Commit Graph

27986 Commits

Author SHA1 Message Date
Teoderick Contreras 3976f0e57d anomaly_init_score 2026-02-26 10:58:28 +01:00
Lou Stella d119763abe Merge pull request #3839 from splunk/yml_validation_cleanups
Yml validation cleanups
2026-02-25 14:17:38 -06:00
Eric McGinnis c733e6c9cc Merge branch 'develop' into yml_validation_cleanups 2026-02-25 11:36:18 -08:00
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Eric McGinnis 1ed6c27923 Update all dates on modified content, including the baseline 2026-02-25 10:13:58 -08:00
Eric McGinnis bdf95f1e90 Restore contents of app template. Replace removed/detections/ that were needlessly updated 2026-02-25 10:09:20 -08:00
pyth0n1c 490ad6daf1 Merge branch 'develop' into yml_validation_cleanups 2026-02-25 10:05:41 -08:00
Lou Stella 695434b155 Merge pull request #3921 from splunk/datefix
datefix
2026-02-25 11:18:06 -06:00
Lou Stella 2ac1ea4234 Merge branch 'develop' into datefix 2026-02-25 10:51:24 -06:00
Bhavin Patel 0fcd63a821 Updated TAs (#3919)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-25 22:21:02 +05:30
ljstella 47533256c7 contentctl version bump 2026-02-25 11:39:59 -05:00
ljstella f38fdc681e technically have to bump version for datefix 2026-02-25 10:24:04 -05:00
ljstella b393da3116 datefix 2026-02-25 10:20:22 -05:00
Bhavin Patel 91b957d103 Updated TAs (#3918)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-24 22:18:56 +05:30
Bhavin Patel 15deedd635 chore: bump contentctl.yml to 5.23.0 (#3913)
Co-authored-by: research bot <research@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-20 10:51:49 +01:00
Bhavin Patel 07d5e7d54d Updated TAs (#3914)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-20 10:49:23 +01:00
Br3akp0int c2044d9a99 Tag Content Related to Dynowiper/Zovwiper (#3907)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
v5.22.0
2026-02-17 23:52:23 +01:00
Rod Soto 02573684ce Add New MCP Related Detections (#3895)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-02-17 23:39:01 +01:00
Br3akp0int 19181a86b5 Add Coverage and Tagging for the XML Runner Loader (#3897)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:20:36 +01:00
Br3akp0int 6b9201dbc3 Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging (#3902)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:02:11 +01:00
Bhavin Patel 79d24587f6 Issue - 3901 (#3905)
* cosolidation of detections

* updating test
2026-02-11 22:33:49 +05:30
Eric McGinnis 15f1e39548 Merge branch 'develop' into yml_validation_cleanups 2026-02-11 08:51:26 -08:00
Bhavin Patel b29ba95b51 Updated TAs (#3906)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-11 22:18:24 +05:30
Bhavin Patel 91ab062bb4 Updated TAs (#3900)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-10 19:52:27 +05:30
bpluta-splunk 7cf9641f5f upodated SPL based on new raw events (#3898)
* upodated SPL based on new raw events

* updating dataset link and data source file

---------

Co-authored-by: Bhavin Patel <bpatel@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-10 12:59:45 +05:30
Bhavin Patel d13e377a27 Bump contentctl.yml to 5.22.0 (#3894)
* chore: bump contentctl.yml to 5.22.0

* remove detections

---------

Co-authored-by: research bot <research@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-02-10 10:27:49 +05:30
Lou Stella 84c05196d0 Merge pull request #3903 from splunk/contentctl_bump
Bumping contentctl
2026-02-09 12:42:20 -05:00
ljstella 7e19147038 Bumping contentctl 2026-02-09 11:21:18 -05:00
Lou Stella 2e7660be9c XML Windows Event Log Cleanup continued (#3887)
* Ported to XmlWinEventlog

* missed one change

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-06 18:58:37 +05:30
Bhavin Patel a43838a3f5 Automated Splunk TA Update 532 (#3891)
* Updated TAs

* Update Splunk app version and hardcoded path

---------

Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-06 18:21:07 +05:30
Lou Stella 73b2b82c67 Merge pull request #3890 from splunk/bump_contentctl_5_5_13 v5.21.0 2026-02-03 17:53:50 -05:00
pyth0n1c 252f1f6002 Update contentctl version to 5.5.13 2026-02-03 14:48:29 -08:00
Lou Stella c09c341ae4 Default.meta changes for default savedsearch stanza (#3815)
* Default.meta changes for default savedsearch stanza

