ljstella
|
bc18194661
|
Reordering keys
|
2026-05-19 14:21:30 -04:00 |
|
ljstella
|
b196ddcf95
|
Baseline cleanup
|
2026-05-19 12:23:15 -04:00 |
|
ljstella
|
e52095cb16
|
Unbalanced $ in message
|
2026-05-19 10:35:40 -04:00 |
|
ljstella
|
9dfb1706f9
|
Manual Review of correlation searches
|
2026-05-19 10:10:45 -04:00 |
|
Eric McGinnis
|
db8c7c8509
|
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
|
2026-05-13 14:02:27 -07:00 |
|
Lou Stella
|
9c183fa110
|
Update Analytics to Support ATT&CK v19 (#4036)
---------
Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
|
2026-05-05 17:29:28 +02:00 |
|
Bhavin Patel
|
ba59855b1d
|
updating risk drilldowns (#4016)
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
|
2026-04-17 17:28:53 +05:30 |
|
Nasreddine Bencherchali
|
bc1b413923
|
Fix Reported Issues - April Batch (#3962)
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-03-30 14:34:11 +05:30 |
|
Lou Stella
|
0f08a8b884
|
Tweaking attack_data links (#3966)
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-03-23 14:38:28 +01:00 |
|
Br3akp0int
|
3da4f7958a
|
anomaly_standard_init_score (#3946)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-03-10 14:19:08 +05:30 |
|
Br3akp0int
|
2e2f6fc649
|
ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
|
2026-03-10 14:10:37 +05:30 |
|
pyth0n1c
|
997eb76be6
|
Remove EXTRA fields that are not part
of the models from yml files
|
2026-03-02 12:28:07 -08:00 |
|
Eric McGinnis
|
c733e6c9cc
|
Merge branch 'develop' into yml_validation_cleanups
|
2026-02-25 11:36:18 -08:00 |
|
Nasreddine Bencherchali
|
11c909f725
|
Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920)
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-02-26 00:00:35 +05:30 |
|
Eric McGinnis
|
1ed6c27923
|
Update all dates on modified content, including the baseline
|
2026-02-25 10:13:58 -08:00 |
|
pyth0n1c
|
490ad6daf1
|
Merge branch 'develop' into yml_validation_cleanups
|
2026-02-25 10:05:41 -08:00 |
|
Rod Soto
|
02573684ce
|
Add New MCP Related Detections (#3895)
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
|
2026-02-17 23:39:01 +01:00 |
|
Eric McGinnis
|
15f1e39548
|
Merge branch 'develop' into yml_validation_cleanups
|
2026-02-11 08:51:26 -08:00 |
|
Nasreddine Bencherchali
|
f49f3a3fc9
|
Fix Validation Issues (#3861)
|
2026-01-30 01:38:34 +01:00 |
|
Eric McGinnis
|
95f20fa74a
|
fix date format
|
2026-01-28 12:05:23 -08:00 |
|
Eric McGinnis
|
f6ea72fa20
|
bump dates and verisons
|
2026-01-28 11:54:20 -08:00 |
|
pyth0n1c
|
0f9014f4b6
|
Merge branch 'develop' into yml_validation_cleanups
|
2026-01-28 11:36:47 -08:00 |
|
Nasreddine Bencherchali
|
6cc12a9b29
|
Analytic Enhancements and Fixes (#3850)
* update `Windows LOLBAS Executed Outside Expected Path`
* Update suspicious_email_attachment_extensions.yml
* update susp extension lookup
* some additional fixes
* Update system_processes_run_from_unexpected_locations.yml
* small changes
* Update detect_rtlo_in_file_name.yml
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-01-12 18:36:12 +05:30 |
|
pyth0n1c
|
3b49316ebd
|
Merge branch 'develop' into yml_validation_cleanups
|
2025-12-22 13:21:53 -08:00 |
|
Nasreddine Bencherchali
|
976c62383e
|
Update Macro Usage (#3840)
* update macro usage
* bump version
* Update detect_hosts_connecting_to_dynamic_domain_providers.yml
* more macro updates
|
2025-12-18 21:42:06 +05:30 |
|
Eric McGinnis
|
9fe76df136
|
accidentally removed security_domain from detection. removed filter macro that was part of baseline, but should not be
|
2025-12-17 11:48:57 -08:00 |
|
Eric McGinnis
|
30a6a9fb21
|
Add some missing products. I assume all these detections want to be for all 3 splunk products.
