divious1
b7ad212344
fix a metric ton of validation errors, also updated the specs
2020-10-08 13:27:10 -04:00
divious1
3987951241
Merge branch 'develop' into response_phases
2020-10-08 10:29:54 -04:00
jzsplunk
0db46f89dc
[TR-82] first cut of validation logic for risk scoring.
2020-09-01 17:55:14 -07:00
divious1
339e117806
skeleton
2020-08-25 18:56:44 -04:00
Patrick Bareiss
7a236f3dd0
new deployment configurations
2020-06-25 10:02:36 +02:00
bpatel
72d3ab875e
converted to spec3 and other updates
2020-05-28 13:31:49 -07:00
bpatel
ad6cf3a4c2
adding docs for spec files
2020-05-18 17:00:15 -07:00
bpatel
2b33d4fe86
spec documentation using jsonschema2md
2020-05-18 16:41:58 -07:00
bpatel
0de08a0f8e
removing required[] from tags
2020-04-30 14:25:09 -07:00
bpatel
d51b7ae991
validate now passes responses
2020-04-30 14:15:23 -07:00
bpatel
f1b70e5d14
adding a required item in spec
2020-04-30 14:02:16 -07:00
Patrick Bareiss
442a575e1d
WIP validate script
2020-04-30 15:51:16 +02:00
Patrick Bareiss
7cbc9a9ba6
WIP
2020-04-30 10:34:18 +02:00
Patrick Bareiss
e610e87ee0
WIP
2020-04-30 10:14:38 +02:00
Patrick Bareiss
d6e5dbc478
spec 3 update
2020-04-29 12:54:27 +02:00
Patrick Bareiss
a569e55051
first version of spec 3
2020-04-24 12:52:33 +02:00
Patrick Bareiss
27f4778f9e
first version of spec 3
2020-04-24 12:51:53 +02:00
bpatel
8e12891adb
spec
2020-04-17 10:52:00 -07:00
Bhavin Patel
916e54d0ff
Merge pull request #429 from splunk/crl-1749ssh
...
CRL-1749 Cloud Stories
2020-04-17 10:36:24 -07:00
bpatel
c45d8dc34f
remove k8s from manifest objects
2020-04-16 16:16:58 -07:00
bpatel
a04b31e038
spec update for CI
2020-04-02 14:18:26 -07:00
bpatel
500a21e8cc
detection, spec and macroupdates
2020-04-02 13:39:29 -07:00
bpatel
9cebb11dc9
detection manifest fixes
2020-03-30 13:22:18 -07:00
bpatel
b74e540486
spec update for security domain
2020-03-02 15:45:55 -08:00
Jason Brewer
c06702a7f4
CRL-1725 - Added update to detections.spec.json to accomodate a new output entity parent_process_name.
2020-02-03 15:32:12 -08:00
divious1
0abf721c3f
introduced mitre technique id to detection spec
2020-01-06 13:31:43 -05:00
David Dorsey
5f30745b7c
Fixed issue in CRL-1387 where the check for executionpolicy bypass
...
was too broad.
Also, added investigation searches for file and registry activity
while I was here
2019-11-06 18:39:21 -08:00
bpatel
541b72fd71
merge with develop and testing
2019-11-05 12:22:01 -08:00
Patrick Bareiss
af66ed5fe3
Changed json to yml
2019-10-16 16:38:05 +02:00
Jose Enrique Hernandez
c9effaf169
Merge branch 'develop' into cloud_cryptominig
2019-10-08 08:40:51 -04:00
Jose Enrique Hernandez
9c6c794b81
Merge pull request #215 from splunk/drilldown
...
Added drilldown search and name to the detection spec.
2019-10-08 08:32:49 -04:00
David Dorsey
fb93597cfc
Merge branch 'macros' into cloud_cryptominig
2019-10-03 17:49:45 -07:00
David Dorsey
82e8b210a9
Files for new cloud cryptominig story.
...
It's a cloud infrastructure generic version of AWS Cryptomining
2019-10-03 17:42:40 -07:00
David Dorsey
24769e88c5
Added lookup to the search specs
2019-10-02 12:01:03 -07:00
David Dorsey
2a8b470241
Added drilldown search and name to the detection spec.
...
Added these fields to the suspicious wevtutil manifest
Updated validate to make sure both entries are there or neither are
Updated generate to output those fields if they are there
2019-10-01 17:31:11 -07:00
David Dorsey
575b766f09
Minor spec change to macro.spec.json
2019-09-30 16:08:08 -07:00
David Dorsey
3d25c40bf7
Updated macro definition in detections, investigations, and baselines to just be a list
...
Broke out macros definition into it's own manifest
Created macro manifests for all of current macros that we ship
Created lookup file manifest
Created lookup file manifests for all current lookup files that we ship
2019-09-30 13:53:25 -07:00
David Dorsey
6ee9d9962c
Added entry for macros in baseline, detections, and investigations spec.
2019-09-25 14:36:35 -05:00
bpatel
e1310d2192
adding ss.conf spec and example
2019-09-12 16:27:11 -07:00
bpatel
4d221f5d18
added entities field and updated spec files
2019-09-04 16:36:08 -07:00
divious1
bb0a440b62
removing example repo as all content is now v2
2019-09-04 12:44:43 -04:00
Rico Valdez
8eb0084ae0
re-applying some fixes for channel. Also, merging in develop broke the spec file, so fixed that.
2019-08-06 20:47:35 -06:00
divious1
b82eaa7750
fixing merge conflicts
2019-08-06 17:45:35 -04:00
Rico Valdez
5836446617
fixed channel in stories, minor tweaks to detections.
...
Also - updated spec to allow validation to pass for UBA detection, as well as updated validation script
2019-08-06 14:58:39 -06:00
Bhavin Patel
57118d085c
Merge pull request #167 from splunk/CRL-1580
...
CRL 1580 :UBA Anomaly
2019-07-26 12:26:53 -07:00
Rico Valdez
bfef6024fe
more tweaks/fixes to manifests - also adjustments to validation script and spec files. Successfully validates with exception of usecase in stories
2019-07-25 14:56:40 -06:00
bpatel
bfa2df0786
updated search and manifest content
2019-07-24 14:29:03 -07:00
divious1
06f5aa70fb
fixing stories that are using product_type
2019-07-18 12:35:45 -04:00
divious1
4c352b9bed
fixing error
2019-07-17 12:52:09 -04:00
divious1
3813882fae
doc generation skeleton
2019-06-19 00:03:14 -04:00