ljstella
56827470ac
Adding script to analyze risk objects on TTP detections
2026-04-07 13:11:59 -04:00
Lou Stella
290486b6fe
Merge pull request #3994 from splunk/update-template-script-2
2026-04-07 07:29:09 -05:00
Henry Yu
e182e32f51
quote the file
2026-04-06 21:04:14 -07:00
Henry Yu
e791773e97
unquote the file
2026-04-06 20:44:11 -07:00
Lou Stella
6e75fc6407
Merge pull request #3991 from splunk/update-template-script
2026-04-06 17:05:24 -05:00
Lou Stella
806f6bdd32
Merge branch 'develop' into update-template-script
2026-04-06 17:03:05 -05:00
Lou Stella
95b35f77c1
Merge pull request #3990 from splunk/kbouchard-patch-1
2026-04-06 17:02:40 -05:00
Lou Stella
93cb3bedd9
Merge branch 'develop' into kbouchard-patch-1
2026-04-06 16:59:28 -05:00
Henry Yu
9b5c9aa7b9
remove the ignore . file change
2026-04-06 14:47:08 -07:00
Henry Yu
924a89e249
add validation for unique name, version pair
2026-04-02 13:06:15 -07:00
Henry Yu
9bc34d412f
group by actual template names instead of file name
2026-04-02 12:38:37 -07:00
Br3akp0int
7293d75700
Tagged Analytics Covering the Axios Compromise Post-Exploitation Activity ( #3982 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com >
2026-04-02 16:07:20 +00:00
Raven Tait
f416da59fe
Add Filter for VMware Tools ( #3983 )
2026-04-02 18:06:04 +02:00
Bhavin Patel
116ab57d18
Remove AITK/MLTK TAs references from Contentctl.yml ( #3911 )
...
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-02 17:47:55 +02:00
Bhavin Patel
8c6453e0ea
Bump contentctl.yml to 5.26.0 ( #3989 )
...
* chore: bump contentctl.yml to 5.26.0
* remove detections
---------
Co-authored-by: research bot <research@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2026-04-02 17:41:06 +02:00
kbouchard
fc1596e371
had to remove 8.5 from the name of response plans
...
had to remove 8.5 from the name of response plans
2026-04-01 20:55:54 -07:00
pyth0n1c
90536d0e5a
Palo Alto Ta 3.0.0 was pulled from Splukbase. ( #3985 )
...
As such we must bump the TA to the newest
(and only) available release, 3.0.1.
v5.25.0
2026-03-31 22:42:26 +05:30
Nasreddine Bencherchali
fd53a2186b
Fix Broken RBA Message ( #3984 )
2026-03-31 15:34:07 +00:00
Lou Stella
39849c0179
Merge pull request #3980 from splunk/sched_task_rba_message
2026-03-30 14:51:23 -05:00
ljstella
d38d8e1519
First pass of RBA message fix
2026-03-30 15:09:36 -04:00
Br3akp0int
ff78e2d159
gh0st ( #3973 )
...
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* small changes
* another update
* final fix
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-30 19:46:33 +05:30
Nasreddine Bencherchali
bc1b413923
Fix Reported Issues - April Batch ( #3962 )
...
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali
b87507b551
Update Suricata TA and Related Analytics ( #3974 )
...
* update suricata ta
* update analytics for new TA
* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-03-28 10:09:22 +00:00
kbouchard
35e6ee2e97
Add files via upload ( #3975 )
...
Updated OOB Response Plan for 8.5 Release of Splunk Enterprise Security
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-28 10:07:40 +00:00
Bhavin Patel
89391cf877
Tune detections based on Athena FPs ( #3972 )
...
---------
Co-authored-by: p4t12ick <patrickbareiss1989@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2026-03-27 16:58:41 +01:00
p4t12ick
fa45863186
Merge pull request #3971 from splunk/detections_improvement
...
Improved detections based on telemetry.
2026-03-27 13:20:26 +01:00
nasbench
30e0c54198
Update ryuk_wake_on_lan_command.yml
2026-03-27 12:21:22 +01:00
P4T12ICK
44f3125d35
bug fix
2026-03-27 10:13:56 +01:00
P4T12ICK
0b219a6b1e
bug fix
2026-03-27 08:28:10 +01:00
P4T12ICK
8be3693cf3
changed back to Anomaly
2026-03-27 08:00:36 +01:00
P4T12ICK
c40b390d3f
updated suggestions
2026-03-27 07:58:29 +01:00
p4t12ick
b4c002efb5
Update detections/endpoint/windows_account_access_removal_via_logoff_exec.yml
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-26 16:45:57 +01:00
p4t12ick
3c1d41e219
Update detections/endpoint/windows_application_whitelisting_bypass_attempt_via_rundll32.yml
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-26 16:45:40 +01:00
p4t12ick
4912e09184
Update detections/endpoint/system_user_discovery_with_whoami.yml
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-26 16:44:53 +01:00
p4t12ick
b4c800deb2
Update detections/endpoint/conti_common_exec_parameter.yml
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-26 16:43:29 +01:00
p4t12ick
6d5d970ee6
Update detections/endpoint/anomalous_usage_of_7zip.yml
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-26 16:43:13 +01:00
P4T12ICK
520bfc060c
bug fix
2026-03-26 10:19:11 +01:00
P4T12ICK
dc3f50b24b
bug fix
2026-03-26 10:13:15 +01:00
P4T12ICK
106a9ba5ca
bug fixes
2026-03-26 09:28:52 +01:00
P4T12ICK
fee2237a5f
bug fix
2026-03-26 08:44:26 +01:00
P4T12ICK
90efd9a8ef
bumped version numbers and dates
2026-03-26 08:01:41 +01:00
P4T12ICK
e86354e45b
bug fix
2026-03-26 07:55:10 +01:00
P4T12ICK
1e0096296b
bug fix
2026-03-26 07:52:19 +01:00
p4t12ick
eb0cb46f71
Merge branch 'develop' into detections_improvement
2026-03-26 07:51:05 +01:00
P4T12ICK
e556cac279
Improved detections based on telemetry.
2026-03-26 07:46:49 +01:00
Br3akp0int
697a77cd08
Add Tagging and Analytic Story for Void Manticore ( #3959 )
...
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-23 17:19:07 +01:00
Lou Stella
0f08a8b884
Tweaking attack_data links ( #3966 )
...
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-23 14:38:28 +01:00
Bhavin Patel
37c9344ca0
chore: bump contentctl.yml to 5.25.0 ( #3968 )
...
Co-authored-by: research bot <research@splunk.com >
2026-03-23 17:52:55 +05:30
Bhavin Patel
45134af4ea
Updated TAs ( #3965 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
v5.24.0
2026-03-19 00:13:23 +05:30
Lou Stella
afccbee627
Changing parameter to hopefully fix TA "dependabot" ( #3964 )
...
* Changing parameter to hopefully work
* typo
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-18 23:41:40 +05:30