Eric McGinnis
|
db8c7c8509
|
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
|
2026-05-13 14:02:27 -07:00 |
|
Nasreddine Bencherchali
|
11c909f725
|
Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920)
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-02-26 00:00:35 +05:30 |
|
Michael Haag
|
b6b0b47a66
|
Storm-0501 Ransomware Analytic Story and Tagging (#3871)
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
|
2026-01-22 22:32:14 +01:00 |
|
Br3akp0int
|
73e69c0b84
|
stealc (#3833)
* stealc
* stealc
* stealc
* updating versions
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
|
2026-01-22 18:51:16 +05:30 |
|
Nasreddine Bencherchali
|
76f629eb2f
|
Update Analytics Performance (#3866)
* Update common_ransomware_notes.yml
* Update detect_rare_executables.yml
* update samsam ext
* update where clause to include null checks
* appinspect fixes
* reduce version
* fix where issue
* Update ransomware_notes_lookup.csv
* more perf enhancements
* Update windows_dotnet_binary_in_non_standard_path.yml
* fix ci issue and enhance description
* Update common_ransomware_extensions.yml
* Update common_ransomware_extensions.yml
* remove unknown and dash values
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-01-22 12:36:31 +00:00 |
|
Nasreddine Bencherchali
|
976c62383e
|
Update Macro Usage (#3840)
* update macro usage
* bump version
* Update detect_hosts_connecting_to_dynamic_domain_providers.yml
* more macro updates
|
2025-12-18 21:42:06 +05:30 |
|
Michael Haag
|
a548ed769a
|
Hellcat United (#3723)
* Hellcat United
* fixes
* 🍱
* 1 mas
* Update powershell_4104_hunting.yml
|
2025-10-16 16:53:02 -07:00 |
|
Teoderick Contreras
|
905a1041d2
|
interlock_ransomware
|
2025-07-29 12:31:56 +02:00 |
|
Eric
|
d9960562b8
|
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
|
2025-05-02 14:10:46 -07:00 |
|
Bhavin Patel
|
9493465161
|
adding new required fields to the new detections and fixing conflicts
|
2025-04-02 11:03:34 -07:00 |
|
Teoderick Contreras
|
b31f246793
|
medusa_ransomware
|
2025-04-01 12:54:03 +02:00 |
|
Teoderick Contreras
|
10710c8675
|
medusa_ransomware
|
2025-04-01 10:17:06 +02:00 |
|
Bhavin Patel
|
96bd1501b6
|
update inspect failures
|
2025-03-27 10:54:24 -07:00 |
|
Patrick Bareiss
|
641c590df7
|
Merge branch 'develop' into output_normalization_endpoint
|
2025-03-19 15:10:33 +01:00 |
|
Br3akp0int
|
4cf39dc734
|
Merge branch 'develop' into medusa_ransomware
|
2025-03-19 10:20:24 +01:00 |
|
Patrick Bareiss
|
1c9debe9a6
|
update versions
|
2025-03-14 13:47:44 +01:00 |
|
Teoderick Contreras
|
456625c7c4
|
medusa_ransomware
|
2025-03-14 11:29:56 +01:00 |
|
Teoderick Contreras
|
c8087bc330
|
systembc
|
2025-03-03 14:12:55 +01:00 |
|
Patrick Bareiss
|
e044e874ba
|
improvements
|
2025-02-18 08:55:49 +01:00 |
|
pyth0n1c
|
fdaa038eab
|
Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
|
2025-01-03 15:47:32 -08:00 |
|
ljstella
|
189cc59547
|
endpoint: remove rba from hunting
|
2024-11-15 11:01:30 -06:00 |
|
ljstella
|
bc14854c55
|
endpoint: more typefixes
|
2024-11-15 10:36:13 -06:00 |
|
ljstella
|
c9186e0b7d
|
endpoint: lowercase rba types
|
2024-11-15 10:16:37 -06:00 |
|
ljstella
|
514123089d
|
endpoint detection score field rename
|
2024-11-15 09:49:53 -06:00 |
|
ljstella
|
f88eb16c6f
|
endpoint detection score fix
|
2024-11-15 09:34:59 -06:00 |
|
ljstella
|
92cc97a5a7
|
endpoint first pass
|
2024-11-14 15:44:51 -06:00 |
|
research-bot
|
7eafc7cd60
|
updating sysmon to XML
|
2024-11-01 13:40:43 -07:00 |
|
research-bot
|
d1c7e1b6e5
|
udpating sysmon source
|
2024-10-30 18:42:30 -07:00 |
|
Bhavin Patel
|
385ac7adc1
|
remove end hours
|
2024-10-23 17:52:24 -07:00 |
|
Bhavin Patel
|
e2bff20247
|
updating detections
|
2024-10-17 08:21:25 -07:00 |
|
Bhavin Patel
|
7539e88c4c
|
Release Branch v4.33.0
|
2024-06-05 21:05:06 +00:00 |
|
Bhavin Patel
|
6c5446cfbc
|
Release Branch - ESCU v4.32.0
|
2024-05-22 16:47:39 +00:00 |
|
Eric McGinnis
|
06a8a487ac
|
Release v4.18.0
|
2023-12-20 16:18:23 +00:00 |
|
P4T12ICK
|
78909f6429
|
merged with develop
|
2023-03-03 12:40:16 +01:00 |
|
P4T12ICK
|
ffa1210a00
|
merged with develop
|
2023-02-02 09:15:59 +01:00 |
|
tccontre
|
bf8f2339b8
|
lockbit-chaos-ransomware
|
2023-01-17 15:37:37 +01:00 |
|
tccontre
|
5955920298
|
lockbit-chaos-ransomware
|
2023-01-16 10:10:28 +01:00 |
|
P4T12ICK
|
fd0c8b349f
|
updated tags
|
2023-01-09 09:33:30 +01:00 |
|
P4T12ICK
|
5ae53c9368
|
Migrated all detections to v4
|
2023-01-03 13:42:10 +01:00 |
|
P4T12ICK
|
6f0ee68913
|
Refactored security content
|
2022-03-09 14:43:09 +01:00 |
|
Jose Enrique Hernandez
|
d78bb53baa
|
Revert "Refactored security content"
|
2022-03-04 15:13:04 -05:00 |
|
P4T12ICK
|
4fd8604b9a
|
removed SAAWS and automated_detection_testing flag
|
2022-01-27 09:50:45 +01:00 |
|
P4T12ICK
|
5e6e987fb7
|
resolved merge conflicts
|
2021-07-21 09:22:09 +02:00 |
|
research bot
|
44ea56053d
|
updating docs and package bits [ci skip]
|
2021-07-20 21:12:30 +00:00 |
|
P4T12ICK
|
65a92a64e1
|
add analytic types to detections
|
2021-07-19 16:49:33 +02:00 |
|
mhaag-spl
|
72d6020209
|
RISKY FRISKY
|
2021-07-13 13:47:54 -06:00 |
|
Rod Soto
|
6f49f38cd5
|
updatedtags
|
2021-03-17 10:06:36 -04:00 |
|
P4T12ICK
|
7c134dbb5d
|
WIP
|
2021-03-10 14:44:44 +01:00 |
|
divious1
|
7615d5ec81
|
fixing merge conflicts
|
2021-02-12 12:27:00 -05:00 |
|
divious1
|
b58843ca9f
|
added datamodels as an array
|
2021-02-10 22:35:58 -05:00 |
|