Commit Graph

486 Commits

Author SHA1 Message Date
Lou Stella 9c183fa110 Update Analytics to Support ATT&CK v19 (#4036)
---------

Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-05 17:29:28 +02:00
Raven Tait 917fe77cc0 Add Big Batch of Snap Attack Converted Rules (#4015)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-05-05 16:11:18 +02:00
Bhavin Patel becdb58b9f Add Secure Access Firewall Detections (#3986)
---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-29 20:41:09 +02:00
Br3akp0int 9972c09298 vip_keylogger (#4024)
* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* Update vip_keylogger.yml

* Update windows_proxy_execution_of__net_utilities_via_scripts.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

* Update powershell_loading_dotnet_into_memory_via_reflection.yml

* Update executables_or_script_creation_in_temp_path.yml

* Update executables_or_script_creation_in_suspicious_path.yml

* Update powershell_pinvoke_process_injection_api_chain.yml

* vip_keylogger

* Update powershell_environment_variable_execution.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-04-29 17:55:13 +05:30
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali ea5bd52238 Fix Issues - 2nd Round (#3996)
* Fix #3993

* Fix incorrect DS entries

* fix security_domain issue

* Fix #3992

* Fix #3988

* Update dump_lsass_via_procdump.yml

* Fix #3987

* Fix #3977

* Update network_connection_discovery_with_arp.yml

* Fix #3998

* Fix #3997

* fix versions

* revert change

* Fix #4012

* Update linux_file_creation_in_init_boot_directory.yml

* Update linux_file_creation_in_init_boot_directory.yml

* Fix #4010 and related

* fix typo

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-04-16 05:24:43 +00:00
Nasreddine Bencherchali bc1b413923 Fix Reported Issues - April Batch (#3962)
* Fix #3961

* Fix #3909

* Fix output fields

* Remove duplicate process_name entry

* Update outbound_network_connection_from_java_using_default_ports.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Fix #3969

* update palo alto TA and beautify analytics

* Update vmware_aria_operations_exploit_attempt.yml

* fix source

* enhance metadata and fp info

* beautify spl for ease of reading

* add some missing attack techniques

* remove unnecessary usage of regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* small fix

* Refine description and improve regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update windows_event_log_security_4756.yml

* description update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali b87507b551 Update Suricata TA and Related Analytics (#3974)
* update suricata ta

* update analytics for new TA

* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml

---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-03-28 10:09:22 +00:00
Br3akp0int 697a77cd08 Add Tagging and Analytic Story for Void Manticore (#3959)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-23 17:19:07 +01:00
Br3akp0int 27aeb7d95d Add BlankGrabber Stealer Related Analytics and Tagging (#3943)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-16 18:09:57 +01:00
Bhavin Patel b3fed38275 Deprecate MLTK detections (#3922)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-03-16 14:59:40 +01:00
Nasreddine Bencherchali 29113be7a7 Fix Broken Link, Versions and Pre-Commit (#3956)
* fix links and versions

* more versions
2026-03-13 19:17:15 +05:30
Br3akp0int de62304785 Add Analytic Story Tagging for Muddy Water (#3947)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-12 16:30:09 +00:00
Nasreddine Bencherchali ed5884f607 More SD-WAN Content (#3944)
* add more sd-wan content

* rename macro

* Update cisco_sd_wan_service_proxy_access.yml

* fix parsing

* Update cisco_sd_wan___arbitrary_file_overwrite_exploitation_activity.yml

* apply review suggestions
2026-03-12 18:16:41 +05:30
Br3akp0int 3da4f7958a anomaly_standard_init_score (#3946)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-10 14:19:08 +05:30
Br3akp0int 2e2f6fc649 ttp_standard_init_score (#3945)
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali f930b525ee Add New Analytics - February Batch (#3886)
* add percent encoded curl exec

* Fix #3916

* Add other calc process names entries

* apply formatting

* add more color

* add cisco sd-wan stuff

* update tags

* Update cisco_sd_wan___low_frequency_rogue_peer.yml

* add ds and maps it

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-03 18:31:37 +05:30
Eric McGinnis c733e6c9cc Merge branch 'develop' into yml_validation_cleanups 2026-02-25 11:36:18 -08:00
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Eric McGinnis 1ed6c27923 Update all dates on modified content, including the baseline 2026-02-25 10:13:58 -08:00
Eric McGinnis 15f1e39548 Merge branch 'develop' into yml_validation_cleanups 2026-02-11 08:51:26 -08:00
Nasreddine Bencherchali a266563b00 Update RBA, logic, and beautify some searches (#3880)
* Update RBA, logic, and beautify searches

* Update internal_horizontal_port_scan_nmap_top_20.yml
2026-01-31 09:57:04 +05:30
Nasreddine Bencherchali c50763d938 Fix Reported Issues (#3873)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-30 16:34:18 +01:00
Nasreddine Bencherchali f49f3a3fc9 Fix Validation Issues (#3861) 2026-01-30 01:38:34 +01:00
Eric McGinnis 74ed412c74 more required bumps 2026-01-28 12:13:38 -08:00
pyth0n1c 0f9014f4b6 Merge branch 'develop' into yml_validation_cleanups 2026-01-28 11:36:47 -08:00
Alex f1693a1a0a Fix search typo in windows abused web services analytic (#3878) 2026-01-24 14:38:30 +01:00
Bhavin Patel 060feb0a42 Updating Query Based on XS Data (#3876) 2026-01-23 15:49:23 +01:00
Bhavin Patel d080ba9f06 Updating Terminology for ES8+ (#3875)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-22 22:59:29 +01:00
Michael Haag d08d829807 VoidLink Tagging (#3870)
* VoidLink

