Eric McGinnis
db8c7c8509
Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit.
2026-05-13 14:02:27 -07:00
Bhavin Patel
becdb58b9f
Add Secure Access Firewall Detections ( #3986 )
...
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-29 20:41:09 +02:00
Br3akp0int
9972c09298
vip_keylogger ( #4024 )
...
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* Update vip_keylogger.yml
* Update windows_proxy_execution_of__net_utilities_via_scripts.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
* Update powershell_loading_dotnet_into_memory_via_reflection.yml
* Update executables_or_script_creation_in_temp_path.yml
* Update executables_or_script_creation_in_suspicious_path.yml
* Update powershell_pinvoke_process_injection_api_chain.yml
* vip_keylogger
* Update powershell_environment_variable_execution.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-04-29 17:55:13 +05:30
Raven Tait
8050483569
Snap Mac Detections ( #3935 )
...
* Snap Mac Detections
* add osquery
* Update links and formatting
* update datasource name
* update formatting
* bump version
* Updates per PR comments
* Add commandline to RBA for gatekeeper bypass
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2026-04-14 19:48:42 +05:30
Br3akp0int
7293d75700
Tagged Analytics Covering the Axios Compromise Post-Exploitation Activity ( #3982 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com >
2026-04-02 16:07:20 +00:00
Br3akp0int
ff78e2d159
gh0st ( #3973 )
...
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* small changes
* another update
* final fix
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-30 19:46:33 +05:30
Br3akp0int
697a77cd08
Add Tagging and Analytic Story for Void Manticore ( #3959 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-23 17:19:07 +01:00
Br3akp0int
27aeb7d95d
Add BlankGrabber Stealer Related Analytics and Tagging ( #3943 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-16 18:09:57 +01:00
Michael Haag
4aeba4c377
Add Lotus Blossom Related Analytics and Tagging ( #3953 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-16 15:47:02 +01:00
Br3akp0int
3208147d4d
Add Coverage For QuietVault ( #3952 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-14 01:11:44 +01:00
Nasreddine Bencherchali
29113be7a7
Fix Broken Link, Versions and Pre-Commit ( #3956 )
...
* fix links and versions
* more versions
2026-03-13 19:17:15 +05:30
Br3akp0int
de62304785
Add Analytic Story Tagging for Muddy Water ( #3947 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-12 16:30:09 +00:00
Nasreddine Bencherchali
f930b525ee
Add New Analytics - February Batch ( #3886 )
...
* add percent encoded curl exec
* Fix #3916
* Add other calc process names entries
* apply formatting
* add more color
* add cisco sd-wan stuff
* update tags
* Update cisco_sd_wan___low_frequency_rogue_peer.yml
* add ds and maps it
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-03 18:31:37 +05:30
pyth0n1c
34be5c0b0c
normalize all legacy line endings ( #3931 )
2026-03-02 23:34:35 +01:00
Br3akp0int
c2044d9a99
Tag Content Related to Dynowiper/Zovwiper ( #3907 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-17 23:52:23 +01:00
Rod Soto
02573684ce
Add New MCP Related Detections ( #3895 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-02-17 23:39:01 +01:00
Br3akp0int
19181a86b5
Add Coverage and Tagging for the XML Runner Loader ( #3897 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-17 20:20:36 +01:00
Br3akp0int
6b9201dbc3
Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging ( #3902 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-17 20:02:11 +01:00
Raven Tait
56675d5fc7
Telnet Auth Bypass CVE ( #3883 )
...
* Telnet Auth Bypass
* Fix CVE in story
* Update rba message
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update rba and description
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-31 10:32:53 +05:30
Bhavin Patel
d080ba9f06
Updating Terminology for ES8+ ( #3875 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-22 22:59:29 +01:00
Michael Haag
b6b0b47a66
Storm-0501 Ransomware Analytic Story and Tagging ( #3871 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-01-22 22:32:14 +01:00
Michael Haag
d08d829807
VoidLink Tagging ( #3870 )
...
* VoidLink
* Update linux_adding_crontab_using_list_parameter.yml
* version
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 19:53:15 +05:30
Br3akp0int
73e69c0b84
stealc ( #3833 )
...
* stealc
* stealc
* stealc
* updating versions
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-01-22 18:51:16 +05:30
Br3akp0int
49673747bf
Add Browser Hijack Analytics ( #3841 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-12 13:05:22 +01:00
Br3akp0int
edd6db09d9
Add New Analytics Covering SesameOp and PromptFlux ( #3827 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-08 00:58:33 +01:00
Raven Tait
498a80d469
Detections for default user agents ( #3842 )
...
