Bhavin Patel
3e040d77b6
yaml failures
2026-04-28 11:36:33 +05:30
Bhavin Patel
3c9904cac4
adding 1st detection and files
2026-04-28 10:35:06 +05:30
Bhavin Patel
a94a743b63
Automated Splunk TA Update 610 ( #4029 )
...
---------
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com >
2026-04-24 08:36:18 +00:00
Bhavin Patel
e98b868b8d
chore: bump contentctl.yml to 5.27.0 ( #4028 )
...
Co-authored-by: research bot <research@splunk.com >
2026-04-24 10:34:16 +02:00
Bhavin Patel
063a6fc38b
Updated TAs ( #4026 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-04-23 10:16:37 +05:30
Lou Stella
8c50bcae82
Merge pull request #4025 from splunk/kbouchard-patch-1
...
Delete response_templates/NIST80061_v2.json
v5.26.0
2026-04-21 15:29:52 -04:00
kbouchard
b27f1889ac
Delete response_templates/NIST80061_v2.json
...
Remove Unwanted Response Template that will cause customer confusion. The plan out there will start with v3.
2026-04-21 08:11:45 -07:00
Bhavin Patel
6ee1a47e71
Updated TAs ( #4022 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2026-04-20 12:18:40 +02:00
Lou Stella
4de7141a2b
Merge pull request #4019 from splunk/dependabot_TA_update
...
data sources dependabot bug
2026-04-17 09:36:22 -04:00
Bhavin Patel
3337b9cd55
adding content.yml
2026-04-17 18:07:45 +05:30
Bhavin Patel
55f8c51579
update commit paths
2026-04-17 18:03:32 +05:30
Bhavin Patel
ba59855b1d
updating risk drilldowns ( #4016 )
...
* updating drilldows
* inspect failures
* updating versions
* updating versins
* chore: empty commit to trigger CI
2026-04-17 17:28:53 +05:30
Nasreddine Bencherchali
ea5bd52238
Fix Issues - 2nd Round ( #3996 )
...
* Fix #3993
* Fix incorrect DS entries
* fix security_domain issue
* Fix #3992
* Fix #3988
* Update dump_lsass_via_procdump.yml
* Fix #3987
* Fix #3977
* Update network_connection_discovery_with_arp.yml
* Fix #3998
* Fix #3997
* fix versions
* revert change
* Fix #4012
* Update linux_file_creation_in_init_boot_directory.yml
* Update linux_file_creation_in_init_boot_directory.yml
* Fix #4010 and related
* fix typo
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-04-16 05:24:43 +00:00
Andrei Banaru
c6241660c7
Remove missing fields in Windows Event Log Cleared detection ( #4001 )
...
* fix: remove missing fields in Windows Event Log Cleared detection
* fix: source should be XmlWinEventLog:System
* update ds and output fields
* Update windows_event_log_security_1102.yml
---------
Co-authored-by: Andrei Banaru <a.banaru@iaea.org >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-04-16 10:52:16 +05:30
Lou Stella
7c439aeda8
Merge pull request #4018 from splunk/5.25.1_changes_for_develop
2026-04-15 18:23:32 -04:00
pyth0n1c
3c16b138e6
Merge branch 'develop' into 5.25.1_changes_for_develop
2026-04-15 15:11:36 -07:00
Eric McGinnis
6a8bfe977c
Fix version and date and update contentctl version in prep for release.
v5.25.1
2026-04-15 12:00:44 -07:00
jwindley
80b29d6651
New MacOS detections T1016 ( #4017 )
...
* New MacOS detections T1016
* Fix pre-commit formatting issues
* Fix based on Bhavin's comments
* update version
* Update linux_system_network_discovery.yml
* Update macos_list_firewall_rules.yml
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2026-04-15 23:36:58 +05:30
Bhavin Patel
c90d744007
Duplicate - Microsoft Intune Bulk Wipe Detected ( #4014 )
...
* updating search
* Update microsoft_intune_bulk_wipe_detected.yml
* Rename microsoft_intune_bulk_wipe_detected.yml to microsoft_intune_bulk_wipe.yml
* Update microsoft_intune_bulk_wipe.yml
* Update detections/cloud/microsoft_intune_bulk_wipe.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* updating refs
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-15 23:08:02 +05:30
Bhavin Patel
48698cbc4f
updating osquery ( #4013 )
2026-04-15 12:39:38 +02:00
Raven Tait
8050483569
Snap Mac Detections ( #3935 )
...
* Snap Mac Detections
* add osquery
* Update links and formatting
* update datasource name
* update formatting
* bump version
* Updates per PR comments
* Add commandline to RBA for gatekeeper bypass
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2026-04-14 19:48:42 +05:30
Lou Stella
8d2510235b
Spelling Fixes ( #4002 )
...
