419 Commits

Author SHA1 Message Date
ljstella bc18194661 Reordering keys 2026-05-19 14:21:30 -04:00
ljstella b196ddcf95 Baseline cleanup 2026-05-19 12:23:15 -04:00
ljstella e52095cb16 Unbalanced $ in message 2026-05-19 10:35:40 -04:00
ljstella 9dfb1706f9 Manual Review of correlation searches 2026-05-19 10:10:45 -04:00
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Lou Stella 9c183fa110 Update Analytics to Support ATT&CK v19 (#4036)
---------

Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-05 17:29:28 +02:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali bc1b413923 Fix Reported Issues - April Batch (#3962)
* Fix #3961

* Fix #3909

* Fix output fields

* Remove duplicate process_name entry

* Update outbound_network_connection_from_java_using_default_ports.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Fix #3969

* update palo alto TA and beautify analytics

* Update vmware_aria_operations_exploit_attempt.yml

* fix source

* enhance metadata and fp info

* beautify spl for ease of reading

* add some missing attack techniques

* remove unnecessary usage of regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* small fix

* Refine description and improve regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update windows_event_log_security_4756.yml

* description update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-30 14:34:11 +05:30
Lou Stella 0f08a8b884 Tweaking attack_data links (#3966)
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-23 14:38:28 +01:00
Br3akp0int 3da4f7958a anomaly_standard_init_score (#3946)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-10 14:19:08 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
pyth0n1c 997eb76be6 Remove EXTRA fields that are not part
of the models from yml files
2026-03-02 12:28:07 -08:00
Eric McGinnis c733e6c9cc Merge branch 'develop' into yml_validation_cleanups 2026-02-25 11:36:18 -08:00
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Eric McGinnis 1ed6c27923 Update all dates on modified content, including the baseline 2026-02-25 10:13:58 -08:00
pyth0n1c 490ad6daf1 Merge branch 'develop' into yml_validation_cleanups 2026-02-25 10:05:41 -08:00
Rod Soto 02573684ce Add New MCP Related Detections (#3895)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-02-17 23:39:01 +01:00
Eric McGinnis 15f1e39548 Merge branch 'develop' into yml_validation_cleanups 2026-02-11 08:51:26 -08:00
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Eric McGinnis 95f20fa74a fix date format 2026-01-28 12:05:23 -08:00
Eric McGinnis f6ea72fa20 bump dates and verisons 2026-01-28 11:54:20 -08:00
pyth0n1c 0f9014f4b6 Merge branch 'develop' into yml_validation_cleanups 2026-01-28 11:36:47 -08:00
Nasreddine Bencherchali 6cc12a9b29 Analytic Enhancements and Fixes (#3850)
* update `Windows LOLBAS Executed Outside Expected Path`

* Update suspicious_email_attachment_extensions.yml

* update susp extension lookup

* some additional fixes

* Update system_processes_run_from_unexpected_locations.yml

* small changes

* Update detect_rtlo_in_file_name.yml

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-12 18:36:12 +05:30
pyth0n1c 3b49316ebd Merge branch 'develop' into yml_validation_cleanups 2025-12-22 13:21:53 -08:00
Nasreddine Bencherchali 976c62383e Update Macro Usage (#3840)
* update macro usage

* bump version

* Update detect_hosts_connecting_to_dynamic_domain_providers.yml

* more macro updates
2025-12-18 21:42:06 +05:30
Eric McGinnis 9fe76df136 accidentally removed security_domain from detection. removed filter macro that was part of baseline, but should not be 2025-12-17 11:48:57 -08:00
Eric McGinnis 30a6a9fb21 Add some missing products. I assume all these detections want to be for all 3 splunk products. 2025-12-17 11:46:11 -08:00
Nasreddine Bencherchali 515d736c62 Add New ASA Analytics (#3794)
* first batch

* more updates

* update tags and filter

* more fixes

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* update to production

* fixes and updates

* update date and fix typos

* apply suggestion

* Update cisco_asa___reconnaissance_command_activity.yml

* add explicit message ids

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-11-21 14:50:18 -08:00
Michael Haag 7b9274f9fb Scattered Lapsus$ Hunters (#3724)
* Scattered Lapsus$ Hunters

* fixes

* 👀

* bump versions

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-10-21 11:27:25 -07:00
Michael Haag a548ed769a Hellcat United (#3723)
* Hellcat United

* fixes

* 🍱

* 1 mas

* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Michael Haag 64ed5bb1e8 APT 37 and The No Good Rustonotto (#3686)
* APT 37 and The No Good Rustonotto

