Commit Graph

581 Commits

Author SHA1 Message Date
mvelazco d81df080b6 updating descriptions 2022-09-06 17:26:06 -04:00
mvelazco d8cce69644 adding new detection 2022-09-06 16:08:35 -04:00
mvelazco 3d308b862f adding new detection 2022-09-02 18:25:34 -04:00
mvelazco 441a1542bd adding new detection. fixing types. adding line to lookup 2022-09-02 18:03:14 -04:00
mvelazco 9e94c62a6a adding new detection 2022-08-30 18:25:25 -04:00
mvelazco 927d46a74e adding new detection 2022-08-30 13:07:41 -04:00
mvelazco 79f7f9c16e adding new detection 2022-08-29 17:00:05 -04:00
mvelazco 0473b83ffb minor fixes 2022-08-29 12:12:42 -04:00
mvelazco 024337cf62 improving detections 2022-08-29 11:46:57 -04:00
mvelazco d9226071a7 Merge branch 'TR-2390_Additional_Azure_Detections' of github.com:splunk/security_content into TR-2390_Additional_Azure_Detections 2022-08-29 11:24:02 -04:00
mvelazco 02976117ce improving detection 2022-08-29 11:24:00 -04:00
pyth0n1c 846867c7d4 Branch was auto-updated. 2022-08-25 16:25:57 -07:00
pyth0n1c a8c2a781be Branch was auto-updated. 2022-08-25 16:25:55 -07:00
pyth0n1c 474ea41291 Finishing updates authors, versions,
and dates on searches.
2022-08-25 15:09:13 -07:00
pyth0n1c 8b47ea7b36 Updating the author(s), versions, and
dates for searches in PR.
2022-08-25 15:08:46 -07:00
mvelazco 2a0c7a69d1 adding new detection 2022-08-25 16:02:54 -04:00
mvelazco 779ec07f0e adding description. updating dataset url 2022-08-24 11:13:03 -04:00
mvelazco f0926a5372 update detections 2022-08-23 23:40:54 -04:00
mvelazco 0a6592b9e2 adding new detection. fixing another 2022-08-23 21:45:22 -04:00
mvelazco 63398504c5 Merge branch 'TR-2361_Azure_AD_Persistence' of github.com:splunk/security_content into TR-2361_Azure_AD_Persistence 2022-08-23 16:28:56 -04:00
mvelazco 63f87f5a12 adding new detection 2022-08-23 16:28:55 -04:00
pyth0n1c a2f1972d54 Branch was auto-updated. 2022-08-23 13:05:56 -07:00
pyth0n1c a1b3e4c6f7 Branch was auto-updated. 2022-08-23 13:05:52 -07:00
pyth0n1c cfa60f73c5 Branch was auto-updated. 2022-08-22 14:51:16 -07:00
mvelazco 0a10ef85d6 fixing detection. adding azure_audit macro 2022-08-22 15:36:25 -04:00
gowthamarajr 136cbb1ea8 Add detection for "Azure AD External Guest User Invited" 2022-08-19 10:39:07 -04:00
mvelazco fae2c64476 adding new detection. other minor changes 2022-08-19 00:16:18 -04:00
mvelazco b81b41e137 small fixes 2022-08-18 17:46:34 -04:00
mvelazco 38ee247989 Merge branch 'TR-2361_Azure_AD_Persistence' of github.com:splunk/security_content into TR-2361_Azure_AD_Persistence 2022-08-18 14:50:18 -04:00
mvelazco 7b137ad6b9 adding new detection and fixing a few others 2022-08-18 14:50:16 -04:00
gowthamarajr 55c18d0c40 Update "Azure AD Service Principal Created" 2022-08-17 18:54:10 -04:00
gowthamarajr da48c720c6 Update "Azure AD Service Principal Created" 2022-08-17 18:53:22 -04:00
gowthamarajr 41a7f4380e Add 2 detections 2022-08-17 18:43:40 -04:00
mvelazco 393e7775f1 fixing typo 2022-08-16 12:19:07 -04:00
mvelazco b2332df9a0 Merge branch 'Update_Azure_Account_Takeover' of github.com:splunk/security_content into Update_Azure_Account_Takeover 2022-08-16 12:13:02 -04:00
mvelazco d00a4b2ae6 updating detection yaml 2022-08-16 12:13:00 -04:00
pyth0n1c 7d441871cb Branch was auto-updated. 2022-08-16 08:40:56 -07:00
gowthamarajr 6759feccd4 Add Azure AD Multi-Factor Authentication Disabled 2022-08-15 17:22:54 -04:00
patel-bhavin 1e4b0353f8 search update 2022-08-12 12:46:25 -07:00
patel-bhavin 6969671bf9 Merge branch 'TR_2329_AWS_Credential_Access' of github.com:splunk/security_content into TR_2329_AWS_Credential_Access 2022-08-12 12:41:19 -07:00
patel-bhavin 24cd1afcb8 updatesusing datamodel 2022-08-12 12:34:02 -07:00
Bhavin Patel 1952b9773b Update aws_credential_access_getpassworddata.yml 2022-08-11 12:10:47 -07:00
patel-bhavin 8d25d3d27a getpassworddata 2022-08-10 16:03:18 -07:00
mvelazco 5579f1ebdb adding new detection 2022-08-10 13:34:18 -04:00
patel-bhavin 8b6df0a600 tagged other detections 2022-08-09 16:25:16 -07:00
gowthamarajr 758f91deea Edit file for aws rds password detection 2022-08-08 02:30:59 -04:00
gowthamarajr 3cc956cd99 Add AWS Credential Access detections 2022-08-08 01:47:33 -04:00
root c71b04a866 Updated detection files with recommended TA list. 2022-08-01 18:43:39 +00:00
pyth0n1c 08107a940e Quoted strings in severity field. Fixed typo
in severity field list from UNKNWON to
UNKOWN.  Removed the non-existent
stats field 'user' (username exists) which
was causing the test to fail, returning
no results.
2022-07-31 15:09:35 -07:00
pyth0n1c 07d72ad142 Fixed a number of detections around anomalous aws
console logins from different areas.  These include
city, country, and region. They are all built around
the same template and could still use some discussion.
2022-07-29 14:22:50 -07:00