Commit Graph

28080 Commits

Author SHA1 Message Date
ljstella 56827470ac Adding script to analyze risk objects on TTP detections 2026-04-07 13:11:59 -04:00
Lou Stella 290486b6fe Merge pull request #3994 from splunk/update-template-script-2 2026-04-07 07:29:09 -05:00
Henry Yu e182e32f51 quote the file 2026-04-06 21:04:14 -07:00
Henry Yu e791773e97 unquote the file 2026-04-06 20:44:11 -07:00
Lou Stella 6e75fc6407 Merge pull request #3991 from splunk/update-template-script 2026-04-06 17:05:24 -05:00
Lou Stella 806f6bdd32 Merge branch 'develop' into update-template-script 2026-04-06 17:03:05 -05:00
Lou Stella 95b35f77c1 Merge pull request #3990 from splunk/kbouchard-patch-1 2026-04-06 17:02:40 -05:00
Lou Stella 93cb3bedd9 Merge branch 'develop' into kbouchard-patch-1 2026-04-06 16:59:28 -05:00
Henry Yu 9b5c9aa7b9 remove the ignore . file change 2026-04-06 14:47:08 -07:00
Henry Yu 924a89e249 add validation for unique name, version pair 2026-04-02 13:06:15 -07:00
Henry Yu 9bc34d412f group by actual template names instead of file name 2026-04-02 12:38:37 -07:00
Br3akp0int 7293d75700 Tagged Analytics Covering the Axios Compromise Post-Exploitation Activity (#3982)
---------

Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com>
2026-04-02 16:07:20 +00:00
Raven Tait f416da59fe Add Filter for VMware Tools (#3983) 2026-04-02 18:06:04 +02:00
Bhavin Patel 116ab57d18 Remove AITK/MLTK TAs references from Contentctl.yml (#3911)
---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-02 17:47:55 +02:00
Bhavin Patel 8c6453e0ea Bump contentctl.yml to 5.26.0 (#3989)
* chore: bump contentctl.yml to 5.26.0

* remove detections

---------

Co-authored-by: research bot <research@splunk.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2026-04-02 17:41:06 +02:00
kbouchard fc1596e371 had to remove 8.5 from the name of response plans
had to remove 8.5 from the name of response plans
2026-04-01 20:55:54 -07:00
pyth0n1c 90536d0e5a Palo Alto Ta 3.0.0 was pulled from Splukbase. (#3985)
As such we must bump the TA to the newest 
(and only) available release, 3.0.1.
v5.25.0
2026-03-31 22:42:26 +05:30
Nasreddine Bencherchali fd53a2186b Fix Broken RBA Message (#3984) 2026-03-31 15:34:07 +00:00
Lou Stella 39849c0179 Merge pull request #3980 from splunk/sched_task_rba_message 2026-03-30 14:51:23 -05:00
ljstella d38d8e1519 First pass of RBA message fix 2026-03-30 15:09:36 -04:00
Br3akp0int ff78e2d159 gh0st (#3973)
* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* gh0st

* small changes

* another update

* final fix

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-30 19:46:33 +05:30
Nasreddine Bencherchali bc1b413923 Fix Reported Issues - April Batch (#3962)
* Fix #3961

* Fix #3909

* Fix output fields

* Remove duplicate process_name entry

* Update outbound_network_connection_from_java_using_default_ports.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Update detect_computer_changed_with_anonymous_account.yml

* Fix #3969

* update palo alto TA and beautify analytics

* Update vmware_aria_operations_exploit_attempt.yml

* fix source

* enhance metadata and fp info

* beautify spl for ease of reading

* add some missing attack techniques

* remove unnecessary usage of regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* small fix

* Refine description and improve regex

* Update windows_uac_bypass_suspicious_escalation_behavior.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update possible_lateral_movement_powershell_spawn.yml

* Update windows_event_log_security_4756.yml

* description update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali b87507b551 Update Suricata TA and Related Analytics (#3974)
* update suricata ta

* update analytics for new TA

* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml

---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-03-28 10:09:22 +00:00
kbouchard 35e6ee2e97 Add files via upload (#3975)
Updated OOB Response Plan for 8.5 Release of Splunk Enterprise Security

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-28 10:07:40 +00:00
Bhavin Patel 89391cf877 Tune detections based on Athena FPs (#3972)
---------

Co-authored-by: p4t12ick <patrickbareiss1989@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2026-03-27 16:58:41 +01:00
p4t12ick fa45863186 Merge pull request #3971 from splunk/detections_improvement
Improved detections based on telemetry.
2026-03-27 13:20:26 +01:00
nasbench 30e0c54198 Update ryuk_wake_on_lan_command.yml 2026-03-27 12:21:22 +01:00
P4T12ICK 44f3125d35 bug fix 2026-03-27 10:13:56 +01:00
P4T12ICK 0b219a6b1e bug fix 2026-03-27 08:28:10 +01:00
P4T12ICK 8be3693cf3 changed back to Anomaly 2026-03-27 08:00:36 +01:00
P4T12ICK c40b390d3f updated suggestions 2026-03-27 07:58:29 +01:00
p4t12ick b4c002efb5 Update detections/endpoint/windows_account_access_removal_via_logoff_exec.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-26 16:45:57 +01:00
p4t12ick 3c1d41e219 Update detections/endpoint/windows_application_whitelisting_bypass_attempt_via_rundll32.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-26 16:45:40 +01:00
p4t12ick 4912e09184 Update detections/endpoint/system_user_discovery_with_whoami.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-26 16:44:53 +01:00
p4t12ick b4c800deb2 Update detections/endpoint/conti_common_exec_parameter.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-26 16:43:29 +01:00
p4t12ick 6d5d970ee6 Update detections/endpoint/anomalous_usage_of_7zip.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-26 16:43:13 +01:00
P4T12ICK 520bfc060c bug fix 2026-03-26 10:19:11 +01:00
P4T12ICK dc3f50b24b bug fix 2026-03-26 10:13:15 +01:00
P4T12ICK 106a9ba5ca bug fixes 2026-03-26 09:28:52 +01:00
P4T12ICK fee2237a5f bug fix 2026-03-26 08:44:26 +01:00
P4T12ICK 90efd9a8ef bumped version numbers and dates 2026-03-26 08:01:41 +01:00
P4T12ICK e86354e45b bug fix 2026-03-26 07:55:10 +01:00
P4T12ICK 1e0096296b bug fix 2026-03-26 07:52:19 +01:00
p4t12ick eb0cb46f71 Merge branch 'develop' into detections_improvement 2026-03-26 07:51:05 +01:00
P4T12ICK e556cac279 Improved detections based on telemetry. 2026-03-26 07:46:49 +01:00
Br3akp0int 697a77cd08 Add Tagging and Analytic Story for Void Manticore (#3959)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-23 17:19:07 +01:00
Lou Stella 0f08a8b884 Tweaking attack_data links (#3966)
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-23 14:38:28 +01:00
Bhavin Patel 37c9344ca0 chore: bump contentctl.yml to 5.25.0 (#3968)
Co-authored-by: research bot <research@splunk.com>
2026-03-23 17:52:55 +05:30
Bhavin Patel 45134af4ea Updated TAs (#3965)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
v5.24.0
2026-03-19 00:13:23 +05:30
Lou Stella afccbee627 Changing parameter to hopefully fix TA "dependabot" (#3964)
* Changing parameter to hopefully work

* typo

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-18 23:41:40 +05:30