Lou Stella
9c183fa110
Update Analytics to Support ATT&CK v19 ( #4036 )
...
---------
Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-05-05 17:29:28 +02:00
Raven Tait
917fe77cc0
Add Big Batch of Snap Attack Converted Rules ( #4015 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-05-05 16:11:18 +02:00
Bhavin Patel
becdb58b9f
Add Secure Access Firewall Detections ( #3986 )
...
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-29 20:41:09 +02:00
Br3akp0int
9972c09298
vip_keylogger ( #4024 )
...
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* vip_keylogger
* Update vip_keylogger.yml
* Update windows_proxy_execution_of__net_utilities_via_scripts.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
* Update powershell_loading_dotnet_into_memory_via_reflection.yml
* Update executables_or_script_creation_in_temp_path.yml
* Update executables_or_script_creation_in_suspicious_path.yml
* Update powershell_pinvoke_process_injection_api_chain.yml
* vip_keylogger
* Update powershell_environment_variable_execution.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
* Update windows_anomalous_registry_value_length_in_environment_key.yml
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-04-29 17:55:13 +05:30
Bhavin Patel
ba59855b1d
updating risk drilldowns ( #4016 )
...
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali
ea5bd52238
Fix Issues - 2nd Round ( #3996 )
...
* Fix #3993
* Fix incorrect DS entries
* fix security_domain issue
* Fix #3992
* Fix #3988
* Update dump_lsass_via_procdump.yml
* Fix #3987
* Fix #3977
* Update network_connection_discovery_with_arp.yml
* Fix #3998
* Fix #3997
* fix versions
* revert change
* Fix #4012
* Update linux_file_creation_in_init_boot_directory.yml
* Update linux_file_creation_in_init_boot_directory.yml
* Fix #4010 and related
* fix typo
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-04-16 05:24:43 +00:00
Nasreddine Bencherchali
bc1b413923
Fix Reported Issues - April Batch ( #3962 )
...
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali
b87507b551
Update Suricata TA and Related Analytics ( #3974 )
...
* update suricata ta
* update analytics for new TA
* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-03-28 10:09:22 +00:00
Br3akp0int
697a77cd08
Add Tagging and Analytic Story for Void Manticore ( #3959 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-23 17:19:07 +01:00
Br3akp0int
27aeb7d95d
Add BlankGrabber Stealer Related Analytics and Tagging ( #3943 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-16 18:09:57 +01:00
Bhavin Patel
b3fed38275
Deprecate MLTK detections ( #3922 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-03-16 14:59:40 +01:00
Nasreddine Bencherchali
29113be7a7
Fix Broken Link, Versions and Pre-Commit ( #3956 )
...
* fix links and versions
* more versions
2026-03-13 19:17:15 +05:30
Br3akp0int
de62304785
Add Analytic Story Tagging for Muddy Water ( #3947 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-12 16:30:09 +00:00
Nasreddine Bencherchali
ed5884f607
More SD-WAN Content ( #3944 )
...
* add more sd-wan content
* rename macro
* Update cisco_sd_wan_service_proxy_access.yml
* fix parsing
* Update cisco_sd_wan___arbitrary_file_overwrite_exploitation_activity.yml
* apply review suggestions
2026-03-12 18:16:41 +05:30
Br3akp0int
3da4f7958a
anomaly_standard_init_score ( #3946 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-10 14:19:08 +05:30
Br3akp0int
2e2f6fc649
ttp_standard_init_score ( #3945 )
...
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
2026-03-10 14:10:37 +05:30
Nasreddine Bencherchali
f930b525ee
Add New Analytics - February Batch ( #3886 )
...
* add percent encoded curl exec
* Fix #3916
* Add other calc process names entries
* apply formatting
* add more color
* add cisco sd-wan stuff
* update tags
* Update cisco_sd_wan___low_frequency_rogue_peer.yml
* add ds and maps it
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-03 18:31:37 +05:30
Eric McGinnis
c733e6c9cc
Merge branch 'develop' into yml_validation_cleanups
2026-02-25 11:36:18 -08:00
Nasreddine Bencherchali
11c909f725
Add YAML Formatting Job ( #3889 )
...
* Add YAML formatting and validation infrastructure
- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag
* comment yaml check from pre-commit
* apply yamlfmt
* Update yaml-validation.yml
* Update yaml-validation.yml
* application folder search formatting
* cloud folder search formatting
* web folder search formatting
* network folder search formatting
* endpoint folder search formatting
* resolve first conflict
* apply formatting
* remove additional pipe
* Update README.md
* update versions
* restore and update formatting (#3920 )
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-02-26 00:00:35 +05:30
Eric McGinnis
1ed6c27923
Update all dates on modified content, including the baseline
2026-02-25 10:13:58 -08:00
Eric McGinnis
15f1e39548
Merge branch 'develop' into yml_validation_cleanups
2026-02-11 08:51:26 -08:00
Nasreddine Bencherchali
a266563b00
Update RBA, logic, and beautify some searches ( #3880 )
...
* Update RBA, logic, and beautify searches
* Update internal_horizontal_port_scan_nmap_top_20.yml
2026-01-31 09:57:04 +05:30
Nasreddine Bencherchali
c50763d938
Fix Reported Issues ( #3873 )
...
