fix merge conflict in contentctl.yml. remove risk_score field from many new or updarted detections.

This commit is contained in:
pyth0n1c
2024-08-21 13:41:58 -07:00
parent 7d401f2d24
commit f172d78c68
36 changed files with 0 additions and 40 deletions
-5
View File
@@ -182,8 +182,6 @@ apps:
version: 1.9.2
description: description of app
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz
<<<<<<< HEAD
=======
- uid: 6853
title: Splunk Add-on for Admon Enrichment
appid: SA-admon
@@ -196,6 +194,3 @@ apps:
version: 3.2.1
description: description of app
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/crowdstrike-falcon-event-streams-technical-add-on_321.tgz
githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
>>>>>>> develop
@@ -63,7 +63,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -67,7 +67,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -67,7 +67,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -64,7 +64,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -63,7 +63,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -63,7 +63,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -43,7 +43,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 64
required_fields:
- _time
- OperationType
@@ -38,7 +38,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 64
required_fields:
- _time
- OperationType
@@ -50,7 +50,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -62,7 +62,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -57,7 +57,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -36,7 +36,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 50
required_fields:
- EventCode
- user
@@ -58,7 +58,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 80
required_fields:
- _time
- OperationType
@@ -52,7 +52,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
required_fields:
- _time
- OperationType
@@ -68,7 +68,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 80
required_fields:
- _time
- OperationType
@@ -55,7 +55,6 @@ tags:
- UserId
- Workload
- Target{}.ID
risk_score: 50
security_domain: threat
tests:
- name: True Positive Test
@@ -52,7 +52,6 @@ tags:
- ModifiedProperties{}.Name
- UserId
- Workload
risk_score: 75
security_domain: threat
tests:
- name: True Positive Test
@@ -54,7 +54,6 @@ tags:
- UserId
- Id
- Workload
risk_score: 25
security_domain: identity
tests:
- name: True Positive Test
@@ -54,7 +54,6 @@ tags:
- ModifiedProperties{}.Name
- UserId
- Workload
risk_score: 75
security_domain: threat
tests:
- name: True Positive Test
@@ -54,7 +54,6 @@ tags:
- UserId
- ObjectId
- Workload
risk_score: 75
security_domain: identity
tests:
- name: True Positive Test
@@ -55,7 +55,6 @@ tags:
- UserId
- ObjectId
- Workload
risk_score: 75
security_domain: identity
tests:
- name: True Positive Test
@@ -49,7 +49,6 @@ tags:
- accounts{}.domain
- accounts{}.dn
- accounts{}.samAccountName
risk_score: 80
security_domain: endpoint
tests:
- name: True Positive Test
@@ -48,7 +48,6 @@ tags:
- accounts{}.domain
- accounts{}.dn
- accounts{}.samAccountName
risk_score: 80
security_domain: endpoint
tests:
- name: True Positive Test
@@ -48,7 +48,6 @@ tags:
- accounts{}.domain
- accounts{}.dn
- accounts{}.samAccountName
risk_score: 90
security_domain: endpoint
tests:
- name: True Positive Test
@@ -48,7 +48,6 @@ tags:
- accounts{}.domain
- accounts{}.dn
- accounts{}.samAccountName
risk_score: 70
security_domain: endpoint
tests:
- name: True Positive Test
@@ -50,7 +50,6 @@ tags:
- event.IncidentType
- event.NumbersOfAlerts
- event.SeverityName
risk_score: 49
security_domain: endpoint
manual_test: This detection is marked manual test because the attack_data file and
TA do not provide the event.EndpointIp and event.EndpointName fields. event.EndpointName
@@ -52,7 +52,6 @@ tags:
- event.IncidentType
- event.NumbersOfAlerts
- event.SeverityName
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
@@ -50,7 +50,6 @@ tags:
- event.IncidentType
- event.NumbersOfAlerts
- event.SeverityName
risk_score: 49
security_domain: endpoint
manual_test: This detection is marked manual test because the attack_data file and
TA do not provide the event.EndpointIp and event.EndpointName fields. event.EndpointName
@@ -50,7 +50,6 @@ tags:
- accounts{}.domain
- accounts{}.dn
- accounts{}.samAccountName
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
@@ -49,7 +49,6 @@ tags:
- accounts{}.domain
- accounts{}.dn
- accounts{}.samAccountName
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
@@ -53,7 +53,6 @@ tags:
- DomainName
- Security
- WorkstationName
risk_score: 50
security_domain: endpoint
tests:
- name: True Positive Test
@@ -53,7 +53,6 @@ tags:
- DomainName
- Security
- WorkstationName
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
@@ -53,7 +53,6 @@ tags:
- DomainName
- Security
- WorkstationName
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
@@ -53,7 +53,6 @@ tags:
- DomainName
- Security
- WorkstationName
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
@@ -53,7 +53,6 @@ tags:
- DomainName
- Security
- WorkstationName
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test