Commit Graph

2257 Commits

Author SHA1 Message Date
Bhavin Patel 9849b76aff Merge branch 'develop' into first_time_seen_cmd_updates 2020-02-07 10:02:26 -08:00
bpatel f307274f95 story mod updates 2020-02-07 10:00:28 -08:00
Bhavin Patel 11e67aefb4 Merge pull request #352 from splunk/fixing_external_pr_ci
fixing issue with seans PR
2020-02-07 09:54:05 -08:00
Jose Enrique Hernandez 08d7ba3900 Merge pull request #346 from splunk/CRL-1726_lookups_csv_ci
CRL-1726 adding logic to copy over lookups
2020-02-06 23:49:33 -05:00
research bot 345858c83b updating docs and package bits [ci skip] 2020-02-06 22:47:39 +00:00
Rico Valdez 537f51434e Merge branch 'develop' of github.com:splunk/security-content into develop
local merge of develop prior to push
2020-02-05 16:28:45 -07:00
Rico Valdez ac7bd7cfee changed the file name of the .csv file and updated the associated yml file 2020-02-05 16:27:57 -07:00
rvaldez617 7d33b5c36c Merge pull request #350 from splunk/issue_323
CRL-1721 - updating files as per Dons/Andrew Lee's feedback
2020-02-05 16:06:17 -07:00
Jose Enrique Hernandez 2fb2d880f0 Merge pull request #344 from smalloy2/develop
Making color contrast changes for 508 compliance
2020-02-04 17:07:13 -05:00
divious1 caa5437fad fixing issue with seans PR 2020-02-04 16:31:56 -05:00
bpatel dbbc58fb43 renaming lookup file in package/lookup 2020-02-04 09:46:22 -08:00
bpatel 8b0f74c34d updating mod dates and version 2020-02-04 09:21:52 -08:00
bpatel 92768472e0 updating files as per Dons feedback 2020-02-04 09:15:39 -08:00
dependabot-preview[bot] e134fb24c8 Merge pull request #349 from splunk/dependabot/pip/nodeenv-1.3.5 2020-02-04 08:35:32 +00:00
dependabot-preview[bot] 6ac73bb183 Bump nodeenv from 1.3.4 to 1.3.5
Bumps [nodeenv](https://github.com/ekalinin/nodeenv) from 1.3.4 to 1.3.5.
- [Release notes](https://github.com/ekalinin/nodeenv/releases)
- [Changelog](https://github.com/ekalinin/nodeenv/blob/master/CHANGES)
- [Commits](https://github.com/ekalinin/nodeenv/compare/1.3.4...1.3.5)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-02-04 08:31:13 +00:00
Jason Brewer e18a1402f4 CRL-1723 : corrected field name in SPL Filesystem.filepath [which does not exist] to Filesystem.file_path. 2020-02-03 21:00:55 -08:00
Jason Brewer c06702a7f4 CRL-1725 - Added update to detections.spec.json to accomodate a new output entity parent_process_name. 2020-02-03 15:32:12 -08:00
Jason Brewer 346709b58f CRL-1725 - Changed prohibited_apps_spawning_cmdprompt.yml to use parent_process_name as entity. Changed supress field to add user. Bumped detection version number and story version numbers on stories/suspicious_cmd_line_executions.yml and stories/suspicious_mshta_activities.yml. 2020-02-03 15:24:49 -08:00
Jose Enrique Hernandez 667ac3ffa3 Merge pull request #345 from splunk/CRL-1727_detection_bug_issue_343
fixing issue #343
2020-02-03 17:36:49 -05:00
divious1 6730dbefd8 adding logic to copy over lookups 2020-02-03 17:35:06 -05:00
divious1 2b6db17c99 fixing issue #343 2020-02-03 17:10:15 -05:00
seanmalloy 6a3c1d4988 Making color contrast changes for 508 compliance 2020-02-03 10:31:13 -08:00
dependabot-preview[bot] 70a3aa3841 Merge pull request #342 from splunk/dependabot/pip/jinja2-2.11.1 2020-01-30 18:28:52 +00:00
dependabot-preview[bot] a696b13961 Bump jinja2 from 2.11.0 to 2.11.1
Bumps [jinja2](https://github.com/pallets/jinja) from 2.11.0 to 2.11.1.
- [Release notes](https://github.com/pallets/jinja/releases)
- [Changelog](https://github.com/pallets/jinja/blob/master/CHANGES.rst)
- [Commits](https://github.com/pallets/jinja/compare/2.11.0...2.11.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-01-30 18:23:29 +00:00
dependabot-preview[bot] 5e88f84ba5 Merge pull request #341 from splunk/dependabot/pip/pre-commit-2.0.1 2020-01-30 02:14:17 +00:00
dependabot-preview[bot] d0d0772679 Bump pre-commit from 2.0.0 to 2.0.1
Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 2.0.0 to 2.0.1.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/master/CHANGELOG.md)
- [Commits](https://github.com/pre-commit/pre-commit/compare/v2.0.0...v2.0.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-01-30 02:09:24 +00:00
dependabot-preview[bot] 90cdbe7ef0 Merge pull request #340 from splunk/dependabot/pip/more-itertools-8.2.0 2020-01-29 13:09:31 +00:00
dependabot-preview[bot] 0b110b541a Bump more-itertools from 8.1.0 to 8.2.0
Bumps [more-itertools](https://github.com/erikrose/more-itertools) from 8.1.0 to 8.2.0.
- [Release notes](https://github.com/erikrose/more-itertools/releases)
- [Commits](https://github.com/erikrose/more-itertools/compare/v8.1.0...v8.2.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-01-29 13:05:09 +00:00
dependabot-preview[bot] c0ef423eef Merge pull request #339 from splunk/dependabot/pip/importlib-metadata-1.5.0 2020-01-29 05:15:01 +00:00
dependabot-preview[bot] 503dbe5e40 Bump importlib-metadata from 1.4.0 to 1.5.0
Bumps [importlib-metadata](http://importlib-metadata.readthedocs.io/) from 1.4.0 to 1.5.0.

