2020-03-16-detect_rare_executables.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-03-16-spike_in_file_writes.md b/docs/_posts/2020-03-16-spike_in_file_writes.md index 7a2b124379..4f92e207a9 100644 --- a/docs/_posts/2020-03-16-spike_in_file_writes.md +++ b/docs/_posts/2020-03-16-spike_in_file_writes.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md index 22987a3ab7..a95ffd32d0 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_cluster_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md index a4aaf7629d..4a01d6ad31 100644 --- a/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md +++ b/docs/_posts/2020-04-15-amazon_eks_kubernetes_pod_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index aa1133c56a..4cff77757a 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md index daac2680d6..058d1e5dd2 100644 --- a/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md +++ b/docs/_posts/2020-06-23-kubernetes_aws_detect_suspicious_kubectl_calls.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md index cf87f364c0..aa48878684 100644 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md index 780e30ab19..e410b32710 100644 --- a/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md +++ b/docs/_posts/2020-07-17-gcp_kubernetes_cluster_pod_scan_detection.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md index 79490e9115..29b6e7695d 100644 --- a/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md +++ b/docs/_posts/2020-07-21-detect_outbound_smb_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md index e3bf0189b9..4243de923a 100644 --- a/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md +++ b/docs/_posts/2020-07-21-detect_outlook_exe_writing_a_zip_file.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md index ebefaebf7e..6b57e1ce33 100644 --- a/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md +++ b/docs/_posts/2020-07-21-detection_of_tools_built_by_nirsoft.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md index 31a2c28fe1..624c2d8604 100644 --- a/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md +++ b/docs/_posts/2020-07-21-email_files_written_outside_of_the_outlook_directory.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md index fa7612e255..806cae541f 100644 --- a/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md +++ b/docs/_posts/2020-07-21-email_servers_sending_high_volume_traffic_to_hosts.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-excessive_dns_failures.md b/docs/_posts/2020-07-21-excessive_dns_failures.md index 446b6fc857..e8872dea56 100644 --- a/docs/_posts/2020-07-21-excessive_dns_failures.md +++ b/docs/_posts/2020-07-21-excessive_dns_failures.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md index 2bd70571d5..6697097663 100644 --- a/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md +++ b/docs/_posts/2020-07-21-first_time_seen_running_windows_service.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md index 2b02f90b3c..39b435b5c4 100644 --- a/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md +++ b/docs/_posts/2020-07-21-hosts_receiving_high_volume_of_network_traffic_from_email_server.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md index ed581283cc..e777a22344 100644 --- a/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md +++ b/docs/_posts/2020-07-21-multiple_okta_users_with_invalid_credentials_from_the_same_ip.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_account_lockout_events.md b/docs/_posts/2020-07-21-okta_account_lockout_events.md index 4f96ebd047..c5149bfbd1 100644 --- a/docs/_posts/2020-07-21-okta_account_lockout_events.md +++ b/docs/_posts/2020-07-21-okta_account_lockout_events.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md index b42cee4c7d..7b6ba38e2d 100644 --- a/docs/_posts/2020-07-21-okta_failed_sso_attempts.md +++ b/docs/_posts/2020-07-21-okta_failed_sso_attempts.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md index ce7829be86..2b11dab2f3 100644 --- a/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md +++ b/docs/_posts/2020-07-21-okta_user_logins_from_multiple_cities.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md index 9b54527c5e..7e3331fa29 100644 --- a/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md +++ b/docs/_posts/2020-07-21-prohibited_network_traffic_allowed.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md index 6532f871e8..254dd5dbe6 100644 --- a/docs/_posts/2020-07-21-protocol_or_port_mismatch.md +++ b/docs/_posts/2020-07-21-protocol_or_port_mismatch.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md index b00c47cbb2..a4a8b0c526 100644 --- a/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md +++ b/docs/_posts/2020-07-21-remote_desktop_network_bruteforce.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md index 62d18e5229..48c07da8a6 100644 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md index 5304bff8ff..319f266239 100644 --- a/docs/_posts/2020-07-21-sql_injection_with_long_urls.md +++ b/docs/_posts/2020-07-21-sql_injection_with_long_urls.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-smb_traffic_spike.md b/docs/_posts/2020-07-22-smb_traffic_spike.md index cf9ea9b2ab..76f7a54e6b 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md index 5b48a0b52c..16c6922284 100644 --- a/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md +++ b/docs/_posts/2020-07-22-smb_traffic_spike_-_mltk.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md index 16e5f54313..24ded7a654 100644 --- a/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md +++ b/docs/_posts/2020-07-22-suspicious_email_attachment_extensions.