Commit Graph

28139 Commits

Author SHA1 Message Date
ljstella 0c869bfc93 yamlfmt 2026-05-20 15:15:09 -04:00
Lou Stella e5dc0c4625 Merge pull request #4089 from splunk/port_playbooks
Port playbooks
2026-05-20 12:35:21 -04:00
ljstella c498d21841 Manual Review completion 2026-05-20 12:15:00 -04:00
Eric McGinnis 13f06b5e1d Complete porinting of playbooks. Fix references to old, removed detections
in playbooks that were previously unvalidated.
Add a MANUAL_REVIEW section, which is commented out,
for clarity and to allow CICD to run and pass on this content.
Renamed an existing playbook because it diverges from the name
of that playbook elsewhere.
2026-05-19 14:28:53 -07:00
pyth0n1c e190246023 Merge branch 'escu6_manual_review' into port_playbooks 2026-05-19 12:22:30 -07:00
ljstella d7b8c0f0d8 Reordering key 2026-05-19 14:25:35 -04:00
Lou Stella d235c3e7d2 Update detections/web/monitor_web_traffic_for_brand_abuse.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-19 14:22:21 -04:00
ljstella bc18194661 Reordering keys 2026-05-19 14:21:30 -04:00
Eric McGinnis 0a8c534612 Update playbooks to new format. 2026-05-19 11:12:49 -07:00
ljstella b196ddcf95 Baseline cleanup 2026-05-19 12:23:15 -04:00
ljstella 53565febce message cleanup 2026-05-19 12:15:48 -04:00
ljstella 15c349bde3 Multiple user type entities 2026-05-19 11:45:53 -04:00
ljstella e52095cb16 Unbalanced $ in message 2026-05-19 10:35:40 -04:00
ljstella baf4b85578 Multiple non-user but no user 2026-05-19 10:34:15 -04:00
ljstella 9dfb1706f9 Manual Review of correlation searches 2026-05-19 10:10:45 -04:00
Eric McGinnis 81bdcbbc89 deprecated macros were not copied over during PORT operation. Fix that. 2026-05-14 07:17:08 -07:00
Eric McGinnis 2b10ef9cd7 remove deployments directory 2026-05-13 17:12:15 -07:00
Eric McGinnis 61f71544c4 Macros were missed during the porting copy over. They have now been added. 2026-05-13 17:09:31 -07:00
Eric McGinnis 58c7164aa2 Fix schema settings in settings.json as file names and paths had changed since the pr was first opened 2026-05-13 14:25:04 -07:00
Eric McGinnis 703bf050e8 Add schema validate vscode or other editor settings. 2026-05-13 14:17:30 -07:00
Eric McGinnis 4d7bdebd3f Add auto generated schemas. Note that thare are some pieces of content missing from here - notably content which has a MANUAL_REVIEW flag. This content does not parse until it has been updated, which means it could not be compiled into the schemas. These files will be updated when all content in the repo successfully parses. 2026-05-13 14:13:49 -07:00
Eric McGinnis 3bdbc59422 The 5 kvstore lookups referenced in the previous commit that were intentionally moved, but not updated, have now been updated with the new format. 2026-05-13 14:04:13 -07:00
Eric McGinnis db8c7c8509 Initial commit of modified objects. A small set of 5 kvstore lookups could not be git moved AND updated in the same operation because git instead interpreted this as deleting the old file and creating a new one. To preserve git history, the files have been moved in this commit and will be updated in the next commit. 2026-05-13 14:02:27 -07:00
Bhavin Patel 29616ca93e Updated TAs (#4079)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-05-12 17:30:36 +02:00
Bhavin Patel d37930351c Bump contentctl.yml to 6.0.0 (#4067)
* chore: bump contentctl.yml to 5.28.0

* Update contentctl.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

---------

Co-authored-by: research bot <research@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-12 11:19:34 +05:30
Bhavin Patel 76dbdce682 Updated TAs (#4069)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-05-07 19:32:10 +05:30
Lou Stella 9c183fa110 Update Analytics to Support ATT&CK v19 (#4036)
---------

Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
v5.27.0
2026-05-05 17:29:28 +02:00
Raven Tait 917fe77cc0 Add Big Batch of Snap Attack Converted Rules (#4015)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-05-05 16:11:18 +02:00
Raven Tait 4d4c7ee091 Add Analytic for Copy Fail (#4063)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-05 03:13:57 +02:00
p4t12ick a9aaf494f6 Improved detections based on telemetry data (#4011)
---------

