dependabot-preview[bot]
|
d0d0772679
|
Bump pre-commit from 2.0.0 to 2.0.1
Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 2.0.0 to 2.0.1.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/master/CHANGELOG.md)
- [Commits](https://github.com/pre-commit/pre-commit/compare/v2.0.0...v2.0.1)
Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
2020-01-30 02:09:24 +00:00 |
|
dependabot-preview[bot]
|
90cdbe7ef0
|
Merge pull request #340 from splunk/dependabot/pip/more-itertools-8.2.0
|
2020-01-29 13:09:31 +00:00 |
|
dependabot-preview[bot]
|
0b110b541a
|
Bump more-itertools from 8.1.0 to 8.2.0
Bumps [more-itertools](https://github.com/erikrose/more-itertools) from 8.1.0 to 8.2.0.
- [Release notes](https://github.com/erikrose/more-itertools/releases)
- [Commits](https://github.com/erikrose/more-itertools/compare/v8.1.0...v8.2.0)
Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
2020-01-29 13:05:09 +00:00 |
|
dependabot-preview[bot]
|
c0ef423eef
|
Merge pull request #339 from splunk/dependabot/pip/importlib-metadata-1.5.0
|
2020-01-29 05:15:01 +00:00 |
|
dependabot-preview[bot]
|
503dbe5e40
|
Bump importlib-metadata from 1.4.0 to 1.5.0
Bumps [importlib-metadata](http://importlib-metadata.readthedocs.io/) from 1.4.0 to 1.5.0.
Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
2020-01-29 05:10:30 +00:00 |
|
Jose Enrique Hernandez
|
a7baf3fcc2
|
Merge pull request #338 from splunk/dependabot_automerge
adding github workflow to auto approve dependabot PRs that passed CI …
|
2020-01-28 22:24:32 -05:00 |
|
divious1
|
d4fbe656d6
|
adding github workflow to auto approve dependabot PRs that passed CI this is to circumvent branch protection
|
2020-01-28 22:12:14 -05:00 |
|
dependabot-preview[bot]
|
94664241b6
|
Merge pull request #337 from splunk/dependabot/pip/pre-commit-2.0.0
|
2020-01-29 03:07:41 +00:00 |
|
dependabot-preview[bot]
|
992eedfecc
|
Bump pre-commit from 1.21.0 to 2.0.0
Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 1.21.0 to 2.0.0.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/master/CHANGELOG.md)
- [Commits](https://github.com/pre-commit/pre-commit/compare/v1.21.0...v2.0.0)
Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
2020-01-29 02:51:57 +00:00 |
|
dependabot-preview[bot]
|
5d49e31f16
|
Merge pull request #328 from splunk/dependabot/pip/identify-1.4.11
|
2020-01-29 00:35:23 +00:00 |
|
dependabot-preview[bot]
|
8caa037cc6
|
Merge pull request #329 from splunk/dependabot/pip/zipp-2.1.0
|
2020-01-28 21:38:59 +00:00 |
|
dependabot-preview[bot]
|
b155dd6d4b
|
Bump identify from 1.4.10 to 1.4.11
Bumps [identify](https://github.com/chriskuehl/identify) from 1.4.10 to 1.4.11.
- [Release notes](https://github.com/chriskuehl/identify/releases)
- [Commits](https://github.com/chriskuehl/identify/compare/v1.4.10...v1.4.11)
Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
2020-01-28 16:13:32 +00:00 |
|
dependabot-preview[bot]
|
453183cbff
|
Merge pull request #332 from splunk/dependabot/pip/jinja2-2.11.0
|
2020-01-28 16:12:24 +00:00 |
|
Jose Enrique Hernandez
|
cf78269d29
|
Merge pull request #335 from splunk/dependabot_automerge
merge all
|
2020-01-28 11:06:49 -05:00 |
|
divious1
|
8b3447c016
|
merge all
|
2020-01-28 11:06:24 -05:00 |
|
Jose Enrique Hernandez
|
78bffbf8d5
|
Merge pull request #334 from splunk/dependabot_automerge
no need to specify path
|
2020-01-28 10:29:56 -05:00 |
|
divious1
|
d9f7c09eac
|
no need to specify path
|
2020-01-28 10:29:16 -05:00 |
|
Jose Enrique Hernandez
|
23174e7c99
|
Merge pull request #330 from splunk/dependabot_automerge
automatically merge deps
|
2020-01-28 10:21:42 -05:00 |
|
dependabot-preview[bot]
|
7bec484354
|
Bump jinja2 from 2.10.3 to 2.11.0
Bumps [jinja2](https://github.com/pallets/jinja) from 2.10.3 to 2.11.0.
- [Release notes](https://github.com/pallets/jinja/releases)
- [Changelog](https://github.com/pallets/jinja/blob/master/CHANGES.rst)
- [Commits](https://github.com/pallets/jinja/compare/2.10.3...2.11.0)
Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
2020-01-28 14:13:11 +00:00 |
|
Bhavin Patel
|
656b66cd71
|
Merge pull request #331 from splunk/develop
Updated Master base on v1.0.49 release
|
2020-01-27 14:00:48 -08:00 |
|
dependabot-preview[bot]
|
0da53bb353
|
Bump zipp from 2.0.0 to 2.1.0
Bumps [zipp](https://github.com/jaraco/zipp) from 2.0.0 to 2.1.0.
