43 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali bc1b413923 Fix Reported Issues - April Batch (#3962)
* Fix #3961

* Fix #3909

* Fix output fields

* Remove duplicate process_name entry

* Update outbound_network_connection_from_java_using_default_ports.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Fix #3969

* update palo alto TA and beautify analytics

* Update vmware_aria_operations_exploit_attempt.yml

* fix source

* enhance metadata and fp info

* beautify spl for ease of reading

* add some missing attack techniques

* remove unnecessary usage of regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* small fix

* Refine description and improve regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update windows_event_log_security_4756.yml

* description update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-30 14:34:11 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Teoderick Contreras 96786372a3 interlock_ransomware 2025-07-28 11:58:45 +02:00
Nasreddine Bencherchali 271fd75425 update analytics after review suggestions 2025-06-02 10:30:36 +02:00
Nasreddine Bencherchali a9c0afadf8 update how to implement section 2025-05-28 13:05:49 +02:00
Nasreddine Bencherchali e42a0eba09 Update tor_traffic.yml 2025-05-27 23:48:24 +02:00
Nasreddine Bencherchali bc5c2a3ddd Update tor_traffic.yml 2025-05-27 23:27:25 +02:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Patrick Bareiss 1c9debe9a6 update versions 2025-03-14 13:47:44 +01:00
Patrick Bareiss f202520e17 output normalization endpoint 2025-03-11 15:24:12 +01:00
pyth0n1c 45599e0b18 Clean up MITRE Tagging. When a type is defined, such as T1003, DO NOT allow a subtype such as T1003.001 to be defined. Remove the generic type T1003 and keep the subtype T1003.001. However, it is acceptable for a subtype to be defined or for a type to be defined separately. It is also okay for multiple subtypes to be defined. 2025-02-10 12:28:22 -08:00
pyth0n1c d1442c2805 remove update_timestamps, confidence, impact,
related_fields, and risk_score from detections
2025-01-03 15:25:52 -08:00
ljstella 1051b93879 network: more typefixes 2024-11-15 10:49:03 -06:00
ljstella ddbaa75ec8 network: lowercase rba types 2024-11-15 10:17:35 -06:00
ljstella 17b942b0db network detection score field rename 2024-11-15 09:51:21 -06:00
ljstella 6792bcccd1 network detections score fix 2024-11-15 09:40:28 -06:00
ljstella f6587bd7a2 network detections initial translation 2024-11-15 08:46:50 -06:00
Bhavin Patel 0bb378b19b updating drilldowns 2024-10-24 14:13:05 -07:00
Bhavin Patel 8b03f3d58f updating all detections with quotes 2024-10-24 14:08:37 -07:00
Bhavin Patel 7bc11be7dc updating drilldown_formatting 2024-10-23 18:25:39 -07:00
Bhavin Patel 385ac7adc1 remove end hours 2024-10-23 17:52:24 -07:00
Bhavin Patel cf169b3de0 adding drilldowns to all 2024-09-30 22:04:57 +05:30
Bhavin Patel 22e5ea3f83 Release Branch - ESCU v4.34.0 2024-06-26 14:41:53 +00:00
Bhavin Patel 6c5446cfbc Release Branch - ESCU v4.32.0 2024-05-22 16:47:39 +00:00
Bhavin Patel 82b699b444 updating tor detection 2023-09-20 11:55:18 -07:00
P4T12ICK 2861d04434 merged with ba ocsf work 2023-03-03 13:28:14 +01:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
P4T12ICK d115bfd4e0 converted ssa detections to ocsf 2023-02-28 12:00:16 +01:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
mhaag-spl a6265b60df Moving Tor Traffic to Experimental 2021-03-10 11:47:34 -07:00
mhaag-spl 51823d81d3 Sunburst malware renamed NOBELIUM Group
Renaming Sunburst Malware to NOBELIUM Group
2021-03-05 10:30:34 -07:00
divious1 b58843ca9f added datamodels as an array 2021-02-10 22:35:58 -05:00
divious1 d0c9c92857 added datamodel field and made all objects also pretty via new tool called pretty_yaml.py 2021-02-10 22:11:24 -05:00
divious1 1ec15cf044 renamed on all detections 2021-02-08 10:18:16 -05:00
divious1 b68e05685e modified type for detections 2021-02-05 14:35:49 -05:00
divious1 e14fade976 adding product tag to all detections 2021-02-03 21:42:46 -05:00
bpatel 7fa41599d5 adding sunburst as tags for relavant detections 2020-12-14 20:29:04 -08:00
divious1 443d86c864 moved detections to their respective folders 2020-10-07 10:31:25 -04:00