Commit Graph

17653 Commits

Author SHA1 Message Date
tccontre 4e393e9509 Update windows_defacement_modify_transcodedwallpaper_file.yml 2022-09-05 10:29:49 +02:00
tccontre 85fc55b281 brute-rate-3 2022-09-05 10:26:55 +02:00
pyth0n1c cca076f667 Branch was auto-updated. 2022-09-02 19:15:41 -04:00
pyth0n1c 3880a4f1cf Branch was auto-updated. 2022-09-02 19:15:38 -04:00
pyth0n1c 6d6c132937 Branch was auto-updated. 2022-09-02 19:15:36 -04:00
pyth0n1c e701306956 Branch was auto-updated. 2022-09-02 19:15:35 -04:00
pyth0n1c 9894bf1583 Branch was auto-updated. 2022-09-02 19:15:34 -04:00
pyth0n1c 7879f6b016 Branch was auto-updated. 2022-09-02 19:15:33 -04:00
pyth0n1c 57028a0345 Branch was auto-updated. 2022-09-02 19:15:32 -04:00
pyth0n1c 5946b4adfa Branch was auto-updated. 2022-09-02 19:15:30 -04:00
pyth0n1c ca65ddd817 Branch was auto-updated. 2022-09-02 19:15:29 -04:00
pyth0n1c 95e4eb048c Merge pull request #2359 from splunk/fix_sourcetype_for_linux_kernel_module_detection
Update linux_kernel_module_enumeration.test.yml

Since this is such a small and simple fix, I have merged it myself without review.
Note that this was just an update to a test file, not a modification to the detection itself.
2022-09-02 19:15:12 -04:00
pyth0n1c 5c4d054652 Update linux_kernel_module_enumeration.test.yml
Changing sourcetype from linux_sysmon --> sysmon_linux
2022-09-02 18:50:48 -04:00
mvelazco 3d308b862f adding new detection 2022-09-02 18:25:34 -04:00
mvelazco 441a1542bd adding new detection. fixing types. adding line to lookup 2022-09-02 18:03:14 -04:00
Michael Haag f0601e4f9d Update ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.yml 2022-09-02 15:04:47 -06:00
Michael Haag 6287645f48 BA 2022-09-02 14:44:39 -06:00
Michael Haag 171f7e2b80 id fix 2022-09-01 15:10:29 -06:00
Michael Haag affae7229d SSA all things 2022-09-01 15:02:44 -06:00
pyth0n1c 31cd39763b Remove a number of updated
files which don't yet exist
in develop and should not have
been in this branch to begin with.
They will be merged as part of
a separate PR.
2022-09-01 12:34:12 -04:00
pyth0n1c fc1db0c161 Fixing modified detection so that it
has its original value.
2022-09-01 12:25:53 -04:00
tccontre e80c5c4e85 Update windows_access_token_manipulation_winlogon_duplicate_token_handle.yml 2022-09-01 18:06:44 +02:00
pyth0n1c 640f932419 Added bubbling up errors so that they can be handled by higher level functions. 2022-09-01 11:47:29 -04:00
pyth0n1c 6da8bc32c1 INTENTIONALLY
INTRODUCES AN ERROR
TO TEST UPDATED
VALIDATION AND PYTEST
WORKFLOWS. REMOVE
THIS CHANGE BEFORE
MERGING THIS PR.
2022-09-01 11:00:02 -04:00
tccontre f68b07ff28 Merge branch 'brute-ratel-3' of github.com:splunk/security_content into brute-ratel-3 2022-09-01 16:42:45 +02:00
tccontre a482779b41 brute-ratel-3 2022-09-01 16:42:25 +02:00
tccontre 324b58bf12 Update windows_service_deletion_in_registry.yml 2022-09-01 15:40:48 +02:00
tccontre d764f48a29 Update windows_input_capture_using_credential_ui_dll.yml 2022-09-01 15:39:08 +02:00
tccontre 8abf778411 Update windows_gather_victim_identity_sam_info.yml 2022-09-01 15:38:42 +02:00
tccontre 25ec32f85d Merge branch 'brute-ratel-3' of github.com:splunk/security_content into brute-ratel-3 2022-09-01 15:18:54 +02:00
tccontre c1491e38d1 brute-ratel-3 2022-09-01 15:18:30 +02:00
tccontre bfee7c9b0a Delete windows_phishing_recent_iso_exec_registry.yml 2022-09-01 13:20:57 +02:00
tccontre d06f714dbb Delete windows_input_capture_using_credential_ui_dll.yml 2022-09-01 13:20:48 +02:00
tccontre c1b7d97eb3 Delete windows_hijack_execution_flow_version_dll_side_load.yml 2022-09-01 13:20:39 +02:00
tccontre 5bcc2edeeb Delete windows_remote_access_software_brc4_loaded_dll.yml 2022-09-01 13:20:25 +02:00
tccontre a04fd01b34 Delete windows_gather_victim_identity_sam_info.test.yml 2022-09-01 13:20:14 +02:00
tccontre 42cf9d4d02 Delete windows_hijack_execution_flow_version_dll_side_load.test.yml 2022-09-01 13:20:04 +02:00
tccontre 183f1f689e Delete windows_input_capture_using_credential_ui_dll.test.yml 2022-09-01 13:19:55 +02:00
tccontre 22721a4554 Delete windows_phishing_recent_iso_exec_registry.test.yml 2022-09-01 13:19:45 +02:00
tccontre ce4f5e5ad3 Delete windows_remote_access_software_brc4_loaded_dll.test.yml 2022-09-01 13:19:35 +02:00
tccontre 954a9e9dd3 Delete windows_gather_victim_identity_sam_info.yml 2022-09-01 13:19:19 +02:00
tccontre 506732a62b brute-ratel-3 2022-09-01 13:16:24 +02:00
tccontre 1557a528cf brute-ratel-2 2022-08-31 10:12:55 +02:00
tccontre c8f038be5d Update windows_remote_access_software_brc4_loaded_dll.yml 2022-08-31 09:44:21 +02:00
mvelazco 9e94c62a6a adding new detection 2022-08-30 18:25:25 -04:00
Rod Soto 537c13d063 addedwords 2022-08-30 11:56:41 -07:00
Michael Haag 4d2c2028bc Update linux_persistence_and_privilege_escalation_risk_behavior.yml 2022-08-30 11:44:59 -06:00
Michael Haag 126049593e Updates 2022-08-30 11:21:46 -06:00
mvelazco 927d46a74e adding new detection 2022-08-30 13:07:41 -04:00
tccontre e90fa05a96 Update windows_remote_access_software_brc4_loaded_dll.yml 2022-08-30 17:49:16 +02:00