From 537a67099217856b0154a3dc55f9dce997c49801 Mon Sep 17 00:00:00 2001 From: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com> Date: Fri, 20 Jun 2025 06:59:37 +0000 Subject: [PATCH] Updated TAs --- contentctl.yml | 4 ++-- data_sources/ms365_defender_incident_alerts.yml | 2 +- data_sources/ms_defender_atp_alerts.yml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/contentctl.yml b/contentctl.yml index 93b8e006a4..f2b995bd31 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -185,9 +185,9 @@ apps: - uid: 6207 title: Splunk Add-on for Microsoft Security appid: Splunk_TA_MS_Security - version: 2.5.2 + version: 2.5.1 description: description of app - hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-security_252.tgz + hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-security_251.tgz - uid: 2734 title: URL Toolbox appid: URL_TOOLBOX diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml index 4bb1baec94..58c9d6c552 100644 --- a/data_sources/ms365_defender_incident_alerts.yml +++ b/data_sources/ms365_defender_incident_alerts.yml @@ -16,7 +16,7 @@ sourcetype: ms365:defender:incident:alerts supported_TA: - name: Splunk Add-on for Microsoft Security url: https://splunkbase.splunk.com/app/6207 - version: 2.5.2 + version: 2.5.1 fields: - actorName - alertId diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml index 1c184c0a5b..3f6eac12ca 100644 --- a/data_sources/ms_defender_atp_alerts.yml +++ b/data_sources/ms_defender_atp_alerts.yml @@ -16,7 +16,7 @@ sourcetype: ms:defender:atp:alerts supported_TA: - name: Splunk Add-on for Microsoft Security url: https://splunkbase.splunk.com/app/6207 - version: 2.5.2 + version: 2.5.1 fields: - column - accountName