72 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Michael Haag b6083e5076 GhostRedirectors 2025-09-18 13:39:40 -06:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Patrick Bareiss 7541027f8e Merge branch 'develop' into output_normalization_endpoint 2025-04-01 09:41:58 +02:00
Michael Haag ec5cf468e3 The Haag Identity: Operation Seashell Blizzard 🌊❄️
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include:
Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately.
Analytics tagged with "Seashell Blizzard" include:
ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal)
Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell)
Credential access monitoring (LSASS dumps via TaskMgr and ProcDump)
Remote access software usage detections (file, process, registry)
Scheduled task abuse detections
SQL Server xp_cmdshell configuration changes
Registry hive dumping detection
Key updates:
- Added "Seashell Blizzard" tag to 20 existing detections

These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.
2025-03-24 14:18:40 -06:00
Patrick Bareiss 0f0ec93d2f improved detections 2025-02-25 08:53:27 +01:00
pyth0n1c 45599e0b18 Clean up MITRE Tagging. When a type is defined, such as T1003, DO NOT allow a subtype such as T1003.001 to be defined. Remove the generic type T1003 and keep the subtype T1003.001. However, it is acceptable for a subtype to be defined or for a type to be defined separately. It is also okay for multiple subtypes to be defined. 2025-02-10 12:28:22 -08:00
pyth0n1c 37566022b0 Merge branch 'rba_migration' into strict_yml_from_rba 2025-01-09 12:06:46 -08:00
Lou Stella f49899a983 Merge branch 'develop' into rba_migration 2025-01-07 09:47:21 -06:00
pyth0n1c fdaa038eab Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00
research-bot 73f13e43f3 version 2024-12-23 10:43:28 -08:00
research-bot cf8036845f updating search 2024-12-23 10:40:21 -08:00
ljstella 6357f1830f Merge branch 'develop' into rba_migration 2024-12-10 11:50:25 -06:00
tccontre 1761f3dbe4 add_more_win_tag 2024-11-28 09:42:44 +01:00
ljstella eb9dfba620 endpoint: threat object type cleanup 2024-11-15 14:51:09 -06:00
ljstella bc14854c55 endpoint: more typefixes 2024-11-15 10:36:13 -06:00
ljstella c9186e0b7d endpoint: lowercase rba types 2024-11-15 10:16:37 -06:00
ljstella 514123089d endpoint detection score field rename 2024-11-15 09:49:53 -06:00
ljstella f88eb16c6f endpoint detection score fix 2024-11-15 09:34:59 -06:00
ljstella 92cc97a5a7 endpoint first pass 2024-11-14 15:44:51 -06:00
research-bot 7eafc7cd60 updating sysmon to XML 2024-11-01 13:40:43 -07:00
research-bot d1c7e1b6e5 udpating sysmon source 2024-10-30 18:42:30 -07:00
Bhavin Patel 0bb378b19b updating drilldowns 2024-10-24 14:13:05 -07:00
Bhavin Patel 8b03f3d58f updating all detections with quotes 2024-10-24 14:08:37 -07:00
Bhavin Patel 7bc11be7dc updating drilldown_formatting 2024-10-23 18:25:39 -07:00
Bhavin Patel 385ac7adc1 remove end hours 2024-10-23 17:52:24 -07:00
Bhavin Patel cf169b3de0 adding drilldowns to all 2024-09-30 22:04:57 +05:30
Patrick 9e0d8426c1 improved data source field 2024-07-16 14:06:31 +02:00
Bhavin Patel 22e5ea3f83 Release Branch - ESCU v4.34.0 2024-06-26 14:41:53 +00:00
Bhavin Patel 6c5446cfbc Release Branch - ESCU v4.32.0 2024-05-22 16:47:39 +00:00
Bhavin Patel 71fad8cc55 4.17.0 release branch 2023-12-06 18:40:13 +00:00
Bhavin Patel 093b299d8d fixed obs stuff 2023-08-21 12:28:13 -07:00
tccontre f78e4404d2 blackbyte_campaign 2023-07-10 12:55:29 +02:00
Michael Haag c541aacf10 T1133 Tags + description updates 2023-06-01 13:44:32 -06:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
Michael Haag 29ab52ac0b ProxyNotShell - A Tale of CVE-2022-41040 and CVE-2022-41082 2022-09-30 05:26:16 -06:00
Michael Haag 2fa429127b CISA AA22-257A tag 2022-09-15 10:07:38 -06:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 68543a8dc1 merged with develop 2022-03-03 13:11:56 +01:00
truptilangalia-crest 179134e8ef test:removed cim version 2022-02-08 12:05:05 +05:30
truptilangalia-crest 08f0ff6405 test: Removed tas with mapping from detection files 2022-01-31 19:46:09 +05:30
P4T12ICK 4fd8604b9a removed SAAWS and automated_detection_testing flag 2022-01-27 09:50:45 +01:00
Detection Testing Service 6fd7a4e812 test: updated supported_tas to recommended_tas 2022-01-19 17:43:41 +05:30
P4T12ICK 338f22f7e2 fixed more detections 2022-01-18 13:13:30 +01:00