ljstella
d7b8c0f0d8
Reordering key
2026-05-19 14:25:35 -04:00
ljstella
bc18194661
Reordering keys
2026-05-19 14:21:30 -04:00
ljstella
53565febce
message cleanup
2026-05-19 12:15:48 -04:00
ljstella
15c349bde3
Multiple user type entities
2026-05-19 11:45:53 -04:00
ljstella
9dfb1706f9
Manual Review of correlation searches
2026-05-19 10:10:45 -04:00
Eric McGinnis
db8c7c8509
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
2026-05-13 14:02:27 -07:00
Lou Stella
9c183fa110
Update Analytics to Support ATT&CK v19 ( #4036 )
...
---------
Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-05-05 17:29:28 +02:00
jwindley
c5e9d4a573
Fixed two detections, and improved macos keychain dumping for more coverage of the technique ( #4034 )
...
* Fix and improve azure high-risk sign-in, curl percent-encoded URL, and macOS keychain dump detections
* Apply suggestions from code review
* Update azure_active_directory_high_risk_sign_in.yml
* Update curl_execution_with_percent_encoded_url.yml
* beautify spl
* Update macos_keychains_dumped.yml
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-29 15:20:25 +02:00
Bhavin Patel
ba59855b1d
updating risk drilldowns ( #4016 )
...
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Bhavin Patel
c90d744007
Duplicate - Microsoft Intune Bulk Wipe Detected ( #4014 )
...
* updating search
* Update microsoft_intune_bulk_wipe_detected.yml
* Rename microsoft_intune_bulk_wipe_detected.yml to microsoft_intune_bulk_wipe.yml
* Update microsoft_intune_bulk_wipe.yml
* Update detections/cloud/microsoft_intune_bulk_wipe.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* updating refs
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-15 23:08:02 +05:30
Nasreddine Bencherchali
bc1b413923
Fix Reported Issues - April Batch ( #3962 )
...
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-30 14:34:11 +05:30
Bhavin Patel
b3fed38275
Deprecate MLTK detections ( #3922 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-03-16 14:59:40 +01:00
Nasreddine Bencherchali
29113be7a7
Fix Broken Link, Versions and Pre-Commit ( #3956 )
...
* fix links and versions
* more versions
2026-03-13 19:17:15 +05:30
Andrei Banaru
d1d4883e18
fix: replace src with src_user ( #3955 )
...
Co-authored-by: Andrei Banaru <a.banaru@iaea.org >
2026-03-13 17:29:46 +05:30
Emil
a0059cf72c
Adding dynamic information to static rba messages ( #3951 )
...
* Adding dynamic information to static rba messages
* Updating rba message to bette represent what the detection triggers on
* Correcting syntax of rba message
* Updating version and date
2026-03-13 11:27:18 +05:30
Br3akp0int
3da4f7958a
anomaly_standard_init_score ( #3946 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-10 14:19:08 +05:30
Br3akp0int
2e2f6fc649
ttp_standard_init_score ( #3945 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali
11c909f725
Add YAML Formatting Job ( #3889 )
...
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920 )
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-26 00:00:35 +05:30
Nasreddine Bencherchali
f49f3a3fc9
Fix Validation Issues ( #3861 )
2026-01-30 01:38:34 +01:00
Bhavin Patel
d080ba9f06
Updating Terminology for ES8+ ( #3875 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-22 22:59:29 +01:00
Michael Haag
b6b0b47a66
Storm-0501 Ransomware Analytic Story and Tagging ( #3871 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-01-22 22:32:14 +01:00
Oliver Springer
2008331fbb
O365 - Expand Detection of New MFA Devices ( #3868 )
...
* Also detect the registration of new mobile authenticator apps
* Update o365_new_mfa_method_registered.yml
---------
Co-authored-by: Oliver Springer <9538543+JTweet@users.noreply.github.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-20 09:22:23 +05:30
Bhavin Patel
121be41015
Merge branch 'develop' into inspect_5.19
2025-12-01 20:07:37 -08:00
Bhavin Patel
17f3101c03
updating versions
2025-12-01 18:10:06 -08:00
Thomas Macfarlane
59c872761b
chore: user_agent field fix in both the Azure AD authentication detections. Minor spelling mistake fixes. ( #3811 )
...
* chore: user_agent field fix in both the Azure AD authentication detections. Minor spelling mistake fixes.
* beautify
* remove rename
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-12-01 16:25:33 -08:00
Michael Haag
442e815dad
npm Supply Chain Compromise & Lifecycle Hook Abuse Detection ( #3806 )
...
