Eric McGinnis
|
db8c7c8509
|
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
|
2026-05-13 14:02:27 -07:00 |
|
Bhavin Patel
|
ba59855b1d
|
updating risk drilldowns (#4016)
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
|
2026-04-17 17:28:53 +05:30 |
|
Nasreddine Bencherchali
|
bc1b413923
|
Fix Reported Issues - April Batch (#3962)
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-03-30 14:34:11 +05:30 |
|
Br3akp0int
|
2e2f6fc649
|
ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
|
2026-03-10 14:10:37 +05:30 |
|
Nasreddine Bencherchali
|
11c909f725
|
Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920)
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
|
2026-02-26 00:00:35 +05:30 |
|
Nasreddine Bencherchali
|
f49f3a3fc9
|
Fix Validation Issues (#3861)
|
2026-01-30 01:38:34 +01:00 |
|
Teoderick Contreras
|
96786372a3
|
interlock_ransomware
|
2025-07-28 11:58:45 +02:00 |
|
Nasreddine Bencherchali
|
271fd75425
|
update analytics after review suggestions
|
2025-06-02 10:30:36 +02:00 |
|
Nasreddine Bencherchali
|
a9c0afadf8
|
update how to implement section
|
2025-05-28 13:05:49 +02:00 |
|
Nasreddine Bencherchali
|
e42a0eba09
|
Update tor_traffic.yml
|
2025-05-27 23:48:24 +02:00 |
|
Nasreddine Bencherchali
|
bc5c2a3ddd
|
Update tor_traffic.yml
|
2025-05-27 23:27:25 +02:00 |
|
Eric
|
d9960562b8
|
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
|
2025-05-02 14:10:46 -07:00 |
|
Patrick Bareiss
|
1c9debe9a6
|
update versions
|
2025-03-14 13:47:44 +01:00 |
|
Patrick Bareiss
|
f202520e17
|
output normalization endpoint
|
2025-03-11 15:24:12 +01:00 |
|
pyth0n1c
|
45599e0b18
|
Clean up MITRE Tagging. When a type is defined, such as T1003, DO NOT allow a subtype such as T1003.001 to be defined. Remove the generic type T1003 and keep the subtype T1003.001. However, it is acceptable for a subtype to be defined or for a type to be defined separately. It is also okay for multiple subtypes to be defined.
|
2025-02-10 12:28:22 -08:00 |
|
pyth0n1c
|
d1442c2805
|
remove update_timestamps, confidence, impact,
related_fields, and risk_score from detections
|
2025-01-03 15:25:52 -08:00 |
|
ljstella
|
1051b93879
|
network: more typefixes
|
2024-11-15 10:49:03 -06:00 |
|
ljstella
|
ddbaa75ec8
|
network: lowercase rba types
|
2024-11-15 10:17:35 -06:00 |
|
ljstella
|
17b942b0db
|
network detection score field rename
|
2024-11-15 09:51:21 -06:00 |
|
ljstella
|
6792bcccd1
|
network detections score fix
|
2024-11-15 09:40:28 -06:00 |
|
ljstella
|
f6587bd7a2
|
network detections initial translation
|
2024-11-15 08:46:50 -06:00 |
|
Bhavin Patel
|
0bb378b19b
|
updating drilldowns
|
2024-10-24 14:13:05 -07:00 |
|
Bhavin Patel
|
8b03f3d58f
|
updating all detections with quotes
|
2024-10-24 14:08:37 -07:00 |
|
Bhavin Patel
|
7bc11be7dc
|
updating drilldown_formatting
|
2024-10-23 18:25:39 -07:00 |
|
Bhavin Patel
|
385ac7adc1
|
remove end hours
|
2024-10-23 17:52:24 -07:00 |
|
Bhavin Patel
|
cf169b3de0
|
adding drilldowns to all
|
2024-09-30 22:04:57 +05:30 |
|
Bhavin Patel
|
22e5ea3f83
|
Release Branch - ESCU v4.34.0
|
2024-06-26 14:41:53 +00:00 |
|
Bhavin Patel
|
6c5446cfbc
|
Release Branch - ESCU v4.32.0
|
2024-05-22 16:47:39 +00:00 |
|
Bhavin Patel
|
82b699b444
|
updating tor detection
|
2023-09-20 11:55:18 -07:00 |
|
P4T12ICK
|
2861d04434
|
merged with ba ocsf work
|
2023-03-03 13:28:14 +01:00 |
|
P4T12ICK
|
78909f6429
|
merged with develop
|
2023-03-03 12:40:16 +01:00 |
|
P4T12ICK
|
d115bfd4e0
|
converted ssa detections to ocsf
|
2023-02-28 12:00:16 +01:00 |
|
P4T12ICK
|
fd0c8b349f
|
updated tags
|
2023-01-09 09:33:30 +01:00 |
|
P4T12ICK
|
5ae53c9368
|
Migrated all detections to v4
|
2023-01-03 13:42:10 +01:00 |
|
mhaag-spl
|
a6265b60df
|
Moving Tor Traffic to Experimental
|
2021-03-10 11:47:34 -07:00 |
|
mhaag-spl
|
51823d81d3
|
Sunburst malware renamed NOBELIUM Group
Renaming Sunburst Malware to NOBELIUM Group
|
2021-03-05 10:30:34 -07:00 |
|
divious1
|
b58843ca9f
|
added datamodels as an array
|
2021-02-10 22:35:58 -05:00 |
|
divious1
|
d0c9c92857
|
added datamodel field and made all objects also pretty via new tool called pretty_yaml.py
|
2021-02-10 22:11:24 -05:00 |
|
divious1
|
1ec15cf044
|
renamed on all detections
|
2021-02-08 10:18:16 -05:00 |
|
divious1
|
b68e05685e
|
modified type for detections
|
2021-02-05 14:35:49 -05:00 |
|
divious1
|
e14fade976
|
adding product tag to all detections
|
2021-02-03 21:42:46 -05:00 |
|
bpatel
|
7fa41599d5
|
adding sunburst as tags for relavant detections
|
2020-12-14 20:29:04 -08:00 |
|
divious1
|
443d86c864
|
moved detections to their respective folders
|
2020-10-07 10:31:25 -04:00 |
|