74 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Nasreddine Bencherchali bc1b413923 Fix Reported Issues - April Batch (#3962)
* Fix #3961

* Fix #3909

* Fix output fields

* Remove duplicate process_name entry

* Update outbound_network_connection_from_java_using_default_ports.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Fix #3969

* update palo alto TA and beautify analytics

* Update vmware_aria_operations_exploit_attempt.yml

* fix source

* enhance metadata and fp info

* beautify spl for ease of reading

* add some missing attack techniques

* remove unnecessary usage of regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* small fix

* Refine description and improve regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update windows_event_log_security_4756.yml

* description update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Br3akp0int 6b9201dbc3 Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging (#3902)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:02:11 +01:00
Michael Haag 58bf9a1bc8 WSUSpect in Custody: CVE-2025-59287 (#3743)
* WSUSpect in Custody: CVE-2025-59287

* WSUS and Updates

* :jt_stare:

* Update windows_wsus_spawning_shell.yml

* Update w3wp_spawning_shell.yml

* deprecate rules and map analytic stories

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-10-27 09:48:44 -07:00
Michael Haag b6083e5076 GhostRedirectors 2025-09-18 13:39:40 -06:00
Michael Haag ea0121c2f1 Scattered Spider Tags 2025-07-31 10:54:21 -06:00
Michael Haag 13b49f5456 Sharing is Caring: A story of CVE-2025-53770 2025-07-20 17:03:37 -06:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Patrick Bareiss 1c9debe9a6 update versions 2025-03-14 13:47:44 +01:00
Patrick Bareiss b52bac9b19 output normalization endpoint 2025-02-14 12:40:57 +01:00
research-bot a059e2db19 updating with rba 2025-01-21 16:16:40 -08:00
pyth0n1c fdaa038eab Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00
tccontre 6fc84d916a crypto_campaign 2024-12-17 11:33:34 +01:00
Lou Stella 88fd263606 Merge branch 'develop' into rba_migration 2024-11-22 08:36:33 -06:00
ljstella 189cc59547 endpoint: remove rba from hunting 2024-11-15 11:01:30 -06:00
Michael Haag d75dc81630 vers up 2024-11-15 09:52:37 -07:00
ljstella bc14854c55 endpoint: more typefixes 2024-11-15 10:36:13 -06:00
ljstella c9186e0b7d endpoint: lowercase rba types 2024-11-15 10:16:37 -06:00
ljstella 514123089d endpoint detection score field rename 2024-11-15 09:49:53 -06:00
ljstella f88eb16c6f endpoint detection score fix 2024-11-15 09:34:59 -06:00
ljstella 92cc97a5a7 endpoint first pass 2024-11-14 15:44:51 -06:00
Nasreddine Bencherchali 99bb3994cd tagging content and typo fixes 2024-11-14 20:01:29 +01:00
Michael Haag 317b01c532 Updates and moar 2024-11-13 13:51:21 -07:00
research-bot 7eafc7cd60 updating sysmon to XML 2024-11-01 13:40:43 -07:00
research-bot d1c7e1b6e5 udpating sysmon source 2024-10-30 18:42:30 -07:00
Bhavin Patel 385ac7adc1 remove end hours 2024-10-23 17:52:24 -07:00
Bhavin Patel e2bff20247 updating detections 2024-10-17 08:21:25 -07:00
Michael Haag 2057e0ab23 Update malicious_powershell_process___encoded_command.yml
Fixed for #2982
2024-07-26 10:45:25 -06:00
Patrick 87108a5aac Improved data sources 2024-07-17 14:41:50 +02:00
Patrick 9e0d8426c1 improved data source field 2024-07-16 14:06:31 +02:00
Bhavin Patel 22e5ea3f83 Release Branch - ESCU v4.34.0 2024-06-26 14:41:53 +00:00
Bhavin Patel 6c5446cfbc Release Branch - ESCU v4.32.0 2024-05-22 16:47:39 +00:00
Bhavin Patel b0eaed8f75 ESCU Release v4.31.0 2024-05-08 16:05:40 +00:00
Gowthamaraj rajendran e06cfa133d Edit how_to_implement for Endpoint.Processes 2023-09-15 10:58:38 -07:00
tccontre aad413f44c volt_typhoon 2023-05-25 12:16:00 +02:00
tccontre 5311028ec7 Update malicious_powershell_process___encoded_command.yml 2023-04-14 10:42:16 +02:00
tccontre 52391f5615 Merge branch 'develop' into sandworm_data_destruction 2023-04-13 19:07:10 +02:00
tccontre e0b697ab6e sandworm_data_destruction 2023-04-12 12:17:43 +02:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
Michael Haag c6db7b5415 CISA AA22-320A 2022-11-16 12:10:42 -07:00
tccontre c96c6d03d3 qakbot_1 2022-10-18 11:57:58 +02:00
tccontre 2dd87d6d33 dcrat-analytics 2022-07-26 12:02:35 +02:00
Rod Soto 8298acf18e powershelldetectionstaghermetic 2022-03-31 15:29:51 -07:00
P4T12ICK e6c8254ede Added automaticc generation of finding report 2022-03-14 12:12:48 +01:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 5fbff3630e merged with develop 2022-02-07 14:55:34 +01:00