* Detections for default user agents
* various updates for user agent detections
* Apply suggestions from code review
* Rename suspicious_user_agent.yml to suspicious_user_agents.yml
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-07 09:34:04 +05:30
Bhavin Patel
6d1b940663
Cisco Isovalent - Add first batch of new detections ( #3706 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-06 01:24:39 +01:00
Raven Tait
6032db5edb
Add tuoni content and named pipe detection ( #3816 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-12-08 21:25:09 +01:00
Nasreddine Bencherchali
5d7c65d30a
React2Shell Analytics ( #3819 )
2025-12-08 15:47:53 +01:00
Michael Haag
442e815dad
npm Supply Chain Compromise & Lifecycle Hook Abuse Detection ( #3806 )
...
* extra content
* 5 more extras
* Hunt 1
* story+extras
* Create linux_shai_hulud_2_exfiltration_artifacts.yml
* Create linux_shai_hulud_workflow_file_modification.yml
* Create linux_suspicious_github_workflow_file_modification.yml
* Create windows_github_workflow_file_creation_hunt.yml
* more
* last 3
* final pass
* Bump versions to resolve merge conflicts with develop branch
* Fix deprecated status for curl/wget bash execution detections
* Add npm Supply Chain Compromise story to file_download_or_read_to_pipe_execution (replacement for deprecated curl/wget bash detections)
* Fix version numbers to match previous build requirements
* Add all required Filesystem fields to windows_suspicious_github_workflow_file_modification search
* Update detections/endpoint/windows_curl_download_to_suspicious_path.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* small fixes
* apply updates
* more updates
* Update shai_hulud_2_exfiltration_artifact_files.yml
* Fix Windows path escaping - use single backslash in YAML block scalar
---------
Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-11-25 14:56:20 -08:00
Rod Soto
b53280a5e9
Rod- Suspicious Local LLM Frameworks ( #3780 )
...
* newstory
* firstdet
* fixeddatasets
* 4688locallmdiscovery
* sys1
* sysmon
* secsys
* llmdns
* suspdownfix
* Update detections/endpoint/suspicious_local_llm_framework_download_and_execution_via_sysmon.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* localdnstosuspicious
* windowsexecutionoflocallllmdet
* fixeddetections
* deletedold
* fixedsearch
* fixedsuspiciouslocalllmframeworkprocessexecnospath
* fixedhowtoimplement
* fixhowtoimp
* fixdescription
* moredetails
* update detections
* small fixes
* updates
* small change
* various fixes
* remove dd for hunting detections
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-11-24 13:06:41 -08:00
Nasreddine Bencherchali
515d736c62
Add New ASA Analytics ( #3794 )
...
* first batch
* more updates
* update tags and filter
* more fixes
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* update to production
* fixes and updates
* update date and fix typos
* apply suggestion
* Update cisco_asa___reconnaissance_command_activity.yml
* add explicit message ids
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-11-21 14:50:18 -08:00
Br3akp0int
888c2249e8
netsupport ( #3798 )
...
* netsupport
* netsupport
* netsupport
* netsupport
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update data_sources/sysmon_eventid_29.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update data_sources/sysmon_eventid_29.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* netsupport
* netsupport
* netsupport
* netsupport
* updates
* small fixes
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-11-21 13:27:52 -08:00
Raven Tait
001a152933
NTLM Reflection via DNS Object SPN Spoofing ( #3789 )
...
* NTLM Reflection via DNS Object SPN Spoofing
* Update to user field
* update data source
* Adding fields manadated in the output fields of Sysmon EventID 22 data source
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-11-18 12:59:34 -08:00
James Hodgkinson
206f28f1c7
Fixing typo in suspicious_ollama_activities.yml ( #3783 )
2025-11-13 17:14:15 -08:00
Br3akp0int
fcf1275e96
castlerat ( #3750 )
...
* castlerat
* castlerat
* castlerat
* castlerat
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-11-07 11:08:44 -08:00
Michael Haag
58bf9a1bc8
WSUSpect in Custody: CVE-2025-59287 ( #3743 )
...
* WSUSpect in Custody: CVE-2025-59287
* WSUS and Updates
* :jt_stare:
* Update windows_wsus_spawning_shell.yml
* Update w3wp_spawning_shell.yml
* deprecate rules and map analytic stories
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-10-27 09:48:44 -07:00
Nasreddine Bencherchali
0227a4f5f1
Add Oracle Exploitation Snort Coverage ( #3742 )
...
* add oracle snort coverage
* fix refs
* Update cisco_secure_firewall___oracle_e_business_suite_exploitation.yml
2025-10-23 14:49:04 -07:00
Raven Tait
7c092c7eb6
HTTP Request Smuggling ( #3731 )
...
