bpatel
541b72fd71
merge with develop and testing
2019-11-05 12:22:01 -08:00
Patrick Bareiss
a2445e1d1a
comment description in transforms.conf
2019-10-31 13:22:12 -07:00
Patrick Bareiss
6c3b53fdb1
added changes for ASX
2019-10-30 10:54:59 -07:00
Patrick Bareiss
0bfe786fcc
Code Refactoring od generate.py
2019-10-29 18:41:12 -07:00
Patrick Bareiss
2004017dea
Code Refactoring od generate.py
2019-10-29 18:35:16 -07:00
Patrick Bareiss
af66ed5fe3
Changed json to yml
2019-10-16 16:38:05 +02:00
Jose Enrique Hernandez
c9effaf169
Merge branch 'develop' into cloud_cryptominig
2019-10-08 08:40:51 -04:00
Jose Enrique Hernandez
9c6c794b81
Merge pull request #215 from splunk/drilldown
...
Added drilldown search and name to the detection spec.
2019-10-08 08:32:49 -04:00
David Dorsey
2a4b29e4c4
New investigation macros
...
Updated validate to check for macro and lookup existence in both
baselines and investigation searches
2019-10-07 22:14:12 -05:00
David Dorsey
9034599d6f
Added in exception handling to cloud compute activity in new region
...
Added a bunch of lookup manifests
Added a bunch of macro manifests
Updated validate to make sure macros listed in detection search have
a macro manifest
2019-10-07 21:50:13 -05:00
David Dorsey
d11219e54d
Updated generate code
2019-10-03 13:45:16 -07:00
David Dorsey
2a8b470241
Added drilldown search and name to the detection spec.
...
Added these fields to the suspicious wevtutil manifest
Updated validate to make sure both entries are there or neither are
Updated generate to output those fields if they are there
2019-10-01 17:31:11 -07:00
David Dorsey
1bda6248ea
Added code to validate macros manifest and lookups manifest
...
Lookup manifest validation also checks to make sure either filename or collection is there
If a filename is listed, it makes sure the file exists as well
2019-09-30 16:08:54 -07:00
divious1
979938f707
cleaned up markdown logic from scripts
2019-09-04 12:42:58 -04:00
Jose Enrique Hernandez
019791e8bd
Merge pull request #185 from splunk/CRL-1591
...
remove incorrect stanzas
2019-08-14 12:10:32 -04:00
bpatel
1dc4964261
remove incorrect stanzas
2019-08-13 11:53:57 -07:00
divious1
b82eaa7750
fixing merge conflicts
2019-08-06 17:45:35 -04:00
Rico Valdez
5836446617
fixed channel in stories, minor tweaks to detections.
...
Also - updated spec to allow validation to pass for UBA detection, as well as updated validation script
2019-08-06 14:58:39 -06:00
divious1
b7fcf3ade1
fixing issue where i wiped out most of the original code
2019-07-29 14:47:02 -04:00
divious1
a41d7a9991
minor modifications base on Jes feedback
2019-07-26 15:48:09 -04:00
Bhavin Patel
fa63216143
Merge pull request #161 from splunk/CRL-1577
...
CRL-1577: updating usage details configuations
2019-07-26 12:30:05 -07:00
Bhavin Patel
57118d085c
Merge pull request #167 from splunk/CRL-1580
...
CRL 1580 :UBA Anomaly
2019-07-26 12:26:53 -07:00
Rico Valdez
bfef6024fe
more tweaks/fixes to manifests - also adjustments to validation script and spec files. Successfully validates with exception of usecase in stories
2019-07-25 14:56:40 -06:00
divious1
06f5aa70fb
fixing stories that are using product_type
2019-07-18 12:35:45 -04:00
bpatel
0173d1a411
search update on UBA
2019-07-17 15:58:52 -07:00
bpatel
2e9d302554
updates to validate and sample UBA manifest for detection
2019-07-15 17:44:10 -07:00
bpatel
ccc472d794
errors in CI
2019-07-10 16:01:51 -07:00
bpatel
b5bc171d0f
correcting paths
2019-07-10 15:59:20 -07:00
bpatel
fcda138cc8
updating usage details configuations
2019-07-10 15:14:39 -07:00
divious1
ec4b2fff18
generate docs automatically
2019-06-19 12:51:52 -04:00
divious1
3813882fae
doc generation skeleton
2019-06-19 00:03:14 -04:00
divious1
7ecce8781f
removed trailing whitespace check
2019-06-05 13:50:12 -04:00
divious1
3d87b6eee8
resolving develop merge conflicts
2019-06-04 15:52:54 -04:00
divious1
32a7974878
corrected generator error
2019-06-03 20:22:50 -04:00
divious1
0a10f7cee5
fixed bug
2019-06-03 19:45:58 -04:00
divious1
1a40ecd329
fixed a bug with generate_inventory
2019-06-03 19:43:16 -04:00
divious1
a5082387b6
fixing bug
2019-05-31 12:29:22 -04:00
bpatel
3eaf538fe8
removing duplicate is_visible and local-true from commands.conf
2019-05-15 14:06:09 -07:00
bpatel
1bdd2e93d3
strip quotes in category, markdown for description
2019-05-10 14:06:39 -07:00
bpatel
d7aead3b45
removing created and update to reference
2019-05-10 12:04:25 -07:00
bpatel
e9135bc01d
description for baselinev1
2019-05-10 10:47:01 -07:00
divious1
e552a8831e
fixing bugs
2019-04-25 17:53:28 -04:00
bpatel
52f20cf934
created date in use case lib
2019-04-25 12:20:04 -07:00
bpatel
e69b9bf457
markdown for use_Case_lib
2019-04-25 11:52:28 -07:00
divious1
20406758b6
updated datamodels and providing tech rendering
2019-04-25 13:05:27 -04:00
bpatel
7e6c59287a
write only once
2019-04-24 18:18:49 -07:00
bpatel
5f7f42e487
update to use spec 1
2019-04-24 18:10:40 -07:00
bpatel
76457c0454
providing tech update on analytic_Stories
2019-04-24 16:22:53 -07:00
divious1
64abae1d75
correct issue with asset_type
2019-04-23 17:40:18 -04:00
divious1
e805cb3ca2
fixed issue with phantom investigations being rendered
2019-04-23 17:30:58 -04:00