Eric McGinnis
|
db8c7c8509
|
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
|
2026-05-13 14:02:27 -07:00 |
|
Br3akp0int
|
3da4f7958a
|
anomaly_standard_init_score (#3946)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-03-10 14:19:08 +05:30 |
|
Nasreddine Bencherchali
|
11c909f725
|
Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920)
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-02-26 00:00:35 +05:30 |
|
Nasreddine Bencherchali
|
f49f3a3fc9
|
Fix Validation Issues (#3861)
|
2026-01-30 01:38:34 +01:00 |
|
Eric
|
d9960562b8
|
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
|
2025-05-02 14:10:46 -07:00 |
|
Patrick Bareiss
|
1c9debe9a6
|
update versions
|
2025-03-14 13:47:44 +01:00 |
|
Patrick Bareiss
|
b52bac9b19
|
output normalization endpoint
|
2025-02-14 12:40:57 +01:00 |
|
pyth0n1c
|
fdaa038eab
|
Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
|
2025-01-03 15:47:32 -08:00 |
|
ljstella
|
bc14854c55
|
endpoint: more typefixes
|
2024-11-15 10:36:13 -06:00 |
|
ljstella
|
c9186e0b7d
|
endpoint: lowercase rba types
|
2024-11-15 10:16:37 -06:00 |
|
ljstella
|
514123089d
|
endpoint detection score field rename
|
2024-11-15 09:49:53 -06:00 |
|
ljstella
|
f88eb16c6f
|
endpoint detection score fix
|
2024-11-15 09:34:59 -06:00 |
|
ljstella
|
92cc97a5a7
|
endpoint first pass
|
2024-11-14 15:44:51 -06:00 |
|
Bhavin Patel
|
385ac7adc1
|
remove end hours
|
2024-10-23 17:52:24 -07:00 |
|
Bhavin Patel
|
e2bff20247
|
updating detections
|
2024-10-17 08:21:25 -07:00 |
|
Patrick
|
87108a5aac
|
Improved data sources
|
2024-07-17 14:41:50 +02:00 |
|
Patrick
|
9e0d8426c1
|
improved data source field
|
2024-07-16 14:06:31 +02:00 |
|
Bhavin Patel
|
22e5ea3f83
|
Release Branch - ESCU v4.34.0
|
2024-06-26 14:41:53 +00:00 |
|
Bhavin Patel
|
6c5446cfbc
|
Release Branch - ESCU v4.32.0
|
2024-05-22 16:47:39 +00:00 |
|
Bhavin Patel
|
fdd1067803
|
updated descriptions
|
2023-10-13 13:26:36 -07:00 |
|
Gowthamaraj rajendran
|
64096b6e44
|
Edit parsing
|
2023-09-29 12:11:01 -07:00 |
|
Gowthamaraj rajendran
|
8cd1076f87
|
Update 50 detections
|
2023-09-29 11:57:39 -07:00 |
|
Gowthamaraj rajendran
|
e06cfa133d
|
Edit how_to_implement for Endpoint.Processes
|
2023-09-15 10:58:38 -07:00 |
|
tccontre
|
d0b0099973
|
minor_fix_long_cmdline
|
2023-08-16 16:30:01 +02:00 |
|
P4T12ICK
|
78909f6429
|
merged with develop
|
2023-03-03 12:40:16 +01:00 |
|
P4T12ICK
|
fd0c8b349f
|
updated tags
|
2023-01-09 09:33:30 +01:00 |
|
P4T12ICK
|
5ae53c9368
|
Migrated all detections to v4
|
2023-01-03 13:42:10 +01:00 |
|
d1vious
|
17d7312bc6
|
excluding experimental detections from the package
|
2022-01-10 18:00:59 -05:00 |
|
P4T12ICK
|
5e6e987fb7
|
resolved merge conflicts
|
2021-07-21 09:22:09 +02:00 |
|
research bot
|
44ea56053d
|
updating docs and package bits [ci skip]
|
2021-07-20 21:12:30 +00:00 |
|
mvelazco
|
589d3f92ed
|
fixing extra space
|
2021-07-20 13:53:50 -04:00 |
|
P4T12ICK
|
4ddd09fd87
|
add analytic types to detections
|
2021-07-19 17:12:54 +02:00 |
|
mvelazco
|
adaa34da25
|
minor fixes
|
2021-07-14 14:47:05 -04:00 |
|
mvelazco
|
31496ca1b5
|
fixing variables on message
|
2021-07-14 14:40:09 -04:00 |
|
mvelazco
|
54633d6bc6
|
RBA support take #3
|
2021-07-12 18:23:31 -04:00 |
|
P4T12ICK
|
7c134dbb5d
|
WIP
|
2021-03-10 14:44:44 +01:00 |
|
divious1
|
b58843ca9f
|
added datamodels as an array
|
2021-02-10 22:35:58 -05:00 |
|
divious1
|
d0c9c92857
|
added datamodel field and made all objects also pretty via new tool called pretty_yaml.py
|
2021-02-10 22:11:24 -05:00 |
|
divious1
|
1ec15cf044
|
renamed on all detections
|
2021-02-08 10:18:16 -05:00 |
|
divious1
|
b68e05685e
|
modified type for detections
|
2021-02-05 14:35:49 -05:00 |
|
divious1
|
e14fade976
|
adding product tag to all detections
|
2021-02-03 21:42:46 -05:00 |
|
P4T12ICK
|
3b411763d3
|
new test file
|
2020-12-08 14:18:59 +01:00 |
|
P4T12ICK
|
dd3e31cd44
|
new test file
|
2020-12-08 14:18:08 +01:00 |
|
root
|
f020f30c5e
|
Added detection testing service results inUnusually Long Command Line
|
2020-12-08 13:17:15 +00:00 |
|
P4T12ICK
|
268ba8ad21
|
new test file
|
2020-12-08 14:00:25 +01:00 |
|
P4T12ICK
|
b00298de86
|
new test file
|
2020-12-08 13:38:41 +01:00 |
|
P4T12ICK
|
c23fe12605
|
updated with develop
|
2020-10-14 09:26:19 +02:00 |
|
divious1
|
443d86c864
|
moved detections to their respective folders
|
2020-10-07 10:31:25 -04:00 |
|