1281 Commits

Author SHA1 Message Date
ljstella d7b8c0f0d8 Reordering key 2026-05-19 14:25:35 -04:00
ljstella bc18194661 Reordering keys 2026-05-19 14:21:30 -04:00
ljstella 53565febce message cleanup 2026-05-19 12:15:48 -04:00
ljstella 15c349bde3 Multiple user type entities 2026-05-19 11:45:53 -04:00
ljstella 9dfb1706f9 Manual Review of correlation searches 2026-05-19 10:10:45 -04:00
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Lou Stella 9c183fa110 Update Analytics to Support ATT&CK v19 (#4036)
---------

Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-05 17:29:28 +02:00
jwindley c5e9d4a573 Fixed two detections, and improved macos keychain dumping for more coverage of the technique (#4034)
* Fix and improve azure high-risk sign-in, curl percent-encoded URL, and macOS keychain dump detections

* Apply suggestions from code review

* Update azure_active_directory_high_risk_sign_in.yml

* Update curl_execution_with_percent_encoded_url.yml

* beautify spl

* Update macos_keychains_dumped.yml

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-29 15:20:25 +02:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Bhavin Patel c90d744007 Duplicate - Microsoft Intune Bulk Wipe Detected (#4014)
* updating search

* Update microsoft_intune_bulk_wipe_detected.yml

* Rename microsoft_intune_bulk_wipe_detected.yml to microsoft_intune_bulk_wipe.yml

* Update microsoft_intune_bulk_wipe.yml

* Update detections/cloud/microsoft_intune_bulk_wipe.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* updating refs

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-15 23:08:02 +05:30
Nasreddine Bencherchali bc1b413923 Fix Reported Issues - April Batch (#3962)
* Fix #3961

* Fix #3909

* Fix output fields

* Remove duplicate process_name entry

* Update outbound_network_connection_from_java_using_default_ports.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Fix #3969

* update palo alto TA and beautify analytics

* Update vmware_aria_operations_exploit_attempt.yml

* fix source

* enhance metadata and fp info

* beautify spl for ease of reading

* add some missing attack techniques

* remove unnecessary usage of regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* small fix

* Refine description and improve regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update windows_event_log_security_4756.yml

* description update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-30 14:34:11 +05:30
Bhavin Patel b3fed38275 Deprecate MLTK detections (#3922)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-03-16 14:59:40 +01:00
Nasreddine Bencherchali 29113be7a7 Fix Broken Link, Versions and Pre-Commit (#3956)
* fix links and versions

* more versions
2026-03-13 19:17:15 +05:30
Andrei Banaru d1d4883e18 fix: replace src with src_user (#3955)
Co-authored-by: Andrei Banaru <a.banaru@iaea.org>
2026-03-13 17:29:46 +05:30
Emil a0059cf72c Adding dynamic information to static rba messages (#3951)
* Adding dynamic information to static rba messages

* Updating rba message to bette represent what the detection triggers on

* Correcting syntax of rba message

* Updating version and date
2026-03-13 11:27:18 +05:30
Br3akp0int 3da4f7958a anomaly_standard_init_score (#3946)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-10 14:19:08 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Bhavin Patel d080ba9f06 Updating Terminology for ES8+ (#3875)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-22 22:59:29 +01:00
Michael Haag b6b0b47a66 Storm-0501 Ransomware Analytic Story and Tagging (#3871)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-01-22 22:32:14 +01:00
Oliver Springer 2008331fbb O365 - Expand Detection of New MFA Devices (#3868)
* Also detect the registration of new mobile authenticator apps

* Update o365_new_mfa_method_registered.yml

---------

Co-authored-by: Oliver Springer <9538543+JTweet@users.noreply.github.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-20 09:22:23 +05:30
Bhavin Patel 121be41015 Merge branch 'develop' into inspect_5.19 2025-12-01 20:07:37 -08:00
Bhavin Patel 17f3101c03 updating versions 2025-12-01 18:10:06 -08:00
Thomas Macfarlane 59c872761b chore: user_agent field fix in both the Azure AD authentication detections. Minor spelling mistake fixes. (#3811)
* chore: user_agent field fix in both the Azure AD authentication detections. Minor spelling mistake fixes.

