Commit Graph

143 Commits

Author SHA1 Message Date
Rod Soto a4b8c67f8b firstfix 2023-03-21 12:25:11 -07:00
pyth0n1c 0640489c50 Fixed filter macro name 2023-02-14 09:17:16 -08:00
pyth0n1c eb124998c7 fixed name 2023-02-14 08:46:33 -08:00
pyth0n1c 9d595cf451 added dataset links 2023-02-14 08:21:48 -08:00
pyth0n1c e6c5fbd101 added all detections for release, still need to update dataset links 2023-02-14 06:46:13 -08:00
srv-rr-gh-researchbt 8583fe64f8 Branch was auto-updated. 2023-02-06 15:57:35 -08:00
pyth0n1c 60ea283f53 Moving failing tests to experimental 2023-02-02 16:32:24 -08:00
pyth0n1c 0daa31c481 Updated the macro in another
search whose test file was changed.
2023-02-01 18:01:19 -08:00
pyth0n1c 9cf9d1d3f7 Fixing incorrect macro in a detection
whose test file was updated.
2023-02-01 17:59:02 -08:00
pyth0n1c 5e911193bd Merge branch 'security_updates' of https://github.com/splunk/security_content into security_updates 2022-11-02 10:05:40 -07:00
pyth0n1c 4351d385d0 Moved detection and test files from production to experimental 2022-11-02 10:02:17 -07:00
Bhavin Patel c76f6c1ce0 Update splunk_xss_in_save_table_dialog_header_in_search_page.yml 2022-11-02 09:14:58 -07:00
pyth0n1c f5eaa40534 Changed media.githubusercontent
to raw.githubusercontent links
2022-11-02 09:02:30 -07:00
Bhavin Patel 79e8b40a67 Update splunk_xss_in_save_table_dialog_header_in_search_page.yml 2022-11-02 08:40:23 -07:00
pyth0n1c 844df50ee5 Fixed format of CVE tag 2022-11-01 08:41:14 -07:00
pyth0n1c a80f89e32c Replaced index= and sourcetype= with appropriate macro. Added that macro as well. 2022-11-01 08:38:04 -07:00
pyth0n1c 689277d6ee Added a number of macros, tests, and detections in support of release of Splunk vulnerabilities and patches. 2022-11-01 08:12:14 -07:00
Michael Haag c8c64150bd updates 2022-10-03 09:20:17 -06:00
Michael Haag d359e51e9e Create okta_risk_threshold_exceeded.yml 2022-09-29 15:08:47 -06:00
Rod Soto 537c13d063 addedwords 2022-08-30 11:56:41 -07:00
d1vious b6e2ff6278 adding updated url 2022-08-16 15:01:17 -04:00
d1vious b7e1a5fe94 adding new detections 2022-08-16 11:30:24 -04:00
Kumar Sharad 4cdbe51506 model to detect risky commands 2022-07-14 16:37:47 +02:00
Kumar Sharad 28c799e829 model to detect risky commands 2022-06-29 23:45:27 +02:00
patel-bhavin cb150c258e minor edits for yml validation and test file name update 2022-06-23 15:21:30 -07:00
Kumar Sharad 8d568ae416 model to detect risky commands 2022-06-23 22:43:22 +02:00
Kumar Sharad 26d6664e7c model to detect risky commands 2022-06-22 17:41:34 +02:00
Kumar Sharad c35c786b09 model to detect risky commands 2022-06-22 17:39:17 +02:00
Kumar Sharad f067ded253 model to detect risky commands 2022-06-22 16:39:33 +02:00
Kumar Sharad 96652af2bf model to detect risky commands 2022-06-22 16:39:33 +02:00
Kumar Sharad 67f35bba10 model to detect risky commands 2022-06-22 16:39:33 +02:00
Lou Stella dbf1c52864 Update splunk_process_injection_forwarder_bundle_downloads.yml 2022-06-16 13:08:02 -05:00
Lou Stella b392ca9aa5 Update splunk_process_injection_forwarder_bundle_downloads.yml
Spelling fix
2022-06-14 09:58:09 -05:00
d1vious 9c3eb1640a fixing tscollect error 2022-06-14 09:17:24 -04:00
Jose Enrique Hernandez 3513587707 Update splunk_protocol_impersonation_weak_encryption_simplerequest.yml 2022-06-14 08:17:53 -04:00
Jose Enrique Hernandez 937a7317cf Update splunk_protocol_impersonation_weak_encryption_simplerequest.yml 2022-06-14 08:17:25 -04:00
Jose Enrique Hernandez 4b95ac0339 Update splunk_digital_certificates_infrastructure_version.yml 2022-06-14 08:15:36 -04:00
Jose Enrique Hernandez b8d7a20e73 fixing dm to drop from davids suggestion 2022-06-14 08:10:11 -04:00
Jose Enrique Hernandez 9e28d378cc updated from karims suggestion 2022-06-14 08:09:20 -04:00
Jose Enrique Hernandez cbbe436585 updated given davids suggestions 2022-06-14 08:07:14 -04:00
Jose Enrique Hernandez 786b26d858 fixing base on feedback from david 2022-06-14 08:04:57 -04:00
Xiao Lin c701be5699 for review comment 2022-06-14 00:30:38 -07:00
Xiao Lin a247079b45 update and typos 2022-06-13 17:15:45 -07:00
Xiao Lin 000e75040d fix typos 2022-06-13 16:39:09 -07:00
Rod Soto 7b2dc90afb fixedsearchdescription 2022-06-13 15:51:53 -07:00
Rod Soto 99cbc03fd5 fixedhosts 2022-06-13 15:47:06 -07:00
Xiao Lin f94759101b Merge branch 'vj9r' of github.com:splunk/security_content into vj9r 2022-06-13 15:33:29 -07:00
Xiao Lin 9a266a78ee update per review comments 2022-06-13 15:33:12 -07:00
Lou Stella be1c572724 Fixed field 2022-06-13 16:50:50 -05:00
Lou Stella a0967fe429 Workbook how_to_implement & references 2022-06-13 16:49:49 -05:00