281 Commits

Author SHA1 Message Date
Lou Stella d235c3e7d2 Update detections/web/monitor_web_traffic_for_brand_abuse.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-19 14:22:21 -04:00
ljstella bc18194661 Reordering keys 2026-05-19 14:21:30 -04:00
ljstella 53565febce message cleanup 2026-05-19 12:15:48 -04:00
ljstella 9dfb1706f9 Manual Review of correlation searches 2026-05-19 10:10:45 -04:00
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali bc1b413923 Fix Reported Issues - April Batch (#3962)
* Fix #3961

* Fix #3909

* Fix output fields

* Remove duplicate process_name entry

* Update outbound_network_connection_from_java_using_default_ports.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Fix #3969

* update palo alto TA and beautify analytics

* Update vmware_aria_operations_exploit_attempt.yml

* fix source

* enhance metadata and fp info

* beautify spl for ease of reading

* add some missing attack techniques

* remove unnecessary usage of regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* small fix

* Refine description and improve regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update windows_event_log_security_4756.yml

* description update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali b87507b551 Update Suricata TA and Related Analytics (#3974)
* update suricata ta

* update analytics for new TA

* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml

---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-03-28 10:09:22 +00:00
Br3akp0int 3da4f7958a anomaly_standard_init_score (#3946)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-10 14:19:08 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Nasreddine Bencherchali c50763d938 Fix Reported Issues (#3873)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-30 16:34:18 +01:00
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Nasreddine Bencherchali 76f629eb2f Update Analytics Performance (#3866)
* Update common_ransomware_notes.yml

* Update detect_rare_executables.yml

* update samsam ext

* update where clause to include null checks

* appinspect fixes

* reduce version

* fix where issue

* Update ransomware_notes_lookup.csv

* more perf enhancements

* Update windows_dotnet_binary_in_non_standard_path.yml

* fix ci issue and enhance description

* Update common_ransomware_extensions.yml

* Update common_ransomware_extensions.yml

* remove unknown and dash values

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 12:36:31 +00:00
Raven Tait 498a80d469 Detections for default user agents (#3842)
* Detections for default user agents

* various updates for user agent detections

* Apply suggestions from code review

* Rename suspicious_user_agent.yml to suspicious_user_agents.yml

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-07 09:34:04 +05:30
Nasreddine Bencherchali 976c62383e Update Macro Usage (#3840)
* update macro usage

* bump version

* Update detect_hosts_connecting_to_dynamic_domain_providers.yml

* more macro updates
2025-12-18 21:42:06 +05:30
Raven Tait 7c092c7eb6 HTTP Request Smuggling (#3731)
* HTTP Request Smuggling

* Updates from PR comments

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-10-21 14:08:57 -07:00
Michael Haag 7b9274f9fb Scattered Lapsus$ Hunters (#3724)
* Scattered Lapsus$ Hunters

* fixes

* 👀

* bump versions

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-10-21 11:27:25 -07:00
Bhavin Patel 22da3767c5 version bumps (#3732) 2025-10-17 11:15:52 -07:00
Michael Haag a548ed769a Hellcat United (#3723)
* Hellcat United

* fixes

* 🍱

* 1 mas

* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Michael Haag 64ed5bb1e8 APT 37 and The No Good Rustonotto (#3686)
* APT 37 and The No Good Rustonotto

## Updated analytics
```
detections/application/detect_html_help_spawn_child_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/bitsadmin_download_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cobalt_strike_named_pipes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_rundll32_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/executables_or_script_creation_in_temp_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/icedid_exfiltrated_archived_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/lolbas_with_network_traffic.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_4104_hunting.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/processes_tapping_keyboard_events.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/registry_keys_used_for_persistence.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_curl_network_connection.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_image_creation_in_appdata_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_mshta_spawn.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_process_executed_from_container_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_scheduled_task_from_public_directory.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_alternate_datastream___base64_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_rar.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archived_collected_data_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_cab_file_on_disk.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_curl_download_to_suspicious_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_invoke_restmethod.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_powershell_uploadstring.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_file_download_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_high_file_deletion_frequency.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_http_network_communication_from_msiexec.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_indicator_removal_via_rmdir.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_input_capture_using_credential_ui_dll.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_iso_lnk_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_child_process_for_download.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_uncommon_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_executed_from_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_execution_from_programdata.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_commonly_abused_processes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_notepad.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_replication_through_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_command.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_name.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_service_created_with_suspicious_service_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_suspicious_driver_loaded_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_usbstor_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_wpdbusenum_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/winevent_scheduled_task_created_within_public_path.yml — APT37 Rustonotto and FadeStealer
detections/web/multiple_archive_files_http_post_traffic.yml — APT37 Rustonotto and FadeStealer
detections/web/plain_http_post_exfiltrated_data.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_expand_cabinet_file_extraction.yml — APT37 Rustonotto and FadeStealer
```

