45 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Patrick Bareiss 3122cbbc8b output improvements 2025-03-18 12:56:30 +01:00
Patrick Bareiss 0a4e58f9cf version bump 2025-02-18 10:06:29 +01:00
Patrick Bareiss 969ba0fb65 all test passed 2025-02-04 11:47:09 +01:00
Patrick Bareiss ed8e3bf842 aws detections 2025-02-03 20:26:34 +01:00
pyth0n1c d1442c2805 remove update_timestamps, confidence, impact,
related_fields, and risk_score from detections
2025-01-03 15:25:52 -08:00
ljstella bf5d4c12c2 cloud: ip address typefix 2024-11-15 10:25:34 -06:00
ljstella a27edb3162 cloud: lowercase rba types 2024-11-15 10:17:19 -06:00
ljstella 77e5b9bca6 cloud detection score field rename 2024-11-15 09:50:35 -06:00
ljstella 3b43f75d02 cloud detection score fix 2024-11-15 09:39:46 -06:00
ljstella 318311f1c7 cloud detections initial translation 2024-11-14 16:45:49 -06:00
Bhavin Patel 0bb378b19b updating drilldowns 2024-10-24 14:13:05 -07:00
Bhavin Patel 8b03f3d58f updating all detections with quotes 2024-10-24 14:08:37 -07:00
Bhavin Patel 7bc11be7dc updating drilldown_formatting 2024-10-23 18:25:39 -07:00
Bhavin Patel 385ac7adc1 remove end hours 2024-10-23 17:52:24 -07:00
Bhavin Patel cf169b3de0 adding drilldowns to all 2024-09-30 22:04:57 +05:30
Bhavin Patel 7539e88c4c Release Branch v4.33.0 2024-06-05 21:05:06 +00:00
Bhavin Patel 6c5446cfbc Release Branch - ESCU v4.32.0 2024-05-22 16:47:39 +00:00
Bhavin Patel 9332e6a24c o365_obs_fix 2023-09-22 15:01:21 -07:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 4fd8604b9a removed SAAWS and automated_detection_testing flag 2022-01-27 09:50:45 +01:00
P4T12ICK 13f072766b change custom command 2021-09-09 09:57:47 +02:00
P4T12ICK 8509ecb3f9 support for devsecops pacckage 2021-08-26 14:59:59 +02:00
P4T12ICK 5e6e987fb7 resolved merge conflicts 2021-07-21 09:22:09 +02:00
research bot 3740535cca updating docs and package bits [ci skip] 2021-07-20 17:49:09 +00:00
github-actions[bot] 5e909eea9b Branch was auto-updated. 2021-07-20 15:56:32 +00:00
P4T12ICK 65a92a64e1 add analytic types to detections 2021-07-19 16:49:33 +02:00
Bhavin Patel 3977a4cbd2 Merge branch 'develop' into cloud_detection_rba_yml 2021-07-12 17:23:24 -05:00
research bot 9987d171cc updating docs and package bits [ci skip] 2021-07-02 16:06:07 +00:00
github-actions[bot] 51ce55801d Branch was auto-updated. 2021-07-02 15:06:54 +00:00
patel-bhavin 6bb811e491 detections 2021-07-01 20:40:44 -05:00
patel-bhavin 8a77bf1b9a updating next 5 2021-07-01 15:10:32 -05:00
patel-bhavin 42d2afeae8 adding keys to all cloud detections with a 2021-06-29 16:58:47 -05:00
divious1 f262360d0a updated CloudTrails to AWS CloudTrails 2021-06-25 14:50:50 -04:00
research bot a40dc12832 updating docs and package bits [ci skip] 2021-04-15 19:40:20 +00:00
root 884fb57647 Added detection testing service results inAWS Excessive Security Scanning 2021-04-14 11:25:51 +00:00
P4T12ICK 1ab072c735 New AWS detection 2021-04-13 16:29:09 +02:00