* Update linux_adding_crontab_using_list_parameter.yml

* version

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 19:53:15 +05:30
Br3akp0int 73e69c0b84 stealc (#3833)
* stealc

* stealc

* stealc

* updating versions

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-01-22 18:51:16 +05:30
Nasreddine Bencherchali 76f629eb2f Update Analytics Performance (#3866)
* Update common_ransomware_notes.yml

* Update detect_rare_executables.yml

* update samsam ext

* update where clause to include null checks

* appinspect fixes

* reduce version

* fix where issue

* Update ransomware_notes_lookup.csv

* more perf enhancements

* Update windows_dotnet_binary_in_non_standard_path.yml

* fix ci issue and enhance description

* Update common_ransomware_extensions.yml

* Update common_ransomware_extensions.yml

* remove unknown and dash values

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-22 12:36:31 +00:00
ljstella c84715dd99 New Year, New Fixes 2026-01-16 13:19:35 -05:00
LaLaGuy 4ce7a1ddcc Update version and date in prohibited network traffic config 2026-01-16 16:45:48 +01:00
LaLaGuy f9e8e6e601 Fix formatting and syntax in prohibited network traffic YAML
space to activate CI.
2026-01-15 19:59:08 +01:00
LaLaGuy e2443809bb Refactor search query for prohibited network traffic
### **Describe the bug**
When interesting_ports_lookup is used, only the port is checked, not the protocol.
Plus, only the first result is returned.
This lookup include several entries for the same port (like 514 rsh/syslog) and the wrong entry can get returned.
This create false match. The wrong enrichment is given (including a wrong transport method) and a notable is generated when it shouldn't.
It can also be greatly optimized by moving the filter logic to the where of the tstats.

### **Expected behavior**
If a 514 udp is detected by the firewall, it should match syslog and not create a notable (or risk) telling me we detected a rsh 514 tcp.

### **Additional context**
Here is a solution (we get the transport from the log instead of adding it from the lookup, add transport to the match and move the filter logique up).
2026-01-15 19:44:41 +01:00
Nasreddine Bencherchali 7941673530 Add Snort/IOS Correlation and Other Things (#3857) 2026-01-12 12:15:11 +01:00
Bhavin Patel 1360c8df28 Merge branch 'develop' into yml_validation_cleanups 2026-01-09 14:25:37 +05:30
Br3akp0int edd6db09d9 Add New Analytics Covering SesameOp and PromptFlux (#3827)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-01-08 00:58:33 +01:00
Raven Tait 498a80d469 Detections for default user agents (#3842)
* Detections for default user agents

* various updates for user agent detections

* Apply suggestions from code review

* Rename suspicious_user_agent.yml to suspicious_user_agents.yml

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-01-07 09:34:04 +05:30
pyth0n1c 3b49316ebd Merge branch 'develop' into yml_validation_cleanups 2025-12-22 13:21:53 -08:00
Nasreddine Bencherchali 976c62383e Update Macro Usage (#3840)
* update macro usage

* bump version

* Update detect_hosts_connecting_to_dynamic_domain_providers.yml

* more macro updates
2025-12-18 21:42:06 +05:30
Eric McGinnis 30a6a9fb21 Add some missing products. I assume all these detections want to be for all 3 splunk products. 2025-12-17 11:46:11 -08:00
Nasreddine Bencherchali 5dca2eab02 Add React2Shell Snort Mapping (#3822) 2025-12-08 20:45:54 +01:00
Nasreddine Bencherchali 431e06d6b8 Update detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml 2025-12-08 14:34:07 +01:00
Nasreddine Bencherchali 5e86aa2345 add lokibot 2025-12-08 14:06:28 +01:00
Nasreddine Bencherchali b3d3fee5ee re-order alphabetically 2025-12-08 13:55:27 +01:00
Nasreddine Bencherchali ce6fbc203d update snort lookup 2025-12-08 13:53:41 +01:00
Emil 064cbaef0d Internal horizontal port scan nmap iteration (#3802)
* Running splunk auto format to structure SPL

* Simplifying query by doing more in initial tstats, adding additional information

Moving more logic to tstats in order to simplify and speed up query. Adding lastTime and  fields, which should help with triage and tuning

* Adding in All_Traffic.rule in order to please validation

* rba to src_ip, remove threat_objects

* Update version and date in YAML configuration

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-12-02 14:51:03 -08:00
Raven Tait 001a152933 NTLM Reflection via DNS Object SPN Spoofing (#3789)
* NTLM Reflection via DNS Object SPN Spoofing

* Update to user field

* update data source

* Adding fields manadated in the output fields of Sysmon EventID 22 data source

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-11-18 12:59:34 -08:00