Namratha Sreekanta
|
84ae1743fe
|
changing file names
|
2022-09-28 13:16:22 -07:00 |
|
Namratha Sreekanta
|
179e58e087
|
changing files
|
2022-09-28 12:36:40 -07:00 |
|
Namratha Sreekanta
|
d1788686d5
|
initial commit for dga
|
2022-09-15 17:50:36 -07:00 |
|
mvelazco
|
441a1542bd
|
adding new detection. fixing types. adding line to lookup
|
2022-09-02 18:03:14 -04:00 |
|
mvelazco
|
6e07f25d0b
|
fixing lookup name typo
|
2022-08-29 17:30:34 -04:00 |
|
mvelazco
|
79f7f9c16e
|
adding new detection
|
2022-08-29 17:00:05 -04:00 |
|
Michael Haag
|
11eb0feac6
|
T1003.001 Update
|
2022-08-25 08:04:20 -06:00 |
|
Michael Haag
|
8248278109
|
Remote Access Software
|
2022-08-22 21:57:53 -06:00 |
|
pyth0n1c
|
f0b053152e
|
Update hijacklibs.csv
Forgot to include one of the dlls,
amsi.dll. This caused the detection
testing to fail.
|
2022-08-22 12:29:21 -07:00 |
|
Michael Haag
|
17ba3c3e51
|
fix
|
2022-08-19 15:21:15 -06:00 |
|
Michael Haag
|
416ddb5fa8
|
lookup 1
|
2022-08-19 14:40:01 -06:00 |
|
pyth0n1c
|
87a8bc0442
|
Merged develop into this branch and resolved merge conflicts.
|
2022-08-03 06:47:22 -07:00 |
|
pyth0n1c
|
2a5a055a7f
|
Branch was auto-updated.
|
2022-07-19 10:46:12 -07:00 |
|
Michael Haag
|
0a56c2470f
|
proto fix
|
2022-07-14 09:50:41 -06:00 |
|
Michael Haag
|
8ec266233b
|
Windows Protocol Handler
|
2022-07-12 14:43:39 -06:00 |
|
pyth0n1c
|
012b360989
|
Branch was auto-updated.
|
2022-07-07 07:56:47 -07:00 |
|
Jose Enrique Hernandez
|
9cc85a614f
|
Update security_services.csv
|
2022-07-07 10:43:17 -04:00 |
|
Kumar Sharad
|
28c799e829
|
model to detect risky commands
|
2022-06-29 23:45:27 +02:00 |
|
Kumar Sharad
|
8d568ae416
|
model to detect risky commands
|
2022-06-23 22:43:22 +02:00 |
|
Kumar Sharad
|
7328ea1aa3
|
model to detect risky commands
|
2022-06-22 19:34:06 +02:00 |
|
Kumar Sharad
|
defa7b1bd0
|
model to detect risky commands
|
2022-06-22 16:57:52 +02:00 |
|
Kumar Sharad
|
629e5c2e5e
|
model to detect risky commands
|
2022-06-22 16:47:07 +02:00 |
|
Kumar Sharad
|
de7c604cd2
|
model to detect risky commands
|
2022-06-22 16:45:48 +02:00 |
|
Kumar Sharad
|
f067ded253
|
model to detect risky commands
|
2022-06-22 16:39:33 +02:00 |
|
Kumar Sharad
|
fe84f9fbf9
|
model to detect risky commands
|
2022-06-22 16:39:33 +02:00 |
|
Kumar Sharad
|
1120d578e5
|
model to detect risky commands
|
2022-06-22 16:39:33 +02:00 |
|
Kumar Sharad
|
96652af2bf
|
model to detect risky commands
|
2022-06-22 16:39:33 +02:00 |
|
Kumar Sharad
|
67f35bba10
|
model to detect risky commands
|
2022-06-22 16:39:33 +02:00 |
|
Kumar Sharad
|
7bb299490f
|
model to detect risky commands
|
2022-06-21 17:47:31 +02:00 |
|
Kumar Sharad
|
f45aadfb8e
|
model to detect risky commands
|
2022-06-21 17:43:49 +02:00 |
|
Kumar Sharad
|
8228c36d18
|
model to detect risky commands
|
2022-06-21 15:39:48 +02:00 |
|
Kumar Sharad
|
693ee6c03d
|
model to detect risky commands
|
2022-06-21 14:55:46 +02:00 |
|
Lou Stella
|
c7dadd566a
|
updating mitre_enrichment lookup
|
2022-05-20 16:15:18 -05:00 |
|
Lou Stella
|
9fb1439059
|
Adding node.exe as an app not allowed to spawn cmd.exe
|
2022-05-02 14:34:06 -05:00 |
|
pyth0n1c
|
6694a5f659
|
building and appinspecting of the package are now working. removed an errorneous comma from lookups/attack_tools.csv that caused errors during appinspect and resulted in a badly cormatted csv.
|
2022-04-23 10:22:56 -07:00 |
|
P4T12ICK
|
403ad09629
|
disable detection enrichment for stories
|
2022-03-30 14:29:57 +02:00 |
|
patel-bhavin
|
bf0c64023f
|
lookups
|
2022-03-29 08:37:14 -07:00 |
|
P4T12ICK
|
afc1860132
|
Add Mitre Attack Csv generation
|
2022-03-29 12:14:20 +02:00 |
|
P4T12ICK
|
0fe8a854ec
|
fixed api and mitre attack enrichment
|
2022-03-28 14:03:10 +02:00 |
|
Lou Stella
|
49b2b9f0d4
|
Updated ransomware_extensions.csv
|
2022-03-01 11:19:55 -06:00 |
|
patel-bhavin
|
68dde34dc8
|
rename typo
|
2022-02-24 14:14:13 -08:00 |
|
patel-bhavin
|
52d0996b0a
|
combined the rest 2
|
2022-02-17 16:28:19 -08:00 |
|
patel-bhavin
|
9d780700de
|
lookupss
|
2022-02-16 16:23:19 -08:00 |
|
Bhavin Patel
|
14c145c133
|
Merge pull request #1953 from splunk/potentially_malicious_code_on_commandline
Potentially malicious code on commandline
|
2022-01-28 13:27:59 -08:00 |
|
patel-bhavin
|
fe5db9e78e
|
adding lookup files
|
2022-01-26 15:34:10 -08:00 |
|
Michael Haag
|
67e413d0e0
|
Update __mlspl_unusual_commandline_detection.yml
|
2022-01-26 11:26:25 -07:00 |
|
Michael Hart
|
39d7121dcd
|
Updating mlmodel to 5.3.x specification as well as the test apparatus
|
2022-01-25 21:42:16 -05:00 |
|
mhaag-spl
|
befe09f77c
|
Nirsoft Software
|
2022-01-24 15:07:20 -07:00 |
|
Michael Hart
|
e962bfb4bd
|
Merge branch 'develop' of github.com:splunk/security_content into potentially_malicious_code_on_commandline
|
2022-01-21 19:26:39 -05:00 |
|
pyth0n1c
|
ad2324d863
|
Branch was auto-updated.
|
2022-01-20 16:07:09 -08:00 |
|