* extra content
* 5 more extras
* Hunt 1
* story+extras
* Create linux_shai_hulud_2_exfiltration_artifacts.yml
* Create linux_shai_hulud_workflow_file_modification.yml
* Create linux_suspicious_github_workflow_file_modification.yml
* Create windows_github_workflow_file_creation_hunt.yml
* more
* last 3
* final pass
* Bump versions to resolve merge conflicts with develop branch
* Fix deprecated status for curl/wget bash execution detections
* Add npm Supply Chain Compromise story to file_download_or_read_to_pipe_execution (replacement for deprecated curl/wget bash detections)
* Fix version numbers to match previous build requirements
* Add all required Filesystem fields to windows_suspicious_github_workflow_file_modification search
* Update detections/endpoint/windows_curl_download_to_suspicious_path.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* small fixes
* apply updates
* more updates
* Update shai_hulud_2_exfiltration_artifact_files.yml
* Fix Windows path escaping - use single backslash in YAML block scalar
---------
Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-11-25 14:56:20 -08:00
Nasreddine Bencherchali
9fc8942993
New Rules & Updates - Oct 25 ( #3726 )
...
* new rules and updates
* fix issues with ci
* rename for accurate macro
* update description and logic
* new wbadmin rule and fix pwsh dataset
* more updates for the weekend
* update network rules filters
* downgrade versions
* Update windows_file_transfer_protocol_in_non_common_process_path.yml
* add missing DS for some rules
* update nirsoft lookup and add new rules
* update more nirsoft stuff
* update snort message
* Update cisco_secure_firewall_filetype_lookup.yml
* new analytic and updates / incl. fix #3730
* Update detect_new_local_admin_account.yml
* add lnx dataset and fix wildcards
2025-10-24 14:19:48 -07:00
Michael Haag
7b9274f9fb
Scattered Lapsus$ Hunters ( #3724 )
...
* Scattered Lapsus$ Hunters
* fixes
* 👀
* bump versions
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-10-21 11:27:25 -07:00
Michael Haag
a548ed769a
Hellcat United ( #3723 )
...
* Hellcat United
* fixes
* 🍱
* 1 mas
* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Bhavin Patel
68e7778b8a
Update azure_ad_multi_source_failed_authentications_spike.yml
2025-09-29 14:45:01 -07:00
Bhavin Patel
f450563436
updateing based on issue
2025-09-18 13:54:48 -07:00
Brian Serocki
939ee285a3
Correct Azure localization issues
2025-09-03 16:07:29 -05:00
Brian Serocki
7b24f8a54f
Correct Azure localization issues
2025-09-03 13:17:03 -05:00
Bhavin Patel
b04570fe56
updating SPL to match the issue fix after testing
2025-08-26 14:14:45 -07:00
Bhavin Patel
f6fdcd098c
updating search and other meta
2025-08-26 12:55:56 -07:00
Jake Enea
e4cfd3c338
aad multiple denied mfa requests: updating version and date
2025-07-31 20:42:11 -04:00
Jake Enea
11a2f6a4ce
aad multiple denied mfa requests: add _time in 'stats count by' to limit to 10 min windows
2025-07-31 20:37:59 -04:00
0xC0FFEEEE
3ccf82c437
update risk message
2025-07-24 09:00:34 +01:00
0xC0FFEEEE
1032077679
Add rule name to risk message
2025-07-23 09:42:34 +01:00
0xC0FFEEEE
afefa1506c
use correct drilldown field
2025-07-23 09:41:21 +01:00
0xC0FFEEEE
43fa38ef77
Add threshold filter
...
Accidentally removed during testing of previous SPL update
2025-07-23 09:39:53 +01:00
0xC0FFEEEE
a278863c13
remove unneccesary json normalization
2025-07-03 09:17:50 +01:00
0xC0FFEEEE
3ba50a2d97
Add support for Set-InboxRule
2025-07-01 16:42:06 +01:00
ljstella
0f3feac263
Version bumps
2025-06-24 12:43:01 -05:00
ljstella
397107f88a
Updated docs links in detections
2025-06-24 11:27:59 -05:00
ljstella
437b5cf59c
Version bump
2025-06-17 09:14:07 -05:00
ljstella
bded2e9379
Silly casing...
2025-06-17 09:09:53 -05:00
ljstella
342b06c308
Swap detections to experimental as test data no longer matches expectations of TA
2025-06-17 09:08:59 -05:00
ljstella
ff624b020a
change to supported sourcetype
2025-06-17 09:08:10 -05:00
Nasreddine Bencherchali
4801780532
Merge branch 'develop' into updates-june
2025-06-17 11:15:26 +02:00