Commit Graph

113 Commits

Author SHA1 Message Date
pyth0n1c 6f9877cd9d Updated all required fields and datamodels again. 2022-03-17 13:25:28 -07:00
pyth0n1c 25cd37992f Revert "Updated all required fields and datamodels again."
This reverts commit 84e65bb3fb.
2022-03-17 13:21:42 -07:00
pyth0n1c 84e65bb3fb Updated all required fields and datamodels again. 2022-03-17 13:10:22 -07:00
pyth0n1c 4d91df0427 Reverted enrichment commit. 2022-03-11 11:54:41 -08:00
pyth0n1c 325db37b95 Ran enrichment tool to update all DataModel and required_fields parts of yml files with most recent and correct codebase. More specifically, ran this tool after correcting some searches with only included a Model, not Model.Submodel declaration in their search. 2022-03-09 14:35:48 -08:00
pyth0n1c 970648ad69 Large number of changes to the
format of datamodels in searches.
This is in support of the script
to automatically parse searches in
order to pull out required fields
and datamodels used or not used
in a search.
2022-03-09 14:10:50 -08:00
Jose Enrique Hernandez d78bb53baa Revert "Refactored security content" 2022-03-04 15:13:04 -05:00
P4T12ICK 886da3c92e merged with develop 2022-03-04 14:35:50 +01:00
patel-bhavin a67a8a4da6 Merge branch 'develop' into refactored_security_content 2022-03-03 12:51:11 -08:00
research bot 67ecd29d53 updating docs and package bits [ci skip] 2022-03-03 18:22:29 +00:00
P4T12ICK 68543a8dc1 merged with develop 2022-03-03 13:11:56 +01:00
d1vious 47dbc6b946 using a different field 2022-02-26 13:39:28 -05:00
d1vious 0d49d7fc55 Merge branch 'CityOfLog4Shells' of github.com:splunk/security_content into CityOfLog4Shells 2022-02-24 23:05:48 -05:00
d1vious 6a50f02ff4 working detection 2022-02-24 23:05:31 -05:00
pyth0n1c df824e79ac Branch was auto-updated. 2022-02-18 15:32:15 -08:00
d1vious ba97944d04 adding ldap detection 2022-02-18 17:39:23 -05:00
d1vious db3605c753 adding ssa detection 2022-02-18 14:26:17 -05:00
truptilangalia-crest 179134e8ef test:removed cim version 2022-02-08 12:05:05 +05:30
truptilangalia-crest 08f0ff6405 test: Removed tas with mapping from detection files 2022-01-31 19:46:09 +05:30
P4T12ICK 4fd8604b9a removed SAAWS and automated_detection_testing flag 2022-01-27 09:50:45 +01:00
Detection Testing Service 6fd7a4e812 test: updated supported_tas to recommended_tas 2022-01-19 17:43:41 +05:30
P4T12ICK 84092434a2 fixed more detections 2022-01-18 12:53:54 +01:00
P4T12ICK 98e5af3713 put baselines and investigations into its own folder 2022-01-17 10:56:04 +01:00
Detection Testing Service a2b6fff739 test:updated ymls 2021-12-15 21:15:02 +05:30
research bot ff3319329e updating docs and package bits [ci skip] 2021-12-15 02:58:27 +00:00
d1vious 16b771eae2 adding tags to detections 2021-12-14 19:38:51 -05:00
patel-bhavin 05b189232d ldap outbound 2021-12-14 10:10:23 -08:00
tlangalia 343ceae12f Updated detection files with supported TA list. 2021-12-14 13:27:55 +05:50
research bot a1afa0fa60 updating docs and package bits [ci skip] 2021-10-28 19:55:37 +00:00
Drew Church 3b18c5abcb Added CVE tags to 35 files 2021-10-22 10:03:24 -07:00
tccontre 9d466adc76 CARS_UPDATE_MITRE_ID_B8
CARS_UPDATE_MITRE_ID_B8
2021-10-15 10:22:43 +02:00
patel-bhavin 333552c326 version 2021-10-06 15:25:22 -07:00
patel-bhavin 966f63d7f1 duplicate 2021-10-06 15:17:00 -07:00
divious1 671e91ecd0 moved to experimental due to lack of testing 2021-09-09 17:30:40 -04:00
research bot 2c9e7b58a8 updating docs and package bits [ci skip] 2021-08-18 16:56:31 +00:00
github-actions[bot] ffa8a4a805 Branch was auto-updated. 2021-07-27 20:53:22 +00:00
root 2fd2af4d29 Added detection testing service results inDNS Query Length With High Standard Deviation 2021-07-27 19:59:57 +00:00
P4T12ICK 686b0b5ca4 converted response_task to investigations 2021-07-26 13:39:17 +02:00
sec-researcher ee3f8638c4 As I know PTR requests can not be used for data exfiltration so having them in search result is just a false positive. Also they have effect on deviation calculation and lead to a lot of false positive in result, specially when PTR requests in the environment is about 20% or more. So I add this filter to the search 'where NOT DNS.message_type IN("Pointer","PTR")' 2021-07-21 18:20:15 +04:30
P4T12ICK 76bbbe4609 add deployments to baselines 2021-07-21 11:31:40 +02:00
P4T12ICK 5e6e987fb7 resolved merge conflicts 2021-07-21 09:22:09 +02:00
research bot 3740535cca updating docs and package bits [ci skip] 2021-07-20 17:49:09 +00:00
github-actions[bot] 23c103c192 Branch was auto-updated. 2021-07-20 15:47:19 +00:00
P4T12ICK 9568fc7807 migrated baselines into detections folder 2021-07-20 13:19:22 +02:00
P4T12ICK cfae82505c add analytic types to detections 2021-07-19 17:41:22 +02:00
tccontre 3d82142995 rba_task_update 2021-07-15 09:39:03 +02:00
tccontre 8477b3e3a0 rba_task_2 2021-07-14 16:35:10 +02:00
tccontre 019e9311f1 rba_task_2 2021-07-14 16:33:48 +02:00
tccontre 197e73cd61 de 2021-06-15 15:51:08 +02:00
tccontre 9e009e50b7 data_exfil 2021-06-15 15:36:41 +02:00