492 Commits

Author SHA1 Message Date
ljstella 0c869bfc93 yamlfmt 2026-05-20 15:15:09 -04:00
ljstella bc18194661 Reordering keys 2026-05-19 14:21:30 -04:00
ljstella 53565febce message cleanup 2026-05-19 12:15:48 -04:00
ljstella baf4b85578 Multiple non-user but no user 2026-05-19 10:34:15 -04:00
ljstella 9dfb1706f9 Manual Review of correlation searches 2026-05-19 10:10:45 -04:00
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Lou Stella 9c183fa110 Update Analytics to Support ATT&CK v19 (#4036)
---------

Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-05 17:29:28 +02:00
Raven Tait 917fe77cc0 Add Big Batch of Snap Attack Converted Rules (#4015)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-05-05 16:11:18 +02:00
Bhavin Patel becdb58b9f Add Secure Access Firewall Detections (#3986)
---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-29 20:41:09 +02:00
Br3akp0int 9972c09298 vip_keylogger (#4024)
* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* Update vip_keylogger.yml

* Update windows_proxy_execution_of__net_utilities_via_scripts.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

* Update powershell_loading_dotnet_into_memory_via_reflection.yml

* Update executables_or_script_creation_in_temp_path.yml

* Update executables_or_script_creation_in_suspicious_path.yml

* Update powershell_pinvoke_process_injection_api_chain.yml

* vip_keylogger

* Update powershell_environment_variable_execution.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-04-29 17:55:13 +05:30
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali ea5bd52238 Fix Issues - 2nd Round (#3996)
* Fix #3993

* Fix incorrect DS entries

* fix security_domain issue

* Fix #3992

* Fix #3988

* Update dump_lsass_via_procdump.yml

* Fix #3987

* Fix #3977

* Update network_connection_discovery_with_arp.yml

* Fix #3998

* Fix #3997

* fix versions

* revert change

* Fix #4012

* Update linux_file_creation_in_init_boot_directory.yml

* Update linux_file_creation_in_init_boot_directory.yml

* Fix #4010 and related

* fix typo

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-04-16 05:24:43 +00:00
Nasreddine Bencherchali bc1b413923 Fix Reported Issues - April Batch (#3962)
* Fix #3961

* Fix #3909

* Fix output fields

* Remove duplicate process_name entry

* Update outbound_network_connection_from_java_using_default_ports.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Fix #3969

* update palo alto TA and beautify analytics

* Update vmware_aria_operations_exploit_attempt.yml

* fix source

* enhance metadata and fp info

* beautify spl for ease of reading

* add some missing attack techniques

* remove unnecessary usage of regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* small fix

* Refine description and improve regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update windows_event_log_security_4756.yml

* description update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali b87507b551 Update Suricata TA and Related Analytics (#3974)
* update suricata ta

* update analytics for new TA

* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml

---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-03-28 10:09:22 +00:00
Br3akp0int 697a77cd08 Add Tagging and Analytic Story for Void Manticore (#3959)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-23 17:19:07 +01:00
Br3akp0int 27aeb7d95d Add BlankGrabber Stealer Related Analytics and Tagging (#3943)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-16 18:09:57 +01:00
Bhavin Patel b3fed38275 Deprecate MLTK detections (#3922)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-03-16 14:59:40 +01:00
Nasreddine Bencherchali 29113be7a7 Fix Broken Link, Versions and Pre-Commit (#3956)
* fix links and versions

* more versions
2026-03-13 19:17:15 +05:30
Br3akp0int de62304785 Add Analytic Story Tagging for Muddy Water (#3947)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-12 16:30:09 +00:00
Nasreddine Bencherchali ed5884f607 More SD-WAN Content (#3944)
* add more sd-wan content

* rename macro

* Update cisco_sd_wan_service_proxy_access.yml

* fix parsing

* Update cisco_sd_wan___arbitrary_file_overwrite_exploitation_activity.yml

* apply review suggestions
2026-03-12 18:16:41 +05:30
Br3akp0int 3da4f7958a anomaly_standard_init_score (#3946)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-10 14:19:08 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali f930b525ee Add New Analytics - February Batch (#3886)
* add percent encoded curl exec

* Fix #3916

* Add other calc process names entries

* apply formatting

* add more color

* add cisco sd-wan stuff

* update tags

* Update cisco_sd_wan___low_frequency_rogue_peer.yml

* add ds and maps it

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-03 18:31:37 +05:30
Eric McGinnis c733e6c9cc Merge branch 'develop' into yml_validation_cleanups 2026-02-25 11:36:18 -08:00
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Eric McGinnis 1ed6c27923 Update all dates on modified content, including the baseline 2026-02-25 10:13:58 -08:00
Eric McGinnis 15f1e39548 Merge branch 'develop' into yml_validation_cleanups 2026-02-11 08:51:26 -08:00
Nasreddine Bencherchali a266563b00 Update RBA, logic, and beautify some searches (#3880)
* Update RBA, logic, and beautify searches

