1160 Commits

Author SHA1 Message Date
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel becdb58b9f Add Secure Access Firewall Detections (#3986)
---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-29 20:41:09 +02:00
Br3akp0int 9972c09298 vip_keylogger (#4024)
* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* Update vip_keylogger.yml

* Update windows_proxy_execution_of__net_utilities_via_scripts.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

* Update powershell_loading_dotnet_into_memory_via_reflection.yml

* Update executables_or_script_creation_in_temp_path.yml

* Update executables_or_script_creation_in_suspicious_path.yml

* Update powershell_pinvoke_process_injection_api_chain.yml

* vip_keylogger

* Update powershell_environment_variable_execution.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-04-29 17:55:13 +05:30
Raven Tait 8050483569 Snap Mac Detections (#3935)
* Snap Mac Detections

* add osquery

* Update links and formatting

* update datasource name

* update formatting

* bump version

* Updates per PR comments

* Add commandline to RBA for gatekeeper bypass

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2026-04-14 19:48:42 +05:30
Br3akp0int 7293d75700 Tagged Analytics Covering the Axios Compromise Post-Exploitation Activity (#3982)
---------

Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com>
2026-04-02 16:07:20 +00:00
Br3akp0int ff78e2d159 gh0st (#3973)
* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* small changes

* another update

* final fix

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-30 19:46:33 +05:30
Br3akp0int 697a77cd08 Add Tagging and Analytic Story for Void Manticore (#3959)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-23 17:19:07 +01:00
Br3akp0int 27aeb7d95d Add BlankGrabber Stealer Related Analytics and Tagging (#3943)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-16 18:09:57 +01:00
Michael Haag 4aeba4c377 Add Lotus Blossom Related Analytics and Tagging (#3953)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-16 15:47:02 +01:00
Br3akp0int 3208147d4d Add Coverage For QuietVault (#3952)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-14 01:11:44 +01:00
Nasreddine Bencherchali 29113be7a7 Fix Broken Link, Versions and Pre-Commit (#3956)
* fix links and versions

* more versions
2026-03-13 19:17:15 +05:30
Br3akp0int de62304785 Add Analytic Story Tagging for Muddy Water (#3947)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-12 16:30:09 +00:00
Nasreddine Bencherchali f930b525ee Add New Analytics - February Batch (#3886)
* add percent encoded curl exec

* Fix #3916

* Add other calc process names entries

* apply formatting

* add more color

* add cisco sd-wan stuff

* update tags

* Update cisco_sd_wan___low_frequency_rogue_peer.yml

* add ds and maps it

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-03 18:31:37 +05:30
pyth0n1c 34be5c0b0c normalize all legacy line endings (#3931) 2026-03-02 23:34:35 +01:00
Br3akp0int c2044d9a99 Tag Content Related to Dynowiper/Zovwiper (#3907)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 23:52:23 +01:00
Rod Soto 02573684ce Add New MCP Related Detections (#3895)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-02-17 23:39:01 +01:00
Br3akp0int 19181a86b5 Add Coverage and Tagging for the XML Runner Loader (#3897)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:20:36 +01:00
Br3akp0int 6b9201dbc3 Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging (#3902)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:02:11 +01:00
Raven Tait 56675d5fc7 Telnet Auth Bypass CVE (#3883)
* Telnet Auth Bypass

* Fix CVE in story

* Update rba message

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update rba and description

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-31 10:32:53 +05:30
Bhavin Patel d080ba9f06 Updating Terminology for ES8+ (#3875)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-22 22:59:29 +01:00
Michael Haag b6b0b47a66 Storm-0501 Ransomware Analytic Story and Tagging (#3871)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-01-22 22:32:14 +01:00
Michael Haag d08d829807 VoidLink Tagging (#3870)
* VoidLink

* Update linux_adding_crontab_using_list_parameter.yml

* version

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 19:53:15 +05:30
Br3akp0int 73e69c0b84 stealc (#3833)
* stealc

* stealc

* stealc

* updating versions

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-01-22 18:51:16 +05:30
Br3akp0int 49673747bf Add Browser Hijack Analytics (#3841)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-12 13:05:22 +01:00
Br3akp0int edd6db09d9 Add New Analytics Covering SesameOp and PromptFlux (#3827)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-08 00:58:33 +01:00
Raven Tait 498a80d469 Detections for default user agents (#3842)
* Detections for default user agents

