Commit Graph

12922 Commits

Author SHA1 Message Date
P4T12ICK 9310c27941 ssa test ci cd 2021-11-24 09:17:42 +01:00
P4T12ICK 421aebbf68 ssa test ci cd 2021-11-24 08:28:45 +01:00
mvelazco 46aa673605 Merge branch 'TR-1085_LateralMovement_3' of github.com:splunk/security_content into TR-1085_LateralMovement_3 2021-11-23 21:04:10 -05:00
mvelazco 33e9597304 updating logic and adding datasets 2021-11-23 21:04:04 -05:00
root 9e165574c0 Added detection testing service results inWsmprovhost.exe LOLBAS Execution Process Spawn 2021-11-24 01:53:58 +00:00
mvelazco eba7f33aa9 Merge branch 'TR-1085_LateralMovement_3' of github.com:splunk/security_content into TR-1085_LateralMovement_3 2021-11-23 20:33:28 -05:00
mvelazco ad273d4ca1 update datasets 2021-11-23 20:33:27 -05:00
pyth0n1c 6b292ba2c1 upload artifacts even if summarize fails. 2021-11-23 17:13:44 -08:00
pyth0n1c a302d952b4 tiny ci change to test everything overnight 2021-11-23 17:12:25 -08:00
pyth0n1c ae7fb14085 Updated summarize_json.py to provide a total success/failure field and also return a nonzero return code if at least one test fails. 2021-11-23 16:38:22 -08:00
Detection Testing Service 25a60dfdc7 Merge branch 'TR-1085_LateralMovement_3' of https://github.com/splunk/security_content into TR-1085_LateralMovement_3 2021-11-24 00:03:26 +00:00
root 6c45a549e3 Added detection testing service results inWmiprsve.exe LOLBAS Execution Process Spawn 2021-11-24 00:03:25 +00:00
pyth0n1c 1a39321be6 Small typo in artifact filename. 2021-11-23 15:54:12 -08:00
Detection Testing Service 2c6ae766cc Merge branch 'TR-1085_LateralMovement_3' of https://github.com/splunk/security_content into TR-1085_LateralMovement_3 2021-11-23 23:52:09 +00:00
root e7ad40a54b Added detection testing service results inMmc.exe LOLBAS Execution Process Spawn 2021-11-23 23:52:08 +00:00
mvelazco 2e86ded458 Merge branch 'TR-1085_LateralMovement_3' of github.com:splunk/security_content into TR-1085_LateralMovement_3 2021-11-23 18:42:50 -05:00
mvelazco c13de25f73 update dataset metadata 2021-11-23 18:42:48 -05:00
pyth0n1c 1afbaa3a1d Fixed bad value substitution into the schema coming from command line arguments. 2021-11-23 15:35:05 -08:00
pyth0n1c 451d2500db Fixed overwriting mode with null if nothing is passed on the command line. 2021-11-23 15:22:11 -08:00
pyth0n1c b0e7c33c4d Changing mode for CI PR test from selected to changes. 2021-11-23 15:14:49 -08:00
pyth0n1c 1015abc30a Finally ready to try the full integration test after modifying the docker-detection-testing.yml with new names, paths, and arguments. Fingers crossed... 2021-11-23 15:10:28 -08:00
pyth0n1c fab525a682 Added support for more command line arguments for number containers and mode and branch. 2021-11-23 14:48:37 -08:00
root 37f4a32647 Added detection testing service results inServices.exe LOLBAS Execution Process Spawn 2021-11-23 22:39:17 +00:00
pyth0n1c dab746bb0c Save out a json file showing the config, to include the command line arguments with credentials removed, whenever a test is actually run. This makes it trivial to reproduce the test run on another machine or again on the same machine. 2021-11-23 14:30:54 -08:00
mvelazco c2fd0a4b29 adding dataset fields 2021-11-23 17:15:06 -05:00
mvelazco 190c0cba21 Merge branch 'TR-1085_LateralMovement_3' of github.com:splunk/security_content into TR-1085_LateralMovement_3 2021-11-23 16:00:06 -05:00
mvelazco 5211a97f11 update detections 2021-11-23 16:00:04 -05:00
pyth0n1c 914f49d6f7 Delete intermediate testing artifacts/container config files in CI. Better job packaging all local apps, not just escu, into the same folder for --mock. 2021-11-23 11:59:01 -08:00
root c8c731e449 Added detection testing service results inWindows Service Created With Suspicious Service Path 2021-11-23 19:20:48 +00:00
mvelazco 4c696f9ad8 updating detections 2021-11-23 14:01:28 -05:00
mvelazco 9b944b67a2 adding 4 new detections 2021-11-23 10:13:07 -05:00
P4T12ICK 8cf8efb30f SSA anommalous usage of archive tools 2021-11-23 13:05:00 +01:00
P4T12ICK 4d6e83bd25 SSA anommalous usage of archive tools 2021-11-23 12:46:02 +01:00
tccontre 83576ecb74 more_ioc_detections 2021-11-23 11:56:00 +01:00
P4T12ICK e48bf8c257 SSA anommalous usage of archive tools 2021-11-23 10:14:50 +01:00
pyth0n1c 3cd1e42ada Huge refactor is almost complete. Able to launch and run multiple containers now as intended 2021-11-22 16:36:21 -08:00
mvelazco f2a7006482 Merge branch 'TR-1085_LateralMovement_3' of github.com:splunk/security_content into TR-1085_LateralMovement_3 2021-11-22 16:21:46 -05:00
mvelazco 8c2baf103e creating an extra detection 2021-11-22 16:21:43 -05:00
root 8482d30656 Added detection testing service results inPossible Browser Pass View Parameter 2021-11-22 14:44:57 +00:00
tccontre 04c433eedf more_ioc_detections 2021-11-22 15:09:53 +01:00
tccontre 3b2bb44e91 more_ioc_detections 2021-11-22 12:39:31 +01:00
Bhavin Patel a1bee25acb Branch was auto-updated. 2021-11-22 02:53:47 -08:00
Bhavin Patel 3f9f549d03 Branch was auto-updated. 2021-11-22 02:53:46 -08:00
Bhavin Patel fe491600d5 Branch was auto-updated. 2021-11-22 02:53:45 -08:00
Bhavin Patel 1449f7c6f1 Branch was auto-updated. 2021-11-22 02:53:44 -08:00
Bhavin Patel a60798b203 Branch was auto-updated. 2021-11-22 02:53:43 -08:00
Bhavin Patel ae506e8798 Branch was auto-updated. 2021-11-22 02:53:39 -08:00
P4T12ICK 2ee09fbceb Merge pull request #1836 from splunk/ssa_insider_secure_delete
ssa_sdelete
2021-11-22 11:53:20 +01:00
P4T12ICK 8b174b9967 small change 2021-11-22 11:07:10 +01:00
tccontre 45e691bd0d ssa_sdelete 2021-11-22 10:39:45 +01:00