Commit Graph

2703 Commits

Author SHA1 Message Date
mhaag-spl 668fba767b Update suspicious_msbuild_rename.yml 2021-08-10 13:28:55 -06:00
mhaag-spl 23a2dcb7c1 Merge branch 'The-Haag-of-The-Storm' of https://github.com/splunk/security_content into The-Haag-of-The-Storm 2021-08-10 12:37:25 -06:00
mhaag-spl 6a81b49ae9 Update suspicious_msbuild_rename.yml 2021-08-10 12:37:22 -06:00
mhaag-spl 6a99bcffa8 Added detection testing service results inDetect Renamed rundll32.exe Rename 2021-08-10 12:26:39 -06:00
mhaag-spl 833001dd15 Update suspicious_rundll32_rename.yml 2021-08-09 14:19:27 -06:00
peter-cg f8fc79d4e1 Adding event_id extraction 2021-08-03 14:56:18 -05:00
Jose Enrique Hernandez b8fea6311e Delete powershell_encoded_command.yml 2021-08-03 14:56:17 -05:00
divious1 d7000e7608 added event_id to ssa detections 2021-08-03 14:56:17 -05:00
research bot df85ff33ad updating docs and package bits [ci skip] 2021-07-29 21:15:45 +00:00
patel-bhavin 9fbeb683ca testing ymls 2021-07-29 12:43:02 -07:00
research bot 4b3e48b6f4 updating docs and package bits [ci skip] 2021-07-28 20:27:55 +00:00
patel-bhavin 9460c02297 Merge branch 'blackbolt_duplicate' of github.com:splunk/security_content into blackbolt_duplicate 2021-07-28 11:45:02 -07:00
patel-bhavin 04e23cba8b search update 2021-07-28 11:44:51 -07:00
Detection Testing Service 76335f0ea7 Merge branch 'blackbolt_duplicate' of https://github.com/splunk/security_content into blackbolt_duplicate 2021-07-28 18:20:18 +00:00
root 8c066fcd26 Added detection testing service results inDetect processes used for System Network Configuration Discovery 2021-07-28 18:20:17 +00:00
root 2fac7f3a74 Added detection testing service results inDetect New Open S3 Buckets over AWS CLI 2021-07-28 18:19:22 +00:00
patel-bhavin ea8de7ad52 Merge branch 'blackbolt_duplicate' of github.com:splunk/security_content into blackbolt_duplicate 2021-07-28 10:52:39 -07:00
patel-bhavin ecf2886c43 revert 2021-07-28 10:52:22 -07:00
Bhavin Patel 74e0266341 Update detect_new_open_s3_buckets_over_aws_cli.yml 2021-07-27 16:50:03 -07:00
Bhavin Patel 79af676857 Update detect_new_open_s3_buckets_over_aws_cli.yml 2021-07-27 16:45:59 -07:00
patel-bhavin 90191cd151 risk_update 2021-07-27 14:51:57 -07:00
patel-bhavin 60d499fb99 Merge branch 'blackbolt_duplicate' of github.com:splunk/security_content into blackbolt_duplicate 2021-07-27 14:41:15 -07:00
patel-bhavin f24ba42985 aws-cli 2021-07-27 14:41:06 -07:00
Bhavin Patel 7431704a71 Merge branch 'develop' into blackbolt_duplicate 2021-07-27 14:01:15 -07:00
patel-bhavin bf6804cef7 adding spl updates 2021-07-27 13:57:33 -07:00
root 2fd2af4d29 Added detection testing service results inDNS Query Length With High Standard Deviation 2021-07-27 19:59:57 +00:00
Jose Enrique Hernandez 4eb9a75f80 Merge branch 'develop' into optimized 2021-07-27 10:54:35 -04:00
Michael Haag 48165c7e35 Merge branch 'develop' into Shadowsinthecopy 2021-07-23 14:10:05 -06:00
mhaag-spl ba92a642a8 SAM I AM
I AM SAM
2021-07-23 14:06:27 -06:00
github-actions[bot] f82a26bf8a Branch was auto-updated. 2021-07-22 19:12:52 +00:00
Michael Haag ad44baef29 Update detect_shared_ec2_snapshot.yml 2021-07-22 13:06:23 -06:00
github-actions[bot] 48babd0a33 Branch was auto-updated. 2021-07-22 16:43:08 +00:00
github-actions[bot] d09c80c1cc Branch was auto-updated. 2021-07-22 16:42:56 +00:00
mhaag-spl afe1d8a286 Update detect_copy_of_shadowcopy_with_script_block_logging.yml 2021-07-22 06:55:12 -06:00
mhaag-spl 9acd9f32f7 Update detect_renamed_psexec.yml
Resolving #1525 . Thank you!
2021-07-22 06:20:47 -06:00
mhaag-spl d207154de3 Update detect_renamed_winrar.yml
Resolving #1524. Thank you!
2021-07-22 06:19:55 -06:00
Amir hossein Mahboubi 70dc0c1a59 Merge branch 'develop' into optimized 2021-07-22 16:35:02 +04:30
mhaag-spl e5d24fba22 Update detect_copy_of_shadowcopy_with_script_block_logging.yml 2021-07-21 15:48:36 -06:00
mhaag-spl 28af2af96c Update detect_copy_of_shadowcopy_with_script_block_logging.yml 2021-07-21 15:46:49 -06:00
mhaag-spl b87f262923 test file 2021-07-21 15:41:42 -06:00
mhaag-spl bd69016d7e PowerShell 4104 copy of Security HIVES
Modified macro to capture both XML rendered and non. Issue is, if you renderXML for powershell logging, it will have different fields. Something to be aware of.
2021-07-21 13:57:10 -06:00
github-actions[bot] 03a9e5f2ea Branch was auto-updated. 2021-07-21 14:14:26 +00:00
sec-researcher ee3f8638c4 As I know PTR requests can not be used for data exfiltration so having them in search result is just a false positive. Also they have effect on deviation calculation and lead to a lot of false positive in result, specially when PTR requests in the environment is about 20% or more. So I add this filter to the search 'where NOT DNS.message_type IN("Pointer","PTR")' 2021-07-21 18:20:15 +04:30
P4T12ICK d3db4a0b1b Merge branch 'develop' into uac_bypass 2021-07-21 14:59:18 +02:00
tccontre f3501d056e uac 2021-07-21 12:33:33 +02:00
tccontre a6fb638b9c Update mshta_spawning_rundll32_or_regsvr32_process.yml 2021-07-21 12:23:36 +02:00
tccontre 87a46e76cb Update wsreset_uac_bypass.yml 2021-07-21 12:22:24 +02:00
root 0dbf7fdab6 Added detection testing service results inDetect shared ec2 snapshot 2021-07-20 23:41:56 +00:00
patel-bhavin 4a1841fbed updates 2021-07-20 15:37:36 -07:00
Bhavin Patel 8d8bdaeaab Merge branch 'develop' into aws_snap_exfil 2021-07-20 15:16:07 -07:00