45 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
ljstella 0f3feac263 Version bumps 2025-06-24 12:43:01 -05:00
ljstella 397107f88a Updated docs links in detections 2025-06-24 11:27:59 -05:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Patrick Bareiss 1c9debe9a6 update versions 2025-03-14 13:47:44 +01:00
Patrick Bareiss 857cb0e5a3 output normalization 2025-02-21 09:14:44 +01:00
Patrick Bareiss e044e874ba improvements 2025-02-18 08:55:49 +01:00
pyth0n1c fdaa038eab Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00
ljstella bc14854c55 endpoint: more typefixes 2024-11-15 10:36:13 -06:00
ljstella c9186e0b7d endpoint: lowercase rba types 2024-11-15 10:16:37 -06:00
ljstella 514123089d endpoint detection score field rename 2024-11-15 09:49:53 -06:00
ljstella f88eb16c6f endpoint detection score fix 2024-11-15 09:34:59 -06:00
ljstella 92cc97a5a7 endpoint first pass 2024-11-14 15:44:51 -06:00
research-bot f6a5e162e7 xml to Xml 2024-11-01 13:39:20 -07:00
Bhavin Patel 0bb378b19b updating drilldowns 2024-10-24 14:13:05 -07:00
Bhavin Patel 8b03f3d58f updating all detections with quotes 2024-10-24 14:08:37 -07:00
Bhavin Patel 7bc11be7dc updating drilldown_formatting 2024-10-23 18:25:39 -07:00
Bhavin Patel 385ac7adc1 remove end hours 2024-10-23 17:52:24 -07:00
Bhavin Patel cf169b3de0 adding drilldowns to all 2024-09-30 22:04:57 +05:30
Bhavin Patel 22e5ea3f83 Release Branch - ESCU v4.34.0 2024-06-26 14:41:53 +00:00
Bhavin Patel 6c5446cfbc Release Branch - ESCU v4.32.0 2024-05-22 16:47:39 +00:00
Bhavin Patel b0eaed8f75 ESCU Release v4.31.0 2024-05-08 16:05:40 +00:00
Bhavin Patel 775d38c96f fix another 30 yamls 2023-08-21 13:13:21 -07:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
pyth0n1c 4a8c5d9a39 Branch was auto-updated. 2022-06-29 12:59:25 -07:00
mhaag-spl 2920c25c93 fixes 2022-06-29 11:45:21 -06:00
pyth0n1c ee8c0b9bb6 Fixed the remaining broken or outdated references. The remaining references that fail validation cannot be easily validated by requests, due to website requirements, or sometimes return errors or take a long time to load. Becuase they usually work, we will leave them as-is. 2022-05-03 16:17:41 -07:00
mhaag-spl 86ef111278 domaintrust 2022-05-02 13:29:09 -06:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 4fd8604b9a removed SAAWS and automated_detection_testing flag 2022-01-27 09:50:45 +01:00
P4T12ICK 84092434a2 fixed more detections 2022-01-18 12:53:54 +01:00
research bot 961a81d4a5 updating docs and package bits [ci skip] 2021-09-27 18:54:15 +00:00
root 6664cbfc24 Added detection testing service results inGet-DomainTrust with PowerShell Script Block 2021-09-08 02:04:03 +00:00
mhaag-spl f6897a31e6 Update get_domaintrust_with_powershell_script_block.yml 2021-09-07 18:13:53 -06:00
mhaag-spl d80cee2e72 Update get_domaintrust_with_powershell_script_block.yml 2021-09-07 18:12:08 -06:00
mhaag-spl 3dd979609d Update get_domaintrust_with_powershell_script_block.yml 2021-09-07 16:16:32 -06:00
mhaag-spl 53827aa5ca Update get_domaintrust_with_powershell_script_block.yml 2021-09-07 15:52:08 -06:00
mhaag-spl e7da16d133 fixes 2021-09-07 15:30:42 -06:00
mhaag-spl 5a782c6746 AD_Discovery_TR-789_3 2021-09-02 09:38:51 -06:00