tccontre
4e393e9509
Update windows_defacement_modify_transcodedwallpaper_file.yml
2022-09-05 10:29:49 +02:00
tccontre
85fc55b281
brute-rate-3
2022-09-05 10:26:55 +02:00
pyth0n1c
cca076f667
Branch was auto-updated.
2022-09-02 19:15:41 -04:00
pyth0n1c
3880a4f1cf
Branch was auto-updated.
2022-09-02 19:15:38 -04:00
pyth0n1c
6d6c132937
Branch was auto-updated.
2022-09-02 19:15:36 -04:00
pyth0n1c
e701306956
Branch was auto-updated.
2022-09-02 19:15:35 -04:00
pyth0n1c
9894bf1583
Branch was auto-updated.
2022-09-02 19:15:34 -04:00
pyth0n1c
7879f6b016
Branch was auto-updated.
2022-09-02 19:15:33 -04:00
pyth0n1c
57028a0345
Branch was auto-updated.
2022-09-02 19:15:32 -04:00
pyth0n1c
5946b4adfa
Branch was auto-updated.
2022-09-02 19:15:30 -04:00
pyth0n1c
ca65ddd817
Branch was auto-updated.
2022-09-02 19:15:29 -04:00
pyth0n1c
95e4eb048c
Merge pull request #2359 from splunk/fix_sourcetype_for_linux_kernel_module_detection
...
Update linux_kernel_module_enumeration.test.yml
Since this is such a small and simple fix, I have merged it myself without review.
Note that this was just an update to a test file, not a modification to the detection itself.
2022-09-02 19:15:12 -04:00
pyth0n1c
5c4d054652
Update linux_kernel_module_enumeration.test.yml
...
Changing sourcetype from linux_sysmon --> sysmon_linux
2022-09-02 18:50:48 -04:00
mvelazco
3d308b862f
adding new detection
2022-09-02 18:25:34 -04:00
mvelazco
441a1542bd
adding new detection. fixing types. adding line to lookup
2022-09-02 18:03:14 -04:00
Michael Haag
f0601e4f9d
Update ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.yml
2022-09-02 15:04:47 -06:00
Michael Haag
6287645f48
BA
2022-09-02 14:44:39 -06:00
Michael Haag
171f7e2b80
id fix
2022-09-01 15:10:29 -06:00
Michael Haag
affae7229d
SSA all things
2022-09-01 15:02:44 -06:00
pyth0n1c
31cd39763b
Remove a number of updated
...
files which don't yet exist
in develop and should not have
been in this branch to begin with.
They will be merged as part of
a separate PR.
2022-09-01 12:34:12 -04:00
pyth0n1c
fc1db0c161
Fixing modified detection so that it
...
has its original value.
2022-09-01 12:25:53 -04:00
tccontre
e80c5c4e85
Update windows_access_token_manipulation_winlogon_duplicate_token_handle.yml
2022-09-01 18:06:44 +02:00
pyth0n1c
640f932419
Added bubbling up errors so that they can be handled by higher level functions.
2022-09-01 11:47:29 -04:00
pyth0n1c
6da8bc32c1
INTENTIONALLY
...
INTRODUCES AN ERROR
TO TEST UPDATED
VALIDATION AND PYTEST
WORKFLOWS. REMOVE
THIS CHANGE BEFORE
MERGING THIS PR.
2022-09-01 11:00:02 -04:00
tccontre
f68b07ff28
Merge branch 'brute-ratel-3' of github.com:splunk/security_content into brute-ratel-3
2022-09-01 16:42:45 +02:00
tccontre
a482779b41
brute-ratel-3
2022-09-01 16:42:25 +02:00
tccontre
324b58bf12
Update windows_service_deletion_in_registry.yml
2022-09-01 15:40:48 +02:00
tccontre
d764f48a29
Update windows_input_capture_using_credential_ui_dll.yml
2022-09-01 15:39:08 +02:00
tccontre
8abf778411
Update windows_gather_victim_identity_sam_info.yml
2022-09-01 15:38:42 +02:00
tccontre
25ec32f85d
Merge branch 'brute-ratel-3' of github.com:splunk/security_content into brute-ratel-3
2022-09-01 15:18:54 +02:00
tccontre
c1491e38d1
brute-ratel-3
2022-09-01 15:18:30 +02:00
tccontre
bfee7c9b0a
Delete windows_phishing_recent_iso_exec_registry.yml
2022-09-01 13:20:57 +02:00
tccontre
d06f714dbb
Delete windows_input_capture_using_credential_ui_dll.yml
2022-09-01 13:20:48 +02:00
tccontre
c1b7d97eb3
Delete windows_hijack_execution_flow_version_dll_side_load.yml
2022-09-01 13:20:39 +02:00
tccontre
5bcc2edeeb
Delete windows_remote_access_software_brc4_loaded_dll.yml
2022-09-01 13:20:25 +02:00
tccontre
a04fd01b34
Delete windows_gather_victim_identity_sam_info.test.yml
2022-09-01 13:20:14 +02:00
tccontre
42cf9d4d02
Delete windows_hijack_execution_flow_version_dll_side_load.test.yml
2022-09-01 13:20:04 +02:00
tccontre
183f1f689e
Delete windows_input_capture_using_credential_ui_dll.test.yml
2022-09-01 13:19:55 +02:00
tccontre
22721a4554
Delete windows_phishing_recent_iso_exec_registry.test.yml
2022-09-01 13:19:45 +02:00
tccontre
ce4f5e5ad3
Delete windows_remote_access_software_brc4_loaded_dll.test.yml
2022-09-01 13:19:35 +02:00
tccontre
954a9e9dd3
Delete windows_gather_victim_identity_sam_info.yml
2022-09-01 13:19:19 +02:00
tccontre
506732a62b
brute-ratel-3
2022-09-01 13:16:24 +02:00
tccontre
1557a528cf
brute-ratel-2
2022-08-31 10:12:55 +02:00
tccontre
c8f038be5d
Update windows_remote_access_software_brc4_loaded_dll.yml
2022-08-31 09:44:21 +02:00
mvelazco
9e94c62a6a
adding new detection
2022-08-30 18:25:25 -04:00
Rod Soto
537c13d063
addedwords
2022-08-30 11:56:41 -07:00
Michael Haag
4d2c2028bc
Update linux_persistence_and_privilege_escalation_risk_behavior.yml
2022-08-30 11:44:59 -06:00
Michael Haag
126049593e
Updates
2022-08-30 11:21:46 -06:00
mvelazco
927d46a74e
adding new detection
2022-08-30 13:07:41 -04:00
tccontre
e90fa05a96
Update windows_remote_access_software_brc4_loaded_dll.yml
2022-08-30 17:49:16 +02:00