* beautify

* remove rename

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-12-01 16:25:33 -08:00
Michael Haag 442e815dad npm Supply Chain Compromise & Lifecycle Hook Abuse Detection (#3806)
* extra content

* 5 more extras

* Hunt 1

* story+extras

* Create linux_shai_hulud_2_exfiltration_artifacts.yml

* Create linux_shai_hulud_workflow_file_modification.yml

* Create linux_suspicious_github_workflow_file_modification.yml

* Create windows_github_workflow_file_creation_hunt.yml

* more

* last 3

* final pass

* Bump versions to resolve merge conflicts with develop branch

* Fix deprecated status for curl/wget bash execution detections

* Add npm Supply Chain Compromise story to file_download_or_read_to_pipe_execution (replacement for deprecated curl/wget bash detections)

* Fix version numbers to match previous build requirements

* Add all required Filesystem fields to windows_suspicious_github_workflow_file_modification search

* Update detections/endpoint/windows_curl_download_to_suspicious_path.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* small fixes

* apply updates

* more updates

* Update shai_hulud_2_exfiltration_artifact_files.yml

* Fix Windows path escaping - use single backslash in YAML block scalar

---------

Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-11-25 14:56:20 -08:00
Nasreddine Bencherchali 9fc8942993 New Rules & Updates - Oct 25 (#3726)
* new rules and updates

* fix issues with ci

* rename for accurate macro

* update description and logic

* new wbadmin rule and fix pwsh dataset

* more updates for the weekend

* update network rules filters

* downgrade versions

* Update windows_file_transfer_protocol_in_non_common_process_path.yml

* add missing DS for some rules

* update nirsoft lookup and add new rules

* update more nirsoft stuff

* update snort message

* Update cisco_secure_firewall_filetype_lookup.yml

* new analytic and updates / incl. fix #3730

* Update detect_new_local_admin_account.yml

* add lnx dataset and fix wildcards
2025-10-24 14:19:48 -07:00
Michael Haag 7b9274f9fb Scattered Lapsus$ Hunters (#3724)
* Scattered Lapsus$ Hunters

* fixes

* 👀

* bump versions

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-10-21 11:27:25 -07:00
Michael Haag a548ed769a Hellcat United (#3723)
* Hellcat United

* fixes

* 🍱

* 1 mas

* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Bhavin Patel 68e7778b8a Update azure_ad_multi_source_failed_authentications_spike.yml 2025-09-29 14:45:01 -07:00
Bhavin Patel f450563436 updateing based on issue 2025-09-18 13:54:48 -07:00
Brian Serocki 939ee285a3 Correct Azure localization issues 2025-09-03 16:07:29 -05:00
Brian Serocki 7b24f8a54f Correct Azure localization issues 2025-09-03 13:17:03 -05:00
Bhavin Patel b04570fe56 updating SPL to match the issue fix after testing 2025-08-26 14:14:45 -07:00
Bhavin Patel f6fdcd098c updating search and other meta 2025-08-26 12:55:56 -07:00
Jake Enea e4cfd3c338 aad multiple denied mfa requests: updating version and date 2025-07-31 20:42:11 -04:00
Jake Enea 11a2f6a4ce aad multiple denied mfa requests: add _time in 'stats count by' to limit to 10 min windows 2025-07-31 20:37:59 -04:00
0xC0FFEEEE 3ccf82c437 update risk message 2025-07-24 09:00:34 +01:00
0xC0FFEEEE 1032077679 Add rule name to risk message 2025-07-23 09:42:34 +01:00
0xC0FFEEEE afefa1506c use correct drilldown field 2025-07-23 09:41:21 +01:00
0xC0FFEEEE 43fa38ef77 Add threshold filter
Accidentally removed during testing of previous SPL update
2025-07-23 09:39:53 +01:00
0xC0FFEEEE a278863c13 remove unneccesary json normalization 2025-07-03 09:17:50 +01:00
0xC0FFEEEE 3ba50a2d97 Add support for Set-InboxRule 2025-07-01 16:42:06 +01:00
ljstella 0f3feac263 Version bumps 2025-06-24 12:43:01 -05:00
ljstella 397107f88a Updated docs links in detections 2025-06-24 11:27:59 -05:00
ljstella 437b5cf59c Version bump 2025-06-17 09:14:07 -05:00
ljstella bded2e9379 Silly casing... 2025-06-17 09:09:53 -05:00
ljstella 342b06c308 Swap detections to experimental as test data no longer matches expectations of TA 2025-06-17 09:08:59 -05:00
ljstella ff624b020a change to supported sourcetype 2025-06-17 09:08:10 -05:00
Nasreddine Bencherchali 4801780532 Merge branch 'develop' into updates-june 2025-06-17 11:15:26 +02:00