66 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Michael Haag b6b0b47a66 Storm-0501 Ransomware Analytic Story and Tagging (#3871)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-01-22 22:32:14 +01:00
Nasreddine Bencherchali 976c62383e Update Macro Usage (#3840)
* update macro usage

* bump version

* Update detect_hosts_connecting_to_dynamic_domain_providers.yml

* more macro updates
2025-12-18 21:42:06 +05:30
Michael Haag a548ed769a Hellcat United (#3723)
* Hellcat United

* fixes

* 🍱

* 1 mas

* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
ljstella d6f03a2d24 Bumped versions 2025-09-09 08:49:59 -04:00
ljstella 8d0935f037 Update attack_data links 2025-09-09 08:35:57 -04:00
Nasreddine Bencherchali 879259dd8b map existing rclone analytic and add a dedicated nvm one 2025-07-04 02:21:13 +02:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Michael Haag 19221004d3 round 2 2025-04-18 10:22:37 -06:00
Bhavin Patel 0d831661a6 updating detections with conflicts 2025-04-02 11:41:46 -07:00
Bhavin Patel cda8da91ac updating detections version 2025-03-27 11:27:43 -07:00
Michael Haag 6b299cf58e Tagged analytics 2025-03-20 11:34:39 -06:00
Patrick Bareiss 641c590df7 Merge branch 'develop' into output_normalization_endpoint 2025-03-19 15:10:33 +01:00
Patrick Bareiss 1c9debe9a6 update versions 2025-03-14 13:47:44 +01:00
Teoderick Contreras c8087bc330 systembc 2025-03-03 14:12:55 +01:00
Patrick Bareiss b52bac9b19 output normalization endpoint 2025-02-14 12:40:57 +01:00
research-bot 76a9a02c9e updating versions 2025-02-05 10:49:03 -08:00
pyth0n1c fdaa038eab Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00
ljstella bc14854c55 endpoint: more typefixes 2024-11-15 10:36:13 -06:00
ljstella c9186e0b7d endpoint: lowercase rba types 2024-11-15 10:16:37 -06:00
ljstella 514123089d endpoint detection score field rename 2024-11-15 09:49:53 -06:00
ljstella f88eb16c6f endpoint detection score fix 2024-11-15 09:34:59 -06:00
ljstella 92cc97a5a7 endpoint first pass 2024-11-14 15:44:51 -06:00
research-bot 7eafc7cd60 updating sysmon to XML 2024-11-01 13:40:43 -07:00
research-bot d1c7e1b6e5 udpating sysmon source 2024-10-30 18:42:30 -07:00
Bhavin Patel 0bb378b19b updating drilldowns 2024-10-24 14:13:05 -07:00
Bhavin Patel 8b03f3d58f updating all detections with quotes 2024-10-24 14:08:37 -07:00
Bhavin Patel 7bc11be7dc updating drilldown_formatting 2024-10-23 18:25:39 -07:00
Bhavin Patel 385ac7adc1 remove end hours 2024-10-23 17:52:24 -07:00
Bhavin Patel cf169b3de0 adding drilldowns to all 2024-09-30 22:04:57 +05:30
ljstella 3e9684660f Endpoint detections 2024-08-15 15:36:03 -05:00
Patrick 87108a5aac Improved data sources 2024-07-17 14:41:50 +02:00
Patrick 9e0d8426c1 improved data source field 2024-07-16 14:06:31 +02:00
Bhavin Patel 22e5ea3f83 Release Branch - ESCU v4.34.0 2024-06-26 14:41:53 +00:00
Bhavin Patel 6c5446cfbc Release Branch - ESCU v4.32.0 2024-05-22 16:47:39 +00:00
Bhavin Patel fdb4417077 Merge branch 'release_v4.12.0' into Edit_How_To_Implement 2023-09-15 12:52:51 -07:00
Gowthamaraj rajendran e06cfa133d Edit how_to_implement for Endpoint.Processes 2023-09-15 10:58:38 -07:00
Bhavin Patel 093b299d8d fixed obs stuff 2023-08-21 12:28:13 -07:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
pyth0n1c 578e6bb088 Updated a very large number of detections whose references were returning HTTP Status 301 - resource moved. For example, this includes a large number of fireeye reports, which are now under mandiant, cobaltstrike info, and microsoft links. 2022-05-02 17:12:50 -07:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 68543a8dc1 merged with develop 2022-03-03 13:11:56 +01:00
truptilangalia-crest 179134e8ef test:removed cim version 2022-02-08 12:05:05 +05:30
truptilangalia-crest 08f0ff6405 test: Removed tas with mapping from detection files 2022-01-31 19:46:09 +05:30