- [Release notes](https://github.com/jaraco/zipp/releases)
- [Changelog](https://github.com/jaraco/zipp/blob/master/CHANGES.rst)
- [Commits](https://github.com/jaraco/zipp/compare/v2.0.0...v2.1.0)
Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
2020-01-27 14:13:08 +00:00 |
|
jzsplunk
|
c92d097eac
|
updating boiler plate, detection not working out of box against T1193 but this may be due to error loading lookup table for supicious file extensions.
|
2020-01-27 03:04:55 -08:00 |
|
jzsplunk
|
d4aa6bc9ea
|
update smb related content. The outbound_smb_connections detection works out of the box against attack ID T1110 when testing in the attack range.
|
2020-01-27 02:33:26 -08:00 |
|
jzsplunk
|
b762034a4b
|
update version info and macros, attack range freezing on testing detection against attack ID T1071 so query is untested against atomic red team test for now
|
2020-01-27 01:44:53 -08:00 |
|
jzsplunk
|
6406cfbc32
|
update version info, add macros for first time seen cmd line detection
|
2020-01-27 01:08:53 -08:00 |
|
divious1
|
d73c378321
|
automatically merge deps
|
2020-01-24 18:16:26 -08:00 |
|
research bot
|
814c7bb023
|
updating docs and package bits [ci skip]
|
2020-01-23 21:58:19 +00:00 |
|
Bhavin Patel
|
f2702a6e10
|
Merge pull request #322 from splunk/CRL-1720
adding definitions
v1.0.49
|
2020-01-23 13:48:36 -08:00 |
|
bpatel
|
9e6becda1f
|
adding definitions
|
2020-01-23 13:31:43 -08:00 |
|
research bot
|
cbd0c380d3
|
updating docs and package bits [ci skip]
|
2020-01-23 01:33:05 +00:00 |
|
Jose Enrique Hernandez
|
2fd12b9155
|
Merge pull request #320 from splunk/don_young_bug
updating the manifest to reflect correct details
|
2020-01-22 17:26:54 -08:00 |
|
Bhavin Patel
|
75485ef666
|
Merge pull request #316 from splunk/CRL-1717_addMacroDefinitionsWhereMissing
CRL-1717 - Added "search *" definitions to the macros without them… resolves #292
|
2020-01-22 14:59:44 -08:00 |
|
Bhavin Patel
|
dd5b1ee344
|
Merge pull request #319 from splunk/dns_hijack_story_update
CRL-1718 updated fields and added macros and lookup entries
|
2020-01-22 14:58:40 -08:00 |
|
dependabot-preview[bot]
|
03f4b9a8b7
|
Merge pull request #309 from splunk/dependabot/pip/more-itertools-8.1.0
|
2020-01-22 21:31:37 +00:00 |
|
divious1
|
0ba1b4c30d
|
fixing mispelling
|
2020-01-22 13:31:09 -08:00 |
|
Jason Brewer
|
c3b04375c9
|
CRL-1719 - Fixing reference to https://attack.mitre.org/wiki/Privilege_Escalation >>> https://attack.mitre.org/tactics/TA0004/
|
2020-01-22 12:17:24 -08:00 |
|
Bhavin Patel
|
38b84113bf
|
Merge pull request #318 from splunk/CRL-1495-update_share_creation_and_deletion
CRL-1495 update share creation and deletion
|
2020-01-22 09:19:43 -08:00 |
|
Bhavin Patel
|
0cef2e73b1
|
Merge pull request #315 from splunk/CRL-1716-FixPowerShellObfusc
CRL-1716 - Fixing by clause to allow searching Processes.process for …
|
2020-01-22 09:18:42 -08:00 |
|
bpatel
|
5d6ef5ce60
|
renaming files
|
2020-01-22 09:14:51 -08:00 |
|
Jason Brewer
|
b85543e0b5
|
CRL-1717 - Addressing comments by removing unnecessary output_filter macros from investigation searches and removing references to those in the investigation definitions.
|
2020-01-22 08:40:30 -08:00 |
|
Jason Brewer
|
b62ce205b8
|
CRL-1716 - Updating per code review requests. Adding output macro file and reference within the detection search.
|
2020-01-22 08:26:16 -08:00 |
|
dependabot-preview[bot]
|
f196179eee
|
Merge pull request #317 from splunk/dependabot/pip/zipp-2.0.0
|
2020-01-22 02:17:12 +00:00 |
|
Jose Enrique Hernandez
|
bfa7317668
|
removing comments
|
2020-01-21 18:14:24 -08:00 |
|
bpatel
|
3bf8cf26de
|
updating the manifest to reflect correct details
|
2020-01-21 18:05:33 -08:00 |
|
bpatel
|
14f54a12e8
|
removing incorrect macro file
|
2020-01-21 17:29:55 -08:00 |
|
dependabot-preview[bot]
|
bccc500554
|
Bump more-itertools from 8.0.2 to 8.1.0
Bumps [more-itertools](https://github.com/erikrose/more-itertools) from 8.0.2 to 8.1.0.
- [Release notes](https://github.com/erikrose/more-itertools/releases)
- [Commits](https://github.com/erikrose/more-itertools/compare/v8.0.2...v8.1.0)
Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
2020-01-21 19:44:25 +00:00 |
|
dependabot-preview[bot]
|
593798dfb3
|
Merge pull request #304 from splunk/dependabot/pip/nodeenv-1.3.4
|
2020-01-21 19:43:03 +00:00 |
|
Jose Enrique Hernandez
|
c6a904b36f
|
Merge pull request #314 from splunk/CRL-1712_netsh_abuse
CRL-1712 Disabling Security Tools
|
2020-01-21 11:42:42 -08:00 |
|
Jose Enrique Hernandez
|
7b976f25f7
|
Update investigate_user_activities_in_all_cloud_region_output_filter.yml
|
2020-01-21 11:34:38 -08:00 |
|
Jose Enrique Hernandez
|
11a1b68979
|
bumping version
|
2020-01-21 11:28:26 -08:00 |
|