* Update internal_horizontal_port_scan_nmap_top_20.yml
2026-01-31 09:57:04 +05:30
Nasreddine Bencherchali c50763d938 Fix Reported Issues (#3873)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-30 16:34:18 +01:00
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Eric McGinnis 74ed412c74 more required bumps 2026-01-28 12:13:38 -08:00
pyth0n1c 0f9014f4b6 Merge branch 'develop' into yml_validation_cleanups 2026-01-28 11:36:47 -08:00
Alex f1693a1a0a Fix search typo in windows abused web services analytic (#3878) 2026-01-24 14:38:30 +01:00
Bhavin Patel 060feb0a42 Updating Query Based on XS Data (#3876) 2026-01-23 15:49:23 +01:00
Bhavin Patel d080ba9f06 Updating Terminology for ES8+ (#3875)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-22 22:59:29 +01:00
Michael Haag d08d829807 VoidLink Tagging (#3870)
* VoidLink

* Update linux_adding_crontab_using_list_parameter.yml

* version

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 19:53:15 +05:30
Br3akp0int 73e69c0b84 stealc (#3833)
* stealc

* stealc

* stealc

* updating versions

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-01-22 18:51:16 +05:30
Nasreddine Bencherchali 76f629eb2f Update Analytics Performance (#3866)
* Update common_ransomware_notes.yml

* Update detect_rare_executables.yml

* update samsam ext

* update where clause to include null checks

* appinspect fixes

* reduce version

* fix where issue

* Update ransomware_notes_lookup.csv

* more perf enhancements

* Update windows_dotnet_binary_in_non_standard_path.yml

* fix ci issue and enhance description

* Update common_ransomware_extensions.yml

* Update common_ransomware_extensions.yml

* remove unknown and dash values

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 12:36:31 +00:00
ljstella c84715dd99 New Year, New Fixes 2026-01-16 13:19:35 -05:00
LaLaGuy 4ce7a1ddcc Update version and date in prohibited network traffic config 2026-01-16 16:45:48 +01:00
LaLaGuy f9e8e6e601 Fix formatting and syntax in prohibited network traffic YAML
space to activate CI.
2026-01-15 19:59:08 +01:00
LaLaGuy e2443809bb Refactor search query for prohibited network traffic
### **Describe the bug**
When interesting_ports_lookup is used, only the port is checked, not the protocol.
Plus, only the first result is returned.
This lookup include several entries for the same port (like 514 rsh/syslog) and the wrong entry can get returned.
This create false match. The wrong enrichment is given (including a wrong transport method) and a notable is generated when it shouldn't.
It can also be greatly optimized by moving the filter logic to the where of the tstats.

### **Expected behavior**
If a 514 udp is detected by the firewall, it should match syslog and not create a notable (or risk) telling me we detected a rsh 514 tcp.

### **Additional context**
Here is a solution (we get the transport from the log instead of adding it from the lookup, add transport to the match and move the filter logique up).
2026-01-15 19:44:41 +01:00
Nasreddine Bencherchali 7941673530 Add Snort/IOS Correlation and Other Things (#3857) 2026-01-12 12:15:11 +01:00
Bhavin Patel 1360c8df28 Merge branch 'develop' into yml_validation_cleanups 2026-01-09 14:25:37 +05:30
Br3akp0int edd6db09d9 Add New Analytics Covering SesameOp and PromptFlux (#3827)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-08 00:58:33 +01:00
Raven Tait 498a80d469 Detections for default user agents (#3842)
* Detections for default user agents

* various updates for user agent detections

* Apply suggestions from code review

* Rename suspicious_user_agent.yml to suspicious_user_agents.yml

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-07 09:34:04 +05:30
pyth0n1c 3b49316ebd Merge branch 'develop' into yml_validation_cleanups 2025-12-22 13:21:53 -08:00
Nasreddine Bencherchali 976c62383e Update Macro Usage (#3840)
* update macro usage

* bump version

* Update detect_hosts_connecting_to_dynamic_domain_providers.yml

* more macro updates
2025-12-18 21:42:06 +05:30
Eric McGinnis 30a6a9fb21 Add some missing products. I assume all these detections want to be for all 3 splunk products. 2025-12-17 11:46:11 -08:00
Nasreddine Bencherchali 5dca2eab02 Add React2Shell Snort Mapping (#3822) 2025-12-08 20:45:54 +01:00