## Updated analytics
```
detections/application/detect_html_help_spawn_child_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/bitsadmin_download_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cobalt_strike_named_pipes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_rundll32_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/executables_or_script_creation_in_temp_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/icedid_exfiltrated_archived_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/lolbas_with_network_traffic.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_4104_hunting.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/processes_tapping_keyboard_events.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/registry_keys_used_for_persistence.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_curl_network_connection.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_image_creation_in_appdata_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_mshta_spawn.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_process_executed_from_container_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_scheduled_task_from_public_directory.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_alternate_datastream___base64_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_rar.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archived_collected_data_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_cab_file_on_disk.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_curl_download_to_suspicious_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_invoke_restmethod.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_powershell_uploadstring.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_file_download_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_high_file_deletion_frequency.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_http_network_communication_from_msiexec.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_indicator_removal_via_rmdir.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_input_capture_using_credential_ui_dll.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_iso_lnk_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_child_process_for_download.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_uncommon_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_executed_from_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_execution_from_programdata.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_commonly_abused_processes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_notepad.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_replication_through_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_command.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_name.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_service_created_with_suspicious_service_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_suspicious_driver_loaded_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_usbstor_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_wpdbusenum_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/winevent_scheduled_task_created_within_public_path.yml — APT37 Rustonotto and FadeStealer
detections/web/multiple_archive_files_http_post_traffic.yml — APT37 Rustonotto and FadeStealer
detections/web/plain_http_post_exfiltrated_data.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_expand_cabinet_file_extraction.yml — APT37 Rustonotto and FadeStealer
```

## New Story

```
stories/apt37_rustonotto_and_fadestealer.yml — APT37 Rustonotto and FadeStealer
```

* Create windows_expand_cabinet_file_extraction.yml

* Apply suggestion from @nasbench

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* updating conflicts

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 13:54:03 -07:00
Rod Soto 0bcb54b6f9 Ollama TA detections (#3710)
* commit1oll

* olldet2

* olldet3

* fixeddet3

* fixsp

* olldet4

* olldet5

* detoll6

* olldet7

* olldet8

* datasets

* testfixes

* modifiedtasearch

* lotsofixes

* fixednewta

* addedmorerefs

* fixedatasource

* fixedthreatobject

* fixedetectionandalertmessage

* fixedalermessage

* fixedquotes

* fixedhowtoimp

* fixeddescriptionandhowto

* changedestforuripat

* fixedowasplink

* Update detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/application/ollama_possible_rce_via_model_loading.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* protoexnassuggestions

* mionr

* remove index=*

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 21:54:37 +02:00
Rod Soto 6cf5b0f8f6 Copilot based Detections (#3693)
* det1

* fixeddt1

* det2

* d3

* det4

* djbk

* d6

* d7

* d8

* addedlnkds

* fixsctype

* pipegone

* fixp

* fixdevices

* jbfix

* datasetfix

* exp

* fixsynthax

* changedstory

* changeprinus

* improvedht

* changedSenderuser

* datas

* fixdoublesearch

* fixedpi

* fixeddescriptionsuser

* fixdatalink

* exportedlogsdatasource

* fixedhowtodatasource

* updating risk stuff

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 12:14:09 -07:00
Bhavin Patel a1d2b73915 updating links 2025-09-25 18:23:04 -07:00
Bhavin Patel e51e23aab1 associating with new story 2025-09-25 18:19:34 -07:00
Bhavin Patel 4d7faff280 link for debug logging 2025-09-25 16:35:50 -07:00
Bhavin Patel 1fc1c5629a adding updates to how to implement 2025-09-25 16:20:10 -07:00
Bhavin Patel 46ab9105c9 updating links 2025-09-25 16:01:23 -07:00
Bhavin Patel 6734892a65 updating the SPL 2025-09-25 15:41:56 -07:00
Bhavin Patel fd9394687e move to public 2025-09-25 13:05:25 -07:00
ljstella 8d0935f037 Update attack_data links 2025-09-09 08:35:57 -04:00
Bhavin Patel 9cff1a1671 Merge branch 'develop' into 3886 2025-08-11 11:19:16 -07:00
Raven Tait 3fd2a02f18 Bump versions 2025-08-06 11:00:30 -05:00
Raven Tait 2dde8e118b Updates for 3886 2025-08-05 12:32:01 -05:00
Bhavin Patel ef128df886 updating spl 2025-08-04 14:53:47 -05:00
Bhavin Patel c6c2175f2a move to prod 2025-08-04 14:00:19 -05:00
Bhavin Patel 2c6248de85 updating based on request from Ryan Long 2025-08-04 13:56:35 -05:00
Bhavin Patel e434b1ac3f remove extraquote 2025-07-21 09:44:10 -07:00
Patrick Bareiss 034c2a7bf6 feedback review 2025-07-21 09:47:20 +02:00
Bhavin Patel efc331be05 Merge branch 'develop' into duo_detections_1 2025-07-18 13:50:53 -07:00