Commit Graph

28175 Commits

Author SHA1 Message Date
Bhavin Patel 8ad653147d testing yaml lint 2026-06-04 10:37:22 +05:30
Bryan Pluta c1c48eef3a updated lantern link 2026-06-03 14:10:53 -05:00
Bryan Pluta 2cfe9b5edd how to implement update 2026-06-03 12:25:54 -05:00
Bhavin Patel 854f1cd115 updating dataset 2026-06-03 22:26:12 +05:30
Bhavin Patel 193d6468c7 adding dest_ip for entitiy 2026-06-03 22:11:39 +05:30
Bhavin Patel a0d5f8bb1b updating as per contentctl ng requirements 2026-06-03 22:08:09 +05:30
Bhavin Patel 9ff25f35d8 Merge branch 'develop' into secureapp 2026-06-03 20:53:55 +05:30
Lou Stella 4493a82b24 Merge pull request #4082 from splunk/escu_6
ESCU 6 YAML Porting and Updates
v6.0.0
2026-05-28 13:42:12 -04:00
Bryan Pluta 732bb720da name change 2026-05-28 10:45:05 -05:00
Bryan Pluta 960f86b36b name change 2026-05-28 08:46:22 -05:00
Lou Stella e547f65647 Merge pull request #4109 from splunk/escu_6_add_mitre_lookup_object
remove mitre_enrichment lookup
2026-05-28 09:30:22 -04:00
pyth0n1c 191d88b919 Merge branch 'escu_6' into escu_6_add_mitre_lookup_object 2026-05-27 16:27:05 -07:00
pyth0n1c 21382d5854 Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6 2026-05-27 16:26:19 -07:00
pyth0n1c 8b46602b10 bump to contentctl 0.7.0 2026-05-27 16:25:10 -07:00
Eric 066be568ff remove unused legacy lookup mitre_enrichment 2026-05-27 14:31:58 -07:00
Bryan Pluta 0f0d5d9a69 new o11y secure application detection 2026-05-27 08:53:31 -05:00
Eric 2b5b07a892 move mitre_enrichment from the app_template and make it its own content object 2026-05-26 15:45:44 -07:00
pyth0n1c 1eee030aea Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6 2026-05-26 12:52:49 -07:00
pyth0n1c 94031fb8ef bump ng version to latest 2026-05-26 12:51:40 -07:00
pyth0n1c ac76e5521e Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6 2026-05-22 09:53:08 -07:00
pyth0n1c 955e428056 Bump to contentctl-ng
0.5.0 to resolve errors
in unit testing workflow
2026-05-22 09:52:15 -07:00
pyth0n1c 705d154891 Merge pull request #4097 from splunk/escu_6_bump_pulled_ta_version
bump pulled AWS TA version
2026-05-21 16:52:05 -07:00
Eric 830c9189e9 bump pulled AWS TA version 2026-05-21 16:06:38 -07:00
pyth0n1c 61f33e2b62 Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6 2026-05-21 15:36:05 -07:00
Eric 295994a577 debug issues with testing from target branch 2026-05-21 15:34:27 -07:00
pyth0n1c 12b801e080 Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6 2026-05-21 15:23:39 -07:00
Eric 1ef4a3c092 Remove separate action, which lead
to some confusing indirection
2026-05-21 15:20:08 -07:00
Eric 101c76e8b8 After discussions with team,
remove the rba_upgrade_tracking.json
file and update the default.xml
file to avoid conflict around
multiple definitions of this file.
2026-05-21 13:26:56 -07:00
Eric 93e2487cb2 Merge branch 'escu_6' of https://github.com/splunk/security_content into escu_6 2026-05-21 13:25:45 -07:00
Lou Stella 6fcd545024 Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6 2026-05-21 16:17:01 -04:00
Eric b6a8382659 fix reference to install and build commands
in workflow
2026-05-21 11:51:00 -07:00
Eric 290e3f66cd Merge branch 'escu_6_workflow_updates_only_no_content' into escu_6 2026-05-21 11:38:56 -07:00
Eric 73c7ac9b2c Add the workflow updates 2026-05-21 11:16:50 -07:00
Lou Stella bd1b475ccb Merge pull request #4088 from splunk/escu6_manual_review
ESCU 6 Manual Migrations
2026-05-21 11:09:25 -04:00
Eric McGinnis e84529f448 added back contentctl.yml as it is required for the legacy testing workflow 2026-05-20 13:31:40 -07:00
Eric McGinnis 1fb3da73f2 Add updated schemas, which has been updated as manual_review content was resolved 2026-05-20 12:19:45 -07:00
ljstella 0c869bfc93 yamlfmt 2026-05-20 15:15:09 -04:00
Lou Stella e5dc0c4625 Merge pull request #4089 from splunk/port_playbooks
Port playbooks
2026-05-20 12:35:21 -04:00
ljstella c498d21841 Manual Review completion 2026-05-20 12:15:00 -04:00
Eric McGinnis 13f06b5e1d Complete porinting of playbooks. Fix references to old, removed detections
in playbooks that were previously unvalidated.
Add a MANUAL_REVIEW section, which is commented out,
for clarity and to allow CICD to run and pass on this content.
Renamed an existing playbook because it diverges from the name
of that playbook elsewhere.
2026-05-19 14:28:53 -07:00
pyth0n1c e190246023 Merge branch 'escu6_manual_review' into port_playbooks 2026-05-19 12:22:30 -07:00
ljstella d7b8c0f0d8 Reordering key 2026-05-19 14:25:35 -04:00
Lou Stella d235c3e7d2 Update detections/web/monitor_web_traffic_for_brand_abuse.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-19 14:22:21 -04:00
ljstella bc18194661 Reordering keys 2026-05-19 14:21:30 -04:00
Eric McGinnis 0a8c534612 Update playbooks to new format. 2026-05-19 11:12:49 -07:00
ljstella b196ddcf95 Baseline cleanup 2026-05-19 12:23:15 -04:00
ljstella 53565febce message cleanup 2026-05-19 12:15:48 -04:00
ljstella 15c349bde3 Multiple user type entities 2026-05-19 11:45:53 -04:00
ljstella e52095cb16 Unbalanced $ in message 2026-05-19 10:35:40 -04:00
ljstella baf4b85578 Multiple non-user but no user 2026-05-19 10:34:15 -04:00