Commit Graph

121 Commits

Author SHA1 Message Date
pyth0n1c d40ca09d61 Merged develop into content_changer_improvements to resolve merge conflict. this was making it impossible to merge the PR in the GitHub Interface. 2022-06-23 14:19:17 -07:00
Jose Enrique Hernandez 0288c10f70 Update splunk_identified_ssl_tls_certificates.yml 2022-06-14 08:18:53 -04:00
Lou Stella a0967fe429 Workbook how_to_implement & references 2022-06-13 16:49:49 -05:00
Michael Haag 66d7814fed Update splunk_identified_ssl_tls_certificates.yml 2022-06-13 15:43:18 -06:00
Michael Haag 46cd276adf Update splunk_identified_ssl_tls_certificates.yml 2022-06-13 15:40:49 -06:00
d1vious 97d51b71bf adding cves 2022-06-01 17:03:00 -04:00
mhaag-spl 6ddebf3a2d ssl tls ver 2022-05-26 12:28:21 -06:00
pyth0n1c 2557d21335 Branch was auto-updated. 2022-05-16 14:25:41 -04:00
mhaag-spl 77abe77035 F5 BIG-IP 2022-05-10 07:20:46 -06:00
pyth0n1c 578e6bb088 Updated a very large number of detections whose references were returning HTTP Status 301 - resource moved. For example, this includes a large number of fireeye reports, which are now under mandiant, cobaltstrike info, and microsoft links. 2022-05-02 17:12:50 -07:00
d1vious fdcd471d5d moving to experimental 2022-04-14 16:37:54 -04:00
P4T12ICK 5dd13ea167 fix broken detections 2022-03-14 15:51:05 +01:00
P4T12ICK e6c8254ede Added automaticc generation of finding report 2022-03-14 12:12:48 +01:00
P4T12ICK 6f0ee68913 Refactored security content 2022-03-09 14:43:09 +01:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 886da3c92e merged with develop 2022-03-04 14:35:50 +01:00
patel-bhavin a67a8a4da6 Merge branch 'develop' into refactored_security_content 2022-03-03 12:51:11 -08:00
research bot 67ecd29d53 updating docs and package bits [ci skip] 2022-03-03 18:22:29 +00:00
P4T12ICK 68543a8dc1 merged with develop 2022-03-03 13:11:56 +01:00
d1vious 47dbc6b946 using a different field 2022-02-26 13:39:28 -05:00
d1vious 0d49d7fc55 Merge branch 'CityOfLog4Shells' of github.com:splunk/security_content into CityOfLog4Shells 2022-02-24 23:05:48 -05:00
d1vious 6a50f02ff4 working detection 2022-02-24 23:05:31 -05:00
pyth0n1c df824e79ac Branch was auto-updated. 2022-02-18 15:32:15 -08:00
d1vious ba97944d04 adding ldap detection 2022-02-18 17:39:23 -05:00
d1vious db3605c753 adding ssa detection 2022-02-18 14:26:17 -05:00
truptilangalia-crest 179134e8ef test:removed cim version 2022-02-08 12:05:05 +05:30
truptilangalia-crest 08f0ff6405 test: Removed tas with mapping from detection files 2022-01-31 19:46:09 +05:30
P4T12ICK 4fd8604b9a removed SAAWS and automated_detection_testing flag 2022-01-27 09:50:45 +01:00
Detection Testing Service 6fd7a4e812 test: updated supported_tas to recommended_tas 2022-01-19 17:43:41 +05:30
P4T12ICK 84092434a2 fixed more detections 2022-01-18 12:53:54 +01:00
P4T12ICK 98e5af3713 put baselines and investigations into its own folder 2022-01-17 10:56:04 +01:00
Detection Testing Service a2b6fff739 test:updated ymls 2021-12-15 21:15:02 +05:30
research bot ff3319329e updating docs and package bits [ci skip] 2021-12-15 02:58:27 +00:00
d1vious 16b771eae2 adding tags to detections 2021-12-14 19:38:51 -05:00
patel-bhavin 05b189232d ldap outbound 2021-12-14 10:10:23 -08:00
tlangalia 343ceae12f Updated detection files with supported TA list. 2021-12-14 13:27:55 +05:50
research bot a1afa0fa60 updating docs and package bits [ci skip] 2021-10-28 19:55:37 +00:00
Drew Church 3b18c5abcb Added CVE tags to 35 files 2021-10-22 10:03:24 -07:00
tccontre 9d466adc76 CARS_UPDATE_MITRE_ID_B8
CARS_UPDATE_MITRE_ID_B8
2021-10-15 10:22:43 +02:00
patel-bhavin 333552c326 version 2021-10-06 15:25:22 -07:00
patel-bhavin 966f63d7f1 duplicate 2021-10-06 15:17:00 -07:00
divious1 671e91ecd0 moved to experimental due to lack of testing 2021-09-09 17:30:40 -04:00
research bot 2c9e7b58a8 updating docs and package bits [ci skip] 2021-08-18 16:56:31 +00:00
github-actions[bot] ffa8a4a805 Branch was auto-updated. 2021-07-27 20:53:22 +00:00
root 2fd2af4d29 Added detection testing service results inDNS Query Length With High Standard Deviation 2021-07-27 19:59:57 +00:00
P4T12ICK 686b0b5ca4 converted response_task to investigations 2021-07-26 13:39:17 +02:00
sec-researcher ee3f8638c4 As I know PTR requests can not be used for data exfiltration so having them in search result is just a false positive. Also they have effect on deviation calculation and lead to a lot of false positive in result, specially when PTR requests in the environment is about 20% or more. So I add this filter to the search 'where NOT DNS.message_type IN("Pointer","PTR")' 2021-07-21 18:20:15 +04:30
P4T12ICK 76bbbe4609 add deployments to baselines 2021-07-21 11:31:40 +02:00
P4T12ICK 5e6e987fb7 resolved merge conflicts 2021-07-21 09:22:09 +02:00
research bot 3740535cca updating docs and package bits [ci skip] 2021-07-20 17:49:09 +00:00