## New Story

```
stories/apt37_rustonotto_and_fadestealer.yml — APT37 Rustonotto and FadeStealer
```

* Create windows_expand_cabinet_file_extraction.yml

* Apply suggestion from @nasbench

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* updating conflicts

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 13:54:03 -07:00
Michael Haag b6083e5076 GhostRedirectors 2025-09-18 13:39:40 -06:00
Teoderick Contreras 96786372a3 interlock_ransomware 2025-07-28 11:58:45 +02:00
Michael Haag 4e3598c522 Update windows_sharepoint_toolpane_endpoint_exploitation_attempt.yml 2025-07-21 13:11:43 -06:00
Michael Haag c5838d60da Create windows_sharepoint_spinstall0_get_request.yml 2025-07-21 09:28:05 -06:00
Michael Haag 13b49f5456 Sharing is Caring: A story of CVE-2025-53770 2025-07-20 17:03:37 -06:00
Nasreddine Bencherchali 523e5f4b94 add ftd equivalent analytic 2025-07-17 20:43:29 +02:00
Nasreddine Bencherchali 483e79feae Update citrix_adc_and_gateway_citrixbleed_2_memory_disclosure.yml
update formatting
2025-07-17 14:56:14 +02:00
Michael Haag c6af7c5b52 Update citrix_adc_and_gateway_citrixbleed_2_memory_disclosure.yml 2025-07-09 11:49:23 -06:00
Michael Haag b74094eb74 CitrixBleed2 2025-07-02 10:33:13 -06:00
ljstella 397107f88a Updated docs links in detections 2025-06-24 11:27:59 -05:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Michael Haag 074d13f001 BasketNetWeaving with Haag: No Shell Left Behind! 2025-04-28 10:33:17 -06:00
Bhavin Patel bb2045cce0 Merge branch 'develop' into crushingit 2025-04-18 12:45:18 -07:00
Michael Haag 9f8f28c0b5 Update crushftp_max_simultaneous_users_from_ip.yml 2025-04-18 13:27:09 -06:00
Michael Haag 95049154e9 Update crushftp_authentication_bypass_exploitation.yml 2025-04-18 13:25:39 -06:00
Bhavin Patel 8e6d4c69bf Merge branch 'develop' into remove_v5.4.0 2025-04-17 12:00:27 -07:00
Michael Haag 657ffbc9e4 Ground Control to Major Haag: Earth Alux
This PR adds a new analytic story for the Earth Alux threat actor, a sophisticated espionage group targeting government, technology, and telecommunications sectors in APAC and Latin America.
2025-04-16 21:55:12 -06:00
Bhavin Patel 5b7cfdb7d3 updating versions 2025-04-16 16:45:16 -07:00
Michael Haag fc81c76727 Haag's Crushed Shell: A Tale of CrushFTP Exploitation
CVE-2025-31161
2025-04-14 12:39:07 -06:00
Bhavin Patel 00253f3c6e Merge branch 'develop' into output_normalization_endpoint 2025-04-01 14:45:19 -07:00
Bhavin Patel 7168e32ea6 Merge branch 'develop' into sunnyside 2025-04-01 14:05:53 -07:00
Michael Haag 55b5bc77d2 fixagai 2025-04-01 14:48:54 -06:00
Michael Haag f435240b83 fixes 2025-04-01 14:34:18 -06:00
Patrick Bareiss 7541027f8e Merge branch 'develop' into output_normalization_endpoint 2025-04-01 09:41:58 +02:00
Michael Haag 20cb4400dc Haag Story 3: Attack Analytics to the Rescue
"There's a snake in my Tomcat!"

When malicious serialized objects started showing up at Sunnyside Server Farm, Security Sheriff Haag rounded up a posse of new detections to keep the web applications safe.

This PR delivers:
- Two new best friends: tomcat_session_file_upload_attempt and tomcat_session_deserialization_attempt
- A brand new playset: "Apache Tomcat Session Deserialization Attacks" analytic story
- No more crying when the bad toys try to upload .session files
- The claw of justice comes down when suspicious JSESSIONID cookies appear

Remember what Security Ranger Haag always says: "To HTTP response codes and beyond!"
2025-03-25 14:08:02 -06:00
Michael Haag ec5cf468e3 The Haag Identity: Operation Seashell Blizzard 🌊❄️
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include:
Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately.
Analytics tagged with "Seashell Blizzard" include:
ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal)
Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell)
Credential access monitoring (LSASS dumps via TaskMgr and ProcDump)
Remote access software usage detections (file, process, registry)
Scheduled task abuse detections
SQL Server xp_cmdshell configuration changes
Registry hive dumping detection
Key updates:
- Added "Seashell Blizzard" tag to 20 existing detections

These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.
2025-03-24 14:18:40 -06:00
Patrick Bareiss 1c9debe9a6 update versions 2025-03-14 13:47:44 +01:00
Patrick Bareiss 67dff5120a Merge branch 'develop' into output_normalization_endpoint 2025-03-13 09:22:06 +01:00
pyth0n1c d77736f7e4 Update detect_web_access_to_decommissioned_s3_bucket.yml
fix tests key again
2025-02-20 14:57:35 -08:00