Commit Graph

89 Commits

Author SHA1 Message Date
divious1 0abf721c3f introduced mitre technique id to detection spec 2020-01-06 13:31:43 -05:00
David Dorsey 5f30745b7c Fixed issue in CRL-1387 where the check for executionpolicy bypass
was too broad.
Also, added investigation searches for file and registry activity
while I was here
2019-11-06 18:39:21 -08:00
bpatel 541b72fd71 merge with develop and testing 2019-11-05 12:22:01 -08:00
Patrick Bareiss af66ed5fe3 Changed json to yml 2019-10-16 16:38:05 +02:00
Jose Enrique Hernandez c9effaf169 Merge branch 'develop' into cloud_cryptominig 2019-10-08 08:40:51 -04:00
Jose Enrique Hernandez 9c6c794b81 Merge pull request #215 from splunk/drilldown
Added drilldown search and name to the detection spec.
2019-10-08 08:32:49 -04:00
David Dorsey fb93597cfc Merge branch 'macros' into cloud_cryptominig 2019-10-03 17:49:45 -07:00
David Dorsey 82e8b210a9 Files for new cloud cryptominig story.
It's a cloud infrastructure generic version of AWS Cryptomining
2019-10-03 17:42:40 -07:00
David Dorsey 24769e88c5 Added lookup to the search specs 2019-10-02 12:01:03 -07:00
David Dorsey 2a8b470241 Added drilldown search and name to the detection spec.
Added these fields to the suspicious wevtutil manifest
Updated validate to make sure both entries are there or neither are
Updated generate to output those fields if they are there
2019-10-01 17:31:11 -07:00
David Dorsey 575b766f09 Minor spec change to macro.spec.json 2019-09-30 16:08:08 -07:00
David Dorsey 3d25c40bf7 Updated macro definition in detections, investigations, and baselines to just be a list
Broke out macros definition into it's own manifest
Created macro manifests for all of current macros that we ship
Created lookup file manifest
Created lookup file manifests for all current lookup files that we ship
2019-09-30 13:53:25 -07:00
David Dorsey 6ee9d9962c Added entry for macros in baseline, detections, and investigations spec. 2019-09-25 14:36:35 -05:00
bpatel e1310d2192 adding ss.conf spec and example 2019-09-12 16:27:11 -07:00
bpatel 4d221f5d18 added entities field and updated spec files 2019-09-04 16:36:08 -07:00
divious1 bb0a440b62 removing example repo as all content is now v2 2019-09-04 12:44:43 -04:00
Rico Valdez 8eb0084ae0 re-applying some fixes for channel. Also, merging in develop broke the spec file, so fixed that. 2019-08-06 20:47:35 -06:00
divious1 b82eaa7750 fixing merge conflicts 2019-08-06 17:45:35 -04:00
Rico Valdez 5836446617 fixed channel in stories, minor tweaks to detections.
Also - updated spec to allow validation to pass for UBA detection, as well as updated validation script
2019-08-06 14:58:39 -06:00
Bhavin Patel 57118d085c Merge pull request #167 from splunk/CRL-1580
CRL 1580 :UBA Anomaly
2019-07-26 12:26:53 -07:00
Rico Valdez bfef6024fe more tweaks/fixes to manifests - also adjustments to validation script and spec files. Successfully validates with exception of usecase in stories 2019-07-25 14:56:40 -06:00
bpatel bfa2df0786 updated search and manifest content 2019-07-24 14:29:03 -07:00
divious1 06f5aa70fb fixing stories that are using product_type 2019-07-18 12:35:45 -04:00
divious1 4c352b9bed fixing error 2019-07-17 12:52:09 -04:00
divious1 3813882fae doc generation skeleton 2019-06-19 00:03:14 -04:00
proyer 842e46f953 add missing providing_technologies to spec 2019-06-04 14:40:53 -04:00
bpatel 926298f6cd validate errors 2019-04-22 13:51:30 -07:00
bpatel 7336624652 conflicts, merge spec update to this branch 2019-04-22 11:44:26 -07:00
bpatel ce0eeade0f spec updates, searches to 2.0 2019-04-18 14:39:01 -07:00
bpatel 3d43375341 fixes and udpates 2019-04-18 13:15:16 -07:00
divious1 bdfc72749a updated validate script, included phantom in generator, fixed some stories to v2 2019-04-18 11:28:26 -04:00
bpatel a449fbb8f7 updating Censys in providing technologies 2019-04-16 11:25:19 -07:00
bpatel cff0563d28 phantom invesigation object 2019-04-16 11:20:37 -07:00
bpatel 86662c3c0a CI errors 2019-04-15 13:37:49 -07:00
bpatel 018cd8256c examples in spec files and docs 2019-04-02 17:00:32 -07:00
divious1 cfeccbd73e removed example spec 2019-04-02 17:31:57 -05:00
divious1 87c1490320 Merge branch 'spec_update' of github.com:splunk/security-content into spec_update 2019-04-02 17:31:29 -05:00
divious1 6112fcc9e6 updating schedule field in specs, also corrected validation logic 2019-04-02 17:31:02 -05:00
divious1 d76848cb39 correct mistakes with the sub schema validation 2019-04-02 17:03:55 -05:00
bpatel 43093da142 story spec with example and docs 2019-04-02 14:28:20 -07:00
divious1 b923dc56c3 updated investigations 2019-04-02 14:47:10 -04:00
divious1 a9bb9bad0d updated spec and examples to correct some def errors 2019-04-02 14:34:35 -04:00
bpatel 35f8c61e8c oneOF example 2019-04-02 10:55:59 -07:00
divious1 e562cc1e37 updated with baseline searches 2019-04-01 16:36:17 -04:00
divious1 f05f011e6b added investigative check functions 2019-03-29 22:59:27 -04:00
divious1 fd6a55d7f4 updated mitre mappings 2019-03-29 13:44:40 -04:00
bpatel 6c24bb91d9 spec omne enums and v2 examples 2019-03-29 12:45:15 -04:00
bpatel a2f431b6cc baseline update 2019-03-29 12:14:44 -04:00
bpatel 6ce4f809af updates 2019-03-28 12:46:04 -04:00
bpatel bdbe20f992 detection spec update 2019-03-28 12:23:29 -04:00