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-22-tor_traffic.md b/docs/_posts/2020-07-22-tor_traffic.md index 824ebb7d8b..838528a2a2 100644 --- a/docs/_posts/2020-07-22-tor_traffic.md +++ b/docs/_posts/2020-07-22-tor_traffic.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md index 4b7bf6cb45..01fafd1994 100644 --- a/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md +++ b/docs/_posts/2020-07-27-aws_detect_attach_to_role_policy.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md index 936ea6b5ad..20e9574cf7 100644 --- a/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_permanent_key_creation.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_role_creation.md b/docs/_posts/2020-07-27-aws_detect_role_creation.md index 1e4ad76c49..757bd609ee 100644 --- a/docs/_posts/2020-07-27-aws_detect_role_creation.md +++ b/docs/_posts/2020-07-27-aws_detect_role_creation.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md index 9cab8e632b..a2fb8275c0 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_assume_role_abuse.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md index 8ad19dea08..9691fa9609 100644 --- a/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md +++ b/docs/_posts/2020-07-27-aws_detect_sts_get_session_token_abuse.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md index 6c82da2d3c..0efdd8f5bb 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_splunk_stream.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md index b0665c3e08..857e9c0cae 100644 --- a/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md +++ b/docs/_posts/2020-07-28-detect_windows_dns_sigred_via_zeek.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md index ecd6aa9334..0659c04bd2 100644 --- a/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md +++ b/docs/_posts/2020-08-02-detect_f5_tmui_rce_cve-2020-5902.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md index e572cc03c0..c6c44c174b 100644 --- a/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md +++ b/docs/_posts/2020-08-05-detect_new_open_gcp_storage_buckets.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md index 21bd4faecb..aabb178903 100644 --- a/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md +++ b/docs/_posts/2020-08-10-detect_gcp_storage_access_from_a_new_ip.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-11-detect_arp_poisoning.md b/docs/_posts/2020-08-11-detect_arp_poisoning.md index 9b10f64ecc..febc2c7941 100644 --- a/docs/_posts/2020-08-11-detect_arp_poisoning.md +++ b/docs/_posts/2020-08-11-detect_arp_poisoning.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md index 93c3dd2be8..ced5f95abd 100644 --- a/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md +++ b/docs/_posts/2020-08-11-detect_rogue_dhcp_server.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md index f64991d252..0e8a26cbc6 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_destroyed.md @@ -25,7 +25,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md index 6433ca235b..27938a0379 100644 --- a/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md +++ b/docs/_posts/2020-08-21-abnormally_high_number_of_cloud_instances_launched.md @@ -25,7 +25,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md index 2d36c928d2..bf41d76542 100644 --- a/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md +++ b/docs/_posts/2020-08-25-phishing_email_detection_by_machine_learning_method_-_ssa.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md index c4160634b6..821224f83e 100644 --- a/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md +++ b/docs/_posts/2020-09-15-detect_zerologon_via_zeek.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md index 9547ad2f6b..cc58a00d98 100644 --- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md +++ b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md index 479e5cee98..ccf3405111 100644 --- a/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md +++ b/docs/_posts/2020-10-08-gcp_detect_gcploit_framework.md @@ -18,7 +18,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md index 5d058bd02e..558b8295ef 100644 --- a/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md +++ b/docs/_posts/2020-10-21-detect_snicat_sni_exfiltration.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md index 077649ca47..6ccc7e0c57 100644 --- a/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md +++ b/docs/_posts/2020-10-28-detect_ipv6_network_infrastructure_threats.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_port_security_violation.md b/docs/_posts/2020-10-28-detect_port_security_violation.md index 4a36ceeb59..08099e1d3c 100644 --- a/docs/_posts/2020-10-28-detect_port_security_violation.md +++ b/docs/_posts/2020-10-28-detect_port_security_violation.md @@ -23,7 +23,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md index 06e45e9821..28c41121b8 100644 --- a/docs/_posts/2020-10-28-detect_software_download_to_network_device.md +++ b/docs/_posts/2020-10-28-detect_software_download_to_network_device.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-10-28-detect_traffic_mirroring.md b/docs/_posts/2020-10-28-detect_traffic_mirroring.md index 1a9fe784d5..6830c99a27 100644 --- a/docs/_posts/2020-10-28-detect_traffic_mirroring.md +++ b/docs/_posts/2020-10-28-detect_traffic_mirroring.md @@ -21,7 +21,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md index 91d668fb23..d80392e8c0 100644 --- a/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md +++ b/docs/_posts/2020-12-14-sunburst_correlation_dll_and_network_event.