Commit Graph

103 Commits

Author SHA1 Message Date
bpatel 541b72fd71 merge with develop and testing 2019-11-05 12:22:01 -08:00
Patrick Bareiss a2445e1d1a comment description in transforms.conf 2019-10-31 13:22:12 -07:00
Patrick Bareiss 6c3b53fdb1 added changes for ASX 2019-10-30 10:54:59 -07:00
Patrick Bareiss 0bfe786fcc Code Refactoring od generate.py 2019-10-29 18:41:12 -07:00
Patrick Bareiss 2004017dea Code Refactoring od generate.py 2019-10-29 18:35:16 -07:00
Patrick Bareiss af66ed5fe3 Changed json to yml 2019-10-16 16:38:05 +02:00
Jose Enrique Hernandez c9effaf169 Merge branch 'develop' into cloud_cryptominig 2019-10-08 08:40:51 -04:00
Jose Enrique Hernandez 9c6c794b81 Merge pull request #215 from splunk/drilldown
Added drilldown search and name to the detection spec.
2019-10-08 08:32:49 -04:00
David Dorsey 2a4b29e4c4 New investigation macros
Updated validate to check for macro and lookup existence in both
    baselines and investigation searches
2019-10-07 22:14:12 -05:00
David Dorsey 9034599d6f Added in exception handling to cloud compute activity in new region
Added a bunch of lookup manifests
Added a bunch of macro manifests
Updated validate to make sure macros listed in detection search have
    a macro manifest
2019-10-07 21:50:13 -05:00
David Dorsey d11219e54d Updated generate code 2019-10-03 13:45:16 -07:00
David Dorsey 2a8b470241 Added drilldown search and name to the detection spec.
Added these fields to the suspicious wevtutil manifest
Updated validate to make sure both entries are there or neither are
Updated generate to output those fields if they are there
2019-10-01 17:31:11 -07:00
David Dorsey 1bda6248ea Added code to validate macros manifest and lookups manifest
Lookup manifest validation also checks to make sure either filename or collection is there
If a filename is listed, it makes sure the file exists as well
2019-09-30 16:08:54 -07:00
divious1 979938f707 cleaned up markdown logic from scripts 2019-09-04 12:42:58 -04:00
Jose Enrique Hernandez 019791e8bd Merge pull request #185 from splunk/CRL-1591
remove incorrect stanzas
2019-08-14 12:10:32 -04:00
bpatel 1dc4964261 remove incorrect stanzas 2019-08-13 11:53:57 -07:00
divious1 b82eaa7750 fixing merge conflicts 2019-08-06 17:45:35 -04:00
Rico Valdez 5836446617 fixed channel in stories, minor tweaks to detections.
Also - updated spec to allow validation to pass for UBA detection, as well as updated validation script
2019-08-06 14:58:39 -06:00
divious1 b7fcf3ade1 fixing issue where i wiped out most of the original code 2019-07-29 14:47:02 -04:00
divious1 a41d7a9991 minor modifications base on Jes feedback 2019-07-26 15:48:09 -04:00
Bhavin Patel fa63216143 Merge pull request #161 from splunk/CRL-1577
CRL-1577: updating usage details configuations
2019-07-26 12:30:05 -07:00
Bhavin Patel 57118d085c Merge pull request #167 from splunk/CRL-1580
CRL 1580 :UBA Anomaly
2019-07-26 12:26:53 -07:00
Rico Valdez bfef6024fe more tweaks/fixes to manifests - also adjustments to validation script and spec files. Successfully validates with exception of usecase in stories 2019-07-25 14:56:40 -06:00
divious1 06f5aa70fb fixing stories that are using product_type 2019-07-18 12:35:45 -04:00
bpatel 0173d1a411 search update on UBA 2019-07-17 15:58:52 -07:00
bpatel 2e9d302554 updates to validate and sample UBA manifest for detection 2019-07-15 17:44:10 -07:00
bpatel ccc472d794 errors in CI 2019-07-10 16:01:51 -07:00
bpatel b5bc171d0f correcting paths 2019-07-10 15:59:20 -07:00
bpatel fcda138cc8 updating usage details configuations 2019-07-10 15:14:39 -07:00
divious1 ec4b2fff18 generate docs automatically 2019-06-19 12:51:52 -04:00
divious1 3813882fae doc generation skeleton 2019-06-19 00:03:14 -04:00
divious1 7ecce8781f removed trailing whitespace check 2019-06-05 13:50:12 -04:00
divious1 3d87b6eee8 resolving develop merge conflicts 2019-06-04 15:52:54 -04:00
divious1 32a7974878 corrected generator error 2019-06-03 20:22:50 -04:00
divious1 0a10f7cee5 fixed bug 2019-06-03 19:45:58 -04:00
divious1 1a40ecd329 fixed a bug with generate_inventory 2019-06-03 19:43:16 -04:00
divious1 a5082387b6 fixing bug 2019-05-31 12:29:22 -04:00
bpatel 3eaf538fe8 removing duplicate is_visible and local-true from commands.conf 2019-05-15 14:06:09 -07:00
bpatel 1bdd2e93d3 strip quotes in category, markdown for description 2019-05-10 14:06:39 -07:00
bpatel d7aead3b45 removing created and update to reference 2019-05-10 12:04:25 -07:00
bpatel e9135bc01d description for baselinev1 2019-05-10 10:47:01 -07:00
divious1 e552a8831e fixing bugs 2019-04-25 17:53:28 -04:00
bpatel 52f20cf934 created date in use case lib 2019-04-25 12:20:04 -07:00
bpatel e69b9bf457 markdown for use_Case_lib 2019-04-25 11:52:28 -07:00
divious1 20406758b6 updated datamodels and providing tech rendering 2019-04-25 13:05:27 -04:00
bpatel 7e6c59287a write only once 2019-04-24 18:18:49 -07:00
bpatel 5f7f42e487 update to use spec 1 2019-04-24 18:10:40 -07:00
bpatel 76457c0454 providing tech update on analytic_Stories 2019-04-24 16:22:53 -07:00
divious1 64abae1d75 correct issue with asset_type 2019-04-23 17:40:18 -04:00
divious1 e805cb3ca2 fixed issue with phantom investigations being rendered 2019-04-23 17:30:58 -04:00