ljstella
0c869bfc93
yamlfmt
2026-05-20 15:15:09 -04:00
ljstella
bc18194661
Reordering keys
2026-05-19 14:21:30 -04:00
ljstella
53565febce
message cleanup
2026-05-19 12:15:48 -04:00
ljstella
baf4b85578
Multiple non-user but no user
2026-05-19 10:34:15 -04:00
ljstella
9dfb1706f9
Manual Review of correlation searches
2026-05-19 10:10:45 -04:00
Eric McGinnis
db8c7c8509
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
2026-05-13 14:02:27 -07:00
Lou Stella
9c183fa110
Update Analytics to Support ATT&CK v19 ( #4036 )
...
---------
Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-05-05 17:29:28 +02:00
Raven Tait
917fe77cc0
Add Big Batch of Snap Attack Converted Rules ( #4015 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-05-05 16:11:18 +02:00
Bhavin Patel
becdb58b9f
Add Secure Access Firewall Detections ( #3986 )
...
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-29 20:41:09 +02:00
Br3akp0int
9972c09298
vip_keylogger ( #4024 )
...
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* Update vip_keylogger.yml
* Update windows_proxy_execution_of__net_utilities_via_scripts.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
* Update powershell_loading_dotnet_into_memory_via_reflection.yml
* Update executables_or_script_creation_in_temp_path.yml
* Update executables_or_script_creation_in_suspicious_path.yml
* Update powershell_pinvoke_process_injection_api_chain.yml
* vip_keylogger
* Update powershell_environment_variable_execution.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-04-29 17:55:13 +05:30
Bhavin Patel
ba59855b1d
updating risk drilldowns ( #4016 )
...
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali
ea5bd52238
Fix Issues - 2nd Round ( #3996 )
...
* Fix #3993
* Fix incorrect DS entries
* fix security_domain issue
* Fix #3992
* Fix #3988
* Update dump_lsass_via_procdump.yml
* Fix #3987
* Fix #3977
* Update network_connection_discovery_with_arp.yml
* Fix #3998
* Fix #3997
* fix versions
* revert change
* Fix #4012
* Update linux_file_creation_in_init_boot_directory.yml
* Update linux_file_creation_in_init_boot_directory.yml
* Fix #4010 and related
* fix typo
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-04-16 05:24:43 +00:00
Nasreddine Bencherchali
bc1b413923
Fix Reported Issues - April Batch ( #3962 )
...
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali
b87507b551
Update Suricata TA and Related Analytics ( #3974 )
...
* update suricata ta
* update analytics for new TA
* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-03-28 10:09:22 +00:00
Br3akp0int
697a77cd08
Add Tagging and Analytic Story for Void Manticore ( #3959 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-23 17:19:07 +01:00
Br3akp0int
27aeb7d95d
Add BlankGrabber Stealer Related Analytics and Tagging ( #3943 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-16 18:09:57 +01:00
Bhavin Patel
b3fed38275
Deprecate MLTK detections ( #3922 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-03-16 14:59:40 +01:00
Nasreddine Bencherchali
29113be7a7
Fix Broken Link, Versions and Pre-Commit ( #3956 )
...
* fix links and versions
* more versions
2026-03-13 19:17:15 +05:30
Br3akp0int
de62304785
Add Analytic Story Tagging for Muddy Water ( #3947 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-12 16:30:09 +00:00
Nasreddine Bencherchali
ed5884f607
More SD-WAN Content ( #3944 )
...
* add more sd-wan content
* rename macro
* Update cisco_sd_wan_service_proxy_access.yml
* fix parsing
* Update cisco_sd_wan___arbitrary_file_overwrite_exploitation_activity.yml
* apply review suggestions
2026-03-12 18:16:41 +05:30
Br3akp0int
3da4f7958a
anomaly_standard_init_score ( #3946 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-10 14:19:08 +05:30
Br3akp0int
2e2f6fc649
ttp_standard_init_score ( #3945 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali
f930b525ee
Add New Analytics - February Batch ( #3886 )
...
* add percent encoded curl exec
* Fix #3916
* Add other calc process names entries
* apply formatting
* add more color
* add cisco sd-wan stuff
* update tags
* Update cisco_sd_wan___low_frequency_rogue_peer.yml
* add ds and maps it
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-03 18:31:37 +05:30
Eric McGinnis
c733e6c9cc
Merge branch 'develop' into yml_validation_cleanups
2026-02-25 11:36:18 -08:00
Nasreddine Bencherchali
11c909f725
Add YAML Formatting Job ( #3889 )
...
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920 )
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-26 00:00:35 +05:30
Eric McGinnis
1ed6c27923
Update all dates on modified content, including the baseline
2026-02-25 10:13:58 -08:00
Eric McGinnis
15f1e39548
Merge branch 'develop' into yml_validation_cleanups
2026-02-11 08:51:26 -08:00
Nasreddine Bencherchali
a266563b00
Update RBA, logic, and beautify some searches ( #3880 )
...
