Bhavin Patel
15deedd635
chore: bump contentctl.yml to 5.23.0 ( #3913 )
...
Co-authored-by: research bot <research@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-20 10:51:49 +01:00
Bhavin Patel
07d5e7d54d
Updated TAs ( #3914 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-02-20 10:49:23 +01:00
Br3akp0int
c2044d9a99
Tag Content Related to Dynowiper/Zovwiper ( #3907 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
v5.22.0
2026-02-17 23:52:23 +01:00
Rod Soto
02573684ce
Add New MCP Related Detections ( #3895 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-02-17 23:39:01 +01:00
Br3akp0int
19181a86b5
Add Coverage and Tagging for the XML Runner Loader ( #3897 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-17 20:20:36 +01:00
Br3akp0int
6b9201dbc3
Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging ( #3902 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-17 20:02:11 +01:00
Bhavin Patel
79d24587f6
Issue - 3901 ( #3905 )
...
* cosolidation of detections
* updating test
2026-02-11 22:33:49 +05:30
Bhavin Patel
b29ba95b51
Updated TAs ( #3906 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-02-11 22:18:24 +05:30
Bhavin Patel
91ab062bb4
Updated TAs ( #3900 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-02-10 19:52:27 +05:30
bpluta-splunk
7cf9641f5f
upodated SPL based on new raw events ( #3898 )
...
* upodated SPL based on new raw events
* updating dataset link and data source file
---------
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-10 12:59:45 +05:30
Bhavin Patel
d13e377a27
Bump contentctl.yml to 5.22.0 ( #3894 )
...
* chore: bump contentctl.yml to 5.22.0
* remove detections
---------
Co-authored-by: research bot <research@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-02-10 10:27:49 +05:30
Lou Stella
84c05196d0
Merge pull request #3903 from splunk/contentctl_bump
...
Bumping contentctl
2026-02-09 12:42:20 -05:00
ljstella
7e19147038
Bumping contentctl
2026-02-09 11:21:18 -05:00
Lou Stella
2e7660be9c
XML Windows Event Log Cleanup continued ( #3887 )
...
* Ported to XmlWinEventlog
* missed one change
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-06 18:58:37 +05:30
Bhavin Patel
a43838a3f5
Automated Splunk TA Update 532 ( #3891 )
...
* Updated TAs
* Update Splunk app version and hardcoded path
---------
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-06 18:21:07 +05:30
Lou Stella
73b2b82c67
Merge pull request #3890 from splunk/bump_contentctl_5_5_13
v5.21.0
2026-02-03 17:53:50 -05:00
pyth0n1c
252f1f6002
Update contentctl version to 5.5.13
2026-02-03 14:48:29 -08:00
Lou Stella
c09c341ae4
Default.meta changes for default savedsearch stanza ( #3815 )
...
* Default.meta changes for default savedsearch stanza
* Update casing
* Bumping for new version with associated changes
* Version bump of contentctl for fixes
2026-02-03 22:37:54 +05:30
Br3akp0int
b5280b610d
browser_hijacking_2 ( #3879 )
...
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* browser_hijacking_2
* Update detections/endpoint/headless_browser_usage.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_browser_launched_with_small_window_size.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_launched_with_disable_popup_blocking.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_with_disabled_extensions.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_with_disabled_extensions.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_browser_launched_with_small_window_size.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_launched_with_disable_popup_blocking.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_loaded_extension_via_command_line.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_launched_with_logging_disabled.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_chromium_process_launched_with_logging_disabled.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* browser_hijacking_2
* Apply suggestion from @nasbench
* Refactor description in windows_chromium_process_launched_with_logging_disabled.yml
Updated the description format for clarity and readability.
* Change type to 'Anomaly' and refine description
Updated the type from 'TTP' to 'Anomaly' and modified the description for clarity.
* Enhance alert message with window dimensions
Added window dimensions to the alert message for clarity.
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-02 20:46:50 +05:30
Vignesh
7777dd91cb
Add Windows TOR Client Execution Detected ( #3881 )
...