Co-authored-by: P4T12ICK <pbareiss@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-05-04 13:31:26 +02:00
Bhavin Patel ccc7f9bfd0 Updated TAs (#4055)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-05-02 13:04:05 +02:00
Bhavin Patel becdb58b9f Add Secure Access Firewall Detections (#3986)
---------

Co-authored-by: Lou Stella <ljstella@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-29 20:41:09 +02:00
jwindley c5e9d4a573 Fixed two detections, and improved macos keychain dumping for more coverage of the technique (#4034)
* Fix and improve azure high-risk sign-in, curl percent-encoded URL, and macOS keychain dump detections

* Apply suggestions from code review

* Update azure_active_directory_high_risk_sign_in.yml

* Update curl_execution_with_percent_encoded_url.yml

* beautify spl

* Update macos_keychains_dumped.yml

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-29 15:20:25 +02:00
Br3akp0int 9972c09298 vip_keylogger (#4024)
* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* vip_keylogger

* Update vip_keylogger.yml

* Update windows_proxy_execution_of__net_utilities_via_scripts.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

* Update powershell_loading_dotnet_into_memory_via_reflection.yml

* Update executables_or_script_creation_in_temp_path.yml

* Update executables_or_script_creation_in_suspicious_path.yml

* Update powershell_pinvoke_process_injection_api_chain.yml

* vip_keylogger

* Update powershell_environment_variable_execution.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

* Update windows_anomalous_registry_value_length_in_environment_key.yml

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-04-29 17:55:13 +05:30
Lou Stella b12fbf3ba0 Merge pull request #4035 from splunk/playbook_update
Playbook Updates
2026-04-28 13:17:31 -04:00
ljstella 75a07833e7 Quotes, ugh. 2026-04-28 11:43:00 -04:00
ljstella 4c48e608dc Pinning ATT&CK 2026-04-28 11:40:32 -04:00
ljstella 7b6dab17f4 SOARHELP-6700 2026-04-28 10:47:57 -04:00
Bhavin Patel 1e1748cec6 Updated TAs (#4033)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-04-28 11:25:21 +02:00
Bhavin Patel a94a743b63 Automated Splunk TA Update 610 (#4029)
---------

Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
2026-04-24 08:36:18 +00:00
Bhavin Patel e98b868b8d chore: bump contentctl.yml to 5.27.0 (#4028)
Co-authored-by: research bot <research@splunk.com>
2026-04-24 10:34:16 +02:00
Bhavin Patel 063a6fc38b Updated TAs (#4026)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-04-23 10:16:37 +05:30
Lou Stella 8c50bcae82 Merge pull request #4025 from splunk/kbouchard-patch-1
Delete response_templates/NIST80061_v2.json
v5.26.0
2026-04-21 15:29:52 -04:00
kbouchard b27f1889ac Delete response_templates/NIST80061_v2.json
Remove Unwanted Response Template that will cause customer confusion.  The plan out there will start with v3.
2026-04-21 08:11:45 -07:00
Bhavin Patel 6ee1a47e71 Updated TAs (#4022)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2026-04-20 12:18:40 +02:00
Lou Stella 4de7141a2b Merge pull request #4019 from splunk/dependabot_TA_update
data sources dependabot bug
2026-04-17 09:36:22 -04:00
Bhavin Patel 3337b9cd55 adding content.yml 2026-04-17 18:07:45 +05:30
Bhavin Patel 55f8c51579 update commit paths 2026-04-17 18:03:32 +05:30
Bhavin Patel ba59855b1d updating risk drilldowns (#4016)
* updating drilldows

* inspect failures

* updating versions

* updating versins

* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali ea5bd52238 Fix Issues - 2nd Round (#3996)
* Fix #3993

* Fix incorrect DS entries

* fix security_domain issue

* Fix #3992

* Fix #3988

* Update dump_lsass_via_procdump.yml

* Fix #3987

* Fix #3977

* Update network_connection_discovery_with_arp.yml

* Fix #3998

* Fix #3997

* fix versions

* revert change

* Fix #4012

* Update linux_file_creation_in_init_boot_directory.yml

* Update linux_file_creation_in_init_boot_directory.yml

* Fix #4010 and related

* fix typo

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2026-04-16 05:24:43 +00:00