22 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Teoderick Contreras 1cc0dc736c linux_auditd_daemon_update 2025-06-12 13:28:03 +02:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Teoderick Contreras 26b65f5da3 Merge branch 'auditd_sourcetype_update' of https://github.com/splunk/security_content into auditd_detection_updates 2025-02-21 10:26:50 +01:00
Teoderick Contreras 23c36c358c auditd_detection_updates 2025-02-20 14:20:12 +01:00
research-bot f909be7cce updating sourcetype, version and date 2025-02-18 14:41:27 -08:00
Nasreddine Bencherchali bd1c8364f1 CI fixes 2025-01-22 20:57:29 +01:00
Nasreddine Bencherchali 8cf6cfecf6 rba changes 2025-01-22 20:18:12 +01:00
Nasreddine Bencherchali 480e29b27b remove fields 2025-01-22 12:12:08 +01:00
Nasreddine Bencherchali a8c3540aa8 typo fixes and some logic update 2025-01-08 14:46:37 +01:00
Bhavin Patel 0bb378b19b updating drilldowns 2024-10-24 14:13:05 -07:00
Bhavin Patel 8b03f3d58f updating all detections with quotes 2024-10-24 14:08:37 -07:00
Bhavin Patel 7bc11be7dc updating drilldown_formatting 2024-10-23 18:25:39 -07:00
Bhavin Patel 385ac7adc1 remove end hours 2024-10-23 17:52:24 -07:00
Bhavin Patel cf169b3de0 adding drilldowns to all 2024-09-30 22:04:57 +05:30
research-bot e557fd760e updating message and text 2024-09-04 15:43:55 +05:30
tccontre 95559144fc linux_auditd_detection 2024-09-04 11:10:43 +02:00
tccontre b6ade7259f linux_auditd_detection 2024-09-02 14:59:47 +02:00
tccontre a94e51bb74 linux_auditd_detection 2024-08-27 10:42:47 +02:00
tccontre 0800a90171 linux_auditd_detection 2024-08-12 12:45:05 +02:00