Teoderick Contreras
3976f0e57d
anomaly_init_score
2026-02-26 10:58:28 +01:00
Lou Stella
d119763abe
Merge pull request #3839 from splunk/yml_validation_cleanups
...
Yml validation cleanups
2026-02-25 14:17:38 -06:00
Eric McGinnis
c733e6c9cc
Merge branch 'develop' into yml_validation_cleanups
2026-02-25 11:36:18 -08:00
Nasreddine Bencherchali
11c909f725
Add YAML Formatting Job ( #3889 )
...
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920 )
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-26 00:00:35 +05:30
Eric McGinnis
1ed6c27923
Update all dates on modified content, including the baseline
2026-02-25 10:13:58 -08:00
Eric McGinnis
bdf95f1e90
Restore contents of app template. Replace removed/detections/ that were needlessly updated
2026-02-25 10:09:20 -08:00
pyth0n1c
490ad6daf1
Merge branch 'develop' into yml_validation_cleanups
2026-02-25 10:05:41 -08:00
Lou Stella
695434b155
Merge pull request #3921 from splunk/datefix
...
datefix
2026-02-25 11:18:06 -06:00
Lou Stella
2ac1ea4234
Merge branch 'develop' into datefix
2026-02-25 10:51:24 -06:00
Bhavin Patel
0fcd63a821
Updated TAs ( #3919 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-02-25 22:21:02 +05:30
ljstella
47533256c7
contentctl version bump
2026-02-25 11:39:59 -05:00
ljstella
f38fdc681e
technically have to bump version for datefix
2026-02-25 10:24:04 -05:00
ljstella
b393da3116
datefix
2026-02-25 10:20:22 -05:00
Bhavin Patel
91b957d103
Updated TAs ( #3918 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-02-24 22:18:56 +05:30
Bhavin Patel
15deedd635
chore: bump contentctl.yml to 5.23.0 ( #3913 )
...
Co-authored-by: research bot <research@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-20 10:51:49 +01:00
Bhavin Patel
07d5e7d54d
Updated TAs ( #3914 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-02-20 10:49:23 +01:00
Br3akp0int
c2044d9a99
Tag Content Related to Dynowiper/Zovwiper ( #3907 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
v5.22.0
2026-02-17 23:52:23 +01:00
Rod Soto
02573684ce
Add New MCP Related Detections ( #3895 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-02-17 23:39:01 +01:00
Br3akp0int
19181a86b5
Add Coverage and Tagging for the XML Runner Loader ( #3897 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-17 20:20:36 +01:00
Br3akp0int
6b9201dbc3
Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging ( #3902 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-17 20:02:11 +01:00
Bhavin Patel
79d24587f6
Issue - 3901 ( #3905 )
...
* cosolidation of detections
* updating test
2026-02-11 22:33:49 +05:30
Eric McGinnis
15f1e39548
Merge branch 'develop' into yml_validation_cleanups
2026-02-11 08:51:26 -08:00
Bhavin Patel
b29ba95b51
Updated TAs ( #3906 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-02-11 22:18:24 +05:30
Bhavin Patel
91ab062bb4
Updated TAs ( #3900 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-02-10 19:52:27 +05:30
bpluta-splunk
7cf9641f5f
upodated SPL based on new raw events ( #3898 )
...
* upodated SPL based on new raw events
* updating dataset link and data source file
---------
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-10 12:59:45 +05:30
Bhavin Patel
d13e377a27
Bump contentctl.yml to 5.22.0 ( #3894 )
...
* chore: bump contentctl.yml to 5.22.0
* remove detections
---------
Co-authored-by: research bot <research@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-02-10 10:27:49 +05:30
Lou Stella
84c05196d0
Merge pull request #3903 from splunk/contentctl_bump
...
Bumping contentctl
2026-02-09 12:42:20 -05:00
ljstella
7e19147038
Bumping contentctl
2026-02-09 11:21:18 -05:00
Lou Stella
2e7660be9c
XML Windows Event Log Cleanup continued ( #3887 )
...
* Ported to XmlWinEventlog
* missed one change
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-06 18:58:37 +05:30
Bhavin Patel
a43838a3f5
Automated Splunk TA Update 532 ( #3891 )
...
* Updated TAs
* Update Splunk app version and hardcoded path
---------
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-06 18:21:07 +05:30
Lou Stella
73b2b82c67
Merge pull request #3890 from splunk/bump_contentctl_5_5_13
v5.21.0
2026-02-03 17:53:50 -05:00
pyth0n1c
252f1f6002
Update contentctl version to 5.5.13
2026-02-03 14:48:29 -08:00
Lou Stella
c09c341ae4
Default.meta changes for default savedsearch stanza ( #3815 )
...
