Commit Graph

27912 Commits

Author SHA1 Message Date
Xiaonan Qi 0922ef16b1 Add redhat yaml extension recommendation 2026-01-13 14:12:08 -08:00
Xiaonan Qi 90e65ef56b Add yaml schemas in vscode settings.json 2026-01-13 14:11:24 -08:00
Eric McGinnis b8ac2c2b8e migrate deprecation info 2026-01-09 11:17:23 -08:00
Bhavin Patel 1360c8df28 Merge branch 'develop' into yml_validation_cleanups 2026-01-09 14:25:37 +05:30
Eric McGinnis aca791beef remove mitre lookup as an apptemplate file so it can later be added as just a normal csvlookup. 2026-01-08 16:15:02 -08:00
Eric McGinnis bc46ab2f27 Remove the default.xml due to conflict. It is not required. 2026-01-08 15:46:21 -08:00
Bhavin Patel 3ca19718c6 minor changes to deprecation_mapping.YML‎ (#3855)
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-08 11:02:53 +00:00
Br3akp0int edd6db09d9 Add New Analytics Covering SesameOp and PromptFlux (#3827)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-08 00:58:33 +01:00
Bhavin Patel 0f5eeb8ceb Updated TAs (#3854)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-01-07 10:17:04 +05:30
Raven Tait 498a80d469 Detections for default user agents (#3842)
* Detections for default user agents

* various updates for user agent detections

* Apply suggestions from code review

* Rename suspicious_user_agent.yml to suspicious_user_agents.yml

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-07 09:34:04 +05:30
Br3akp0int af847b6343 Update Driver and Extensionless Files Related Detections (#3846)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-06 02:02:25 +01:00
Bhavin Patel 6d1b940663 Cisco Isovalent - Add first batch of new detections (#3706)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-06 01:24:39 +01:00
Lou Stella ab6a3f046e Merge pull request #3852 from splunk/dependabot/github_actions/actions/checkout-6
Bump actions/checkout from 5 to 6
2025-12-23 10:12:26 -06:00
Lou Stella 3f62a1873f Merge branch 'develop' into dependabot/github_actions/actions/checkout-6 2025-12-23 10:08:37 -06:00
Lou Stella 497301220e Merge pull request #3851 from splunk/dependabot/github_actions/actions/upload-artifact-6
Bump actions/upload-artifact from 5 to 6
2025-12-23 10:07:50 -06:00
dependabot[bot] e2147cd6c4 Bump actions/checkout from 5 to 6
Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-22 23:09:39 +00:00
dependabot[bot] 62403fcde4 Bump actions/upload-artifact from 5 to 6
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 5 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-22 23:09:30 +00:00
pyth0n1c 3b49316ebd Merge branch 'develop' into yml_validation_cleanups 2025-12-22 13:21:53 -08:00
Eric McGinnis 0f1862c4eb add deprecation info to one detection 2025-12-22 13:21:40 -08:00
Nasreddine Bencherchali 7fe10bbef8 Move Unused Macros to Deprecate Sub-Folder (#3847) 2025-12-22 14:01:09 +01:00
Bhavin Patel cd961cac5b Updated TAs (#3849)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2025-12-21 19:20:09 +01:00
Bhavin Patel 4e90912faf Updated TAs (#3845)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2025-12-19 21:10:10 +05:30
henryy-splunk 49652d55f9 Add description and fix template names for response plans (#3844)
* Add description, template name, and fix default version

* don't set default
2025-12-19 14:18:02 +05:30
Nasreddine Bencherchali 976c62383e Update Macro Usage (#3840)
* update macro usage

* bump version

* Update detect_hosts_connecting_to_dynamic_domain_providers.yml

* more macro updates
2025-12-18 21:42:06 +05:30
Eric McGinnis 9fe76df136 accidentally removed security_domain from detection. removed filter macro that was part of baseline, but should not be 2025-12-17 11:48:57 -08:00
Eric McGinnis 30a6a9fb21 Add some missing products. I assume all these detections want to be for all 3 splunk products. 2025-12-17 11:46:11 -08:00
Lou Stella 2accf6560f Merge pull request #3838 from splunk/housekeeping/response-templates
Housekeeping re: response templates
2025-12-17 11:44:36 -06:00
ljstella def30e3ba3 Add codeowners for response templates 2025-12-17 12:25:42 -05:00
ljstella 5bed4a5f8f Update labeler config for Response Templates 2025-12-17 12:10:46 -05:00
xqi-splunk 3953a43f05 Concept Shippable Response Plans (#3803)
* Create response_plan directory

* Update directory name

* Copy response_templates artifacts to dist/api

* Add response-templates schema validation workflow

* Add feature branch for testing purpose

* Update endpoint to playground

* Revert back debug changes

* Move scripts to workflows

* Remove manual check in

* Add sorting for version and template name

* Raise exception when file name not match

* Add indentation for json output

* Add debug option to dump json schema

* Generate merged templates at runtime

* Rename openAPI spec yaml to yml

* Move validation to build.yml

* Use stem to get file name

* Fix python package install

* Update version sorting using int

* Update openAPI spec for version

* Move build response templates to separate workflow

* Fix naming in build-response-templates.yml

* Update response templates to the ones for first release

* Fix naming of response templates

* Response templates to be added by response plan team

* Keep response_templates directory

* Skip .gitkeep checking when check non-json files

* Remove the .gitkeep

* Initial version of Response Templates

* Initial version of Response Templates

* Initial version of Response Templates

* Revert "Initial version of Response Templates"

This reverts commit 3a174dd02e.

