Xiaonan Qi
0922ef16b1
Add redhat yaml extension recommendation
2026-01-13 14:12:08 -08:00
Xiaonan Qi
90e65ef56b
Add yaml schemas in vscode settings.json
2026-01-13 14:11:24 -08:00
Eric McGinnis
b8ac2c2b8e
migrate deprecation info
2026-01-09 11:17:23 -08:00
Bhavin Patel
1360c8df28
Merge branch 'develop' into yml_validation_cleanups
2026-01-09 14:25:37 +05:30
Eric McGinnis
aca791beef
remove mitre lookup as an apptemplate file so it can later be added as just a normal csvlookup.
2026-01-08 16:15:02 -08:00
Eric McGinnis
bc46ab2f27
Remove the default.xml due to conflict. It is not required.
2026-01-08 15:46:21 -08:00
Bhavin Patel
3ca19718c6
minor changes to deprecation_mapping.YML ( #3855 )
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-08 11:02:53 +00:00
Br3akp0int
edd6db09d9
Add New Analytics Covering SesameOp and PromptFlux ( #3827 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-08 00:58:33 +01:00
Bhavin Patel
0f5eeb8ceb
Updated TAs ( #3854 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-01-07 10:17:04 +05:30
Raven Tait
498a80d469
Detections for default user agents ( #3842 )
...
* Detections for default user agents
* various updates for user agent detections
* Apply suggestions from code review
* Rename suspicious_user_agent.yml to suspicious_user_agents.yml
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-07 09:34:04 +05:30
Br3akp0int
af847b6343
Update Driver and Extensionless Files Related Detections ( #3846 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-06 02:02:25 +01:00
Bhavin Patel
6d1b940663
Cisco Isovalent - Add first batch of new detections ( #3706 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-06 01:24:39 +01:00
Lou Stella
ab6a3f046e
Merge pull request #3852 from splunk/dependabot/github_actions/actions/checkout-6
...
Bump actions/checkout from 5 to 6
2025-12-23 10:12:26 -06:00
Lou Stella
3f62a1873f
Merge branch 'develop' into dependabot/github_actions/actions/checkout-6
2025-12-23 10:08:37 -06:00
Lou Stella
497301220e
Merge pull request #3851 from splunk/dependabot/github_actions/actions/upload-artifact-6
...
Bump actions/upload-artifact from 5 to 6
2025-12-23 10:07:50 -06:00
dependabot[bot]
e2147cd6c4
Bump actions/checkout from 5 to 6
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-22 23:09:39 +00:00
dependabot[bot]
62403fcde4
Bump actions/upload-artifact from 5 to 6
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 5 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-12-22 23:09:30 +00:00
pyth0n1c
3b49316ebd
Merge branch 'develop' into yml_validation_cleanups
2025-12-22 13:21:53 -08:00
Eric McGinnis
0f1862c4eb
add deprecation info to one detection
2025-12-22 13:21:40 -08:00
Nasreddine Bencherchali
7fe10bbef8
Move Unused Macros to Deprecate Sub-Folder ( #3847 )
2025-12-22 14:01:09 +01:00
Bhavin Patel
cd961cac5b
Updated TAs ( #3849 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2025-12-21 19:20:09 +01:00
Bhavin Patel
4e90912faf
Updated TAs ( #3845 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2025-12-19 21:10:10 +05:30
henryy-splunk
49652d55f9
Add description and fix template names for response plans ( #3844 )
...
* Add description, template name, and fix default version
* don't set default
2025-12-19 14:18:02 +05:30
Nasreddine Bencherchali
976c62383e
Update Macro Usage ( #3840 )
...
* update macro usage
* bump version
* Update detect_hosts_connecting_to_dynamic_domain_providers.yml
* more macro updates
2025-12-18 21:42:06 +05:30
Eric McGinnis
9fe76df136
accidentally removed security_domain from detection. removed filter macro that was part of baseline, but should not be
2025-12-17 11:48:57 -08:00
Eric McGinnis
30a6a9fb21
Add some missing products. I assume all these detections want to be for all 3 splunk products.
2025-12-17 11:46:11 -08:00
Lou Stella
2accf6560f
Merge pull request #3838 from splunk/housekeeping/response-templates
...
Housekeeping re: response templates
2025-12-17 11:44:36 -06:00
ljstella
def30e3ba3
Add codeowners for response templates
2025-12-17 12:25:42 -05:00
ljstella
5bed4a5f8f
Update labeler config for Response Templates
2025-12-17 12:10:46 -05:00
xqi-splunk
3953a43f05
Concept Shippable Response Plans ( #3803 )
...
* Create response_plan directory
* Update directory name
* Copy response_templates artifacts to dist/api
* Add response-templates schema validation workflow
* Add feature branch for testing purpose
* Update endpoint to playground
* Revert back debug changes
* Move scripts to workflows
* Remove manual check in
* Add sorting for version and template name
* Raise exception when file name not match
* Add indentation for json output
* Add debug option to dump json schema
* Generate merged templates at runtime
* Rename openAPI spec yaml to yml
* Move validation to build.yml
* Use stem to get file name
* Fix python package install
* Update version sorting using int
* Update openAPI spec for version
* Move build response templates to separate workflow
* Fix naming in build-response-templates.yml
* Update response templates to the ones for first release
* Fix naming of response templates
* Response templates to be added by response plan team
* Keep response_templates directory
* Skip .gitkeep checking when check non-json files
* Remove the .gitkeep
* Initial version of Response Templates
* Initial version of Response Templates
* Initial version of Response Templates
* Revert "Initial version of Response Templates"
This reverts commit 3a174dd02e .
