mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
@@ -5,7 +5,7 @@
|
||||
"id": {
|
||||
"group": null,
|
||||
"name": "DA-ESS-ContentUpdate",
|
||||
"version": "4.11.1"
|
||||
"version": "4.12.0"
|
||||
},
|
||||
"author": [
|
||||
{
|
||||
|
||||
+606
-524
File diff suppressed because one or more lines are too long
Vendored
+2
-2
@@ -4,7 +4,7 @@
|
||||
is_configured = false
|
||||
state = enabled
|
||||
state_change_requires_restart = false
|
||||
build = 16958
|
||||
build = 17107
|
||||
|
||||
[triggers]
|
||||
reload.analytic_stories = simple
|
||||
@@ -20,7 +20,7 @@ reload.es_investigations = simple
|
||||
|
||||
[launcher]
|
||||
author = Splunk
|
||||
version = 4.11.1
|
||||
version = 4.12.0
|
||||
description = Explore the Analytic Stories included with ES Content Updates.
|
||||
|
||||
[ui]
|
||||
|
||||
Vendored
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-09-05T22:20:53 UTC
|
||||
# On Date: 2023-09-20T19:43:15 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,2 +1,2 @@
|
||||
[content-version]
|
||||
version = 4.11.1
|
||||
version = 4.12.0
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-09-05T22:20:53 UTC
|
||||
# On Date: 2023-09-20T19:43:15 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
Vendored
+33
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-09-05T22:20:53 UTC
|
||||
# On Date: 2023-09-20T19:43:15 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -2237,6 +2237,14 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[headless_browser_mockbin_or_mocky_request_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[headless_browser_usage_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[hide_user_account_from_sign_in_screen_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -3757,6 +3765,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_ad_abnormal_object_access_activity_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_ad_adminsdholder_acl_modified_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -3789,6 +3801,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_ad_privileged_object_access_activity_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_ad_replication_request_initiated_by_user_account_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -4125,10 +4141,22 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_find_domain_organizational_units_with_getdomainou_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_find_interesting_acl_with_findinterestingdomainacl_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_findstr_gpp_discovery_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_forest_discovery_with_getforestdomain_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_gather_victim_host_information_camera_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -4145,6 +4173,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_get_local_admin_with_findlocaladminaccess_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_group_policy_object_created_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
Vendored
+1117
-775
File diff suppressed because it is too large
Load Diff
Vendored
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-09-05T22:20:53 UTC
|
||||
# On Date: 2023-09-20T19:43:15 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2023-09-05T22:20:53 UTC
|
||||
# On Date: 2023-09-20T19:43:15 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
@@ -81,8 +81,8 @@
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1087",
|
||||
"score": 29,
|
||||
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_special_privileged_logon_on_multiple_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml"
|
||||
"score": 35,
|
||||
"comment": "https://github.com/splunk/security_content/blob/develop/detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_abnormal_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_special_privileged_logon_on_multiple_hosts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml"
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1210",
|
||||
@@ -481,8 +481,8 @@
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1087.002",
|
||||
"score": 20,
|
||||
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml"
|
||||
"score": 26,
|
||||
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_abnormal_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_ad_privileged_object_access_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_domain_organizational_units_with_getdomainou.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_find_interesting_acl_with_findinterestingdomainacl.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_forest_discovery_with_getforestdomain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_get_local_admin_with_findlocaladminaccess.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_root_domain_linked_policies_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_suspect_process_with_authentication_traffic.yml"
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1547.014",
|
||||
@@ -814,6 +814,11 @@
|
||||
"score": 8,
|
||||
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_with_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_common_abused_cmd_shell_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_post_exploitation_risk_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_system_network_connections_discovery_netsh.yml"
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1564.003",
|
||||
"score": 2,
|
||||
"comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/headless_browser_mockbin_or_mocky_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/headless_browser_usage.yml"
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1222.001",
|
||||
"score": 2,
|
||||
|
||||
Reference in New Issue
Block a user