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-13 13:38:11 +02:00
Lou Stella
aa672c674a
Pushing deprecations ( #4003 )
2026-04-09 12:12:20 +02:00
Lou Stella
290486b6fe
Merge pull request #3994 from splunk/update-template-script-2
2026-04-07 07:29:09 -05:00
Henry Yu
e182e32f51
quote the file
2026-04-06 21:04:14 -07:00
Henry Yu
e791773e97
unquote the file
2026-04-06 20:44:11 -07:00
Lou Stella
6e75fc6407
Merge pull request #3991 from splunk/update-template-script
2026-04-06 17:05:24 -05:00
Lou Stella
806f6bdd32
Merge branch 'develop' into update-template-script
2026-04-06 17:03:05 -05:00
Lou Stella
95b35f77c1
Merge pull request #3990 from splunk/kbouchard-patch-1
2026-04-06 17:02:40 -05:00
Lou Stella
93cb3bedd9
Merge branch 'develop' into kbouchard-patch-1
2026-04-06 16:59:28 -05:00
Henry Yu
9b5c9aa7b9
remove the ignore . file change
2026-04-06 14:47:08 -07:00
Henry Yu
924a89e249
add validation for unique name, version pair
2026-04-02 13:06:15 -07:00
Henry Yu
9bc34d412f
group by actual template names instead of file name
2026-04-02 12:38:37 -07:00
Br3akp0int
7293d75700
Tagged Analytics Covering the Axios Compromise Post-Exploitation Activity ( #3982 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nbencher@cisco.com >
2026-04-02 16:07:20 +00:00
Raven Tait
f416da59fe
Add Filter for VMware Tools ( #3983 )
2026-04-02 18:06:04 +02:00
Bhavin Patel
116ab57d18
Remove AITK/MLTK TAs references from Contentctl.yml ( #3911 )
...
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-04-02 17:47:55 +02:00
Bhavin Patel
8c6453e0ea
Bump contentctl.yml to 5.26.0 ( #3989 )
...
* chore: bump contentctl.yml to 5.26.0
* remove detections
---------
Co-authored-by: research bot <research@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2026-04-02 17:41:06 +02:00
kbouchard
fc1596e371
had to remove 8.5 from the name of response plans
...
had to remove 8.5 from the name of response plans
2026-04-01 20:55:54 -07:00
pyth0n1c
90536d0e5a
Palo Alto Ta 3.0.0 was pulled from Splukbase. ( #3985 )
...
As such we must bump the TA to the newest
(and only) available release, 3.0.1.
v5.25.0
2026-03-31 22:42:26 +05:30
Nasreddine Bencherchali
fd53a2186b
Fix Broken RBA Message ( #3984 )
2026-03-31 15:34:07 +00:00
Lou Stella
39849c0179
Merge pull request #3980 from splunk/sched_task_rba_message
2026-03-30 14:51:23 -05:00
ljstella
d38d8e1519
First pass of RBA message fix
2026-03-30 15:09:36 -04:00
Br3akp0int
ff78e2d159
gh0st ( #3973 )
...
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* gh0st
* small changes
* another update
* final fix
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2026-03-30 19:46:33 +05:30
Nasreddine Bencherchali
bc1b413923
Fix Reported Issues - April Batch ( #3962 )
...
* Fix #3961
* Fix #3909
* Fix output fields
* Remove duplicate process_name entry
* Update outbound_network_connection_from_java_using_default_ports.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Update detect_computer_changed_with_anonymous_account.yml
* Fix #3969
* update palo alto TA and beautify analytics
* Update vmware_aria_operations_exploit_attempt.yml
* fix source
* enhance metadata and fp info
* beautify spl for ease of reading
* add some missing attack techniques
* remove unnecessary usage of regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* small fix
* Refine description and improve regex
* Update windows_uac_bypass_suspicious_escalation_behavior.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update possible_lateral_movement_powershell_spawn.yml
* Update windows_event_log_security_4756.yml
* description update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-30 14:34:11 +05:30
Nasreddine Bencherchali
b87507b551
Update Suricata TA and Related Analytics ( #3974 )
...
* update suricata ta
* update analytics for new TA
* Update ivanti_epmm_remote_unauthenticated_api_access_cve_2023_35078.yml
---------
Co-authored-by: Lou Stella <ljstella@gmail.com >
2026-03-28 10:09:22 +00:00
kbouchard
35e6ee2e97
Add files via upload ( #3975 )
...
Updated OOB Response Plan for 8.5 Release of Splunk Enterprise Security
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2026-03-28 10:07:40 +00:00
Bhavin Patel
89391cf877
Tune detections based on Athena FPs ( #3972 )
...
---------
Co-authored-by: p4t12ick <patrickbareiss1989@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com >
2026-03-27 16:58:41 +01:00
p4t12ick
fa45863186
Merge pull request #3971 from splunk/detections_improvement
...
Improved detections based on telemetry.
2026-03-27 13:20:26 +01:00
nasbench
30e0c54198
Update ryuk_wake_on_lan_command.yml
2026-03-27 12:21:22 +01:00
P4T12ICK
44f3125d35
bug fix
2026-03-27 10:13:56 +01:00