Eric McGinnis
|
db8c7c8509
|
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
|
2026-05-13 14:02:27 -07:00 |
|
Nasreddine Bencherchali
|
bc1b413923
|
Fix Reported Issues - April Batch (#3962)
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-03-30 14:34:11 +05:30 |
|
Nasreddine Bencherchali
|
11c909f725
|
Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920)
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-02-26 00:00:35 +05:30 |
|
Br3akp0int
|
6b9201dbc3
|
Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging (#3902)
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
|
2026-02-17 20:02:11 +01:00 |
|
Michael Haag
|
58bf9a1bc8
|
WSUSpect in Custody: CVE-2025-59287 (#3743)
* WSUSpect in Custody: CVE-2025-59287
* WSUS and Updates
* :jt_stare:
* Update windows_wsus_spawning_shell.yml
* Update w3wp_spawning_shell.yml
* deprecate rules and map analytic stories
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
|
2025-10-27 09:48:44 -07:00 |
|
Michael Haag
|
b6083e5076
|
GhostRedirectors
|
2025-09-18 13:39:40 -06:00 |
|
Michael Haag
|
ea0121c2f1
|
Scattered Spider Tags
|
2025-07-31 10:54:21 -06:00 |
|
Michael Haag
|
13b49f5456
|
Sharing is Caring: A story of CVE-2025-53770
|
2025-07-20 17:03:37 -06:00 |
|
Eric
|
d9960562b8
|
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
|
2025-05-02 14:10:46 -07:00 |
|
Patrick Bareiss
|
1c9debe9a6
|
update versions
|
2025-03-14 13:47:44 +01:00 |
|
Patrick Bareiss
|
b52bac9b19
|
output normalization endpoint
|
2025-02-14 12:40:57 +01:00 |
|
research-bot
|
a059e2db19
|
updating with rba
|
2025-01-21 16:16:40 -08:00 |
|
pyth0n1c
|
fdaa038eab
|
Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
|
2025-01-03 15:47:32 -08:00 |
|
tccontre
|
6fc84d916a
|
crypto_campaign
|
2024-12-17 11:33:34 +01:00 |
|
Lou Stella
|
88fd263606
|
Merge branch 'develop' into rba_migration
|
2024-11-22 08:36:33 -06:00 |
|
ljstella
|
189cc59547
|
endpoint: remove rba from hunting
|
2024-11-15 11:01:30 -06:00 |
|
Michael Haag
|
d75dc81630
|
vers up
|
2024-11-15 09:52:37 -07:00 |
|
ljstella
|
bc14854c55
|
endpoint: more typefixes
|
2024-11-15 10:36:13 -06:00 |
|
ljstella
|
c9186e0b7d
|
endpoint: lowercase rba types
|
2024-11-15 10:16:37 -06:00 |
|
ljstella
|
514123089d
|
endpoint detection score field rename
|
2024-11-15 09:49:53 -06:00 |
|
ljstella
|
f88eb16c6f
|
endpoint detection score fix
|
2024-11-15 09:34:59 -06:00 |
|
ljstella
|
92cc97a5a7
|
endpoint first pass
|
2024-11-14 15:44:51 -06:00 |
|
Nasreddine Bencherchali
|
99bb3994cd
|
tagging content and typo fixes
|
2024-11-14 20:01:29 +01:00 |
|
Michael Haag
|
317b01c532
|
Updates and moar
|
2024-11-13 13:51:21 -07:00 |
|
research-bot
|
7eafc7cd60
|
updating sysmon to XML
|
2024-11-01 13:40:43 -07:00 |
|
research-bot
|
d1c7e1b6e5
|
udpating sysmon source
|
2024-10-30 18:42:30 -07:00 |
|
Bhavin Patel
|
385ac7adc1
|
remove end hours
|
2024-10-23 17:52:24 -07:00 |
|
Bhavin Patel
|
e2bff20247
|
updating detections
|
2024-10-17 08:21:25 -07:00 |
|
Michael Haag
|
2057e0ab23
|
Update malicious_powershell_process___encoded_command.yml
Fixed for #2982
|
2024-07-26 10:45:25 -06:00 |
|
Patrick
|
87108a5aac
|
Improved data sources
|
2024-07-17 14:41:50 +02:00 |
|
Patrick
|
9e0d8426c1
|
improved data source field
|
2024-07-16 14:06:31 +02:00 |
|
Bhavin Patel
|
22e5ea3f83
|
Release Branch - ESCU v4.34.0
|
2024-06-26 14:41:53 +00:00 |
|
Bhavin Patel
|
6c5446cfbc
|
Release Branch - ESCU v4.32.0
|
2024-05-22 16:47:39 +00:00 |
|
Bhavin Patel
|
b0eaed8f75
|
ESCU Release v4.31.0
|
2024-05-08 16:05:40 +00:00 |
|
Gowthamaraj rajendran
|
e06cfa133d
|
Edit how_to_implement for Endpoint.Processes
|
2023-09-15 10:58:38 -07:00 |
|
tccontre
|
aad413f44c
|
volt_typhoon
|
2023-05-25 12:16:00 +02:00 |
|
tccontre
|
5311028ec7
|
Update malicious_powershell_process___encoded_command.yml
|
2023-04-14 10:42:16 +02:00 |
|
tccontre
|
52391f5615
|
Merge branch 'develop' into sandworm_data_destruction
|
2023-04-13 19:07:10 +02:00 |
|
tccontre
|
e0b697ab6e
|
sandworm_data_destruction
|
2023-04-12 12:17:43 +02:00 |
|
P4T12ICK
|
78909f6429
|
merged with develop
|
2023-03-03 12:40:16 +01:00 |
|
P4T12ICK
|
fd0c8b349f
|
updated tags
|
2023-01-09 09:33:30 +01:00 |
|
P4T12ICK
|
5ae53c9368
|
Migrated all detections to v4
|
2023-01-03 13:42:10 +01:00 |
|
Michael Haag
|
c6db7b5415
|
CISA AA22-320A
|
2022-11-16 12:10:42 -07:00 |
|
tccontre
|
c96c6d03d3
|
qakbot_1
|
2022-10-18 11:57:58 +02:00 |
|
tccontre
|
2dd87d6d33
|
dcrat-analytics
|
2022-07-26 12:02:35 +02:00 |
|
Rod Soto
|
8298acf18e
|
powershelldetectionstaghermetic
|
2022-03-31 15:29:51 -07:00 |
|
P4T12ICK
|
e6c8254ede
|
Added automaticc generation of finding report
|
2022-03-14 12:12:48 +01:00 |
|
P4T12ICK
|
6f0ee68913
|
Refactored security content
|
2022-03-09 14:43:09 +01:00 |
|
Jose Enrique Hernandez
|
d78bb53baa
|
Revert "Refactored security content"
|
2022-03-04 15:13:04 -05:00 |
|
P4T12ICK
|
5fbff3630e
|
merged with develop
|
2022-02-07 14:55:34 +01:00 |
|