David Sarkisyan
1610a7cf68
Fix regsvr32 typo ( #4117 )
...
Co-authored-by: David Sarkisyan <281478990+srkyn@users.noreply.github.com >
2026-06-08 16:16:26 +02:00
Bhavin Patel
0c3e5887e8
Bump contentctl.yml and build.yml to 6.1.0 ( #4113 )
...
* chore: bump contentctl.yml and build.yml to 6.1.0
* move to removed
* status is removed
---------
Co-authored-by: research bot <research@splunk.com >
2026-06-08 15:58:54 +02:00
Lou Stella
4493a82b24
Merge pull request #4082 from splunk/escu_6
...
ESCU 6 YAML Porting and Updates
v6.0.0
2026-05-28 13:42:12 -04:00
Lou Stella
e547f65647
Merge pull request #4109 from splunk/escu_6_add_mitre_lookup_object
...
remove mitre_enrichment lookup
2026-05-28 09:30:22 -04:00
pyth0n1c
191d88b919
Merge branch 'escu_6' into escu_6_add_mitre_lookup_object
2026-05-27 16:27:05 -07:00
pyth0n1c
21382d5854
Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6
2026-05-27 16:26:19 -07:00
pyth0n1c
8b46602b10
bump to contentctl 0.7.0
2026-05-27 16:25:10 -07:00
Eric
066be568ff
remove unused legacy lookup mitre_enrichment
2026-05-27 14:31:58 -07:00
Eric
2b5b07a892
move mitre_enrichment from the app_template and make it its own content object
2026-05-26 15:45:44 -07:00
pyth0n1c
1eee030aea
Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6
2026-05-26 12:52:49 -07:00
pyth0n1c
94031fb8ef
bump ng version to latest
2026-05-26 12:51:40 -07:00
pyth0n1c
ac76e5521e
Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6
2026-05-22 09:53:08 -07:00
pyth0n1c
955e428056
Bump to contentctl-ng
...
0.5.0 to resolve errors
in unit testing workflow
2026-05-22 09:52:15 -07:00
pyth0n1c
705d154891
Merge pull request #4097 from splunk/escu_6_bump_pulled_ta_version
...
bump pulled AWS TA version
2026-05-21 16:52:05 -07:00
Eric
830c9189e9
bump pulled AWS TA version
2026-05-21 16:06:38 -07:00
pyth0n1c
61f33e2b62
Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6
2026-05-21 15:36:05 -07:00
Eric
295994a577
debug issues with testing from target branch
2026-05-21 15:34:27 -07:00
pyth0n1c
12b801e080
Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6
2026-05-21 15:23:39 -07:00
Eric
1ef4a3c092
Remove separate action, which lead
...
to some confusing indirection
2026-05-21 15:20:08 -07:00
Eric
101c76e8b8
After discussions with team,
...
remove the rba_upgrade_tracking.json
file and update the default.xml
file to avoid conflict around
multiple definitions of this file.
2026-05-21 13:26:56 -07:00
Eric
93e2487cb2
Merge branch 'escu_6' of https://github.com/splunk/security_content into escu_6
2026-05-21 13:25:45 -07:00
Lou Stella
6fcd545024
Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6
2026-05-21 16:17:01 -04:00
Eric
b6a8382659
fix reference to install and build commands
...
in workflow
2026-05-21 11:51:00 -07:00
Eric
290e3f66cd
Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6
2026-05-21 11:38:56 -07:00
Eric
73c7ac9b2c
Add the workflow updates
2026-05-21 11:16:50 -07:00
Lou Stella
bd1b475ccb
Merge pull request #4088 from splunk/escu6_manual_review
...
ESCU 6 Manual Migrations
2026-05-21 11:09:25 -04:00
Eric McGinnis
e84529f448
added back contentctl.yml as it is required for the legacy testing workflow
2026-05-20 13:31:40 -07:00
Eric McGinnis
1fb3da73f2
Add updated schemas, which has been updated as manual_review content was resolved
2026-05-20 12:19:45 -07:00
ljstella
0c869bfc93
yamlfmt
2026-05-20 15:15:09 -04:00
Lou Stella
e5dc0c4625
Merge pull request #4089 from splunk/port_playbooks
...
Port playbooks
2026-05-20 12:35:21 -04:00
ljstella
c498d21841
Manual Review completion
2026-05-20 12:15:00 -04:00
Eric McGinnis
13f06b5e1d
Complete porinting of playbooks. Fix references to old, removed detections
...
in playbooks that were previously unvalidated.
Add a MANUAL_REVIEW section, which is commented out,
for clarity and to allow CICD to run and pass on this content.
Renamed an existing playbook because it diverges from the name
of that playbook elsewhere.
2026-05-19 14:28:53 -07:00
pyth0n1c
e190246023
Merge branch 'escu6_manual_review' into port_playbooks
2026-05-19 12:22:30 -07:00
ljstella
d7b8c0f0d8
Reordering key
2026-05-19 14:25:35 -04:00
Lou Stella
d235c3e7d2
Update detections/web/monitor_web_traffic_for_brand_abuse.yml
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-05-19 14:22:21 -04:00
ljstella
bc18194661
Reordering keys
2026-05-19 14:21:30 -04:00
Eric McGinnis
0a8c534612
Update playbooks to new format.
2026-05-19 11:12:49 -07:00
ljstella
b196ddcf95
Baseline cleanup
2026-05-19 12:23:15 -04:00
ljstella
53565febce
message cleanup
2026-05-19 12:15:48 -04:00
ljstella
15c349bde3
Multiple user type entities
2026-05-19 11:45:53 -04:00
ljstella
e52095cb16
Unbalanced $ in message
2026-05-19 10:35:40 -04:00
ljstella
baf4b85578
Multiple non-user but no user
2026-05-19 10:34:15 -04:00
ljstella
9dfb1706f9
Manual Review of correlation searches
2026-05-19 10:10:45 -04:00
Eric McGinnis
81bdcbbc89
deprecated macros were not copied over during PORT operation. Fix that.
2026-05-14 07:17:08 -07:00
Eric McGinnis
2b10ef9cd7
remove deployments directory
2026-05-13 17:12:15 -07:00
Eric McGinnis
61f71544c4
Macros were missed during the porting copy over. They have now been added.
2026-05-13 17:09:31 -07:00
Eric McGinnis
58c7164aa2
Fix schema settings in settings.json as file names and paths had changed since the pr was first opened
2026-05-13 14:25:04 -07:00
Eric McGinnis
703bf050e8
Add schema validate vscode or other editor settings.
2026-05-13 14:17:30 -07:00
Eric McGinnis
4d7bdebd3f
Add auto generated schemas. Note that thare are some pieces of content missing from here - notably content which has a MANUAL_REVIEW flag. This content does not parse until it has been updated, which means it could not be compiled into the schemas. These files will be updated when all content in the repo successfully parses.
2026-05-13 14:13:49 -07:00
Eric McGinnis
3bdbc59422
The 5 kvstore lookups referenced in the previous commit that were intentionally moved, but not updated, have now been updated with the new format.
2026-05-13 14:04:13 -07:00