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-30 16:34:18 +01:00
Nasreddine Bencherchali
f49f3a3fc9
Fix Validation Issues ( #3861 )
2026-01-30 01:38:34 +01:00
Eric McGinnis
74ed412c74
more required bumps
2026-01-28 12:13:38 -08:00
pyth0n1c
0f9014f4b6
Merge branch 'develop' into yml_validation_cleanups
2026-01-28 11:36:47 -08:00
Alex
f1693a1a0a
Fix search typo in windows abused web services analytic ( #3878 )
2026-01-24 14:38:30 +01:00
Bhavin Patel
060feb0a42
Updating Query Based on XS Data ( #3876 )
2026-01-23 15:49:23 +01:00
Bhavin Patel
d080ba9f06
Updating Terminology for ES8+ ( #3875 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-22 22:59:29 +01:00
Michael Haag
d08d829807
VoidLink Tagging ( #3870 )
...
* VoidLink
* Update linux_adding_crontab_using_list_parameter.yml
* version
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 19:53:15 +05:30
Br3akp0int
73e69c0b84
stealc ( #3833 )
...
* stealc
* stealc
* stealc
* updating versions
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2026-01-22 18:51:16 +05:30
Nasreddine Bencherchali
76f629eb2f
Update Analytics Performance ( #3866 )
...
* Update common_ransomware_notes.yml
* Update detect_rare_executables.yml
* update samsam ext
* update where clause to include null checks
* appinspect fixes
* reduce version
* fix where issue
* Update ransomware_notes_lookup.csv
* more perf enhancements
* Update windows_dotnet_binary_in_non_standard_path.yml
* fix ci issue and enhance description
* Update common_ransomware_extensions.yml
* Update common_ransomware_extensions.yml
* remove unknown and dash values
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-22 12:36:31 +00:00
ljstella
c84715dd99
New Year, New Fixes
2026-01-16 13:19:35 -05:00
LaLaGuy
4ce7a1ddcc
Update version and date in prohibited network traffic config
2026-01-16 16:45:48 +01:00
LaLaGuy
f9e8e6e601
Fix formatting and syntax in prohibited network traffic YAML
...
space to activate CI.
2026-01-15 19:59:08 +01:00
LaLaGuy
e2443809bb
Refactor search query for prohibited network traffic
...
### **Describe the bug**
When interesting_ports_lookup is used, only the port is checked, not the protocol.
Plus, only the first result is returned.
This lookup include several entries for the same port (like 514 rsh/syslog) and the wrong entry can get returned.
This create false match. The wrong enrichment is given (including a wrong transport method) and a notable is generated when it shouldn't.
It can also be greatly optimized by moving the filter logic to the where of the tstats.
### **Expected behavior**
If a 514 udp is detected by the firewall, it should match syslog and not create a notable (or risk) telling me we detected a rsh 514 tcp.
### **Additional context**
Here is a solution (we get the transport from the log instead of adding it from the lookup, add transport to the match and move the filter logique up).
2026-01-15 19:44:41 +01:00
Nasreddine Bencherchali
7941673530
Add Snort/IOS Correlation and Other Things ( #3857 )
2026-01-12 12:15:11 +01:00
Bhavin Patel
1360c8df28
Merge branch 'develop' into yml_validation_cleanups
2026-01-09 14:25:37 +05:30
Br3akp0int
edd6db09d9
Add New Analytics Covering SesameOp and PromptFlux ( #3827 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-01-08 00:58:33 +01:00
Raven Tait
498a80d469
Detections for default user agents ( #3842 )
...
* Detections for default user agents
* various updates for user agent detections
* Apply suggestions from code review
* Rename suspicious_user_agent.yml to suspicious_user_agents.yml
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-01-07 09:34:04 +05:30
pyth0n1c
3b49316ebd
Merge branch 'develop' into yml_validation_cleanups
2025-12-22 13:21:53 -08:00
Nasreddine Bencherchali
976c62383e
Update Macro Usage ( #3840 )
...
* update macro usage
* bump version
* Update detect_hosts_connecting_to_dynamic_domain_providers.yml
* more macro updates
2025-12-18 21:42:06 +05:30
Eric McGinnis
30a6a9fb21
Add some missing products. I assume all these detections want to be for all 3 splunk products.
2025-12-17 11:46:11 -08:00
Nasreddine Bencherchali
5dca2eab02
Add React2Shell Snort Mapping ( #3822 )
2025-12-08 20:45:54 +01:00
Nasreddine Bencherchali
431e06d6b8
Update detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml
2025-12-08 14:34:07 +01:00
Nasreddine Bencherchali
5e86aa2345
add lokibot
2025-12-08 14:06:28 +01:00
Nasreddine Bencherchali
b3d3fee5ee
re-order alphabetically
2025-12-08 13:55:27 +01:00
Nasreddine Bencherchali
ce6fbc203d
update snort lookup
2025-12-08 13:53:41 +01:00
Emil
064cbaef0d
Internal horizontal port scan nmap iteration ( #3802 )
...
* Running splunk auto format to structure SPL
* Simplifying query by doing more in initial tstats, adding additional information
Moving more logic to tstats in order to simplify and speed up query. Adding lastTime and fields, which should help with triage and tuning
* Adding in All_Traffic.rule in order to please validation
* rba to src_ip, remove threat_objects
* Update version and date in YAML configuration
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-12-02 14:51:03 -08:00
Raven Tait
001a152933
NTLM Reflection via DNS Object SPN Spoofing ( #3789 )
...
* NTLM Reflection via DNS Object SPN Spoofing
* Update to user field
* update data source
* Adding fields manadated in the output fields of Sysmon EventID 22 data source
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-11-18 12:59:34 -08:00