Eric McGinnis
db8c7c8509
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
2026-05-13 14:02:27 -07:00
Bhavin Patel
ba59855b1d
updating risk drilldowns ( #4016 )
...
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Br3akp0int
2e2f6fc649
ttp_standard_init_score ( #3945 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali
11c909f725
Add YAML Formatting Job ( #3889 )
...
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920 )
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-26 00:00:35 +05:30
Michael Haag
b6083e5076
GhostRedirectors
2025-09-18 13:39:40 -06:00
Eric
d9960562b8
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
2025-05-02 14:10:46 -07:00
Patrick Bareiss
7541027f8e
Merge branch 'develop' into output_normalization_endpoint
2025-04-01 09:41:58 +02:00
Michael Haag
ec5cf468e3
The Haag Identity: Operation Seashell Blizzard 🌊 ❄️
...
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include:
Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately.
Analytics tagged with "Seashell Blizzard" include:
ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal)
Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell)
Credential access monitoring (LSASS dumps via TaskMgr and ProcDump)
Remote access software usage detections (file, process, registry)
Scheduled task abuse detections
SQL Server xp_cmdshell configuration changes
Registry hive dumping detection
Key updates:
- Added "Seashell Blizzard" tag to 20 existing detections
These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.
2025-03-24 14:18:40 -06:00
Patrick Bareiss
0f0ec93d2f
improved detections
2025-02-25 08:53:27 +01:00
pyth0n1c
45599e0b18
Clean up MITRE Tagging. When a type is defined, such as T1003, DO NOT allow a subtype such as T1003.001 to be defined. Remove the generic type T1003 and keep the subtype T1003.001. However, it is acceptable for a subtype to be defined or for a type to be defined separately. It is also okay for multiple subtypes to be defined.
2025-02-10 12:28:22 -08:00
pyth0n1c
37566022b0
Merge branch 'rba_migration' into strict_yml_from_rba
2025-01-09 12:06:46 -08:00
Lou Stella
f49899a983
Merge branch 'develop' into rba_migration
2025-01-07 09:47:21 -06:00
pyth0n1c
fdaa038eab
Finish removing extra fields, or renaming
...
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00
research-bot
73f13e43f3
version
2024-12-23 10:43:28 -08:00
research-bot
cf8036845f
updating search
2024-12-23 10:40:21 -08:00
ljstella
6357f1830f
Merge branch 'develop' into rba_migration
2024-12-10 11:50:25 -06:00
tccontre
1761f3dbe4
add_more_win_tag
2024-11-28 09:42:44 +01:00
ljstella
eb9dfba620
endpoint: threat object type cleanup
2024-11-15 14:51:09 -06:00
ljstella
bc14854c55
endpoint: more typefixes
2024-11-15 10:36:13 -06:00
ljstella
c9186e0b7d
endpoint: lowercase rba types
2024-11-15 10:16:37 -06:00
ljstella
514123089d
endpoint detection score field rename
2024-11-15 09:49:53 -06:00
ljstella
f88eb16c6f
endpoint detection score fix
2024-11-15 09:34:59 -06:00
ljstella
92cc97a5a7
endpoint first pass
2024-11-14 15:44:51 -06:00
research-bot
7eafc7cd60
updating sysmon to XML
2024-11-01 13:40:43 -07:00
research-bot
d1c7e1b6e5
udpating sysmon source
2024-10-30 18:42:30 -07:00
Bhavin Patel
0bb378b19b
updating drilldowns
2024-10-24 14:13:05 -07:00
Bhavin Patel
8b03f3d58f
updating all detections with quotes
2024-10-24 14:08:37 -07:00
Bhavin Patel
7bc11be7dc
updating drilldown_formatting
2024-10-23 18:25:39 -07:00
Bhavin Patel
385ac7adc1
remove end hours
2024-10-23 17:52:24 -07:00
Bhavin Patel
cf169b3de0
adding drilldowns to all
2024-09-30 22:04:57 +05:30
Patrick
9e0d8426c1
improved data source field
2024-07-16 14:06:31 +02:00
Bhavin Patel
22e5ea3f83
Release Branch - ESCU v4.34.0
2024-06-26 14:41:53 +00:00
Bhavin Patel
6c5446cfbc
Release Branch - ESCU v4.32.0
2024-05-22 16:47:39 +00:00
Bhavin Patel
71fad8cc55
4.17.0 release branch
2023-12-06 18:40:13 +00:00
Bhavin Patel
093b299d8d
fixed obs stuff
2023-08-21 12:28:13 -07:00
tccontre
f78e4404d2
blackbyte_campaign
2023-07-10 12:55:29 +02:00
Michael Haag
c541aacf10
T1133 Tags + description updates
2023-06-01 13:44:32 -06:00
P4T12ICK
78909f6429
merged with develop
2023-03-03 12:40:16 +01:00
P4T12ICK
fd0c8b349f
updated tags
2023-01-09 09:33:30 +01:00
P4T12ICK
5ae53c9368
Migrated all detections to v4
2023-01-03 13:42:10 +01:00
Michael Haag
29ab52ac0b
ProxyNotShell - A Tale of CVE-2022-41040 and CVE-2022-41082
2022-09-30 05:26:16 -06:00
Michael Haag
2fa429127b
CISA AA22-257A tag
2022-09-15 10:07:38 -06:00
P4T12ICK
6f0ee68913
Refactored security content
2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez
d78bb53baa
Revert "Refactored security content"
2022-03-04 15:13:04 -05:00
P4T12ICK
68543a8dc1
merged with develop
2022-03-03 13:11:56 +01:00
truptilangalia-crest
179134e8ef
test:removed cim version
2022-02-08 12:05:05 +05:30
truptilangalia-crest
08f0ff6405
test: Removed tas with mapping from detection files
2022-01-31 19:46:09 +05:30
P4T12ICK
4fd8604b9a
removed SAAWS and automated_detection_testing flag
2022-01-27 09:50:45 +01:00
Detection Testing Service
6fd7a4e812
test: updated supported_tas to recommended_tas
2022-01-19 17:43:41 +05:30
P4T12ICK
338f22f7e2
fixed more detections
2022-01-18 13:13:30 +01:00