From e6ec9a99c51355ee2db4f40bdade2a9fb1e034e1 Mon Sep 17 00:00:00 2001 From: Patrick Bareiss Date: Tue, 18 Feb 2025 11:11:15 +0100 Subject: [PATCH] version bump --- .../cloud/asl_aws_concurrent_sessions_from_different_ips.yml | 2 +- ...tect_users_creating_keys_with_encrypt_policy_without_mfa.yml | 2 +- detections/cloud/asl_aws_disable_bucket_versioning.yml | 2 +- detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml | 2 +- detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml | 2 +- detections/cloud/aws_concurrent_sessions_from_different_ips.yml | 2 +- ...tect_users_creating_keys_with_encrypt_policy_without_mfa.yml | 2 +- detections/cloud/aws_iam_accessdenied_discovery_events.yml | 2 +- detections/cloud/aws_saml_update_identity_provider.yml | 2 +- detections/deprecated/aws_detect_attach_to_role_policy.yml | 2 +- detections/deprecated/aws_detect_role_creation.yml | 2 +- detections/deprecated/aws_detect_sts_assume_role_abuse.yml | 2 +- .../deprecated/aws_detect_sts_get_session_token_abuse.yml | 2 +- 13 files changed, 13 insertions(+), 13 deletions(-) diff --git a/detections/cloud/asl_aws_concurrent_sessions_from_different_ips.yml b/detections/cloud/asl_aws_concurrent_sessions_from_different_ips.yml index 31d8a82fd8..eaf8027900 100644 --- a/detections/cloud/asl_aws_concurrent_sessions_from_different_ips.yml +++ b/detections/cloud/asl_aws_concurrent_sessions_from_different_ips.yml @@ -1,6 +1,6 @@ name: ASL AWS Concurrent Sessions From Different Ips id: b3424bbe-3204-4469-887b-ec144483a336 -version: 6 +version: 7 date: '2024-11-14' author: Patrick Bareiss, Splunk status: production diff --git a/detections/cloud/asl_aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml b/detections/cloud/asl_aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml index 587c97d919..9ad002d4d2 100644 --- a/detections/cloud/asl_aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml +++ b/detections/cloud/asl_aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml @@ -1,6 +1,6 @@ name: ASL AWS Detect Users creating keys with encrypt policy without MFA id: 16ae9076-d1d5-411c-8fdd-457504b33dac -version: 1 +version: 2 date: '2024-12-16' author: Patrick Bareiss, Splunk status: production diff --git a/detections/cloud/asl_aws_disable_bucket_versioning.yml b/detections/cloud/asl_aws_disable_bucket_versioning.yml index 32b08c3e6e..658ec386de 100644 --- a/detections/cloud/asl_aws_disable_bucket_versioning.yml +++ b/detections/cloud/asl_aws_disable_bucket_versioning.yml @@ -1,6 +1,6 @@ name: ASL AWS Disable Bucket Versioning id: f32598bb-fa5f-4afd-8ab3-0263cc28efbc -version: 1 +version: 2 date: '2024-12-16' author: Patrick Bareiss, Splunk status: production diff --git a/detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml b/detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml index 065f517035..8108ed6e5b 100644 --- a/detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml +++ b/detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml @@ -1,6 +1,6 @@ name: ASL AWS IAM AccessDenied Discovery Events id: a4f39755-b1e2-40bb-b2dc-4449c45b0bf2 -version: 1 +version: 2 date: '2025-01-08' author: Patrick Bareiss, Splunk status: production diff --git a/detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml b/detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml index b8dafe5438..760ec5d535 100644 --- a/detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml +++ b/detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml @@ -1,6 +1,6 @@ name: ASL AWS IAM Assume Role Policy Brute Force id: 726959fe-316d-445c-a584-fa187d64e295 -version: 1 +version: 2 date: '2025-01-08' author: Patrick Bareiss, Splunk status: production diff --git a/detections/cloud/aws_concurrent_sessions_from_different_ips.yml