* Revert "Initial version of Response Templates"

This reverts commit 26fa66ddde.

* Revert "Initial version of Response Templates"

This reverts commit 6014b4870b.

* Initial version of Response Templates

* Initial version of Response Templates

* Update and rename AccountCompromise_v14.json to AccountCompromise_v2.json

* Update and rename DataBreach_v15.json to DataBreach_v2.json

* Update and rename GenericIncidentResponse_v13.json to GenericIncidentResponse_v2.json

* Update and rename NIST80061_v14.json to NIST80061_v2.json

* Update and rename NetworkIndicatorEnrichment_v6.json to NetworkIndicatorEnrichment_v2.json

* Update and rename SelfReplicatingMalware_v14.json to SelfReplicatingMalware_v2.json

* Update and rename SuspiciousEmail_v35.json to SuspiciousEmail_v2.json

* Update and rename VulnerabilityDisclosure_v10.json to VulnerabilityDisclosure_v2.json

* Add comments

---------

Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Christian Cloutier <ccloutier@splunk.com>
Co-authored-by: kbouchard <47464052+kbouchardherjavecgroup@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-12-17 02:30:20 +05:30
dependabot[bot] 2a219fe9b6 Bump actions/upload-artifact from 5 to 6 (#3837)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 5 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-12-16 18:28:24 +05:30
dependabot[bot] b616f6b87f Bump peter-evans/create-pull-request from 7 to 8 (#3836)
Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) from 7 to 8.
- [Release notes](https://github.com/peter-evans/create-pull-request/releases)
- [Commits](https://github.com/peter-evans/create-pull-request/compare/v7...v8)

---
updated-dependencies:
- dependency-name: peter-evans/create-pull-request
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-12-16 18:22:07 +05:30
Bhavin Patel 9635667aac Fix Inspect CI - Bump analytic version (#3834) 2025-12-16 10:51:30 +01:00
Bhavin Patel 2bcff6573a Bump contentctl.yml to 5.20.0 (#3829)
* chore: bump contentctl.yml to 5.20.0

* move removed detections

---------

Co-authored-by: research bot <research@splunk.com>
2025-12-15 23:12:19 +05:30
Bhavin Patel 78d7f8cebd Updated TAs (#3832)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2025-12-12 15:06:49 +01:00
Lou Stella 61d302d922 Merge pull request #3825 from splunk/519_integration_fixes
v5.19.0 Integration Testing Failures
v5.19.0
2025-12-09 06:36:27 -06:00
Nasreddine Bencherchali ecf54630c1 Merge branch 'develop' into 519_integration_fixes 2025-12-09 12:06:44 +01:00
Bhavin Patel 378879ae67 Updated TAs (#3826)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2025-12-09 12:06:36 +01:00
ljstella ef25edaeca Message formatting changes 2025-12-08 21:26:34 -05:00
ljstella 50fff2dc09 RBA Messages 2025-12-08 20:43:02 -05:00
Lou Stella abb24f5002 Merge pull request #3824 from splunk/uptoprod
One More Fix
2025-12-08 14:50:02 -06:00
Lou Stella 2da13ca0f0 Merge pull request #3823 from splunk/uptoprod 2025-12-08 14:38:09 -06:00
Nasreddine Bencherchali 8a1e1c1729 Update linux_suspicious_react_or_next_js_child_process.yml 2025-12-08 21:38:05 +01:00
Nasreddine Bencherchali 4aa1c0b5f9 Update linux_suspicious_react_or_next_js_child_process.yml 2025-12-08 21:35:33 +01:00
Raven Tait 6032db5edb Add tuoni content and named pipe detection (#3816)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-12-08 21:25:09 +01:00
Nasreddine Bencherchali 5dca2eab02 Add React2Shell Snort Mapping (#3822) 2025-12-08 20:45:54 +01:00
Bhavin Patel 4b60fecd8e Automated Splunk TA Update 473 (#3820)
* Updated TAs

* Adding ta-ollama

---------

Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
Co-authored-by: ljstella <lstella@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-12-08 16:05:19 +01:00
Nasreddine Bencherchali 5d7c65d30a React2Shell Analytics (#3819) 2025-12-08 15:47:53 +01:00
Nasreddine Bencherchali 533e39c255 Merge pull request #3821 from splunk/update-snort-lookup
Add CastleRAT and LokiBot Snort IDs
2025-12-08 15:25:56 +01:00
Nasreddine Bencherchali 431e06d6b8 Update detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml 2025-12-08 14:34:07 +01:00