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md index 3e53222c6b..04c0c6f028 100644 --- a/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md +++ b/docs/_posts/2020-12-16-high_number_of_login_failures_from_a_single_source.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-06-supernova_webshell.md b/docs/_posts/2021-01-06-supernova_webshell.md index b5b9dc7948..6ea9194963 100644 --- a/docs/_posts/2021-01-06-supernova_webshell.md +++ b/docs/_posts/2021-01-06-supernova_webshell.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md index 13732800a2..99cff9d716 100644 --- a/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md +++ b/docs/_posts/2021-01-26-detect_spike_in_aws_security_hub_alerts_for_user.md @@ -13,7 +13,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md index 2f6499c27f..e652e13a6f 100644 --- a/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md +++ b/docs/_posts/2021-01-27-detect_baron_samedit_cve-2021-3156.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md index 9f5442976c..05cdbd8a88 100644 --- a/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md +++ b/docs/_posts/2021-01-28-detect_baron_samedit_cve-2021-3156_via_osquery.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md index 1dc823f1d3..88b4e9883e 100644 --- a/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md +++ b/docs/_posts/2021-01-29-detect_baron_samedit_cve-2021-3156_segfault.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md index a2e6e3c585..f204dc8f9a 100644 --- a/docs/_posts/2021-02-22-suspicious_curl_network_connection.md +++ b/docs/_posts/2021-02-22-suspicious_curl_network_connection.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md index 6d8f482138..4a129773da 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md index c29cc0d9bc..bf387af096 100644 --- a/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md +++ b/docs/_posts/2021-02-22-suspicious_plistbuddy_usage_via_osquery.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md index 67d0580c7e..56ec8ce0e8 100644 --- a/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md +++ b/docs/_posts/2021-02-22-suspicious_sqlite3_lsquarantine_behavior.md @@ -16,7 +16,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-05-21-winrm_spawning_a_process.md b/docs/_posts/2021-05-21-winrm_spawning_a_process.md index aab8f21b03..93e02ebeed 100644 --- a/docs/_posts/2021-05-21-winrm_spawning_a_process.md +++ b/docs/_posts/2021-05-21-winrm_spawning_a_process.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md index a4d85a7711..34197f534e 100644 --- a/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md +++ b/docs/_posts/2021-08-19-protocols_passing_authentication_in_cleartext.md @@ -14,7 +14,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md index 6d495797e5..b14393b1f9 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md +++ b/docs/_posts/2021-08-27-exchange_powershell_abuse_via_ssrf.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md index bc0e356282..4408e2f45b 100644 --- a/docs/_posts/2021-08-27-exchange_powershell_module_usage.md +++ b/docs/_posts/2021-08-27-exchange_powershell_module_usage.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-09-28-print_processor_registry_autostart.md b/docs/_posts/2021-09-28-print_processor_registry_autostart.md index 427c90cfcf..c42bfcd7cd 100644 --- a/docs/_posts/2021-09-28-print_processor_registry_autostart.md +++ b/docs/_posts/2021-09-28-print_processor_registry_autostart.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md index aa5770e84c..ece38cfeb0 100644 --- a/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md +++ b/docs/_posts/2021-10-24-gdrive_suspicious_file_sharing.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md index 8111844a05..9610e848a8 100644 --- a/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md +++ b/docs/_posts/2021-10-24-gsuite_suspicious_calendar_invite.md @@ -15,7 +15,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md index 9cd388701b..d37e705f32 100644 --- a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md @@ -22,7 +22,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md index c46271bfd9..379c80715c 100644 --- a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md +++ b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md @@ -20,7 +20,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md index 117be67220..9c198f7cd6 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md +++ b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md index d83c8647c1..e75547efe1 100644 --- a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md +++ b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md @@ -19,7 +19,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-13-linux_java_spawning_shell.md b/docs/_posts/2021-12-13-linux_java_spawning_shell.md index 465d7feba8..4f14ea95b4 100644 --- a/docs/_posts/2021-12-13-linux_java_spawning_shell.md +++ b/docs/_posts/2021-12-13-linux_java_spawning_shell.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} diff --git a/docs/_posts/2021-12-13-windows_java_spawning_shells.md b/docs/_posts/2021-12-13-windows_java_spawning_shells.md index d45c272b7f..b443e3945b 100644 --- a/docs/_posts/2021-12-13-windows_java_spawning_shells.md +++ b/docs/_posts/2021-12-13-windows_java_spawning_shells.md @@ -17,7 +17,7 @@ tags: --- ### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION -We have not been table to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. +We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is **NOT** supported. [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success}