b/detections/cloud/aws_concurrent_sessions_from_different_ips.yml index 86f240062a..9787083dff 100644 --- a/detections/cloud/aws_concurrent_sessions_from_different_ips.yml +++ b/detections/cloud/aws_concurrent_sessions_from_different_ips.yml @@ -1,6 +1,6 @@ name: AWS Concurrent Sessions From Different Ips id: 51c04fdb-2746-465a-b86e-b413a09c9085 -version: 5 +version: 6 date: '2024-11-14' author: Bhavin Patel, Splunk status: production diff --git a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml index 7662059987..52c5bb40a6 100644 --- a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml +++ b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml @@ -1,6 +1,6 @@ name: AWS Detect Users creating keys with encrypt policy without MFA id: c79c164f-4b21-4847-98f9-cf6a9f49179e -version: 4 +version: 5 date: '2024-11-14' author: Rod Soto, Patrick Bareiss Splunk status: production diff --git a/detections/cloud/aws_iam_accessdenied_discovery_events.yml b/detections/cloud/aws_iam_accessdenied_discovery_events.yml index 218b4bc3aa..f3f2d7600f 100644 --- a/detections/cloud/aws_iam_accessdenied_discovery_events.yml +++ b/detections/cloud/aws_iam_accessdenied_discovery_events.yml @@ -1,6 +1,6 @@ name: AWS IAM AccessDenied Discovery Events id: 3e1f1568-9633-11eb-a69c-acde48001122 -version: 5 +version: 6 date: '2024-11-14' author: Michael Haag, Splunk status: production diff --git a/detections/cloud/aws_saml_update_identity_provider.yml b/detections/cloud/aws_saml_update_identity_provider.yml index 63c9b1f306..51e9b3ea04 100644 --- a/detections/cloud/aws_saml_update_identity_provider.yml +++ b/detections/cloud/aws_saml_update_identity_provider.yml @@ -1,6 +1,6 @@ name: AWS SAML Update identity provider id: 2f0604c6-6030-11eb-ae93-0242ac130002 -version: 6 +version: 7 date: '2024-11-14' author: Rod Soto, Splunk status: production diff --git a/detections/deprecated/aws_detect_attach_to_role_policy.yml b/detections/deprecated/aws_detect_attach_to_role_policy.yml index 15cd19619d..ddde29333c 100644 --- a/detections/deprecated/aws_detect_attach_to_role_policy.yml +++ b/detections/deprecated/aws_detect_attach_to_role_policy.yml @@ -1,6 +1,6 @@ name: aws detect attach to role policy id: 88fc31dd-f331-448c-9856-d3d51dd5d3a1 -version: 4 +version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated diff --git a/detections/deprecated/aws_detect_role_creation.yml b/detections/deprecated/aws_detect_role_creation.yml index 830b7c96a6..b60812c49c 100644 --- a/detections/deprecated/aws_detect_role_creation.yml +++ b/detections/deprecated/aws_detect_role_creation.yml @@ -1,6 +1,6 @@ name: aws detect role creation id: 5f04081e-ddee-4353-afe4-504f288de9ad -version: 4 +version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated diff --git a/detections/deprecated/aws_detect_sts_assume_role_abuse.yml b/detections/deprecated/aws_detect_sts_assume_role_abuse.yml index 21aa5e16fb..e83636a56d 100644 --- a/detections/deprecated/aws_detect_sts_assume_role_abuse.yml +++ b/detections/deprecated/aws_detect_sts_assume_role_abuse.yml @@ -1,6 +1,6 @@ name: aws detect sts assume role abuse id: 8e565314-b6a2-46d8-9f05-1a34a176a662 -version: 4 +version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated diff --git a/detections/deprecated/aws_detect_sts_get_session_token_abuse.yml b/detections/deprecated/aws_detect_sts_get_session_token_abuse.yml index 41055eee3e..80ed8b1698 100644 --- a/detections/deprecated/aws_detect_sts_get_session_token_abuse.yml +++ b/detections/deprecated/aws_detect_sts_get_session_token_abuse.yml @@ -1,6 +1,6 @@ name: aws detect sts get session token abuse id: 85d7b35f-b8b5-4b01-916f-29b81e7a0551 -version: 4 +version: 5 date: '2024-11-14' author: Rod Soto, Splunk status: deprecated