Commit Graph

128 Commits

Author SHA1 Message Date
pyth0n1c 72f7731c6b Restored all the detections to the versions in develop. 2022-07-22 13:07:44 -07:00
pyth0n1c 89fb987623 Merge latest from develop, taking all of their changes 2022-07-22 12:58:35 -07:00
pyth0n1c d40ca09d61 Merged develop into content_changer_improvements to resolve merge conflict. this was making it impossible to merge the PR in the GitHub Interface. 2022-06-23 14:19:17 -07:00
Jose Enrique Hernandez 0288c10f70 Update splunk_identified_ssl_tls_certificates.yml 2022-06-14 08:18:53 -04:00
Lou Stella a0967fe429 Workbook how_to_implement & references 2022-06-13 16:49:49 -05:00
Michael Haag 66d7814fed Update splunk_identified_ssl_tls_certificates.yml 2022-06-13 15:43:18 -06:00
Michael Haag 46cd276adf Update splunk_identified_ssl_tls_certificates.yml 2022-06-13 15:40:49 -06:00
d1vious 97d51b71bf adding cves 2022-06-01 17:03:00 -04:00
mhaag-spl 6ddebf3a2d ssl tls ver 2022-05-26 12:28:21 -06:00
pyth0n1c 27bb4a28fc Fixed the ordering of all detections. This tool previously messed up that order... 2022-05-24 13:01:09 -07:00
pyth0n1c 2557d21335 Branch was auto-updated. 2022-05-16 14:25:41 -04:00
mhaag-spl 77abe77035 F5 BIG-IP 2022-05-10 07:20:46 -06:00
pyth0n1c 578e6bb088 Updated a very large number of detections whose references were returning HTTP Status 301 - resource moved. For example, this includes a large number of fireeye reports, which are now under mandiant, cobaltstrike info, and microsoft links. 2022-05-02 17:12:50 -07:00
pyth0n1c e3725e5d22 Quoted large number of strings in detections to address the problem of these strings, which are values, being misidentified by the tool as submodel.fieldname format. Committing these changes and reviewing automated testing to make sure none of these changes broke the detections. 2022-04-15 15:23:04 -07:00
d1vious fdcd471d5d moving to experimental 2022-04-14 16:37:54 -04:00
P4T12ICK 5dd13ea167 fix broken detections 2022-03-14 15:51:05 +01:00
P4T12ICK e6c8254ede Added automaticc generation of finding report 2022-03-14 12:12:48 +01:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 886da3c92e merged with develop 2022-03-04 14:35:50 +01:00
patel-bhavin a67a8a4da6 Merge branch 'develop' into refactored_security_content 2022-03-03 12:51:11 -08:00
research bot 67ecd29d53 updating docs and package bits [ci skip] 2022-03-03 18:22:29 +00:00
P4T12ICK 68543a8dc1 merged with develop 2022-03-03 13:11:56 +01:00
d1vious 47dbc6b946 using a different field 2022-02-26 13:39:28 -05:00
d1vious 0d49d7fc55 Merge branch 'CityOfLog4Shells' of github.com:splunk/security_content into CityOfLog4Shells 2022-02-24 23:05:48 -05:00
d1vious 6a50f02ff4 working detection 2022-02-24 23:05:31 -05:00
pyth0n1c df824e79ac Branch was auto-updated. 2022-02-18 15:32:15 -08:00
d1vious ba97944d04 adding ldap detection 2022-02-18 17:39:23 -05:00
d1vious db3605c753 adding ssa detection 2022-02-18 14:26:17 -05:00
truptilangalia-crest 179134e8ef test:removed cim version 2022-02-08 12:05:05 +05:30
truptilangalia-crest 08f0ff6405 test: Removed tas with mapping from detection files 2022-01-31 19:46:09 +05:30
P4T12ICK 4fd8604b9a removed SAAWS and automated_detection_testing flag 2022-01-27 09:50:45 +01:00
Detection Testing Service 6fd7a4e812 test: updated supported_tas to recommended_tas 2022-01-19 17:43:41 +05:30
P4T12ICK 84092434a2 fixed more detections 2022-01-18 12:53:54 +01:00
P4T12ICK 98e5af3713 put baselines and investigations into its own folder 2022-01-17 10:56:04 +01:00
pyth0n1c ecf27cf81f Updated almost all detections again. Changed required_fields from submodel.fieldname to model.submodel.fieldname as discussed with the CREST Team. 2022-01-12 11:31:15 -08:00
pyth0n1c 2670d58f50 Massive commit - the field and datamodel update tool has updated almost all of our detections. We will commit and then run a test on everything to see if we broke any searches. 2022-01-10 15:58:14 -08:00
pyth0n1c 4a34f4445d Updated a large number of searches which uses datamodels from 'datamodel=datamodel' to 'datamodel=datamodel.submodel'. This is more explicit and allows us to better enumerate and check required_fields and declared datamodels 2022-01-10 12:52:16 -08:00
Detection Testing Service a2b6fff739 test:updated ymls 2021-12-15 21:15:02 +05:30
research bot ff3319329e updating docs and package bits [ci skip] 2021-12-15 02:58:27 +00:00
d1vious 16b771eae2 adding tags to detections 2021-12-14 19:38:51 -05:00
patel-bhavin 05b189232d ldap outbound 2021-12-14 10:10:23 -08:00
tlangalia 343ceae12f Updated detection files with supported TA list. 2021-12-14 13:27:55 +05:50
research bot a1afa0fa60 updating docs and package bits [ci skip] 2021-10-28 19:55:37 +00:00
Drew Church 3b18c5abcb Added CVE tags to 35 files 2021-10-22 10:03:24 -07:00
tccontre 9d466adc76 CARS_UPDATE_MITRE_ID_B8
CARS_UPDATE_MITRE_ID_B8
2021-10-15 10:22:43 +02:00
patel-bhavin 333552c326 version 2021-10-06 15:25:22 -07:00
patel-bhavin 966f63d7f1 duplicate 2021-10-06 15:17:00 -07:00
divious1 671e91ecd0 moved to experimental due to lack of testing 2021-09-09 17:30:40 -04:00
research bot 2c9e7b58a8 updating docs and package bits [ci skip] 2021-08-18 16:56:31 +00:00