* HTTP Request Smuggling
* Updates from PR comments
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-10-21 14:08:57 -07:00
Michael Haag
7b9274f9fb
Scattered Lapsus$ Hunters ( #3724 )
...
* Scattered Lapsus$ Hunters
* fixes
* 👀
* bump versions
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-10-21 11:27:25 -07:00
Michael Haag
a548ed769a
Hellcat United ( #3723 )
...
* Hellcat United
* fixes
* 🍱
* 1 mas
* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Michael Haag
64ed5bb1e8
APT 37 and The No Good Rustonotto ( #3686 )
...
* APT 37 and The No Good Rustonotto
## Updated analytics
```
detections/application/detect_html_help_spawn_child_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/bitsadmin_download_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cobalt_strike_named_pipes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_rundll32_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/executables_or_script_creation_in_temp_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/icedid_exfiltrated_archived_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/lolbas_with_network_traffic.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_4104_hunting.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/processes_tapping_keyboard_events.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/registry_keys_used_for_persistence.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_curl_network_connection.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_image_creation_in_appdata_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_mshta_spawn.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_process_executed_from_container_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_scheduled_task_from_public_directory.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_alternate_datastream___base64_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_rar.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archived_collected_data_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_cab_file_on_disk.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_curl_download_to_suspicious_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_invoke_restmethod.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_powershell_uploadstring.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_file_download_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_high_file_deletion_frequency.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_http_network_communication_from_msiexec.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_indicator_removal_via_rmdir.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_input_capture_using_credential_ui_dll.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_iso_lnk_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_child_process_for_download.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_uncommon_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_executed_from_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_execution_from_programdata.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_commonly_abused_processes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_notepad.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_replication_through_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_command.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_name.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_service_created_with_suspicious_service_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_suspicious_driver_loaded_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_usbstor_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_wpdbusenum_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/winevent_scheduled_task_created_within_public_path.yml — APT37 Rustonotto and FadeStealer
detections/web/multiple_archive_files_http_post_traffic.yml — APT37 Rustonotto and FadeStealer
detections/web/plain_http_post_exfiltrated_data.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_expand_cabinet_file_extraction.yml — APT37 Rustonotto and FadeStealer
```
## New Story
```
stories/apt37_rustonotto_and_fadestealer.yml — APT37 Rustonotto and FadeStealer
```
* Create windows_expand_cabinet_file_extraction.yml
* Apply suggestion from @nasbench
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* updating conflicts
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-10-13 13:54:03 -07:00
Rod Soto
0bcb54b6f9
Ollama TA detections ( #3710 )
...
* commit1oll
* olldet2
* olldet3
* fixeddet3
* fixsp
* olldet4
* olldet5
* detoll6
* olldet7
* olldet8
* datasets
* testfixes
* modifiedtasearch
* lotsofixes
* fixednewta
* addedmorerefs
* fixedatasource
* fixedthreatobject
* fixedetectionandalertmessage
* fixedalermessage
* fixedquotes
* fixedhowtoimp
* fixeddescriptionandhowto
* changedestforuripat
* fixedowasplink
* Update detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/application/ollama_possible_rce_via_model_loading.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* protoexnassuggestions
* mionr
* remove index=*
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-10-13 21:54:37 +02:00
Rod Soto
6cf5b0f8f6
Copilot based Detections ( #3693 )
...
* det1
* fixeddt1
* det2
* d3
* det4
* djbk
* d6
* d7
* d8
* addedlnkds
* fixsctype
* pipegone
* fixp
* fixdevices
* jbfix
* datasetfix
* exp
* fixsynthax
* changedstory
* changeprinus
* improvedht
* changedSenderuser
* datas
* fixdoublesearch
* fixedpi
* fixeddescriptionsuser
* fixdatalink
* exportedlogsdatasource
* fixedhowtodatasource
* updating risk stuff
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-10-13 12:14:09 -07:00
Br3akp0int
a52d560c80
lokibot ( #3701 )
...
* lokibot
* lokibot
* lokibot
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-10-10 18:32:18 +00:00
Bhavin Patel
3784436646
Merge branch 'develop' into promptlock
2025-09-29 12:06:29 -07:00
Bhavin Patel
8b2056475f
Merge branch 'develop' into GhostRedirector
2025-09-29 11:34:54 -07:00
Bhavin Patel
a1d2b73915
updating links
2025-09-25 18:23:04 -07:00
Bhavin Patel
e51e23aab1
associating with new story
2025-09-25 18:19:34 -07:00
Bhavin Patel
46ab9105c9
updating links
2025-09-25 16:01:23 -07:00