Commit Graph

28010 Commits

Author SHA1 Message Date
Br3akp0int 88f318923e Merge branch 'develop' into ttp_init_score 2026-03-10 09:15:23 +01:00
Emil b1425aadfa Split and tweak of linux_docker_privilege_escalation (#3929)
* Splitting linux_docker_privilege_escalation into two detections, modifying the queries to more precisely trigger on the activity

* Adding back original author, removing trailing whitespace

* deprecate and update metadata

* Update linux_docker_shell_execution.yml

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-10 12:46:59 +05:30
Bhavin Patel 96a4df100d Automated Splunk TA Update 560 (#3938)
* Updated TAs

* updating app name

* testing TA

* remove comments

---------

Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-03-06 12:26:52 +05:30
Lou Stella 22953496b2 Merge pull request #3937 from splunk/bump_contentctl_5.24.0
Bump contentctl.yml to 5.24.0
2026-03-05 12:14:22 -06:00
ljstella ba6f9b948d Bumping requirements.txt 2026-03-05 12:28:06 -05:00
ljstella 8f80f086b3 Actually remove the detection 2026-03-05 09:15:43 -05:00
ljstella 5440317966 Removed detection for v5.24.0 2026-03-05 09:12:44 -05:00
research bot 1eaa1a12d2 chore: bump contentctl.yml to 5.24.0 2026-03-04 19:11:57 +00:00
dependabot[bot] 261b5fee45 Bump aws-actions/configure-aws-credentials from 5 to 6 (#3933)
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 5 to 6.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws-actions/configure-aws-credentials/compare/v5...v6)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
v5.23.0
2026-03-03 20:47:16 +00:00
dependabot[bot] 2f600e1214 Bump actions/upload-artifact from 6 to 7 (#3932)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 6 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-03 20:46:02 +00:00
Bhavin Patel 7217019457 fix rba message (#3934) 2026-03-03 21:40:57 +01:00
Nasreddine Bencherchali f930b525ee Add New Analytics - February Batch (#3886)
* add percent encoded curl exec

* Fix #3916

* Add other calc process names entries

* apply formatting

* add more color

* add cisco sd-wan stuff

* update tags

* Update cisco_sd_wan___low_frequency_rogue_peer.yml

* add ds and maps it

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-03-03 18:31:37 +05:30
pyth0n1c 34be5c0b0c normalize all legacy line endings (#3931) 2026-03-02 23:34:35 +01:00
pyth0n1c cb067903a3 Merge pull request #3930 from splunk/remove_extra_fields
Remove EXTRA fields
2026-03-02 13:39:11 -08:00
pyth0n1c 997eb76be6 Remove EXTRA fields that are not part
of the models from yml files
2026-03-02 12:28:07 -08:00
p4t12ick b6888c5e86 Merge pull request #3927 from splunk/ta_update_script
bug fix: update dependencies Ci CD TA update script
2026-02-26 15:14:38 +01:00
p4t12ick 773343a116 Merge branch 'develop' into ta_update_script 2026-02-26 15:10:58 +01:00
P4T12ICK 5ed4c94984 bug fix: update dependencies 2026-02-26 15:10:00 +01:00
p4t12ick eb01d70fc6 Merge pull request #3926 from splunk/ta_update_script
Ta update script
2026-02-26 15:07:08 +01:00
p4t12ick ee4d95617a Merge branch 'develop' into ta_update_script 2026-02-26 14:59:17 +01:00
P4T12ICK f367fb9c33 update dependencies 2026-02-26 13:41:54 +01:00
p4t12ick 7db20a500e ta update script (#3925)
* ta update script

* update workflow name

---------

Co-authored-by: P4T12ICK <pbareiss@splunk.com>
2026-02-26 17:00:12 +05:30
P4T12ICK ffe80a677c update workflow name 2026-02-26 12:21:54 +01:00
P4T12ICK 4f8de77e32 ta update script 2026-02-26 11:45:35 +01:00
Teoderick Contreras a652f33f3e ttp_init_score 2026-02-26 11:37:27 +01:00
Lou Stella d119763abe Merge pull request #3839 from splunk/yml_validation_cleanups
Yml validation cleanups
2026-02-25 14:17:38 -06:00
Eric McGinnis c733e6c9cc Merge branch 'develop' into yml_validation_cleanups 2026-02-25 11:36:18 -08:00
Nasreddine Bencherchali 11c909f725 Add YAML Formatting Job (#3889)
* Add YAML formatting and validation infrastructure

- Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings
- Add yamllint configuration (.yamllint) for syntax validation (detections/ only)
- Add pre-commit hook for automatic YAML formatting
- Add CI validation script with unified error output
- Add GitHub Actions workflow for PR validation
- Add documentation for setup and usage
- Support custom yamlfmt binary path via --yamlfmt-path flag

* comment yaml check from pre-commit

* apply yamlfmt

* Update yaml-validation.yml

* Update yaml-validation.yml

* application folder search formatting

* cloud folder search formatting

* web folder search formatting

* network folder search formatting

* endpoint folder search formatting

* resolve first conflict

* apply formatting

* remove additional pipe

* Update README.md

* update versions

* restore and update formatting (#3920)

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-26 00:00:35 +05:30
Eric McGinnis 1ed6c27923 Update all dates on modified content, including the baseline 2026-02-25 10:13:58 -08:00
Eric McGinnis bdf95f1e90 Restore contents of app template. Replace removed/detections/ that were needlessly updated 2026-02-25 10:09:20 -08:00
pyth0n1c 490ad6daf1 Merge branch 'develop' into yml_validation_cleanups 2026-02-25 10:05:41 -08:00
Lou Stella 695434b155 Merge pull request #3921 from splunk/datefix
datefix
2026-02-25 11:18:06 -06:00
Lou Stella 2ac1ea4234 Merge branch 'develop' into datefix 2026-02-25 10:51:24 -06:00
Bhavin Patel 0fcd63a821 Updated TAs (#3919)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-25 22:21:02 +05:30
ljstella 47533256c7 contentctl version bump 2026-02-25 11:39:59 -05:00
ljstella f38fdc681e technically have to bump version for datefix 2026-02-25 10:24:04 -05:00
ljstella b393da3116 datefix 2026-02-25 10:20:22 -05:00
Bhavin Patel 91b957d103 Updated TAs (#3918)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-24 22:18:56 +05:30
Bhavin Patel 15deedd635 chore: bump contentctl.yml to 5.23.0 (#3913)
Co-authored-by: research bot <research@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-20 10:51:49 +01:00
Bhavin Patel 07d5e7d54d Updated TAs (#3914)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-20 10:49:23 +01:00
Br3akp0int c2044d9a99 Tag Content Related to Dynowiper/Zovwiper (#3907)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
v5.22.0
2026-02-17 23:52:23 +01:00
Rod Soto 02573684ce Add New MCP Related Detections (#3895)
---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-02-17 23:39:01 +01:00
Br3akp0int 19181a86b5 Add Coverage and Tagging for the XML Runner Loader (#3897)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:20:36 +01:00
Br3akp0int 6b9201dbc3 Add SolarWinds WHD RCE Post Exploitation Coverage/Tagging (#3902)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-02-17 20:02:11 +01:00
Bhavin Patel 79d24587f6 Issue - 3901 (#3905)
* cosolidation of detections

* updating test
2026-02-11 22:33:49 +05:30
Eric McGinnis 15f1e39548 Merge branch 'develop' into yml_validation_cleanups 2026-02-11 08:51:26 -08:00
Bhavin Patel b29ba95b51 Updated TAs (#3906)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-11 22:18:24 +05:30
Bhavin Patel 91ab062bb4 Updated TAs (#3900)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-02-10 19:52:27 +05:30
bpluta-splunk 7cf9641f5f upodated SPL based on new raw events (#3898)
* upodated SPL based on new raw events

* updating dataset link and data source file

---------

Co-authored-by: Bhavin Patel <bpatel@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-02-10 12:59:45 +05:30
Bhavin Patel d13e377a27 Bump contentctl.yml to 5.22.0 (#3894)
* chore: bump contentctl.yml to 5.22.0

* remove detections

---------

Co-authored-by: research bot <research@splunk.com>
Co-authored-by: Lou Stella <ljstella@gmail.com>
2026-02-10 10:27:49 +05:30