* various updates for user agent detections

* Apply suggestions from code review

* Rename suspicious_user_agent.yml to suspicious_user_agents.yml

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-07 09:34:04 +05:30
Bhavin Patel 6d1b940663 Cisco Isovalent - Add first batch of new detections (#3706)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-06 01:24:39 +01:00
Raven Tait 6032db5edb Add tuoni content and named pipe detection (#3816)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-12-08 21:25:09 +01:00
Nasreddine Bencherchali 5d7c65d30a React2Shell Analytics (#3819) 2025-12-08 15:47:53 +01:00
Michael Haag 442e815dad npm Supply Chain Compromise & Lifecycle Hook Abuse Detection (#3806)
* extra content

* 5 more extras

* Hunt 1

* story+extras

* Create linux_shai_hulud_2_exfiltration_artifacts.yml

* Create linux_shai_hulud_workflow_file_modification.yml

* Create linux_suspicious_github_workflow_file_modification.yml

* Create windows_github_workflow_file_creation_hunt.yml

* more

* last 3

* final pass

* Bump versions to resolve merge conflicts with develop branch

* Fix deprecated status for curl/wget bash execution detections

* Add npm Supply Chain Compromise story to file_download_or_read_to_pipe_execution (replacement for deprecated curl/wget bash detections)

* Fix version numbers to match previous build requirements

* Add all required Filesystem fields to windows_suspicious_github_workflow_file_modification search

* Update detections/endpoint/windows_curl_download_to_suspicious_path.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* small fixes

* apply updates

* more updates

* Update shai_hulud_2_exfiltration_artifact_files.yml

* Fix Windows path escaping - use single backslash in YAML block scalar

---------

Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-11-25 14:56:20 -08:00
Rod Soto b53280a5e9 Rod- Suspicious Local LLM Frameworks (#3780)
* newstory

* firstdet

* fixeddatasets

* 4688locallmdiscovery

* sys1

* sysmon

* secsys

* llmdns

* suspdownfix

* Update detections/endpoint/suspicious_local_llm_framework_download_and_execution_via_sysmon.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* localdnstosuspicious

* windowsexecutionoflocallllmdet

* fixeddetections

* deletedold

* fixedsearch

* fixedsuspiciouslocalllmframeworkprocessexecnospath

* fixedhowtoimplement

* fixhowtoimp

* fixdescription

* moredetails

* update detections

* small fixes

* updates

* small change

* various fixes

* remove dd for hunting detections

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-11-24 13:06:41 -08:00
Nasreddine Bencherchali 515d736c62 Add New ASA Analytics (#3794)
* first batch

* more updates

* update tags and filter

* more fixes

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* update to production

* fixes and updates

* update date and fix typos

* apply suggestion

* Update cisco_asa___reconnaissance_command_activity.yml

* add explicit message ids

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-11-21 14:50:18 -08:00
Br3akp0int 888c2249e8 netsupport (#3798)
* netsupport

* netsupport

* netsupport

* netsupport

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update data_sources/sysmon_eventid_29.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update data_sources/sysmon_eventid_29.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* netsupport

* netsupport

* netsupport

* netsupport

* updates

* small fixes

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-11-21 13:27:52 -08:00
Raven Tait 001a152933 NTLM Reflection via DNS Object SPN Spoofing (#3789)
* NTLM Reflection via DNS Object SPN Spoofing

* Update to user field

* update data source

* Adding fields manadated in the output fields of Sysmon EventID 22 data source

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-11-18 12:59:34 -08:00
James Hodgkinson 206f28f1c7 Fixing typo in suspicious_ollama_activities.yml (#3783) 2025-11-13 17:14:15 -08:00
Br3akp0int fcf1275e96 castlerat (#3750)
* castlerat

* castlerat

* castlerat

* castlerat

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-11-07 11:08:44 -08:00
Michael Haag 58bf9a1bc8 WSUSpect in Custody: CVE-2025-59287 (#3743)
* WSUSpect in Custody: CVE-2025-59287

* WSUS and Updates

* :jt_stare:

* Update windows_wsus_spawning_shell.yml

* Update w3wp_spawning_shell.yml

* deprecate rules and map analytic stories

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-10-27 09:48:44 -07:00
Nasreddine Bencherchali 0227a4f5f1 Add Oracle Exploitation Snort Coverage (#3742)
* add oracle snort coverage

* fix refs

* Update cisco_secure_firewall___oracle_e_business_suite_exploitation.yml
2025-10-23 14:49:04 -07:00
Raven Tait 7c092c7eb6 HTTP Request Smuggling (#3731)
* HTTP Request Smuggling