* Revert "Initial version of Response Templates"
This reverts commit 26fa66ddde .
* Revert "Initial version of Response Templates"
This reverts commit 6014b4870b .
* Initial version of Response Templates
* Initial version of Response Templates
* Update and rename AccountCompromise_v14.json to AccountCompromise_v2.json
* Update and rename DataBreach_v15.json to DataBreach_v2.json
* Update and rename GenericIncidentResponse_v13.json to GenericIncidentResponse_v2.json
* Update and rename NIST80061_v14.json to NIST80061_v2.json
* Update and rename NetworkIndicatorEnrichment_v6.json to NetworkIndicatorEnrichment_v2.json
* Update and rename SelfReplicatingMalware_v14.json to SelfReplicatingMalware_v2.json
* Update and rename SuspiciousEmail_v35.json to SuspiciousEmail_v2.json
* Update and rename VulnerabilityDisclosure_v10.json to VulnerabilityDisclosure_v2.json
* Add comments
---------
Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com >
Co-authored-by: Christian Cloutier <ccloutier@splunk.com >
Co-authored-by: kbouchard <47464052+kbouchardherjavecgroup@users.noreply.github.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-12-17 02:30:20 +05:30
dependabot[bot]
2a219fe9b6
Bump actions/upload-artifact from 5 to 6 ( #3837 )
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 5 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-12-16 18:28:24 +05:30
dependabot[bot]
b616f6b87f
Bump peter-evans/create-pull-request from 7 to 8 ( #3836 )
...
Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request ) from 7 to 8.
- [Release notes](https://github.com/peter-evans/create-pull-request/releases )
- [Commits](https://github.com/peter-evans/create-pull-request/compare/v7...v8 )
---
updated-dependencies:
- dependency-name: peter-evans/create-pull-request
dependency-version: '8'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-12-16 18:22:07 +05:30
Bhavin Patel
9635667aac
Fix Inspect CI - Bump analytic version ( #3834 )
2025-12-16 10:51:30 +01:00
Bhavin Patel
2bcff6573a
Bump contentctl.yml to 5.20.0 ( #3829 )
...
* chore: bump contentctl.yml to 5.20.0
* move removed detections
---------
Co-authored-by: research bot <research@splunk.com >
2025-12-15 23:12:19 +05:30
Bhavin Patel
78d7f8cebd
Updated TAs ( #3832 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2025-12-12 15:06:49 +01:00
Lou Stella
61d302d922
Merge pull request #3825 from splunk/519_integration_fixes
...
v5.19.0 Integration Testing Failures
v5.19.0
2025-12-09 06:36:27 -06:00
Nasreddine Bencherchali
ecf54630c1
Merge branch 'develop' into 519_integration_fixes
2025-12-09 12:06:44 +01:00
Bhavin Patel
378879ae67
Updated TAs ( #3826 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2025-12-09 12:06:36 +01:00
ljstella
ef25edaeca
Message formatting changes
2025-12-08 21:26:34 -05:00
ljstella
50fff2dc09
RBA Messages
2025-12-08 20:43:02 -05:00
Lou Stella
abb24f5002
Merge pull request #3824 from splunk/uptoprod
...
One More Fix
2025-12-08 14:50:02 -06:00
Lou Stella
2da13ca0f0
Merge pull request #3823 from splunk/uptoprod
2025-12-08 14:38:09 -06:00
Nasreddine Bencherchali
8a1e1c1729
Update linux_suspicious_react_or_next_js_child_process.yml
2025-12-08 21:38:05 +01:00
Nasreddine Bencherchali
4aa1c0b5f9
Update linux_suspicious_react_or_next_js_child_process.yml
2025-12-08 21:35:33 +01:00
Raven Tait
6032db5edb
Add tuoni content and named pipe detection ( #3816 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-12-08 21:25:09 +01:00
Nasreddine Bencherchali
5dca2eab02
Add React2Shell Snort Mapping ( #3822 )
2025-12-08 20:45:54 +01:00
Bhavin Patel
4b60fecd8e
Automated Splunk TA Update 473 ( #3820 )
...
* Updated TAs
* Adding ta-ollama
---------
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
Co-authored-by: ljstella <lstella@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-12-08 16:05:19 +01:00
Nasreddine Bencherchali
5d7c65d30a
React2Shell Analytics ( #3819 )
2025-12-08 15:47:53 +01:00
Nasreddine Bencherchali
533e39c255
Merge pull request #3821 from splunk/update-snort-lookup
...
Add CastleRAT and LokiBot Snort IDs
2025-12-08 15:25:56 +01:00
Nasreddine Bencherchali
431e06d6b8
Update detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml
2025-12-08 14:34:07 +01:00