Commit Graph

26624 Commits

Author SHA1 Message Date
Bhavin Patel 9051096f9d test_@ 2025-03-27 16:51:07 -07:00
Bhavin Patel 0cf28f67e5 test 2025-03-27 16:42:11 -07:00
Bhavin Patel 74c482d90d intentional fail and catch 2025-03-27 16:39:14 -07:00
Bhavin Patel de96c7884c Merge branch 'develop' into unit-test-ci 2025-03-27 15:25:00 -07:00
pyth0n1c 8d5975884c Merge pull request #3430 from splunk/cisco_ai
bug in cisco detection
2025-03-27 14:52:57 -07:00
Bhavin Patel f7ff5d2af2 Update crushftp_server_side_template_injection.yml 2025-03-27 14:19:21 -07:00
Bhavin Patel 2a9d3e477e verbose mode 2025-03-27 14:13:28 -07:00
Bhavin Patel aef3f08c76 fail when ctl test fails 2025-03-27 14:09:26 -07:00
Bhavin Patel c009a27c12 add back manual_test 2025-03-27 14:01:20 -07:00
Bhavin Patel 5000fe16cb reverrt ctl 2025-03-27 13:41:17 -07:00
Bhavin Patel cdd70a10aa test with local data 2025-03-27 13:32:37 -07:00
Bhavin Patel 1c949f6a6f Merge pull request #3426 from splunk/cim_bug
Update CIM app title
2025-03-27 08:25:20 -07:00
P4T12ICK b96e63d86e Merge branch 'develop' into cim_bug 2025-03-27 07:25:51 +01:00
pyth0n1c 1d2d0352ed Merge pull request #3428 from splunk/fix-bad-attack-data-link
Update living_off_the_land_detection.yml attack_data
2025-03-26 14:37:47 -07:00
pyth0n1c 17b1fd44c7 Update living_off_the_land_detection.yml attack_data
We did not catch this previously because it is a correlation search, so the links are not checked. I found this manually.
2025-03-26 14:08:52 -07:00
Bhavin Patel 13800a7ec1 Merge pull request #3412 from splunk/cisco_ai_defense
Cisco AI defense - Move to prod
2025-03-26 14:01:00 -07:00
Bhavin Patel ea0b365690 Merge branch 'develop' into cisco_ai_defense 2025-03-26 13:44:06 -07:00
Bhavin Patel eaf9ad89ea Merge pull request #3408 from splunk/process-injection-detection-enhanced
0xC0FFEEEE - process injection into commonly abused processes
2025-03-26 13:29:55 -07:00
Bhavin Patel 88d699f518 Merge branch 'develop' into cisco_ai_defense 2025-03-26 12:40:28 -07:00
Bhavin Patel 377efcc0b0 updating name 2025-03-26 12:39:02 -07:00
Bhavin Patel 76ef391ac3 updating title to full name 2025-03-26 12:04:02 -07:00
Bhavin Patel e7e5dcbc03 Merge branch 'develop' into process-injection-detection-enhanced 2025-03-26 11:05:22 -07:00
Bhavin Patel 0f102fcfcd Merge pull request #3325 from splunk/output_normalization_o365
o365 detections output normalization
2025-03-25 13:56:31 -07:00
Bhavin Patel 63380103e5 udpate date format 2025-03-25 12:07:17 -07:00
Bhavin Patel 87eeec65a6 updating dates and verrsion 2025-03-25 11:21:38 -07:00
Bhavin Patel 09f12546fb Merge branch 'develop' into output_normalization_o365 2025-03-25 10:42:52 -07:00
Bhavin Patel 5768076812 Merge pull request #3420 from splunk/auto-ta-update-215
Automated Splunk TA Update 215
2025-03-25 09:01:24 -07:00
ljstella 843ab78068 Revert linux TA 2025-03-25 09:46:21 -05:00
patel-bhavin 5886f46ba5 Updated TAs 2025-03-25 06:58:01 +00:00
Bhavin Patel b186cc921e Merge pull request #3409 from splunk/auto-ta-update-210
Automated Splunk TA Update 210
2025-03-24 15:03:24 -07:00
Bhavin Patel 5bb6ac53b3 Empty commit 2025-03-24 14:41:21 -07:00
Bhavin Patel cacaa8ac07 yaml update 2025-03-21 11:58:12 -07:00
Bhavin Patel 30135a6a15 dd udpate 2025-03-21 11:56:19 -07:00
Bhavin Patel 20f1307ddf updating date 2025-03-21 11:54:35 -07:00
Bhavin Patel 912238a4a4 move to prodcution after testing 2025-03-21 11:54:03 -07:00
Bhavin Patel 753cf9e3f5 Update linux_secure.yml 2025-03-20 09:42:10 -07:00
patel-bhavin d3f6dc856d Updated TAs 2025-03-20 06:58:09 +00:00
Michael Haag feb0f44dad updates 2025-03-19 10:25:30 -06:00
Michael Haag e38e283413 Add new detection for process injection into commonly abused processes
Replacing #3389
2025-03-19 10:19:14 -06:00
P4T12ICK f243d22f61 Merge branch 'develop' into output_normalization_o365 2025-03-19 15:02:08 +01:00
Bhavin Patel 45838649b8 Merge pull request #3366 from splunk/remove_detections
Remove 151 Deprecated detections, stories, baselines, investigations - Github
v5.2.0
2025-03-18 16:14:36 -07:00
Eric 011b33cb5b Merge branch 'remove_detections' of https://github.com/splunk/security_content into remove_detections 2025-03-18 15:42:04 -07:00
Eric 58aca7db99 Update the deprecation_info.csv file, manually generated with a version of contentctl that has not yet been merged or released in main branch. 2025-03-18 15:41:21 -07:00
Bhavin Patel 59b9657e4a Merge branch 'develop' into remove_detections 2025-03-18 15:32:53 -07:00
Bhavin Patel 7ba4dc0a4d Merge pull request #3405 from splunk/risk_message
update spl
2025-03-18 15:22:18 -07:00
Bhavin Patel 2f128036c1 Merge branch 'develop' into risk_message 2025-03-18 15:08:01 -07:00
Bhavin Patel df44136390 Merge pull request #3287 from delgado-jacob/datasource_enrichment
Add descriptions and Mitre components to data sources
2025-03-18 15:07:51 -07:00
Bhavin Patel ea3fa4daf6 updating search 2025-03-18 14:52:30 -07:00
delgado-jacob 4b70500f07 Merge remote-tracking branch 'origin/datasource_enrichment' into datasource_enrichment 2025-03-18 14:29:50 -07:00
delgado-jacob 6488af7c57 Add Zeek TA, fix detection source list 2025-03-18 14:29:30 -07:00