48 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Br3akp0int 3da4f7958a anomaly_standard_init_score (#3946)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-10 14:19:08 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Patrick Bareiss 1c9debe9a6 update versions 2025-03-14 13:47:44 +01:00
Patrick Bareiss b52bac9b19 output normalization endpoint 2025-02-14 12:40:57 +01:00
pyth0n1c fdaa038eab Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00
ljstella bc14854c55 endpoint: more typefixes 2024-11-15 10:36:13 -06:00
ljstella c9186e0b7d endpoint: lowercase rba types 2024-11-15 10:16:37 -06:00
ljstella 514123089d endpoint detection score field rename 2024-11-15 09:49:53 -06:00
ljstella f88eb16c6f endpoint detection score fix 2024-11-15 09:34:59 -06:00
ljstella 92cc97a5a7 endpoint first pass 2024-11-14 15:44:51 -06:00
Bhavin Patel 385ac7adc1 remove end hours 2024-10-23 17:52:24 -07:00
Bhavin Patel e2bff20247 updating detections 2024-10-17 08:21:25 -07:00
Patrick 87108a5aac Improved data sources 2024-07-17 14:41:50 +02:00
Patrick 9e0d8426c1 improved data source field 2024-07-16 14:06:31 +02:00
Bhavin Patel 22e5ea3f83 Release Branch - ESCU v4.34.0 2024-06-26 14:41:53 +00:00
Bhavin Patel 6c5446cfbc Release Branch - ESCU v4.32.0 2024-05-22 16:47:39 +00:00
Bhavin Patel fdd1067803 updated descriptions 2023-10-13 13:26:36 -07:00
Gowthamaraj rajendran 64096b6e44 Edit parsing 2023-09-29 12:11:01 -07:00
Gowthamaraj rajendran 8cd1076f87 Update 50 detections 2023-09-29 11:57:39 -07:00
Gowthamaraj rajendran e06cfa133d Edit how_to_implement for Endpoint.Processes 2023-09-15 10:58:38 -07:00
tccontre d0b0099973 minor_fix_long_cmdline 2023-08-16 16:30:01 +02:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
d1vious 17d7312bc6 excluding experimental detections from the package 2022-01-10 18:00:59 -05:00
P4T12ICK 5e6e987fb7 resolved merge conflicts 2021-07-21 09:22:09 +02:00
research bot 44ea56053d updating docs and package bits [ci skip] 2021-07-20 21:12:30 +00:00
mvelazco 589d3f92ed fixing extra space 2021-07-20 13:53:50 -04:00
P4T12ICK 4ddd09fd87 add analytic types to detections 2021-07-19 17:12:54 +02:00
mvelazco adaa34da25 minor fixes 2021-07-14 14:47:05 -04:00
mvelazco 31496ca1b5 fixing variables on message 2021-07-14 14:40:09 -04:00
mvelazco 54633d6bc6 RBA support take #3 2021-07-12 18:23:31 -04:00
P4T12ICK 7c134dbb5d WIP 2021-03-10 14:44:44 +01:00
divious1 b58843ca9f added datamodels as an array 2021-02-10 22:35:58 -05:00
divious1 d0c9c92857 added datamodel field and made all objects also pretty via new tool called pretty_yaml.py 2021-02-10 22:11:24 -05:00
divious1 1ec15cf044 renamed on all detections 2021-02-08 10:18:16 -05:00
divious1 b68e05685e modified type for detections 2021-02-05 14:35:49 -05:00
divious1 e14fade976 adding product tag to all detections 2021-02-03 21:42:46 -05:00
P4T12ICK 3b411763d3 new test file 2020-12-08 14:18:59 +01:00
P4T12ICK dd3e31cd44 new test file 2020-12-08 14:18:08 +01:00
root f020f30c5e Added detection testing service results inUnusually Long Command Line 2020-12-08 13:17:15 +00:00
P4T12ICK 268ba8ad21 new test file 2020-12-08 14:00:25 +01:00
P4T12ICK b00298de86 new test file 2020-12-08 13:38:41 +01:00
P4T12ICK c23fe12605 updated with develop 2020-10-14 09:26:19 +02:00
divious1 443d86c864 moved detections to their respective folders 2020-10-07 10:31:25 -04:00