Commit Graph

83 Commits

Author SHA1 Message Date
P4T12ICK 403ad09629 disable detection enrichment for stories 2022-03-30 14:29:57 +02:00
patel-bhavin bf0c64023f lookups 2022-03-29 08:37:14 -07:00
P4T12ICK afc1860132 Add Mitre Attack Csv generation 2022-03-29 12:14:20 +02:00
P4T12ICK 0fe8a854ec fixed api and mitre attack enrichment 2022-03-28 14:03:10 +02:00
Lou Stella 49b2b9f0d4 Updated ransomware_extensions.csv 2022-03-01 11:19:55 -06:00
patel-bhavin 68dde34dc8 rename typo 2022-02-24 14:14:13 -08:00
patel-bhavin 52d0996b0a combined the rest 2 2022-02-17 16:28:19 -08:00
patel-bhavin 9d780700de lookupss 2022-02-16 16:23:19 -08:00
Bhavin Patel 14c145c133 Merge pull request #1953 from splunk/potentially_malicious_code_on_commandline
Potentially malicious code on commandline
2022-01-28 13:27:59 -08:00
patel-bhavin fe5db9e78e adding lookup files 2022-01-26 15:34:10 -08:00
Michael Haag 67e413d0e0 Update __mlspl_unusual_commandline_detection.yml 2022-01-26 11:26:25 -07:00
Michael Hart 39d7121dcd Updating mlmodel to 5.3.x specification as well as the test apparatus 2022-01-25 21:42:16 -05:00
mhaag-spl befe09f77c Nirsoft Software 2022-01-24 15:07:20 -07:00
Michael Hart e962bfb4bd Merge branch 'develop' of github.com:splunk/security_content into potentially_malicious_code_on_commandline 2022-01-21 19:26:39 -05:00
pyth0n1c ad2324d863 Branch was auto-updated. 2022-01-20 16:07:09 -08:00
patel-bhavin 6d13de615c duplicate 2022-01-20 15:50:28 -08:00
mhaag-spl 5bfcf2eea3 InstallUtil and DotNet Assemblies 2022-01-20 14:34:04 -07:00
Michael Hart 14db58ca19 Adding a yaml file to ensure that contentctl copies the mlmodel file to the right place 2022-01-20 08:32:39 -05:00
Michael Hart 82e6efb466 Adding in model lookup file 2022-01-19 20:04:16 -05:00
mhaag-spl ee3e77b45c DefaultAccount 2021-11-15 14:30:14 -07:00
P4T12ICK 45fd279a31 updated detections 2021-09-06 10:59:00 +02:00
P4T12ICK 99f0349e9f circle ci detecction 2021-09-02 10:42:01 +02:00
P4T12ICK 7f980b6a46 circle ci detecction 2021-09-01 17:54:38 +02:00
P4T12ICK bbf0a39460 new detection 2021-08-23 13:07:23 +02:00
P4T12ICK 9f6ec5febb new detection 2021-08-23 11:39:21 +02:00
P4T12ICK 622442cd3a new detection 2021-08-23 10:21:21 +02:00
P4T12ICK 749df59357 new detection 2021-08-23 10:17:40 +02:00
patel-bhavin c3db579480 lookup bug in generate 2021-07-13 11:52:17 -05:00
patel-bhavin 50bdf277c6 lookup definitions 2021-07-12 19:02:32 -05:00
patel-bhavin a0a57ab600 atttacker_tools_files 2021-07-12 18:54:24 -05:00
tccontre 69b11d3471 rttp4 2021-06-25 10:21:04 +02:00
Vatsal Jagani 838bbc4a58 JSWorm ransomware notes and extensions added. 2021-06-02 16:26:02 +05:30
mhaag-spl 2b5eb6fbc4 Masquerading - detections + analytic story 2021-04-26 13:38:52 -06:00
tcontreras 48120285ba clop_lookup_entry 2021-03-23 17:00:55 +01:00
divious1 6afaf49e44 fixing error reported by user 2021-02-16 09:45:00 -05:00
David Dorsey 88c9469541 More language clean up 2021-01-22 09:37:51 -06:00
David Dorsey 26050fae29 More language clean up 2021-01-22 09:34:33 -06:00
bpatel f5e653a552 duplicate PR 2021-01-21 11:27:24 -08:00
bpatel 1075e6b175 adding the lost lookup file 2020-12-15 18:30:54 -08:00
P4T12ICK 5fee68375f fix_bugs 2020-12-11 10:51:02 +01:00
bpatel dd647457c6 more app inspect 2020-12-08 15:14:11 -08:00
bpatel 25c7f33866 app inspect failures fixes 2020-12-08 14:56:39 -08:00
Ԝеѕ 0f2056149f add additional suspicious file extensions
chm, vbe, additional media double ext exe's
2020-11-18 16:19:11 -05:00
bpatel 8895ffddf7 updating macro fields 2020-11-16 17:22:29 -08:00
Bhavin Patel 3aa06e82b6 Merge branch 'develop' into mustang_beta 2020-11-10 09:59:18 -08:00
divious1 77af8684bc ryuk story and detections 2020-11-06 12:32:48 -05:00
bpatel 0cce001a42 merge with develop 2020-10-19 11:19:41 -07:00
wesinator 91a8cf9e08 add additional dynamic domains
now-dns, other missing domains
2020-10-13 12:44:52 -04:00
bpatel abac1c8b62 convert to kvstore and spl updates 2020-10-12 12:14:50 -07:00
bpatel 97ac9c5f62 spl updates and kvstore file 2020-10-12 11:49:37 -07:00