Commit Graph

27956 Commits

Author SHA1 Message Date
Bhavin Patel 15deedd635 chore: bump contentctl.yml to 5.23.0 (#3913)
Co-authored-by: research bot <research@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-20 10:51:49 +01:00
Bhavin Patel 07d5e7d54d Updated TAs (#3914)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-20 10:49:23 +01:00
Br3akp0int c2044d9a99 Tag Content Related to Dynowiper/Zovwiper (#3907)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
v5.22.0
2026-02-17 23:52:23 +01:00
Rod Soto 02573684ce Add New MCP Related Detections (#3895)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-02-17 23:39:01 +01:00
Br3akp0int 19181a86b5 Add Coverage and Tagging for the XML Runner Loader (#3897)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:20:36 +01:00
Br3akp0int 6b9201dbc3 Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging (#3902)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:02:11 +01:00
Bhavin Patel 79d24587f6 Issue - 3901 (#3905)
* cosolidation of detections

* updating test
2026-02-11 22:33:49 +05:30
Bhavin Patel b29ba95b51 Updated TAs (#3906)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-11 22:18:24 +05:30
Bhavin Patel 91ab062bb4 Updated TAs (#3900)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-10 19:52:27 +05:30
bpluta-splunk 7cf9641f5f upodated SPL based on new raw events (#3898)
* upodated SPL based on new raw events

* updating dataset link and data source file

---------

Co-authored-by: Bhavin Patel <bpatel@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-10 12:59:45 +05:30
Bhavin Patel d13e377a27 Bump contentctl.yml to 5.22.0 (#3894)
* chore: bump contentctl.yml to 5.22.0

* remove detections

---------

Co-authored-by: research bot <research@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-02-10 10:27:49 +05:30
Lou Stella 84c05196d0 Merge pull request #3903 from splunk/contentctl_bump
Bumping contentctl
2026-02-09 12:42:20 -05:00
ljstella 7e19147038 Bumping contentctl 2026-02-09 11:21:18 -05:00
Lou Stella 2e7660be9c XML Windows Event Log Cleanup continued (#3887)
* Ported to XmlWinEventlog

* missed one change

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-06 18:58:37 +05:30
Bhavin Patel a43838a3f5 Automated Splunk TA Update 532 (#3891)
* Updated TAs

* Update Splunk app version and hardcoded path

---------

Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-06 18:21:07 +05:30
Lou Stella 73b2b82c67 Merge pull request #3890 from splunk/bump_contentctl_5_5_13 v5.21.0 2026-02-03 17:53:50 -05:00
pyth0n1c 252f1f6002 Update contentctl version to 5.5.13 2026-02-03 14:48:29 -08:00
Lou Stella c09c341ae4 Default.meta changes for default savedsearch stanza (#3815)
* Default.meta changes for default savedsearch stanza

* Update casing

* Bumping for new version with associated changes

* Version bump of contentctl for fixes
2026-02-03 22:37:54 +05:30
Br3akp0int b5280b610d browser_hijacking_2 (#3879)
* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* browser_hijacking_2

* Update detections/endpoint/headless_browser_usage.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_browser_launched_with_small_window_size.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_launched_with_disable_popup_blocking.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_with_disabled_extensions.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_with_disabled_extensions.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_browser_launched_with_small_window_size.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_launched_with_disable_popup_blocking.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_loaded_extension_via_command_line.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_launched_with_logging_disabled.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_chromium_process_launched_with_logging_disabled.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* browser_hijacking_2

* Apply suggestion from @nasbench

* Refactor description in windows_chromium_process_launched_with_logging_disabled.yml

Updated the description format for clarity and readability.

* Change type to 'Anomaly' and refine description

Updated the type from 'TTP' to 'Anomaly' and modified the description for clarity.

* Enhance alert message with window dimensions

Added window dimensions to the alert message for clarity.

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-02 20:46:50 +05:30
Vignesh 7777dd91cb Add Windows TOR Client Execution Detected (#3881)
* Add Windows TOR Client Execution Detected

This detection is used to detects the execution of TOR browser and it's components on windows systems.

If you need any further information, please reach out to me via Slack.

Slack ID - Vignesh Subramanian

* Update Windows TOR Client Execution Detection

1. Focused on detecting tor.exe and added the process_path field to detect TOR execution within Brave Browser. 

Brave Browser includes a built-in TOR client that is not explicitly named tor.exe during process creation; instead, it appears as tor-0.4.8.19-win32-brave-0. To capture this, I added the Brave Browser path to the detection logic to identify the presence of TOR within Brave. 

I also introduced wildcards in the path to support any version TOR binaries used by Brave, ensuring that different version numbers are correctly matched. 

2. Avoided using escape characters to improve readability.

3. The provided ID has been added.

4. The process field has been added as a threat object.

5. Additional tokens have been included in the risk-based alerting message to make it clearer and more meaningful.

6. The word “detection” has been removed from the title, which is now: "Windows TOR Client Execution"

7. Added the correct attack dataset link from (https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1090.003/windows_tor_client_execution/windows-sysmon.log)

* Revise Windows TOR Client Execution detection details

Updated the detection configuration for Windows TOR Client Execution, including changes to the description, how to implement, known false positives, and drilldown searches.

