Commit Graph

18530 Commits

Author SHA1 Message Date
mvelazco 3d308b862f adding new detection 2022-09-02 18:25:34 -04:00
mvelazco 441a1542bd adding new detection. fixing types. adding line to lookup 2022-09-02 18:03:14 -04:00
Michael Haag f0601e4f9d Update ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.yml 2022-09-02 15:04:47 -06:00
Michael Haag 6287645f48 BA 2022-09-02 14:44:39 -06:00
Michael Haag 171f7e2b80 id fix 2022-09-01 15:10:29 -06:00
Michael Haag affae7229d SSA all things 2022-09-01 15:02:44 -06:00
pyth0n1c 31cd39763b Remove a number of updated
files which don't yet exist
in develop and should not have
been in this branch to begin with.
They will be merged as part of
a separate PR.
2022-09-01 12:34:12 -04:00
pyth0n1c fc1db0c161 Fixing modified detection so that it
has its original value.
2022-09-01 12:25:53 -04:00
tccontre e80c5c4e85 Update windows_access_token_manipulation_winlogon_duplicate_token_handle.yml 2022-09-01 18:06:44 +02:00
pyth0n1c 640f932419 Added bubbling up errors so that they can be handled by higher level functions. 2022-09-01 11:47:29 -04:00
pyth0n1c 6da8bc32c1 INTENTIONALLY
INTRODUCES AN ERROR
TO TEST UPDATED
VALIDATION AND PYTEST
WORKFLOWS. REMOVE
THIS CHANGE BEFORE
MERGING THIS PR.
2022-09-01 11:00:02 -04:00
tccontre f68b07ff28 Merge branch 'brute-ratel-3' of github.com:splunk/security_content into brute-ratel-3 2022-09-01 16:42:45 +02:00
tccontre a482779b41 brute-ratel-3 2022-09-01 16:42:25 +02:00
tccontre 324b58bf12 Update windows_service_deletion_in_registry.yml 2022-09-01 15:40:48 +02:00
tccontre d764f48a29 Update windows_input_capture_using_credential_ui_dll.yml 2022-09-01 15:39:08 +02:00
tccontre 8abf778411 Update windows_gather_victim_identity_sam_info.yml 2022-09-01 15:38:42 +02:00
tccontre 25ec32f85d Merge branch 'brute-ratel-3' of github.com:splunk/security_content into brute-ratel-3 2022-09-01 15:18:54 +02:00
tccontre c1491e38d1 brute-ratel-3 2022-09-01 15:18:30 +02:00
tccontre bfee7c9b0a Delete windows_phishing_recent_iso_exec_registry.yml 2022-09-01 13:20:57 +02:00
tccontre d06f714dbb Delete windows_input_capture_using_credential_ui_dll.yml 2022-09-01 13:20:48 +02:00
tccontre c1b7d97eb3 Delete windows_hijack_execution_flow_version_dll_side_load.yml 2022-09-01 13:20:39 +02:00
tccontre 5bcc2edeeb Delete windows_remote_access_software_brc4_loaded_dll.yml 2022-09-01 13:20:25 +02:00
tccontre a04fd01b34 Delete windows_gather_victim_identity_sam_info.test.yml 2022-09-01 13:20:14 +02:00
tccontre 42cf9d4d02 Delete windows_hijack_execution_flow_version_dll_side_load.test.yml 2022-09-01 13:20:04 +02:00
tccontre 183f1f689e Delete windows_input_capture_using_credential_ui_dll.test.yml 2022-09-01 13:19:55 +02:00
tccontre 22721a4554 Delete windows_phishing_recent_iso_exec_registry.test.yml 2022-09-01 13:19:45 +02:00
tccontre ce4f5e5ad3 Delete windows_remote_access_software_brc4_loaded_dll.test.yml 2022-09-01 13:19:35 +02:00
tccontre 954a9e9dd3 Delete windows_gather_victim_identity_sam_info.yml 2022-09-01 13:19:19 +02:00
tccontre 506732a62b brute-ratel-3 2022-09-01 13:16:24 +02:00
tccontre 1557a528cf brute-ratel-2 2022-08-31 10:12:55 +02:00
tccontre c8f038be5d Update windows_remote_access_software_brc4_loaded_dll.yml 2022-08-31 09:44:21 +02:00
mvelazco 9e94c62a6a adding new detection 2022-08-30 18:25:25 -04:00
Rod Soto 537c13d063 addedwords 2022-08-30 11:56:41 -07:00
Michael Haag 4d2c2028bc Update linux_persistence_and_privilege_escalation_risk_behavior.yml 2022-08-30 11:44:59 -06:00
Michael Haag 126049593e Updates 2022-08-30 11:21:46 -06:00
mvelazco 927d46a74e adding new detection 2022-08-30 13:07:41 -04:00
tccontre e90fa05a96 Update windows_remote_access_software_brc4_loaded_dll.yml 2022-08-30 17:49:16 +02:00
tccontre ec1a26ed46 Update windows_phishing_recent_iso_exec_registry.yml 2022-08-30 17:46:57 +02:00
tccontre d91a14c4d4 Update windows_hijack_execution_flow_version_dll_side_load.yml 2022-08-30 17:42:04 +02:00
Michael Haag 44bc5ac3da Update windows_ingress_tool_transfer_using_explorer.yml 2022-08-30 06:38:55 -06:00
Michael Haag e9484c657f Update ssa___windows_lolbin_binary_in_non_standard_path.yml 2022-08-30 06:31:00 -06:00
tccontre 8d6d137ba1 Update windows_remote_access_software_brc4_loaded_dll.yml 2022-08-30 13:11:24 +02:00
tccontre b401ed9d50 brute-ratel-2 2022-08-30 13:08:04 +02:00
mvelazco 6e07f25d0b fixing lookup name typo 2022-08-29 17:30:34 -04:00
mvelazco 79f7f9c16e adding new detection 2022-08-29 17:00:05 -04:00
research bot 2adb6ca2ff updating docs and package bits [ci skip] 2022-08-29 17:48:48 +00:00
tccontre 34c6bb1887 Rename windows_service_created_in_uncommon_service_path.test.yml to windows_service_created_with_suspicious_service_path.test.yml 2022-08-29 19:09:19 +02:00
tccontre c79cb8f97b Update windows_service_created_in_uncommon_service_path.test.yml 2022-08-29 19:05:32 +02:00
tccontre b59f8ecd34 Update and rename windows_service_created_in_uncommon_service_path.yml to windows_service_created_with_suspicious_service_path.yml
windows_service_created_with_suspicious_service_path_filter
2022-08-29 19:04:50 +02:00
mvelazco 0473b83ffb minor fixes 2022-08-29 12:12:42 -04:00