Commit Graph

250 Commits

Author SHA1 Message Date
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Michael Haag 074d13f001 BasketNetWeaving with Haag: No Shell Left Behind! 2025-04-28 10:33:17 -06:00
Bhavin Patel bb2045cce0 Merge branch 'develop' into crushingit 2025-04-18 12:45:18 -07:00
Michael Haag 9f8f28c0b5 Update crushftp_max_simultaneous_users_from_ip.yml 2025-04-18 13:27:09 -06:00
Michael Haag 95049154e9 Update crushftp_authentication_bypass_exploitation.yml 2025-04-18 13:25:39 -06:00
Bhavin Patel 8e6d4c69bf Merge branch 'develop' into remove_v5.4.0 2025-04-17 12:00:27 -07:00
Michael Haag 657ffbc9e4 Ground Control to Major Haag: Earth Alux
This PR adds a new analytic story for the Earth Alux threat actor, a sophisticated espionage group targeting government, technology, and telecommunications sectors in APAC and Latin America.
2025-04-16 21:55:12 -06:00
Bhavin Patel 5b7cfdb7d3 updating versions 2025-04-16 16:45:16 -07:00
Michael Haag fc81c76727 Haag's Crushed Shell: A Tale of CrushFTP Exploitation
CVE-2025-31161
2025-04-14 12:39:07 -06:00
Bhavin Patel 00253f3c6e Merge branch 'develop' into output_normalization_endpoint 2025-04-01 14:45:19 -07:00
Bhavin Patel 7168e32ea6 Merge branch 'develop' into sunnyside 2025-04-01 14:05:53 -07:00
Michael Haag 55b5bc77d2 fixagai 2025-04-01 14:48:54 -06:00
Michael Haag f435240b83 fixes 2025-04-01 14:34:18 -06:00
Patrick Bareiss 7541027f8e Merge branch 'develop' into output_normalization_endpoint 2025-04-01 09:41:58 +02:00
Michael Haag 20cb4400dc Haag Story 3: Attack Analytics to the Rescue
"There's a snake in my Tomcat!"

When malicious serialized objects started showing up at Sunnyside Server Farm, Security Sheriff Haag rounded up a posse of new detections to keep the web applications safe.

This PR delivers:
- Two new best friends: tomcat_session_file_upload_attempt and tomcat_session_deserialization_attempt
- A brand new playset: "Apache Tomcat Session Deserialization Attacks" analytic story
- No more crying when the bad toys try to upload .session files
- The claw of justice comes down when suspicious JSESSIONID cookies appear

Remember what Security Ranger Haag always says: "To HTTP response codes and beyond!"
2025-03-25 14:08:02 -06:00
Michael Haag ec5cf468e3 The Haag Identity: Operation Seashell Blizzard 🌊❄️
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include:
Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately.
Analytics tagged with "Seashell Blizzard" include:
ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal)
Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell)
Credential access monitoring (LSASS dumps via TaskMgr and ProcDump)
Remote access software usage detections (file, process, registry)
Scheduled task abuse detections
SQL Server xp_cmdshell configuration changes
Registry hive dumping detection
Key updates:
- Added "Seashell Blizzard" tag to 20 existing detections

These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.
2025-03-24 14:18:40 -06:00
Patrick Bareiss 1c9debe9a6 update versions 2025-03-14 13:47:44 +01:00
Patrick Bareiss 67dff5120a Merge branch 'develop' into output_normalization_endpoint 2025-03-13 09:22:06 +01:00
pyth0n1c d77736f7e4 Update detect_web_access_to_decommissioned_s3_bucket.yml
fix tests key again
2025-02-20 14:57:35 -08:00
Jose Hernandez 36f3b6eb35 shipping as experimental 2025-02-20 17:11:38 -05:00
Jose Hernandez 441ba47f3d fixing merge conflicts 2025-02-20 17:06:33 -05:00
pyth0n1c fde93c6d32 convert csv lookup to kvstore lookup.
Update references in description files
as well.
2025-02-19 14:50:53 -08:00
research-bot ddf3ed0797 adding baseline key to test 2025-02-18 08:49:59 -08:00
research-bot 43c999440c updating yamls 2025-02-18 08:42:18 -08:00
research-bot 2d54affae2 updating dummy dataset links 2025-02-13 17:30:11 -08:00
research-bot 0ec052b8f9 updating yaml to pass build and adding lookup, minor fixes 2025-02-13 15:36:01 -08:00
Jose Hernandez d83efc4dd1 adding datasets 2025-02-13 16:58:01 -05:00
Jose Enrique Hernandez fda0c88916 Merge branch 'develop' into 8_million_requests 2025-02-13 16:42:17 -05:00
Jose Hernandez 172e1d5db5 first draft 2025-02-12 18:03:06 -05:00
pyth0n1c 45599e0b18 Clean up MITRE Tagging. When a type is defined, such as T1003, DO NOT allow a subtype such as T1003.001 to be defined. Remove the generic type T1003 and keep the subtype T1003.001. However, it is acceptable for a subtype to be defined or for a type to be defined separately. It is also okay for multiple subtypes to be defined. 2025-02-10 12:28:22 -08:00
Steven Dick 41c92476b9 Update detect_remote_access_software_usage_url.yml 2025-02-06 08:04:38 -05:00
Steven Dick 7773664924 Update detect_remote_access_software_usage_url.yml 2025-02-06 07:57:46 -05:00
research-bot 76a9a02c9e updating versions 2025-02-05 10:49:03 -08:00
research-bot 6c3e7df1ad notable to finding 2 2025-01-24 17:03:47 -08:00
Nasreddine Bencherchali c0418cff2e Merge branch 'develop' of https://github.com/splunk/security_content into major-updates 2025-01-22 11:40:26 +01:00
Michael Haag 8ce3783394 Update windows_exchange_autodiscover_ssrf_abuse.yml
- Updated detection description to better explain ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) attack patterns
- Enhanced search query:
  - X-Rps-CAT parameter
  - Suspicious user agent strings
2025-01-16 10:02:05 -07:00
pyth0n1c fdaa038eab Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00
pyth0n1c d1442c2805 remove update_timestamps, confidence, impact,
related_fields, and risk_score from detections
2025-01-03 15:25:52 -08:00
ljstella 9ab5e6a7e1 web: cleanup TBD messages 2024-11-27 12:34:16 -06:00
ljstella e0718d1b31 web: threat object type cleanup 2024-11-15 14:56:20 -06:00
ljstella b600be3ad9 web: remove rba config from correlations 2024-11-15 11:42:52 -06:00
ljstella dfd645f846 web: more cleanup 2024-11-15 11:31:28 -06:00
ljstella 8d7aabc2cd web: remove rba from hunting 2024-11-15 11:01:13 -06:00
ljstella 4a3bc666ed web: more typefixes 2024-11-15 10:49:15 -06:00
ljstella 393c038cf4 web: more typefixes 2024-11-15 10:37:23 -06:00
ljstella ce696ff0bf web: ip address typefix 2024-11-15 10:24:43 -06:00
ljstella 6384bea952 web: lowercase rba types 2024-11-15 10:17:03 -06:00
ljstella a33df66bec web detection score field rename 2024-11-15 09:50:18 -06:00
ljstella c4eb58cd71 web detections score fix 2024-11-15 09:40:45 -06:00
ljstella c218c03e48 web detections initial translation 2024-11-15 09:04:43 -06:00