* Update RBA, logic, and beautify searches
* Update internal_horizontal_port_scan_nmap_top_20.yml
2026-01-31 09:57:04 +05:30
Nasreddine Bencherchali
c50763d938
Fix Reported Issues ( #3873 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-30 16:34:18 +01:00
Nasreddine Bencherchali
f49f3a3fc9
Fix Validation Issues ( #3861 )
2026-01-30 01:38:34 +01:00
Eric McGinnis
74ed412c74
more required bumps
2026-01-28 12:13:38 -08:00
pyth0n1c
0f9014f4b6
Merge branch 'develop' into yml_validation_cleanups
2026-01-28 11:36:47 -08:00
Alex
f1693a1a0a
Fix search typo in windows abused web services analytic ( #3878 )
2026-01-24 14:38:30 +01:00
Bhavin Patel
060feb0a42
Updating Query Based on XS Data ( #3876 )
2026-01-23 15:49:23 +01:00
Bhavin Patel
d080ba9f06
Updating Terminology for ES8+ ( #3875 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-22 22:59:29 +01:00
Michael Haag
d08d829807
VoidLink Tagging ( #3870 )
...
* VoidLink
* Update linux_adding_crontab_using_list_parameter.yml
* version
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 19:53:15 +05:30
Br3akp0int
73e69c0b84
stealc ( #3833 )
...
* stealc
* stealc
* stealc
* updating versions
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-01-22 18:51:16 +05:30
Nasreddine Bencherchali
76f629eb2f
Update Analytics Performance ( #3866 )
...
* Update common_ransomware_notes.yml
* Update detect_rare_executables.yml
* update samsam ext
* update where clause to include null checks
* appinspect fixes
* reduce version
* fix where issue
* Update ransomware_notes_lookup.csv
* more perf enhancements
* Update windows_dotnet_binary_in_non_standard_path.yml
* fix ci issue and enhance description
* Update common_ransomware_extensions.yml
* Update common_ransomware_extensions.yml
* remove unknown and dash values
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 12:36:31 +00:00
ljstella
c84715dd99
New Year, New Fixes
2026-01-16 13:19:35 -05:00
LaLaGuy
4ce7a1ddcc
Update version and date in prohibited network traffic config
2026-01-16 16:45:48 +01:00
LaLaGuy
f9e8e6e601
Fix formatting and syntax in prohibited network traffic YAML
...
space to activate CI.
2026-01-15 19:59:08 +01:00
LaLaGuy
e2443809bb
Refactor search query for prohibited network traffic
...
### **Describe the bug**
When interesting_ports_lookup is used, only the port is checked, not the protocol.
Plus, only the first result is returned.
This lookup include several entries for the same port (like 514 rsh/syslog) and the wrong entry can get returned.
This create false match. The wrong enrichment is given (including a wrong transport method) and a notable is generated when it shouldn't.
It can also be greatly optimized by moving the filter logic to the where of the tstats.
### **Expected behavior**
If a 514 udp is detected by the firewall, it should match syslog and not create a notable (or risk) telling me we detected a rsh 514 tcp.
### **Additional context**
Here is a solution (we get the transport from the log instead of adding it from the lookup, add transport to the match and move the filter logique up).
2026-01-15 19:44:41 +01:00
Nasreddine Bencherchali
7941673530
Add Snort/IOS Correlation and Other Things ( #3857 )
2026-01-12 12:15:11 +01:00
Bhavin Patel
1360c8df28
Merge branch 'develop' into yml_validation_cleanups
2026-01-09 14:25:37 +05:30
Br3akp0int
edd6db09d9
Add New Analytics Covering SesameOp and PromptFlux ( #3827 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-08 00:58:33 +01:00
Raven Tait
498a80d469
Detections for default user agents ( #3842 )
...
* Detections for default user agents
* various updates for user agent detections
* Apply suggestions from code review
* Rename suspicious_user_agent.yml to suspicious_user_agents.yml
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-07 09:34:04 +05:30
pyth0n1c
3b49316ebd
Merge branch 'develop' into yml_validation_cleanups
2025-12-22 13:21:53 -08:00
Nasreddine Bencherchali
976c62383e
Update Macro Usage ( #3840 )
...
* update macro usage
* bump version
* Update detect_hosts_connecting_to_dynamic_domain_providers.yml
* more macro updates
2025-12-18 21:42:06 +05:30
Eric McGinnis
30a6a9fb21
Add some missing products. I assume all these detections want to be for all 3 splunk products.
2025-12-17 11:46:11 -08:00
Nasreddine Bencherchali
5dca2eab02
Add React2Shell Snort Mapping ( #3822 )
2025-12-08 20:45:54 +01:00