research bot
|
2c9e7b58a8
|
updating docs and package bits [ci skip]
|
2021-08-18 16:56:31 +00:00 |
|
github-actions[bot]
|
ffa8a4a805
|
Branch was auto-updated.
|
2021-07-27 20:53:22 +00:00 |
|
root
|
2fd2af4d29
|
Added detection testing service results inDNS Query Length With High Standard Deviation
|
2021-07-27 19:59:57 +00:00 |
|
P4T12ICK
|
686b0b5ca4
|
converted response_task to investigations
|
2021-07-26 13:39:17 +02:00 |
|
sec-researcher
|
ee3f8638c4
|
As I know PTR requests can not be used for data exfiltration so having them in search result is just a false positive. Also they have effect on deviation calculation and lead to a lot of false positive in result, specially when PTR requests in the environment is about 20% or more. So I add this filter to the search 'where NOT DNS.message_type IN("Pointer","PTR")'
|
2021-07-21 18:20:15 +04:30 |
|
P4T12ICK
|
76bbbe4609
|
add deployments to baselines
|
2021-07-21 11:31:40 +02:00 |
|
P4T12ICK
|
5e6e987fb7
|
resolved merge conflicts
|
2021-07-21 09:22:09 +02:00 |
|
research bot
|
3740535cca
|
updating docs and package bits [ci skip]
|
2021-07-20 17:49:09 +00:00 |
|
github-actions[bot]
|
23c103c192
|
Branch was auto-updated.
|
2021-07-20 15:47:19 +00:00 |
|
P4T12ICK
|
9568fc7807
|
migrated baselines into detections folder
|
2021-07-20 13:19:22 +02:00 |
|
P4T12ICK
|
cfae82505c
|
add analytic types to detections
|
2021-07-19 17:41:22 +02:00 |
|
tccontre
|
3d82142995
|
rba_task_update
|
2021-07-15 09:39:03 +02:00 |
|
tccontre
|
8477b3e3a0
|
rba_task_2
|
2021-07-14 16:35:10 +02:00 |
|
tccontre
|
019e9311f1
|
rba_task_2
|
2021-07-14 16:33:48 +02:00 |
|
tccontre
|
197e73cd61
|
de
|
2021-06-15 15:51:08 +02:00 |
|
tccontre
|
9e009e50b7
|
data_exfil
|
2021-06-15 15:36:41 +02:00 |
|
research bot
|
2d61b8e675
|
updating docs and package bits [ci skip]
|
2021-05-24 17:47:29 +00:00 |
|
tccontre
|
0249f2ce27
|
fix_validate
|
2021-05-18 10:47:53 +02:00 |
|
research bot
|
1aeb0a9f6a
|
updating docs and package bits [ci skip]
|
2021-04-29 21:32:44 +00:00 |
|
Michael Haag
|
80904c3093
|
Update plain_http_post_exfiltrated_data.yml
|
2021-04-23 11:48:49 -06:00 |
|
Michael Haag
|
84e775e972
|
Update multiple_archive_files_http_post_traffic.yml
|
2021-04-23 11:44:45 -06:00 |
|
root
|
bd66b44311
|
Added detection testing service results inMultiple Archive Files Http Post Traffic
|
2021-04-23 15:06:39 +00:00 |
|
root
|
7e31007e97
|
Added detection testing service results inPlain HTTP POST Exfiltrated Data
|
2021-04-23 14:49:36 +00:00 |
|
tcontreras
|
6ed8a29e4e
|
fix_error
|
2021-04-22 15:48:54 +02:00 |
|
tcontreras
|
162b9f0cc3
|
net_exfil
|
2021-04-22 15:37:09 +02:00 |
|
P4T12ICK
|
edaf9598f2
|
fixed merging issues
|
2021-03-11 19:03:54 +01:00 |
|
P4T12ICK
|
6e826b4e68
|
add required fields and check
|
2021-03-11 09:11:48 +01:00 |
|
mhaag-spl
|
b15aaa55df
|
Moving non-passed to experimental and deprecating some
|
2021-03-10 13:27:00 -07:00 |
|
mhaag-spl
|
a6265b60df
|
Moving Tor Traffic to Experimental
|
2021-03-10 11:47:34 -07:00 |
|
P4T12ICK
|
df31ce2246
|
WIP
|
2021-03-10 15:22:35 +01:00 |
|
P4T12ICK
|
c1c1d1733e
|
WIP
|
2021-03-10 15:22:14 +01:00 |
|
mhaag-spl
|
51823d81d3
|
Sunburst malware renamed NOBELIUM Group
Renaming Sunburst Malware to NOBELIUM Group
|
2021-03-05 10:30:34 -07:00 |
|
divious1
|
b58843ca9f
|
added datamodels as an array
|
2021-02-10 22:35:58 -05:00 |
|
divious1
|
d0c9c92857
|
added datamodel field and made all objects also pretty via new tool called pretty_yaml.py
|
2021-02-10 22:11:24 -05:00 |
|
divious1
|
1ec15cf044
|
renamed on all detections
|
2021-02-08 10:18:16 -05:00 |
|
divious1
|
b68e05685e
|
modified type for detections
|
2021-02-05 14:35:49 -05:00 |
|
divious1
|
e14fade976
|
adding product tag to all detections
|
2021-02-03 21:42:46 -05:00 |
|
github-actions[bot]
|
c88cc88d1b
|
Branch was auto-updated.
|
2021-01-25 19:02:14 +00:00 |
|
David Dorsey
|
88c9469541
|
More language clean up
|
2021-01-22 09:37:51 -06:00 |
|
David Dorsey
|
fd76342c94
|
Changed the language in some of the descriptions
|
2021-01-21 23:53:47 -06:00 |
|
P4T12ICK
|
0d75faf323
|
new test file
|
2021-01-19 13:55:33 +01:00 |
|
P4T12ICK
|
98175156b7
|
Merge branch 'detection_testing_branch' of github.com:splunk/security-content into detection_testing_branch
|
2021-01-18 15:47:15 +01:00 |
|
P4T12ICK
|
477221da99
|
detection testing
|
2021-01-18 15:46:53 +01:00 |
|
root
|
a88d8291fe
|
Added detection testing service results inDNS Query Length With High Standard Deviation
|
2021-01-18 14:41:53 +00:00 |
|
P4T12ICK
|
44bf41a678
|
new test file
|
2021-01-18 15:22:05 +01:00 |
|
P4T12ICK
|
27b27a5b59
|
detection testing branch
|
2021-01-18 14:10:47 +01:00 |
|
root
|
b751d5ddb8
|
Added detection testing service results inDetect hosts connecting to dynamic domain providers
|
2021-01-14 15:15:59 +00:00 |
|
P4T12ICK
|
c871d6804a
|
improved detections and tests
|
2021-01-14 15:01:16 +01:00 |
|
github-actions[bot]
|
162d729fff
|
Branch was auto-updated.
|
2021-01-06 20:21:46 +00:00 |
|
divious1
|
1e64964226
|
adding changes from suggestions on issue#1053
|
2021-01-05 14:45:35 -05:00 |
|