mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
network: more typefixes
This commit is contained in:
@@ -47,7 +47,7 @@ rba:
|
||||
$src$, kindly review.
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 63
|
||||
threat_objects:
|
||||
- field: domain
|
||||
|
||||
@@ -51,7 +51,7 @@ rba:
|
||||
message: A DNS data exfiltration request was sent by this host $src$ , kindly review.
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 45
|
||||
threat_objects:
|
||||
- field: query
|
||||
|
||||
@@ -56,7 +56,7 @@ rba:
|
||||
host $host$
|
||||
risk_objects:
|
||||
- field: host
|
||||
type: hostname
|
||||
type: system
|
||||
score: 56
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -42,7 +42,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -56,7 +56,7 @@ rba:
|
||||
message: A domain for a known remote access software $query$ was contacted by $src$.
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 4
|
||||
threat_objects:
|
||||
- field: query
|
||||
|
||||
@@ -57,7 +57,7 @@ rba:
|
||||
detected from $src$.
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -31,7 +31,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -35,7 +35,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
+1
-1
@@ -50,7 +50,7 @@ rba:
|
||||
message: A suspicious DNS TXT response was detected on host $src$ , kindly review.
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 45
|
||||
threat_objects:
|
||||
- field: answer
|
||||
|
||||
@@ -34,7 +34,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -33,7 +33,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -46,7 +46,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -45,7 +45,7 @@ rba:
|
||||
query in host $host$
|
||||
risk_objects:
|
||||
- field: host
|
||||
type: hostname
|
||||
type: system
|
||||
score: 56
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -33,7 +33,7 @@ rba:
|
||||
message: Excessive DNS failures detected on $src$
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -50,7 +50,7 @@ rba:
|
||||
occurred.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 70
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
+1
-1
@@ -42,7 +42,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -50,7 +50,7 @@ rba:
|
||||
IPs
|
||||
risk_objects:
|
||||
- field: src_ip
|
||||
type: hostname
|
||||
type: system
|
||||
score: 64
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -51,7 +51,7 @@ rba:
|
||||
IPs
|
||||
risk_objects:
|
||||
- field: src_ip
|
||||
type: hostname
|
||||
type: system
|
||||
score: 72
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -50,7 +50,7 @@ rba:
|
||||
message: $src_ip$ has scanned $totalDestPortCount$ ports on $dest_ip$
|
||||
risk_objects:
|
||||
- field: src_ip
|
||||
type: hostname
|
||||
type: system
|
||||
score: 64
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -36,7 +36,7 @@ rba:
|
||||
message: Large volume of IDS signatures triggered by $src$
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 64
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -27,7 +27,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -43,7 +43,7 @@ rba:
|
||||
message: An endpoint, $src$, is beaconing out to the reverse proxy service of Ngrok.
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 50
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -32,7 +32,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -37,7 +37,7 @@ rba:
|
||||
type: user
|
||||
score: 25
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -30,10 +30,10 @@ rba:
|
||||
message: $dest$ may be the target of an RDP Bruteforce
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -31,7 +31,7 @@ rba:
|
||||
message: Anomalous splike of SMB traffic sent from $src$
|
||||
risk_objects:
|
||||
- field: src
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -46,7 +46,7 @@ rba:
|
||||
message: tbd
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 25
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -36,7 +36,7 @@ rba:
|
||||
email domain on $dest$.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 15
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
@@ -36,7 +36,7 @@ rba:
|
||||
alternative name on $dest$.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: hostname
|
||||
type: system
|
||||
score: 15
|
||||
threat_objects: []
|
||||
tags:
|
||||
|
||||
Reference in New Issue
Block a user