Eric McGinnis
db8c7c8509
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
2026-05-13 14:02:27 -07:00
Bhavin Patel
ba59855b1d
updating risk drilldowns ( #4016 )
...
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Br3akp0int
3da4f7958a
anomaly_standard_init_score ( #3946 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-10 14:19:08 +05:30
Nasreddine Bencherchali
11c909f725
Add YAML Formatting Job ( #3889 )
...
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920 )
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-26 00:00:35 +05:30
Nasreddine Bencherchali
76f629eb2f
Update Analytics Performance ( #3866 )
...
* Update common_ransomware_notes.yml
* Update detect_rare_executables.yml
* update samsam ext
* update where clause to include null checks
* appinspect fixes
* reduce version
* fix where issue
* Update ransomware_notes_lookup.csv
* more perf enhancements
* Update windows_dotnet_binary_in_non_standard_path.yml
* fix ci issue and enhance description
* Update common_ransomware_extensions.yml
* Update common_ransomware_extensions.yml
* remove unknown and dash values
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 12:36:31 +00:00
Michael Haag
7b9274f9fb
Scattered Lapsus$ Hunters ( #3724 )
...
* Scattered Lapsus$ Hunters
* fixes
* 👀
* bump versions
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-10-21 11:27:25 -07:00
Michael Haag
b6083e5076
GhostRedirectors
2025-09-18 13:39:40 -06:00
Michael Haag
7883693801
Merge branch 'develop' into scatteringspider
2025-08-01 10:21:00 -06:00
Michael Haag
ea0121c2f1
Scattered Spider Tags
2025-07-31 10:54:21 -06:00
Teoderick Contreras
96786372a3
interlock_ransomware
2025-07-28 11:58:45 +02:00
Eric
d9960562b8
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
2025-05-02 14:10:46 -07:00
Michael Haag
19221004d3
round 2
2025-04-18 10:22:37 -06:00
Bhavin Patel
0d831661a6
updating detections with conflicts
2025-04-02 11:41:46 -07:00
Michael Haag
7666d3793f
Merge branch 'develop' into cactus
2025-04-01 14:56:49 -06:00
Patrick Bareiss
7541027f8e
Merge branch 'develop' into output_normalization_endpoint
2025-04-01 09:41:58 +02:00
Michael Haag
ec5cf468e3
The Haag Identity: Operation Seashell Blizzard 🌊 ❄️
...
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include:
Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately.
Analytics tagged with "Seashell Blizzard" include:
ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal)
Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell)
Credential access monitoring (LSASS dumps via TaskMgr and ProcDump)
Remote access software usage detections (file, process, registry)
Scheduled task abuse detections
SQL Server xp_cmdshell configuration changes
Registry hive dumping detection
Key updates:
- Added "Seashell Blizzard" tag to 20 existing detections
These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.
2025-03-24 14:18:40 -06:00
Michael Haag
6b299cf58e
Tagged analytics
2025-03-20 11:34:39 -06:00
Patrick Bareiss
1c9debe9a6
update versions
2025-03-14 13:47:44 +01:00
Patrick Bareiss
e044e874ba
improvements
2025-02-18 08:55:49 +01:00
Steven Dick
0885f557bb
Update detect_remote_access_software_usage_file.yml
2025-02-06 08:03:56 -05:00
Steven Dick
dea4448a4f
Update detect_remote_access_software_usage_file.yml
2025-02-06 07:58:47 -05:00
pyth0n1c
fdaa038eab
Finish removing extra fields, or renaming
...
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00
ljstella
8f18a20d94
endpoint: more typefixes
2024-11-15 10:48:49 -06:00
ljstella
bc14854c55
endpoint: more typefixes
2024-11-15 10:36:13 -06:00
ljstella
c9186e0b7d
endpoint: lowercase rba types
2024-11-15 10:16:37 -06:00
ljstella
514123089d
endpoint detection score field rename
2024-11-15 09:49:53 -06:00
ljstella
f88eb16c6f
endpoint detection score fix
2024-11-15 09:34:59 -06:00
ljstella
92cc97a5a7
endpoint first pass
2024-11-14 15:44:51 -06:00
Bhavin Patel
0bb378b19b
updating drilldowns
2024-10-24 14:13:05 -07:00
Bhavin Patel
8b03f3d58f
updating all detections with quotes
2024-10-24 14:08:37 -07:00
Bhavin Patel
7bc11be7dc
updating drilldown_formatting
2024-10-23 18:25:39 -07:00
Bhavin Patel
385ac7adc1
remove end hours
2024-10-23 17:52:24 -07:00
Bhavin Patel
cf169b3de0
adding drilldowns to all
2024-09-30 22:04:57 +05:30
Michael Haag
dafa859f55
The Haag Element: Breaking Down AA24-241A
2024-09-03 13:03:21 -06:00
ljstella
a980709e4b
Modified macro name for clarity, updated how to implements with details
2024-07-26 14:11:24 -05:00
Lou Stella
6f18511791
Merge branch 'develop' into nterl0k-rmm_must_die_update_1
2024-07-26 12:09:47 -05:00
ljstella
469cff4ab4
Missed one.
2024-07-25 11:16:08 -05:00
Michael Haag
c35925b3a9
Haag's Hunt for Gozi Gremlins
2024-07-24 14:36:47 -06:00
Steven Dick
dbe3816d82
Update detect_remote_access_software_usage_file.yml
2024-07-09 08:40:01 -04:00
Bhavin Patel
22e5ea3f83
Release Branch - ESCU v4.34.0
2024-06-26 14:41:53 +00:00
Bhavin Patel
6c5446cfbc
Release Branch - ESCU v4.32.0
2024-05-22 16:47:39 +00:00
Bhavin Patel
046acb8871
ESCU v4.26.0 Release branch
2024-03-06 19:30:20 +00:00