* Add Windows TOR Client Execution Detected
This detection is used to detects the execution of TOR browser and it's components on windows systems.
If you need any further information, please reach out to me via Slack.
Slack ID - Vignesh Subramanian
* Update Windows TOR Client Execution Detection
1. Focused on detecting tor.exe and added the process_path field to detect TOR execution within Brave Browser.
Brave Browser includes a built-in TOR client that is not explicitly named tor.exe during process creation; instead, it appears as tor-0.4.8.19-win32-brave-0. To capture this, I added the Brave Browser path to the detection logic to identify the presence of TOR within Brave.
I also introduced wildcards in the path to support any version TOR binaries used by Brave, ensuring that different version numbers are correctly matched.
2. Avoided using escape characters to improve readability.
3. The provided ID has been added.
4. The process field has been added as a threat object.
5. Additional tokens have been included in the risk-based alerting message to make it clearer and more meaningful.
6. The word “detection” has been removed from the title, which is now: "Windows TOR Client Execution"
7. Added the correct attack dataset link from (https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1090.003/windows_tor_client_execution/windows-sysmon.log )
* Revise Windows TOR Client Execution detection details
Updated the detection configuration for Windows TOR Client Execution, including changes to the description, how to implement, known false positives, and drilldown searches.
---------
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-02-02 20:02:06 +05:30
Bhavin Patel
c233cf9c04
Updated TAs ( #3884 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-01-31 19:40:56 +01:00
Raven Tait
56675d5fc7
Telnet Auth Bypass CVE ( #3883 )
...
* Telnet Auth Bypass
* Fix CVE in story
* Update rba message
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update rba and description
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-31 10:32:53 +05:30
Nasreddine Bencherchali
a266563b00
Update RBA, logic, and beautify some searches ( #3880 )
...
* Update RBA, logic, and beautify searches
* Update internal_horizontal_port_scan_nmap_top_20.yml
2026-01-31 09:57:04 +05:30
Nasreddine Bencherchali
c50763d938
Fix Reported Issues ( #3873 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-30 16:34:18 +01:00
Andrei Banaru
28a213f97f
Add Missing Time to Set Default PowerShell Execution Policy To Unrestricted or Bypass ( #3882 )
...
---------
Co-authored-by: Andrei Banaru <a.banaru@iaea.org >
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-30 12:41:19 +01:00
Nasreddine Bencherchali
f49f3a3fc9
Fix Validation Issues ( #3861 )
2026-01-30 01:38:34 +01:00
Bhavin Patel
29ece397e8
Update Outlook writing zip Analytic ( #3877 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-28 13:49:21 +01:00
Alex
f1693a1a0a
Fix search typo in windows abused web services analytic ( #3878 )
2026-01-24 14:38:30 +01:00
Bhavin Patel
060feb0a42
Updating Query Based on XS Data ( #3876 )
2026-01-23 15:49:23 +01:00
Bhavin Patel
d080ba9f06
Updating Terminology for ES8+ ( #3875 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-22 22:59:29 +01:00
Michael Haag
b6b0b47a66
Storm-0501 Ransomware Analytic Story and Tagging ( #3871 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-01-22 22:32:14 +01:00
Michael Haag
d08d829807
VoidLink Tagging ( #3870 )
...
* VoidLink
* Update linux_adding_crontab_using_list_parameter.yml
* version
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 19:53:15 +05:30
Br3akp0int
73e69c0b84
stealc ( #3833 )
...
* stealc
* stealc
* stealc
* updating versions
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-01-22 18:51:16 +05:30
Emil
9c9482bfb9
Additional information in Risk Message for Services LOLBAS spawn detection ( #3874 )
...
* Adding process_name to risk_message as this gives a better further insigth into the LOLBAS activity observed
* Ensuring message is a string
* Adding suggestions from @nasbench, sticking with process as threat_object as this gives the most information, also bumping version and date
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 12:38:58 +00:00
Nasreddine Bencherchali
76f629eb2f
Update Analytics Performance ( #3866 )
...
