pyth0n1c
|
d40ca09d61
|
Merged develop into content_changer_improvements to resolve merge conflict. this was making it impossible to merge the PR in the GitHub Interface.
|
2022-06-23 14:19:17 -07:00 |
|
Jose Enrique Hernandez
|
0288c10f70
|
Update splunk_identified_ssl_tls_certificates.yml
|
2022-06-14 08:18:53 -04:00 |
|
Lou Stella
|
a0967fe429
|
Workbook how_to_implement & references
|
2022-06-13 16:49:49 -05:00 |
|
Michael Haag
|
66d7814fed
|
Update splunk_identified_ssl_tls_certificates.yml
|
2022-06-13 15:43:18 -06:00 |
|
Michael Haag
|
46cd276adf
|
Update splunk_identified_ssl_tls_certificates.yml
|
2022-06-13 15:40:49 -06:00 |
|
d1vious
|
97d51b71bf
|
adding cves
|
2022-06-01 17:03:00 -04:00 |
|
mhaag-spl
|
6ddebf3a2d
|
ssl tls ver
|
2022-05-26 12:28:21 -06:00 |
|
pyth0n1c
|
2557d21335
|
Branch was auto-updated.
|
2022-05-16 14:25:41 -04:00 |
|
mhaag-spl
|
77abe77035
|
F5 BIG-IP
|
2022-05-10 07:20:46 -06:00 |
|
pyth0n1c
|
578e6bb088
|
Updated a very large number of detections whose references were returning HTTP Status 301 - resource moved. For example, this includes a large number of fireeye reports, which are now under mandiant, cobaltstrike info, and microsoft links.
|
2022-05-02 17:12:50 -07:00 |
|
d1vious
|
fdcd471d5d
|
moving to experimental
|
2022-04-14 16:37:54 -04:00 |
|
P4T12ICK
|
5dd13ea167
|
fix broken detections
|
2022-03-14 15:51:05 +01:00 |
|
P4T12ICK
|
e6c8254ede
|
Added automaticc generation of finding report
|
2022-03-14 12:12:48 +01:00 |
|
P4T12ICK
|
6f0ee68913
|
Refactored security content
|
2022-03-09 14:43:09 +01:00 |
|
Jose Enrique Hernandez
|
d78bb53baa
|
Revert "Refactored security content"
|
2022-03-04 15:13:04 -05:00 |
|
P4T12ICK
|
886da3c92e
|
merged with develop
|
2022-03-04 14:35:50 +01:00 |
|
patel-bhavin
|
a67a8a4da6
|
Merge branch 'develop' into refactored_security_content
|
2022-03-03 12:51:11 -08:00 |
|
research bot
|
67ecd29d53
|
updating docs and package bits [ci skip]
|
2022-03-03 18:22:29 +00:00 |
|
P4T12ICK
|
68543a8dc1
|
merged with develop
|
2022-03-03 13:11:56 +01:00 |
|
d1vious
|
47dbc6b946
|
using a different field
|
2022-02-26 13:39:28 -05:00 |
|
d1vious
|
0d49d7fc55
|
Merge branch 'CityOfLog4Shells' of github.com:splunk/security_content into CityOfLog4Shells
|
2022-02-24 23:05:48 -05:00 |
|
d1vious
|
6a50f02ff4
|
working detection
|
2022-02-24 23:05:31 -05:00 |
|
pyth0n1c
|
df824e79ac
|
Branch was auto-updated.
|
2022-02-18 15:32:15 -08:00 |
|
d1vious
|
ba97944d04
|
adding ldap detection
|
2022-02-18 17:39:23 -05:00 |
|
d1vious
|
db3605c753
|
adding ssa detection
|
2022-02-18 14:26:17 -05:00 |
|
truptilangalia-crest
|
179134e8ef
|
test:removed cim version
|
2022-02-08 12:05:05 +05:30 |
|
truptilangalia-crest
|
08f0ff6405
|
test: Removed tas with mapping from detection files
|
2022-01-31 19:46:09 +05:30 |
|
P4T12ICK
|
4fd8604b9a
|
removed SAAWS and automated_detection_testing flag
|
2022-01-27 09:50:45 +01:00 |
|
Detection Testing Service
|
6fd7a4e812
|
test: updated supported_tas to recommended_tas
|
2022-01-19 17:43:41 +05:30 |
|
P4T12ICK
|
84092434a2
|
fixed more detections
|
2022-01-18 12:53:54 +01:00 |
|
P4T12ICK
|
98e5af3713
|
put baselines and investigations into its own folder
|
2022-01-17 10:56:04 +01:00 |
|
Detection Testing Service
|
a2b6fff739
|
test:updated ymls
|
2021-12-15 21:15:02 +05:30 |
|
research bot
|
ff3319329e
|
updating docs and package bits [ci skip]
|
2021-12-15 02:58:27 +00:00 |
|
d1vious
|
16b771eae2
|
adding tags to detections
|
2021-12-14 19:38:51 -05:00 |
|
patel-bhavin
|
05b189232d
|
ldap outbound
|
2021-12-14 10:10:23 -08:00 |
|
tlangalia
|
343ceae12f
|
Updated detection files with supported TA list.
|
2021-12-14 13:27:55 +05:50 |
|
research bot
|
a1afa0fa60
|
updating docs and package bits [ci skip]
|
2021-10-28 19:55:37 +00:00 |
|
Drew Church
|
3b18c5abcb
|
Added CVE tags to 35 files
|
2021-10-22 10:03:24 -07:00 |
|
tccontre
|
9d466adc76
|
CARS_UPDATE_MITRE_ID_B8
CARS_UPDATE_MITRE_ID_B8
|
2021-10-15 10:22:43 +02:00 |
|
patel-bhavin
|
333552c326
|
version
|
2021-10-06 15:25:22 -07:00 |
|
patel-bhavin
|
966f63d7f1
|
duplicate
|
2021-10-06 15:17:00 -07:00 |
|
divious1
|
671e91ecd0
|
moved to experimental due to lack of testing
|
2021-09-09 17:30:40 -04:00 |
|
research bot
|
2c9e7b58a8
|
updating docs and package bits [ci skip]
|
2021-08-18 16:56:31 +00:00 |
|
github-actions[bot]
|
ffa8a4a805
|
Branch was auto-updated.
|
2021-07-27 20:53:22 +00:00 |
|
root
|
2fd2af4d29
|
Added detection testing service results inDNS Query Length With High Standard Deviation
|
2021-07-27 19:59:57 +00:00 |
|
P4T12ICK
|
686b0b5ca4
|
converted response_task to investigations
|
2021-07-26 13:39:17 +02:00 |
|
sec-researcher
|
ee3f8638c4
|
As I know PTR requests can not be used for data exfiltration so having them in search result is just a false positive. Also they have effect on deviation calculation and lead to a lot of false positive in result, specially when PTR requests in the environment is about 20% or more. So I add this filter to the search 'where NOT DNS.message_type IN("Pointer","PTR")'
|
2021-07-21 18:20:15 +04:30 |
|
P4T12ICK
|
76bbbe4609
|
add deployments to baselines
|
2021-07-21 11:31:40 +02:00 |
|
P4T12ICK
|
5e6e987fb7
|
resolved merge conflicts
|
2021-07-21 09:22:09 +02:00 |
|
research bot
|
3740535cca
|
updating docs and package bits [ci skip]
|
2021-07-20 17:49:09 +00:00 |
|