Commit Graph

134 Commits

Author SHA1 Message Date
Xiao Lin 3369d15d72 rm wrong commit 2022-06-13 10:40:47 -07:00
pyth0n1c d5fa5ddc0b Branch was auto-updated. 2022-06-13 09:51:47 -07:00
Xiao Lin 6efcbd4b93 add risky command ML detection 2022-06-13 09:50:58 -07:00
pyth0n1c fe2713e077 Fixed a detection which was
using the wrong macro
2022-06-08 12:40:52 -07:00
pyth0n1c 47cd84d377 Wrong sourcetype declared in one
of the test files, causing it to fail.
Fixed missing backticks on some
macros.
2022-06-08 11:46:42 -07:00
pyth0n1c e8abbd916b Added missing _internal custom_indexes
to relevant test files.  Removed the |
character from searches that use 
index and sourcetype macros at the
beginning of the search.
2022-06-08 11:08:21 -07:00
pyth0n1c 3fb342d4c4 Fixed improperly named macro.
Renamed the macro in the tests
that use that macro. Added the
optional field, "custom_index"
to the test files which MUST
upload data into the _audit
index.  This branch doesn't
support custom_index yet,
but those changes will be merged
soon from another branch.
2022-06-08 10:31:53 -07:00
Rod Soto 61e827c41e added - to CVE 2022-06-01 17:38:28 -07:00
Rod Soto 9b6cd6a022 added tags 2022-06-01 17:31:53 -07:00
Rod Soto ae4dc00392 tags added 2022-06-01 17:21:54 -07:00
Rod Soto d5a1d0010e added cis tags 2022-06-01 17:19:38 -07:00
d1vious 97d51b71bf adding cves 2022-06-01 17:03:00 -04:00
Lou Stella 96a391dbc9 Updating DM 2022-05-31 10:38:13 -05:00
mhaag-spl ce599810c6 confidence 2022-05-27 15:00:35 -06:00
mhaag-spl 926e63649a delete usage 2022-05-27 14:41:34 -06:00
mhaag-spl 177a9736d3 Update splunk_command_and_scripting_interpreter_risky_commands.yml
fixed
2022-05-27 14:25:20 -06:00
mhaag-spl 21d5a68dd9 Splunk Command and Scripting Interpreter Risky Commands 2022-05-26 11:28:08 -06:00
Lou Stella 7d2a728085 anomaly for non TLS forwarders 2022-05-26 12:21:20 -05:00
Rod Soto d43d0ce270 killchain 2022-05-26 10:18:53 -07:00
Rod Soto 2a9d78d7fd fixedimpact 2022-05-26 10:16:31 -07:00
Rod Soto a1e472d68d MMerge branch 'vj9r' of github.com:splunk/security_content into vj9r
yup# Please enter a commit message to explain why this merge is necessary,
2022-05-26 10:08:45 -07:00
Rod Soto d0e6ef17ce fixedmacros 2022-05-26 10:08:38 -07:00
Lou Stella 7b1fb93a7e Merge branch 'vj9r' of https://github.com/splunk/security_content into vj9r 2022-05-26 12:05:16 -05:00
Lou Stella 234be83ef1 Updated observable 2022-05-26 12:05:14 -05:00
Rod Soto 4b7bfb516a terge branch 'vj9r' of github.com:splunk/security_content into vj9r 2022-05-26 10:00:24 -07:00
Rod Soto 522e569ced splkselfsigneddetection 2022-05-26 09:58:07 -07:00
Lou Stella 76f9fe7bbd Updated validation issues 2022-05-26 11:55:26 -05:00
Lou Stella ef9c0ab696 Updated references 2022-05-26 11:40:47 -05:00
Lou Stella 92037c5992 deployment server 2022-05-26 11:39:00 -05:00
Lou Stella 44a1886061 Missing field 2022-05-26 10:32:49 -05:00
Lou Stella a766811c56 0602 hunt 2022-05-26 10:32:09 -05:00
Rod Soto 39ee01a256 datasetx 2022-05-26 08:04:57 -07:00
Rod Soto f29d6f9920 renamedsearch 2022-05-26 07:44:46 -07:00
Rod Soto b9d79c5ab1 changednameofdetection 2022-05-26 07:25:17 -07:00
Lou Stella ef54563755 Adding detection 2022-05-25 13:54:26 -05:00
Rod Soto 6ee7163421 Hostname 2022-05-24 17:40:12 -07:00
Rod Soto 16641935e0 fixanotherytpo 2022-05-24 17:37:39 -07:00
Rod Soto 5680afbce7 fixtype 2022-05-24 17:35:46 -07:00
Rod Soto 99d314eeea initialsearchskeleton 2022-05-24 17:29:15 -07:00
Rod Soto a802fecce8 initialdraftc 2022-05-24 14:01:02 -07:00
Rod Soto 9d1e62c7d0 initialdraftb 2022-05-24 13:55:47 -07:00
Rod Soto 352ac64d51 initialdrafta 2022-05-24 13:12:46 -07:00
Rod Soto 872fa44741 initialdraft 2022-05-24 13:04:12 -07:00
Lou Stella eff1576b4b Required Fields 2022-05-02 15:22:41 -05:00
Lou Stella 3f7fdbb0dd Cleaned up search 2022-05-02 15:15:47 -05:00
Lou Stella 6fe602533b Removed detection 2022-05-02 14:30:43 -05:00
pyth0n1c 92e4622843 Branch was auto-updated. 2022-05-02 08:59:29 -07:00
Lou Stella 80e87b95d9 Dates & Refs 2022-05-02 09:50:39 -05:00
Rod Soto 5b59b4cf50 changedateindes 2022-04-29 15:03:37 -07:00
Rod Soto a71f12b921 Merge branch 'TR-1828' of github.com:splunk/security_content into TR-1828 2022-04-29 10:18:39 -07:00