Xiao Lin
3369d15d72
rm wrong commit
2022-06-13 10:40:47 -07:00
pyth0n1c
d5fa5ddc0b
Branch was auto-updated.
2022-06-13 09:51:47 -07:00
Xiao Lin
6efcbd4b93
add risky command ML detection
2022-06-13 09:50:58 -07:00
pyth0n1c
fe2713e077
Fixed a detection which was
...
using the wrong macro
2022-06-08 12:40:52 -07:00
pyth0n1c
47cd84d377
Wrong sourcetype declared in one
...
of the test files, causing it to fail.
Fixed missing backticks on some
macros.
2022-06-08 11:46:42 -07:00
pyth0n1c
e8abbd916b
Added missing _internal custom_indexes
...
to relevant test files. Removed the |
character from searches that use
index and sourcetype macros at the
beginning of the search.
2022-06-08 11:08:21 -07:00
pyth0n1c
3fb342d4c4
Fixed improperly named macro.
...
Renamed the macro in the tests
that use that macro. Added the
optional field, "custom_index"
to the test files which MUST
upload data into the _audit
index. This branch doesn't
support custom_index yet,
but those changes will be merged
soon from another branch.
2022-06-08 10:31:53 -07:00
Rod Soto
61e827c41e
added - to CVE
2022-06-01 17:38:28 -07:00
Rod Soto
9b6cd6a022
added tags
2022-06-01 17:31:53 -07:00
Rod Soto
ae4dc00392
tags added
2022-06-01 17:21:54 -07:00
Rod Soto
d5a1d0010e
added cis tags
2022-06-01 17:19:38 -07:00
d1vious
97d51b71bf
adding cves
2022-06-01 17:03:00 -04:00
Lou Stella
96a391dbc9
Updating DM
2022-05-31 10:38:13 -05:00
mhaag-spl
ce599810c6
confidence
2022-05-27 15:00:35 -06:00
mhaag-spl
926e63649a
delete usage
2022-05-27 14:41:34 -06:00
mhaag-spl
177a9736d3
Update splunk_command_and_scripting_interpreter_risky_commands.yml
...
fixed
2022-05-27 14:25:20 -06:00
mhaag-spl
21d5a68dd9
Splunk Command and Scripting Interpreter Risky Commands
2022-05-26 11:28:08 -06:00
Lou Stella
7d2a728085
anomaly for non TLS forwarders
2022-05-26 12:21:20 -05:00
Rod Soto
d43d0ce270
killchain
2022-05-26 10:18:53 -07:00
Rod Soto
2a9d78d7fd
fixedimpact
2022-05-26 10:16:31 -07:00
Rod Soto
a1e472d68d
MMerge branch 'vj9r' of github.com:splunk/security_content into vj9r
...
yup# Please enter a commit message to explain why this merge is necessary,
2022-05-26 10:08:45 -07:00
Rod Soto
d0e6ef17ce
fixedmacros
2022-05-26 10:08:38 -07:00
Lou Stella
7b1fb93a7e
Merge branch 'vj9r' of https://github.com/splunk/security_content into vj9r
2022-05-26 12:05:16 -05:00
Lou Stella
234be83ef1
Updated observable
2022-05-26 12:05:14 -05:00
Rod Soto
4b7bfb516a
terge branch 'vj9r' of github.com:splunk/security_content into vj9r
2022-05-26 10:00:24 -07:00
Rod Soto
522e569ced
splkselfsigneddetection
2022-05-26 09:58:07 -07:00
Lou Stella
76f9fe7bbd
Updated validation issues
2022-05-26 11:55:26 -05:00
Lou Stella
ef9c0ab696
Updated references
2022-05-26 11:40:47 -05:00
Lou Stella
92037c5992
deployment server
2022-05-26 11:39:00 -05:00
Lou Stella
44a1886061
Missing field
2022-05-26 10:32:49 -05:00
Lou Stella
a766811c56
0602 hunt
2022-05-26 10:32:09 -05:00
Rod Soto
39ee01a256
datasetx
2022-05-26 08:04:57 -07:00
Rod Soto
f29d6f9920
renamedsearch
2022-05-26 07:44:46 -07:00
Rod Soto
b9d79c5ab1
changednameofdetection
2022-05-26 07:25:17 -07:00
Lou Stella
ef54563755
Adding detection
2022-05-25 13:54:26 -05:00
Rod Soto
6ee7163421
Hostname
2022-05-24 17:40:12 -07:00
Rod Soto
16641935e0
fixanotherytpo
2022-05-24 17:37:39 -07:00
Rod Soto
5680afbce7
fixtype
2022-05-24 17:35:46 -07:00
Rod Soto
99d314eeea
initialsearchskeleton
2022-05-24 17:29:15 -07:00
Rod Soto
a802fecce8
initialdraftc
2022-05-24 14:01:02 -07:00
Rod Soto
9d1e62c7d0
initialdraftb
2022-05-24 13:55:47 -07:00
Rod Soto
352ac64d51
initialdrafta
2022-05-24 13:12:46 -07:00
Rod Soto
872fa44741
initialdraft
2022-05-24 13:04:12 -07:00
Lou Stella
eff1576b4b
Required Fields
2022-05-02 15:22:41 -05:00
Lou Stella
3f7fdbb0dd
Cleaned up search
2022-05-02 15:15:47 -05:00
Lou Stella
6fe602533b
Removed detection
2022-05-02 14:30:43 -05:00
pyth0n1c
92e4622843
Branch was auto-updated.
2022-05-02 08:59:29 -07:00
Lou Stella
80e87b95d9
Dates & Refs
2022-05-02 09:50:39 -05:00
Rod Soto
5b59b4cf50
changedateindes
2022-04-29 15:03:37 -07:00
Rod Soto
a71f12b921
Merge branch 'TR-1828' of github.com:splunk/security_content into TR-1828
2022-04-29 10:18:39 -07:00