* Updates from PR comments

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-10-21 14:08:57 -07:00
Michael Haag 7b9274f9fb Scattered Lapsus$ Hunters (#3724)
* Scattered Lapsus$ Hunters

* fixes

* 👀

* bump versions

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-10-21 11:27:25 -07:00
Michael Haag a548ed769a Hellcat United (#3723)
* Hellcat United

* fixes

* 🍱

* 1 mas

* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Michael Haag 64ed5bb1e8 APT 37 and The No Good Rustonotto (#3686)
* APT 37 and The No Good Rustonotto

## Updated analytics
```
detections/application/detect_html_help_spawn_child_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/bitsadmin_download_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cobalt_strike_named_pipes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_rundll32_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/executables_or_script_creation_in_temp_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/icedid_exfiltrated_archived_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/lolbas_with_network_traffic.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_4104_hunting.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/processes_tapping_keyboard_events.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/registry_keys_used_for_persistence.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_curl_network_connection.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_image_creation_in_appdata_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_mshta_spawn.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_process_executed_from_container_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_scheduled_task_from_public_directory.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_alternate_datastream___base64_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_rar.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archived_collected_data_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_cab_file_on_disk.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_curl_download_to_suspicious_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_invoke_restmethod.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_powershell_uploadstring.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_file_download_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_high_file_deletion_frequency.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_http_network_communication_from_msiexec.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_indicator_removal_via_rmdir.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_input_capture_using_credential_ui_dll.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_iso_lnk_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_child_process_for_download.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_uncommon_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_executed_from_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_execution_from_programdata.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_commonly_abused_processes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_notepad.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_replication_through_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_command.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_name.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_service_created_with_suspicious_service_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_suspicious_driver_loaded_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_usbstor_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_wpdbusenum_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/winevent_scheduled_task_created_within_public_path.yml — APT37 Rustonotto and FadeStealer
detections/web/multiple_archive_files_http_post_traffic.yml — APT37 Rustonotto and FadeStealer
detections/web/plain_http_post_exfiltrated_data.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_expand_cabinet_file_extraction.yml — APT37 Rustonotto and FadeStealer
```

## New Story

```
stories/apt37_rustonotto_and_fadestealer.yml — APT37 Rustonotto and FadeStealer
```

* Create windows_expand_cabinet_file_extraction.yml

* Apply suggestion from @nasbench

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* updating conflicts

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 13:54:03 -07:00
Rod Soto 0bcb54b6f9 Ollama TA detections (#3710)
* commit1oll

* olldet2

* olldet3

* fixeddet3

* fixsp

* olldet4

* olldet5

* detoll6

* olldet7

* olldet8

* datasets

* testfixes

* modifiedtasearch

* lotsofixes

* fixednewta

* addedmorerefs

* fixedatasource

* fixedthreatobject

* fixedetectionandalertmessage

* fixedalermessage

* fixedquotes

* fixedhowtoimp

* fixeddescriptionandhowto

* changedestforuripat

* fixedowasplink

* Update detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/application/ollama_possible_rce_via_model_loading.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* protoexnassuggestions

* mionr

* remove index=*

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 21:54:37 +02:00
Rod Soto 6cf5b0f8f6 Copilot based Detections (#3693)
* det1

* fixeddt1

* det2

* d3

* det4

* djbk

* d6

* d7

* d8

* addedlnkds

* fixsctype

* pipegone

* fixp

* fixdevices

* jbfix

* datasetfix

* exp

* fixsynthax

* changedstory

* changeprinus

* improvedht

* changedSenderuser

* datas

* fixdoublesearch

* fixedpi

* fixeddescriptionsuser

* fixdatalink

* exportedlogsdatasource

* fixedhowtodatasource

* updating risk stuff

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 12:14:09 -07:00
Br3akp0int a52d560c80 lokibot (#3701)
* lokibot

* lokibot

* lokibot

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-10-10 18:32:18 +00:00
Bhavin Patel 3784436646 Merge branch 'develop' into promptlock 2025-09-29 12:06:29 -07:00
Bhavin Patel 8b2056475f Merge branch 'develop' into GhostRedirector 2025-09-29 11:34:54 -07:00
Bhavin Patel a1d2b73915 updating links 2025-09-25 18:23:04 -07:00
Bhavin Patel e51e23aab1 associating with new story 2025-09-25 18:19:34 -07:00
Bhavin Patel 46ab9105c9 updating links 2025-09-25 16:01:23 -07:00