Lou Stella
d235c3e7d2
Update detections/web/monitor_web_traffic_for_brand_abuse.yml
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-05-19 14:22:21 -04:00
ljstella
bc18194661
Reordering keys
2026-05-19 14:21:30 -04:00
ljstella
53565febce
message cleanup
2026-05-19 12:15:48 -04:00
ljstella
9dfb1706f9
Manual Review of correlation searches
2026-05-19 10:10:45 -04:00
Eric McGinnis
db8c7c8509
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
2026-05-13 14:02:27 -07:00
Bhavin Patel
ba59855b1d
updating risk drilldowns ( #4016 )
...
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali
bc1b413923
Fix Reported Issues - April Batch ( #3962 )
...
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali
b87507b551
Update Suricata TA and Related Analytics ( #3974 )
...
* update suricata ta
* update analytics for new TA
* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-03-28 10:09:22 +00:00
Br3akp0int
3da4f7958a
anomaly_standard_init_score ( #3946 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-10 14:19:08 +05:30
Br3akp0int
2e2f6fc649
ttp_standard_init_score ( #3945 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali
11c909f725
Add YAML Formatting Job ( #3889 )
...
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920 )
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-26 00:00:35 +05:30
Nasreddine Bencherchali
c50763d938
Fix Reported Issues ( #3873 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-30 16:34:18 +01:00
Nasreddine Bencherchali
f49f3a3fc9
Fix Validation Issues ( #3861 )
2026-01-30 01:38:34 +01:00
Nasreddine Bencherchali
76f629eb2f
Update Analytics Performance ( #3866 )
...
* Update common_ransomware_notes.yml
* Update detect_rare_executables.yml
* update samsam ext
* update where clause to include null checks
* appinspect fixes
* reduce version
* fix where issue
* Update ransomware_notes_lookup.csv
* more perf enhancements
* Update windows_dotnet_binary_in_non_standard_path.yml
* fix ci issue and enhance description
* Update common_ransomware_extensions.yml
* Update common_ransomware_extensions.yml
* remove unknown and dash values
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 12:36:31 +00:00
Raven Tait
498a80d469
Detections for default user agents ( #3842 )
...
* Detections for default user agents
* various updates for user agent detections
* Apply suggestions from code review
* Rename suspicious_user_agent.yml to suspicious_user_agents.yml
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-07 09:34:04 +05:30
Nasreddine Bencherchali
976c62383e
Update Macro Usage ( #3840 )
...
* update macro usage
* bump version
* Update detect_hosts_connecting_to_dynamic_domain_providers.yml
* more macro updates
2025-12-18 21:42:06 +05:30
Raven Tait
7c092c7eb6
HTTP Request Smuggling ( #3731 )
...
* HTTP Request Smuggling
* Updates from PR comments
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-10-21 14:08:57 -07:00
Michael Haag
7b9274f9fb
Scattered Lapsus$ Hunters ( #3724 )
...
* Scattered Lapsus$ Hunters
* fixes
* 👀
* bump versions
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-10-21 11:27:25 -07:00
Bhavin Patel
22da3767c5
version bumps ( #3732 )
2025-10-17 11:15:52 -07:00
Michael Haag
a548ed769a
Hellcat United ( #3723 )
...
* Hellcat United
* fixes
* 🍱
* 1 mas
* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Michael Haag
64ed5bb1e8
APT 37 and The No Good Rustonotto ( #3686 )
...
* APT 37 and The No Good Rustonotto
## Updated analytics
```
detections/application/detect_html_help_spawn_child_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/bitsadmin_download_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cobalt_strike_named_pipes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_rundll32_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/executables_or_script_creation_in_temp_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/icedid_exfiltrated_archived_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/lolbas_with_network_traffic.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_4104_hunting.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/processes_tapping_keyboard_events.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/registry_keys_used_for_persistence.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_curl_network_connection.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_image_creation_in_appdata_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_mshta_spawn.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_process_executed_from_container_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_scheduled_task_from_public_directory.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_alternate_datastream___base64_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_rar.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archived_collected_data_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_cab_file_on_disk.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_curl_download_to_suspicious_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_invoke_restmethod.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_powershell_uploadstring.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_file_download_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_high_file_deletion_frequency.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_http_network_communication_from_msiexec.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_indicator_removal_via_rmdir.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_input_capture_using_credential_ui_dll.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_iso_lnk_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_child_process_for_download.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_uncommon_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_executed_from_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_execution_from_programdata.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_commonly_abused_processes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_notepad.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_replication_through_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_command.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_name.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_service_created_with_suspicious_service_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_suspicious_driver_loaded_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_usbstor_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_wpdbusenum_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/winevent_scheduled_task_created_within_public_path.yml — APT37 Rustonotto and FadeStealer
detections/web/multiple_archive_files_http_post_traffic.yml — APT37 Rustonotto and FadeStealer
detections/web/plain_http_post_exfiltrated_data.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_expand_cabinet_file_extraction.yml — APT37 Rustonotto and FadeStealer
```
## New Story
```
stories/apt37_rustonotto_and_fadestealer.yml — APT37 Rustonotto and FadeStealer
```
* Create windows_expand_cabinet_file_extraction.yml
* Apply suggestion from @nasbench
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* updating conflicts
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-10-13 13:54:03 -07:00
Michael Haag
b6083e5076
GhostRedirectors
2025-09-18 13:39:40 -06:00
Teoderick Contreras
96786372a3
interlock_ransomware
2025-07-28 11:58:45 +02:00
Michael Haag
4e3598c522
Update windows_sharepoint_toolpane_endpoint_exploitation_attempt.yml
2025-07-21 13:11:43 -06:00
Michael Haag
c5838d60da
Create windows_sharepoint_spinstall0_get_request.yml
2025-07-21 09:28:05 -06:00
Michael Haag
13b49f5456
Sharing is Caring: A story of CVE-2025-53770
2025-07-20 17:03:37 -06:00
Nasreddine Bencherchali
523e5f4b94
add ftd equivalent analytic
2025-07-17 20:43:29 +02:00
Nasreddine Bencherchali
483e79feae
Update citrix_adc_and_gateway_citrixbleed_2_memory_disclosure.yml
...