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-01-29 05:10:30 +00:00
Jose Enrique Hernandez a7baf3fcc2 Merge pull request #338 from splunk/dependabot_automerge
adding github workflow to auto approve dependabot PRs that passed CI …
2020-01-28 22:24:32 -05:00
divious1 d4fbe656d6 adding github workflow to auto approve dependabot PRs that passed CI this is to circumvent branch protection 2020-01-28 22:12:14 -05:00
dependabot-preview[bot] 94664241b6 Merge pull request #337 from splunk/dependabot/pip/pre-commit-2.0.0 2020-01-29 03:07:41 +00:00
dependabot-preview[bot] 992eedfecc Bump pre-commit from 1.21.0 to 2.0.0
Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 1.21.0 to 2.0.0.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/master/CHANGELOG.md)
- [Commits](https://github.com/pre-commit/pre-commit/compare/v1.21.0...v2.0.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-01-29 02:51:57 +00:00
dependabot-preview[bot] 5d49e31f16 Merge pull request #328 from splunk/dependabot/pip/identify-1.4.11 2020-01-29 00:35:23 +00:00
dependabot-preview[bot] 8caa037cc6 Merge pull request #329 from splunk/dependabot/pip/zipp-2.1.0 2020-01-28 21:38:59 +00:00
dependabot-preview[bot] b155dd6d4b Bump identify from 1.4.10 to 1.4.11
Bumps [identify](https://github.com/chriskuehl/identify) from 1.4.10 to 1.4.11.
- [Release notes](https://github.com/chriskuehl/identify/releases)
- [Commits](https://github.com/chriskuehl/identify/compare/v1.4.10...v1.4.11)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-01-28 16:13:32 +00:00
dependabot-preview[bot] 453183cbff Merge pull request #332 from splunk/dependabot/pip/jinja2-2.11.0 2020-01-28 16:12:24 +00:00
Jose Enrique Hernandez cf78269d29 Merge pull request #335 from splunk/dependabot_automerge
merge all
2020-01-28 11:06:49 -05:00
divious1 8b3447c016 merge all 2020-01-28 11:06:24 -05:00
Jose Enrique Hernandez 78bffbf8d5 Merge pull request #334 from splunk/dependabot_automerge
no need to specify path
2020-01-28 10:29:56 -05:00
divious1 d9f7c09eac no need to specify path 2020-01-28 10:29:16 -05:00
Jose Enrique Hernandez 23174e7c99 Merge pull request #330 from splunk/dependabot_automerge
automatically merge deps
2020-01-28 10:21:42 -05:00
dependabot-preview[bot] 7bec484354 Bump jinja2 from 2.10.3 to 2.11.0
Bumps [jinja2](https://github.com/pallets/jinja) from 2.10.3 to 2.11.0.
- [Release notes](https://github.com/pallets/jinja/releases)
- [Changelog](https://github.com/pallets/jinja/blob/master/CHANGES.rst)
- [Commits](https://github.com/pallets/jinja/compare/2.10.3...2.11.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-01-28 14:13:11 +00:00
Bhavin Patel 656b66cd71 Merge pull request #331 from splunk/develop
Updated Master base on v1.0.49 release
2020-01-27 14:00:48 -08:00
dependabot-preview[bot] 0da53bb353 Bump zipp from 2.0.0 to 2.1.0
Bumps [zipp](https://github.com/jaraco/zipp) from 2.0.0 to 2.1.0.
- [Release notes](https://github.com/jaraco/zipp/releases)
- [Changelog](https://github.com/jaraco/zipp/blob/master/CHANGES.rst)
- [Commits](https://github.com/jaraco/zipp/compare/v2.0.0...v2.1.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
2020-01-27 14:13:08 +00:00
jzsplunk c92d097eac updating boiler plate, detection not working out of box against T1193 but this may be due to error loading lookup table for supicious file extensions. 2020-01-27 03:04:55 -08:00
jzsplunk d4aa6bc9ea update smb related content. The outbound_smb_connections detection works out of the box against attack ID T1110 when testing in the attack range. 2020-01-27 02:33:26 -08:00
jzsplunk b762034a4b update version info and macros, attack range freezing on testing detection against attack ID T1071 so query is untested against atomic red team test for now 2020-01-27 01:44:53 -08:00
jzsplunk 6406cfbc32 update version info, add macros for first time seen cmd line detection 2020-01-27 01:08:53 -08:00