|
2025-12-17 11:46:11 -08:00 |
|
Nasreddine Bencherchali
|
515d736c62
|
Add New ASA Analytics (#3794)
* first batch
* more updates
* update tags and filter
* more fixes
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* update to production
* fixes and updates
* update date and fix typos
* apply suggestion
* Update cisco_asa___reconnaissance_command_activity.yml
* add explicit message ids
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2025-11-21 14:50:18 -08:00 |
|
Michael Haag
|
7b9274f9fb
|
Scattered Lapsus$ Hunters (#3724)
* Scattered Lapsus$ Hunters
* fixes
* 👀
* bump versions
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
|
2025-10-21 11:27:25 -07:00 |
|
Michael Haag
|
a548ed769a
|
Hellcat United (#3723)
* Hellcat United
* fixes
* 🍱
* 1 mas
* Update powershell_4104_hunting.yml
|
2025-10-16 16:53:02 -07:00 |
|
Michael Haag
|
64ed5bb1e8
|
APT 37 and The No Good Rustonotto (#3686)
* APT 37 and The No Good Rustonotto
## Updated analytics
```
detections/application/detect_html_help_spawn_child_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/bitsadmin_download_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cobalt_strike_named_pipes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_rundll32_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/executables_or_script_creation_in_temp_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/icedid_exfiltrated_archived_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/lolbas_with_network_traffic.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_4104_hunting.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/processes_tapping_keyboard_events.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/registry_keys_used_for_persistence.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_curl_network_connection.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_image_creation_in_appdata_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_mshta_spawn.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_process_executed_from_container_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_scheduled_task_from_public_directory.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_alternate_datastream___base64_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_rar.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archived_collected_data_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_cab_file_on_disk.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_curl_download_to_suspicious_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_invoke_restmethod.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_powershell_uploadstring.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_file_download_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_high_file_deletion_frequency.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_http_network_communication_from_msiexec.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_indicator_removal_via_rmdir.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_input_capture_using_credential_ui_dll.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_iso_lnk_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_child_process_for_download.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_uncommon_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_executed_from_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_execution_from_programdata.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_commonly_abused_processes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_notepad.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_replication_through_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_command.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_name.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_service_created_with_suspicious_service_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_suspicious_driver_loaded_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_usbstor_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_wpdbusenum_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/winevent_scheduled_task_created_within_public_path.yml — APT37 Rustonotto and FadeStealer
detections/web/multiple_archive_files_http_post_traffic.yml — APT37 Rustonotto and FadeStealer
detections/web/plain_http_post_exfiltrated_data.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_expand_cabinet_file_extraction.yml — APT37 Rustonotto and FadeStealer
```
## New Story
```
stories/apt37_rustonotto_and_fadestealer.yml — APT37 Rustonotto and FadeStealer
```
* Create windows_expand_cabinet_file_extraction.yml
* Apply suggestion from @nasbench
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
* updating conflicts
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
|
2025-10-13 13:54:03 -07:00 |
|
Rod Soto
|
0bcb54b6f9
|
Ollama TA detections (#3710)
* commit1oll
* olldet2
* olldet3
* fixeddet3
* fixsp
* olldet4
* olldet5
* detoll6
* olldet7
* olldet8
* datasets
* testfixes
* modifiedtasearch
* lotsofixes
* fixednewta
* addedmorerefs
* fixedatasource
* fixedthreatobject
* fixedetectionandalertmessage
* fixedalermessage
* fixedquotes
* fixedhowtoimp
* fixeddescriptionandhowto
* changedestforuripat
* fixedowasplink
* Update detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
* Update detections/application/ollama_possible_rce_via_model_loading.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
* Update detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
* protoexnassuggestions
* mionr
* remove index=*
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
|
2025-10-13 21:54:37 +02:00 |
|
Rod Soto
|
6cf5b0f8f6
|
Copilot based Detections (#3693)
* det1
* fixeddt1
* det2
* d3
* det4
* djbk
* d6
* d7
* d8
* addedlnkds
* fixsctype
* pipegone
* fixp
* fixdevices
* jbfix
* datasetfix
* exp
* fixsynthax
* changedstory
* changeprinus
* improvedht
* changedSenderuser
* datas
* fixdoublesearch
* fixedpi
* fixeddescriptionsuser
* fixdatalink
* exportedlogsdatasource
* fixedhowtodatasource
* updating risk stuff
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
|
2025-10-13 12:14:09 -07:00 |
|
Bhavin Patel
|
a1d2b73915
|
updating links
|
2025-09-25 18:23:04 -07:00 |
|
Bhavin Patel
|
e51e23aab1
|
associating with new story
|
2025-09-25 18:19:34 -07:00 |
|
Bhavin Patel
|
4d7faff280
|
link for debug logging
|
2025-09-25 16:35:50 -07:00 |
|
Bhavin Patel
|
1fc1c5629a
|
adding updates to how to implement
|
2025-09-25 16:20:10 -07:00 |
|
Bhavin Patel
|
46ab9105c9
|
updating links
|
2025-09-25 16:01:23 -07:00 |
|
Bhavin Patel
|
6734892a65
|
updating the SPL
|
2025-09-25 15:41:56 -07:00 |
|
Bhavin Patel
|
fd9394687e
|
move to public
|
2025-09-25 13:05:25 -07:00 |
|
ljstella
|
8d0935f037
|
Update attack_data links
|
2025-09-09 08:35:57 -04:00 |
|
Bhavin Patel
|
9cff1a1671
|
Merge branch 'develop' into 3886
|
2025-08-11 11:19:16 -07:00 |
|
Raven Tait
|
3fd2a02f18
|
Bump versions
|
2025-08-06 11:00:30 -05:00 |
|
Raven Tait
|
2dde8e118b
|
Updates for 3886
|
2025-08-05 12:32:01 -05:00 |
|
Bhavin Patel
|
ef128df886
|
updating spl
|
2025-08-04 14:53:47 -05:00 |
|
Bhavin Patel
|
c6c2175f2a
|
move to prod
|
2025-08-04 14:00:19 -05:00 |
|
Bhavin Patel
|
2c6248de85
|
updating based on request from Ryan Long
|
2025-08-04 13:56:35 -05:00 |
|
Bhavin Patel
|
e434b1ac3f
|
remove extraquote
|
2025-07-21 09:44:10 -07:00 |
|
Patrick Bareiss
|
034c2a7bf6
|
feedback review
|
2025-07-21 09:47:20 +02:00 |
|
Bhavin Patel
|
efc331be05
|
Merge branch 'develop' into duo_detections_1
|
2025-07-18 13:50:53 -07:00 |
|