update formatting
2025-07-17 14:56:14 +02:00
Michael Haag
c6af7c5b52
Update citrix_adc_and_gateway_citrixbleed_2_memory_disclosure.yml
2025-07-09 11:49:23 -06:00
Michael Haag
b74094eb74
CitrixBleed2
2025-07-02 10:33:13 -06:00
ljstella
397107f88a
Updated docs links in detections
2025-06-24 11:27:59 -05:00
Eric
d9960562b8
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
2025-05-02 14:10:46 -07:00
Michael Haag
074d13f001
BasketNetWeaving with Haag: No Shell Left Behind!
2025-04-28 10:33:17 -06:00
Bhavin Patel
bb2045cce0
Merge branch 'develop' into crushingit
2025-04-18 12:45:18 -07:00
Michael Haag
9f8f28c0b5
Update crushftp_max_simultaneous_users_from_ip.yml
2025-04-18 13:27:09 -06:00
Michael Haag
95049154e9
Update crushftp_authentication_bypass_exploitation.yml
2025-04-18 13:25:39 -06:00
Bhavin Patel
8e6d4c69bf
Merge branch 'develop' into remove_v5.4.0
2025-04-17 12:00:27 -07:00
Michael Haag
657ffbc9e4
Ground Control to Major Haag: Earth Alux
...
This PR adds a new analytic story for the Earth Alux threat actor, a sophisticated espionage group targeting government, technology, and telecommunications sectors in APAC and Latin America.
2025-04-16 21:55:12 -06:00
Bhavin Patel
5b7cfdb7d3
updating versions
2025-04-16 16:45:16 -07:00
Michael Haag
fc81c76727
Haag's Crushed Shell: A Tale of CrushFTP Exploitation
...
CVE-2025-31161
2025-04-14 12:39:07 -06:00
Bhavin Patel
00253f3c6e
Merge branch 'develop' into output_normalization_endpoint
2025-04-01 14:45:19 -07:00
Bhavin Patel
7168e32ea6
Merge branch 'develop' into sunnyside
2025-04-01 14:05:53 -07:00
Michael Haag
55b5bc77d2
fixagai
2025-04-01 14:48:54 -06:00
Michael Haag
f435240b83
fixes
2025-04-01 14:34:18 -06:00
Patrick Bareiss
7541027f8e
Merge branch 'develop' into output_normalization_endpoint
2025-04-01 09:41:58 +02:00
Michael Haag
20cb4400dc
Haag Story 3: Attack Analytics to the Rescue
...
"There's a snake in my Tomcat!"
When malicious serialized objects started showing up at Sunnyside Server Farm, Security Sheriff Haag rounded up a posse of new detections to keep the web applications safe.
This PR delivers:
- Two new best friends: tomcat_session_file_upload_attempt and tomcat_session_deserialization_attempt
- A brand new playset: "Apache Tomcat Session Deserialization Attacks" analytic story
- No more crying when the bad toys try to upload .session files
- The claw of justice comes down when suspicious JSESSIONID cookies appear
Remember what Security Ranger Haag always says: "To HTTP response codes and beyond!"
2025-03-25 14:08:02 -06:00
Michael Haag
ec5cf468e3
The Haag Identity: Operation Seashell Blizzard 🌊 ❄️
...
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include:
Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately.
Analytics tagged with "Seashell Blizzard" include:
ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal)
Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell)
Credential access monitoring (LSASS dumps via TaskMgr and ProcDump)
Remote access software usage detections (file, process, registry)
Scheduled task abuse detections
SQL Server xp_cmdshell configuration changes
Registry hive dumping detection
Key updates:
- Added "Seashell Blizzard" tag to 20 existing detections
These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.
2025-03-24 14:18:40 -06:00
Patrick Bareiss
1c9debe9a6
update versions
2025-03-14 13:47:44 +01:00
Patrick Bareiss
67dff5120a
Merge branch 'develop' into output_normalization_endpoint
2025-03-13 09:22:06 +01:00
pyth0n1c
d77736f7e4
Update detect_web_access_to_decommissioned_s3_bucket.yml
...
fix tests key again
2025-02-20 14:57:35 -08:00