Eric McGinnis
|
db8c7c8509
|
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
|
2026-05-13 14:02:27 -07:00 |
|
Nasreddine Bencherchali
|
11c909f725
|
Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920)
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-02-26 00:00:35 +05:30 |
|
ljstella
|
0f3feac263
|
Version bumps
|
2025-06-24 12:43:01 -05:00 |
|
ljstella
|
397107f88a
|
Updated docs links in detections
|
2025-06-24 11:27:59 -05:00 |
|
Eric
|
d9960562b8
|
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
|
2025-05-02 14:10:46 -07:00 |
|
Patrick Bareiss
|
1c9debe9a6
|
update versions
|
2025-03-14 13:47:44 +01:00 |
|
Patrick Bareiss
|
e044e874ba
|
improvements
|
2025-02-18 08:55:49 +01:00 |
|
pyth0n1c
|
fdaa038eab
|
Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
|
2025-01-03 15:47:32 -08:00 |
|
ljstella
|
189cc59547
|
endpoint: remove rba from hunting
|
2024-11-15 11:01:30 -06:00 |
|
ljstella
|
bc14854c55
|
endpoint: more typefixes
|
2024-11-15 10:36:13 -06:00 |
|
ljstella
|
c9186e0b7d
|
endpoint: lowercase rba types
|
2024-11-15 10:16:37 -06:00 |
|
ljstella
|
514123089d
|
endpoint detection score field rename
|
2024-11-15 09:49:53 -06:00 |
|
ljstella
|
f88eb16c6f
|
endpoint detection score fix
|
2024-11-15 09:34:59 -06:00 |
|
ljstella
|
92cc97a5a7
|
endpoint first pass
|
2024-11-14 15:44:51 -06:00 |
|
research-bot
|
f6a5e162e7
|
xml to Xml
|
2024-11-01 13:39:20 -07:00 |
|
Bhavin Patel
|
385ac7adc1
|
remove end hours
|
2024-10-23 17:52:24 -07:00 |
|
Bhavin Patel
|
e2bff20247
|
updating detections
|
2024-10-17 08:21:25 -07:00 |
|
Bhavin Patel
|
22e5ea3f83
|
Release Branch - ESCU v4.34.0
|
2024-06-26 14:41:53 +00:00 |
|
Bhavin Patel
|
6c5446cfbc
|
Release Branch - ESCU v4.32.0
|
2024-05-22 16:47:39 +00:00 |
|
Bhavin Patel
|
7cead8e956
|
second set of fixes
|
2023-09-22 15:47:54 -07:00 |
|
P4T12ICK
|
78909f6429
|
merged with develop
|
2023-03-03 12:40:16 +01:00 |
|
P4T12ICK
|
fd0c8b349f
|
updated tags
|
2023-01-09 09:33:30 +01:00 |
|
P4T12ICK
|
5ae53c9368
|
Migrated all detections to v4
|
2023-01-03 13:42:10 +01:00 |
|
pyth0n1c
|
38d32c3341
|
Branch was auto-updated.
|
2022-05-16 13:06:58 -04:00 |
|
pyth0n1c
|
578e6bb088
|
Updated a very large number of detections whose references were returning HTTP Status 301 - resource moved. For example, this includes a large number of fireeye reports, which are now under mandiant, cobaltstrike info, and microsoft links.
|
2022-05-02 17:12:50 -07:00 |
|
tccontre
|
f69fce02dc
|
pwh_xml
|
2022-03-23 10:59:43 +01:00 |
|
P4T12ICK
|
6f0ee68913
|
Refactored security content
|
2022-03-09 14:43:09 +01:00 |
|
Jose Enrique Hernandez
|
d78bb53baa
|
Revert "Refactored security content"
|
2022-03-04 15:13:04 -05:00 |
|
P4T12ICK
|
5fbff3630e
|
merged with develop
|
2022-02-07 14:55:34 +01:00 |
|
P4T12ICK
|
4fd8604b9a
|
removed SAAWS and automated_detection_testing flag
|
2022-01-27 09:50:45 +01:00 |
|
mvelazco
|
2cba1d3408
|
fixing wrong data models
Active Directory Discovery analytic story
|
2022-01-18 12:58:06 -05:00 |
|
P4T12ICK
|
84092434a2
|
fixed more detections
|
2022-01-18 12:53:54 +01:00 |
|
research bot
|
961a81d4a5
|
updating docs and package bits [ci skip]
|
2021-09-27 18:54:15 +00:00 |
|
mvelazco
|
47e3c2bf9e
|
fixing message field
|
2021-09-14 11:54:58 -04:00 |
|
mvelazco
|
2e6bb4886b
|
Merge branch 'AD_Discovery_TR-789_9' of github.com:splunk/security_content into AD_Discovery_TR-789_9
|
2021-09-14 10:01:54 -04:00 |
|
mvelazco
|
379f8e82c1
|
adding required_fields
|
2021-09-14 10:01:52 -04:00 |
|
root
|
31a0177b31
|
Added detection testing service results inGetCurrent User with PowerShell Script Block
|
2021-09-14 13:35:28 +00:00 |
|
mvelazco
|
687fb1745c
|
adding 4 detections
|
2021-09-13 17:22:30 -04:00 |
|