* Update casing

* Bumping for new version with associated changes

* Version bump of contentctl for fixes
2026-02-03 22:37:54 +05:30
Br3akp0int b5280b610d browser_hijacking_2 (#3879)
* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* Update detections/endpoint/headless_browser_usage.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_browser_launched_with_small_window_size.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_launched_with_disable_popup_blocking.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_with_disabled_extensions.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_with_disabled_extensions.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_browser_launched_with_small_window_size.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_launched_with_disable_popup_blocking.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_loaded_extension_via_command_line.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_launched_with_logging_disabled.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_launched_with_logging_disabled.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* browser_hijacking_2

* Apply suggestion from @nasbench

* Refactor description in windows_chromium_process_launched_with_logging_disabled.yml

Updated the description format for clarity and readability.

* Change type to 'Anomaly' and refine description

Updated the type from 'TTP' to 'Anomaly' and modified the description for clarity.

* Enhance alert message with window dimensions

Added window dimensions to the alert message for clarity.

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-02 20:46:50 +05:30
Vignesh 7777dd91cb Add Windows TOR Client Execution Detected (#3881)
* Add Windows TOR Client Execution Detected

This detection is used to detects the execution of TOR browser and it's components on windows systems.

If you need any further information, please reach out to me via Slack.

Slack ID - Vignesh Subramanian

* Update Windows TOR Client Execution Detection

1. Focused on detecting tor.exe and added the process_path field to detect TOR execution within Brave Browser. 

Brave Browser includes a built-in TOR client that is not explicitly named tor.exe during process creation; instead, it appears as tor-0.4.8.19-win32-brave-0. To capture this, I added the Brave Browser path to the detection logic to identify the presence of TOR within Brave. 

I also introduced wildcards in the path to support any version TOR binaries used by Brave, ensuring that different version numbers are correctly matched. 

2. Avoided using escape characters to improve readability.

3. The provided ID has been added.

4. The process field has been added as a threat object.

5. Additional tokens have been included in the risk-based alerting message to make it clearer and more meaningful.

6. The word “detection” has been removed from the title, which is now: "Windows TOR Client Execution"

7. Added the correct attack dataset link from (https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1090.003/windows_tor_client_execution/windows-sysmon.log)

* Revise Windows TOR Client Execution detection details

Updated the detection configuration for Windows TOR Client Execution, including changes to the description, how to implement, known false positives, and drilldown searches.

---------

Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-02 20:02:06 +05:30
Bhavin Patel c233cf9c04 Updated TAs (#3884)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-01-31 19:40:56 +01:00
Raven Tait 56675d5fc7 Telnet Auth Bypass CVE (#3883)
* Telnet Auth Bypass

* Fix CVE in story

* Update rba message

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update rba and description

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-31 10:32:53 +05:30
Nasreddine Bencherchali a266563b00 Update RBA, logic, and beautify some searches (#3880)
* Update RBA, logic, and beautify searches

* Update internal_horizontal_port_scan_nmap_top_20.yml
2026-01-31 09:57:04 +05:30
Nasreddine Bencherchali c50763d938 Fix Reported Issues (#3873)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-30 16:34:18 +01:00
Andrei Banaru 28a213f97f Add Missing Time to Set Default PowerShell Execution Policy To Unrestricted or Bypass (#3882)
---------

Co-authored-by: Andrei Banaru <a.banaru@iaea.org>
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-30 12:41:19 +01:00
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Eric McGinnis 74ed412c74 more required bumps 2026-01-28 12:13:38 -08:00
Eric McGinnis 95f20fa74a fix date format 2026-01-28 12:05:23 -08:00
Eric McGinnis f6ea72fa20 bump dates and verisons 2026-01-28 11:54:20 -08:00
Eric McGinnis 5786c3164f Accidentally renamed extension for file 2026-01-28 11:47:22 -08:00
Eric McGinnis adba89740a fix wrong format failing validations 2026-01-28 11:44:39 -08:00
pyth0n1c 0f9014f4b6 Merge branch 'develop' into yml_validation_cleanups 2026-01-28 11:36:47 -08:00
Bhavin Patel 29ece397e8 Update Outlook writing zip Analytic (#3877)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-28 13:49:21 +01:00
Alex f1693a1a0a Fix search typo in windows abused web services analytic (#3878) 2026-01-24 14:38:30 +01:00
Bhavin Patel 060feb0a42 Updating Query Based on XS Data (#3876) 2026-01-23 15:49:23 +01:00