* Update common_ransomware_notes.yml
* Update detect_rare_executables.yml
* update samsam ext
* update where clause to include null checks
* appinspect fixes
* reduce version
* fix where issue
* Update ransomware_notes_lookup.csv
* more perf enhancements
* Update windows_dotnet_binary_in_non_standard_path.yml
* fix ci issue and enhance description
* Update common_ransomware_extensions.yml
* Update common_ransomware_extensions.yml
* remove unknown and dash values
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 12:36:31 +00:00
Bhavin Patel
ce2de7a83c
chore: bump contentctl.yml to 5.21.0 ( #3872 )
...
Co-authored-by: research bot <research@splunk.com >
2026-01-21 16:04:40 +01:00
Oliver Springer
2008331fbb
O365 - Expand Detection of New MFA Devices ( #3868 )
...
* Also detect the registration of new mobile authenticator apps
* Update o365_new_mfa_method_registered.yml
---------
Co-authored-by: Oliver Springer <9538543+JTweet@users.noreply.github.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
v5.20.0
2026-01-20 09:22:23 +05:30
Lou Stella
d51b057f0b
Merge pull request #3865 from LaLaGuy/patch---ESCU---Prohibited-Network-Traffic-Allowed---Rule
...
Refactor search query for prohibited network traffic
2026-01-16 13:35:52 -06:00
ljstella
c84715dd99
New Year, New Fixes
2026-01-16 13:19:35 -05:00
Lou Stella
0fd8a68691
Merge branch 'develop' into patch---ESCU---Prohibited-Network-Traffic-Allowed---Rule
2026-01-16 11:24:33 -06:00
LaLaGuy
4ce7a1ddcc
Update version and date in prohibited network traffic config
2026-01-16 16:45:48 +01:00
Raven Tait
20b0368e51
Added New HijackLibs Entry ( #3864 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-15 20:40:42 +01:00
LaLaGuy
f9e8e6e601
Fix formatting and syntax in prohibited network traffic YAML
...
space to activate CI.
2026-01-15 19:59:08 +01:00
LaLaGuy
e2443809bb
Refactor search query for prohibited network traffic
...
### **Describe the bug**
When interesting_ports_lookup is used, only the port is checked, not the protocol.
Plus, only the first result is returned.
This lookup include several entries for the same port (like 514 rsh/syslog) and the wrong entry can get returned.
This create false match. The wrong enrichment is given (including a wrong transport method) and a notable is generated when it shouldn't.
It can also be greatly optimized by moving the filter logic to the where of the tstats.
### **Expected behavior**
If a 514 udp is detected by the firewall, it should match syslog and not create a notable (or risk) telling me we detected a rsh 514 tcp.
### **Additional context**
Here is a solution (we get the transport from the log instead of adding it from the lookup, add transport to the match and move the filter logique up).
2026-01-15 19:44:41 +01:00
Bhavin Patel
26b24aaa6e
in prep for v5.20.0 ( #3862 )
2026-01-15 01:20:02 +05:30
Bhavin Patel
5f2d1c77e1
fix ( #3859 )
2026-01-14 11:12:32 +05:30
Nasreddine Bencherchali
6cc12a9b29
Analytic Enhancements and Fixes ( #3850 )
...
* update `Windows LOLBAS Executed Outside Expected Path`
* Update suspicious_email_attachment_extensions.yml
* update susp extension lookup
* some additional fixes
* Update system_processes_run_from_unexpected_locations.yml
* small changes
* Update detect_rtlo_in_file_name.yml
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-12 18:36:12 +05:30
Br3akp0int
49673747bf
Add Browser Hijack Analytics ( #3841 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-12 13:05:22 +01:00
Nasreddine Bencherchali
7941673530
Add Snort/IOS Correlation and Other Things ( #3857 )
2026-01-12 12:15:11 +01:00
Bhavin Patel
06db914290
Updated TAs ( #3858 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-01-10 14:20:32 +01:00