* Default.meta changes for default savedsearch stanza
* Update casing
* Bumping for new version with associated changes
* Version bump of contentctl for fixes
2026-02-03 22:37:54 +05:30
Br3akp0int
b5280b610d
browser_hijacking_2 ( #3879 )
...
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* Update detections/endpoint/headless_browser_usage.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_browser_launched_with_small_window_size.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_launched_with_disable_popup_blocking.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_with_disabled_extensions.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_with_disabled_extensions.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_browser_launched_with_small_window_size.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_launched_with_disable_popup_blocking.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_loaded_extension_via_command_line.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_launched_with_logging_disabled.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_launched_with_logging_disabled.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* browser_hijacking_2
* Apply suggestion from @nasbench
* Refactor description in windows_chromium_process_launched_with_logging_disabled.yml
Updated the description format for clarity and readability.
* Change type to 'Anomaly' and refine description
Updated the type from 'TTP' to 'Anomaly' and modified the description for clarity.
* Enhance alert message with window dimensions
Added window dimensions to the alert message for clarity.
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-02 20:46:50 +05:30
Vignesh
7777dd91cb
Add Windows TOR Client Execution Detected ( #3881 )
...
* Add Windows TOR Client Execution Detected
This detection is used to detects the execution of TOR browser and it's components on windows systems.
If you need any further information, please reach out to me via Slack.
Slack ID - Vignesh Subramanian
* Update Windows TOR Client Execution Detection
1. Focused on detecting tor.exe and added the process_path field to detect TOR execution within Brave Browser.
Brave Browser includes a built-in TOR client that is not explicitly named tor.exe during process creation; instead, it appears as tor-0.4.8.19-win32-brave-0. To capture this, I added the Brave Browser path to the detection logic to identify the presence of TOR within Brave.
I also introduced wildcards in the path to support any version TOR binaries used by Brave, ensuring that different version numbers are correctly matched.
2. Avoided using escape characters to improve readability.
3. The provided ID has been added.
4. The process field has been added as a threat object.
5. Additional tokens have been included in the risk-based alerting message to make it clearer and more meaningful.
6. The word “detection” has been removed from the title, which is now: "Windows TOR Client Execution"
7. Added the correct attack dataset link from (https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1090.003/windows_tor_client_execution/windows-sysmon.log )
* Revise Windows TOR Client Execution detection details
Updated the detection configuration for Windows TOR Client Execution, including changes to the description, how to implement, known false positives, and drilldown searches.
---------
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-02 20:02:06 +05:30
Bhavin Patel
c233cf9c04
Updated TAs ( #3884 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-01-31 19:40:56 +01:00
Raven Tait
56675d5fc7
Telnet Auth Bypass CVE ( #3883 )
...
* Telnet Auth Bypass
* Fix CVE in story
* Update rba message
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update rba and description
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-31 10:32:53 +05:30
Nasreddine Bencherchali
a266563b00
Update RBA, logic, and beautify some searches ( #3880 )
...
* Update RBA, logic, and beautify searches
* Update internal_horizontal_port_scan_nmap_top_20.yml
2026-01-31 09:57:04 +05:30
Nasreddine Bencherchali
c50763d938
Fix Reported Issues ( #3873 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-30 16:34:18 +01:00
Andrei Banaru
28a213f97f
Add Missing Time to Set Default PowerShell Execution Policy To Unrestricted or Bypass ( #3882 )
...
---------
Co-authored-by: Andrei Banaru <a.banaru@iaea.org >
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-30 12:41:19 +01:00
Nasreddine Bencherchali
f49f3a3fc9
Fix Validation Issues ( #3861 )
2026-01-30 01:38:34 +01:00
Eric McGinnis
74ed412c74
more required bumps
2026-01-28 12:13:38 -08:00
Eric McGinnis
95f20fa74a
fix date format
2026-01-28 12:05:23 -08:00
Eric McGinnis
f6ea72fa20
bump dates and verisons
2026-01-28 11:54:20 -08:00
Eric McGinnis
5786c3164f
Accidentally renamed extension for file
2026-01-28 11:47:22 -08:00
Eric McGinnis
adba89740a
fix wrong format failing validations
2026-01-28 11:44:39 -08:00
pyth0n1c
0f9014f4b6
Merge branch 'develop' into yml_validation_cleanups
2026-01-28 11:36:47 -08:00
Bhavin Patel
29ece397e8
Update Outlook writing zip Analytic ( #3877 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-28 13:49:21 +01:00
Alex
f1693a1a0a
Fix search typo in windows abused web services analytic ( #3878 )
2026-01-24 14:38:30 +01:00
Bhavin Patel
060feb0a42
Updating Query Based on XS Data ( #3876 )
2026-01-23 15:49:23 +01:00