---------

Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-02 20:02:06 +05:30
Bhavin Patel c233cf9c04 Updated TAs (#3884)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-01-31 19:40:56 +01:00
Raven Tait 56675d5fc7 Telnet Auth Bypass CVE (#3883)
* Telnet Auth Bypass

* Fix CVE in story

* Update rba message

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update rba and description

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-31 10:32:53 +05:30
Nasreddine Bencherchali a266563b00 Update RBA, logic, and beautify some searches (#3880)
* Update RBA, logic, and beautify searches

* Update internal_horizontal_port_scan_nmap_top_20.yml
2026-01-31 09:57:04 +05:30
Nasreddine Bencherchali c50763d938 Fix Reported Issues (#3873)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-30 16:34:18 +01:00
Andrei Banaru 28a213f97f Add Missing Time to Set Default PowerShell Execution Policy To Unrestricted or Bypass (#3882)
---------

Co-authored-by: Andrei Banaru <a.banaru@iaea.org>
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-30 12:41:19 +01:00
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Bhavin Patel 29ece397e8 Update Outlook writing zip Analytic (#3877)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-28 13:49:21 +01:00
Alex f1693a1a0a Fix search typo in windows abused web services analytic (#3878) 2026-01-24 14:38:30 +01:00
Bhavin Patel 060feb0a42 Updating Query Based on XS Data (#3876) 2026-01-23 15:49:23 +01:00
Bhavin Patel d080ba9f06 Updating Terminology for ES8+ (#3875)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-22 22:59:29 +01:00
Michael Haag b6b0b47a66 Storm-0501 Ransomware Analytic Story and Tagging (#3871)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-01-22 22:32:14 +01:00
Michael Haag d08d829807 VoidLink Tagging (#3870)
* VoidLink

* Update linux_adding_crontab_using_list_parameter.yml

* version

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 19:53:15 +05:30
Br3akp0int 73e69c0b84 stealc (#3833)
* stealc

* stealc

* stealc

* updating versions

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-01-22 18:51:16 +05:30
Emil 9c9482bfb9 Additional information in Risk Message for Services LOLBAS spawn detection (#3874)
* Adding process_name to risk_message as this gives a better further insigth into the LOLBAS activity observed

* Ensuring message is a string

* Adding suggestions from @nasbench, sticking with process as threat_object as this gives the most information, also bumping version and date

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 12:38:58 +00:00
Nasreddine Bencherchali 76f629eb2f Update Analytics Performance (#3866)
* Update common_ransomware_notes.yml

* Update detect_rare_executables.yml

* update samsam ext

* update where clause to include null checks

* appinspect fixes

* reduce version

* fix where issue

* Update ransomware_notes_lookup.csv

* more perf enhancements

* Update windows_dotnet_binary_in_non_standard_path.yml

* fix ci issue and enhance description

* Update common_ransomware_extensions.yml

* Update common_ransomware_extensions.yml

* remove unknown and dash values

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 12:36:31 +00:00
Bhavin Patel ce2de7a83c chore: bump contentctl.yml to 5.21.0 (#3872)
Co-authored-by: research bot <research@splunk.com>
2026-01-21 16:04:40 +01:00
Oliver Springer 2008331fbb O365 - Expand Detection of New MFA Devices (#3868)
* Also detect the registration of new mobile authenticator apps

* Update o365_new_mfa_method_registered.yml

---------

Co-authored-by: Oliver Springer <9538543+JTweet@users.noreply.github.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
v5.20.0
2026-01-20 09:22:23 +05:30
Lou Stella d51b057f0b Merge pull request #3865 from LaLaGuy/patch---ESCU---Prohibited-Network-Traffic-Allowed---Rule
Refactor search query for prohibited network traffic
2026-01-16 13:35:52 -06:00
ljstella c84715dd99 New Year, New Fixes 2026-01-16 13:19:35 -05:00
Lou Stella 0fd8a68691 Merge branch 'develop' into patch---ESCU---Prohibited-Network-Traffic-Allowed---Rule 2026-01-16 11:24:33 -06:00
LaLaGuy 4ce7a1ddcc Update version and date in prohibited network traffic config 2026-01-16 16:45:48 +01:00
Raven Tait 20b0368e51 Added New HijackLibs Entry (#3864)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-15 20:40:42 +01:00
LaLaGuy f9e8e6e601 Fix formatting and syntax in prohibited network traffic YAML
space to activate CI.
2026-01-15 19:59:08 +01:00
LaLaGuy e2443809bb Refactor search query for prohibited network traffic
### **Describe the bug**
When interesting_ports_lookup is used, only the port is checked, not the protocol.
Plus, only the first result is returned.
This lookup include several entries for the same port (like 514 rsh/syslog) and the wrong entry can get returned.
This create false match. The wrong enrichment is given (including a wrong transport method) and a notable is generated when it shouldn't.
It can also be greatly optimized by moving the filter logic to the where of the tstats.

### **Expected behavior**
If a 514 udp is detected by the firewall, it should match syslog and not create a notable (or risk) telling me we detected a rsh 514 tcp.

### **Additional context**
Here is a solution (we get the transport from the log instead of adding it from the lookup, add transport to the match and move the filter logique up).
2026-01-15 19:44:41 +01:00
Bhavin Patel 26b24aaa6e in prep for v5.20.0 (#3862) 2026-01-15 01:20:02 +05:30
Bhavin Patel 5f2d1c77e1 fix (#3859) 2026-01-14 11:12:32 +05:30
Nasreddine Bencherchali 6cc12a9b29 Analytic Enhancements and Fixes (#3850)
* update `Windows LOLBAS Executed Outside Expected Path`

* Update suspicious_email_attachment_extensions.yml

* update susp extension lookup

* some additional fixes

* Update system_processes_run_from_unexpected_locations.yml

* small changes

* Update detect_rtlo_in_file_name.yml

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-12 18:36:12 +05:30
Br3akp0int 49673747bf Add Browser Hijack Analytics (#3841)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-12 13:05:22 +01:00
Nasreddine Bencherchali 7941673530 Add Snort/IOS Correlation and Other Things (#3857) 2026-01-12 12:15:11 +01:00
Bhavin Patel 06db914290 Updated TAs (#3858)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-01-10 14:20:32 +01:00