Commit Graph

27859 Commits

Author SHA1 Message Date
Nasreddine Bencherchali 731df609cf fix auditd PATH type detections (#3810)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-12-03 00:41:30 +01:00
Nasreddine Bencherchali d8ddca1a2d Merge branch 'develop' into fix_cwd_path_detections 2025-12-03 00:25:40 +01:00
Nasreddine Bencherchali 8cff5c05eb update descriptions 2025-12-03 00:23:36 +01:00
Emil 064cbaef0d Internal horizontal port scan nmap iteration (#3802)
* Running splunk auto format to structure SPL

* Simplifying query by doing more in initial tstats, adding additional information

Moving more logic to tstats in order to simplify and speed up query. Adding lastTime and  fields, which should help with triage and tuning

* Adding in All_Traffic.rule in order to please validation

* rba to src_ip, remove threat_objects

* Update version and date in YAML configuration

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-12-02 14:51:03 -08:00
Nasreddine Bencherchali 572a93567f add missing extension 2025-12-02 18:59:42 +01:00
Nasreddine Bencherchali ff4fda6445 update indentations and logic 2025-12-02 18:58:56 +01:00
Nasreddine Bencherchali 4a5ab34b37 Merge pull request #3813 from splunk/inspect_5.19
updating versions
2025-12-02 10:50:13 +01:00
Bhavin Patel 121be41015 Merge branch 'develop' into inspect_5.19 2025-12-01 20:07:37 -08:00
Bhavin Patel 17f3101c03 updating versions 2025-12-01 18:10:06 -08:00
Thomas Macfarlane 59c872761b chore: user_agent field fix in both the Azure AD authentication detections. Minor spelling mistake fixes. (#3811)
* chore: user_agent field fix in both the Azure AD authentication detections. Minor spelling mistake fixes.

* beautify

* remove rename

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-12-01 16:25:33 -08:00
Teoderick Contreras ab35d310e8 fix_cwd_path_detections 2025-11-28 09:33:10 +01:00
Teoderick Contreras 0d47dd6127 fix_cwd_path_detections 2025-11-27 15:36:14 +01:00
Nasreddine Bencherchali ac7dcfbb84 Merge pull request #3808 from splunk/auto-ta-update-462
Automated Splunk TA Update 462
2025-11-27 12:33:37 +01:00
patel-bhavin 9604770975 Updated TAs 2025-11-27 06:59:55 +00:00
Michael Haag 442e815dad npm Supply Chain Compromise & Lifecycle Hook Abuse Detection (#3806)
* extra content

* 5 more extras

* Hunt 1

* story+extras

* Create linux_shai_hulud_2_exfiltration_artifacts.yml

* Create linux_shai_hulud_workflow_file_modification.yml

* Create linux_suspicious_github_workflow_file_modification.yml

* Create windows_github_workflow_file_creation_hunt.yml

* more

* last 3

* final pass

* Bump versions to resolve merge conflicts with develop branch

* Fix deprecated status for curl/wget bash execution detections

* Add npm Supply Chain Compromise story to file_download_or_read_to_pipe_execution (replacement for deprecated curl/wget bash detections)

* Fix version numbers to match previous build requirements

* Add all required Filesystem fields to windows_suspicious_github_workflow_file_modification search

* Update detections/endpoint/windows_curl_download_to_suspicious_path.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* small fixes

* apply updates

* more updates

* Update shai_hulud_2_exfiltration_artifact_files.yml

* Fix Windows path escaping - use single backslash in YAML block scalar

---------

Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-11-25 14:56:20 -08:00
dependabot[bot] 984e65062b Bump actions/checkout from 5 to 6 (#3804)
Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-11-24 15:56:11 -08:00
Rod Soto b53280a5e9 Rod- Suspicious Local LLM Frameworks (#3780)
* newstory

* firstdet

* fixeddatasets

* 4688locallmdiscovery

* sys1

* sysmon

* secsys

* llmdns

* suspdownfix

* Update detections/endpoint/suspicious_local_llm_framework_download_and_execution_via_sysmon.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* localdnstosuspicious

* windowsexecutionoflocallllmdet

* fixeddetections

* deletedold

* fixedsearch

* fixedsuspiciouslocalllmframeworkprocessexecnospath

* fixedhowtoimplement

* fixhowtoimp

* fixdescription

* moredetails

* update detections

* small fixes

* updates

* small change

* various fixes

* remove dd for hunting detections

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-11-24 13:06:41 -08:00
Nasreddine Bencherchali 515d736c62 Add New ASA Analytics (#3794)
* first batch

* more updates

* update tags and filter

* more fixes

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* Update cisco_asa___reconnaissance_command_activity.yml

* update to production

* fixes and updates

* update date and fix typos

* apply suggestion

* Update cisco_asa___reconnaissance_command_activity.yml

* add explicit message ids

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-11-21 14:50:18 -08:00
Br3akp0int 888c2249e8 netsupport (#3798)
* netsupport

* netsupport

* netsupport

* netsupport

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update data_sources/sysmon_eventid_29.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update data_sources/sysmon_eventid_29.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* netsupport

* netsupport

* netsupport

* netsupport

* updates

* small fixes

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-11-21 13:27:52 -08:00
Bhavin Patel 19d3c489fe CIM App name and Switch sourcetypes (#3799)
* fix app issue

* splunkbase_file_name

* updating detections

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-11-21 08:33:33 -08:00
Nasreddine Bencherchali c3aaf7147b Merge pull request #3800 from splunk/auto-ta-update-456
Automated Splunk TA Update 456
2025-11-21 16:31:43 +01:00
patel-bhavin 50989c2650 Updated TAs 2025-11-21 06:59:48 +00:00
Nasreddine Bencherchali 902d2cf325 Merge pull request #3797 from splunk/auto-ta-update-455
Automated Splunk TA Update 455
2025-11-20 17:05:14 +01:00
patel-bhavin 1bd5621d23 Updated TAs 2025-11-20 06:58:48 +00:00
Nasreddine Bencherchali 4610e52c6e Add @nasbench as code owner (#3795) 2025-11-18 14:43:17 -08:00
Raven Tait 001a152933 NTLM Reflection via DNS Object SPN Spoofing (#3789)
* NTLM Reflection via DNS Object SPN Spoofing

* Update to user field

* update data source

* Adding fields manadated in the output fields of Sysmon EventID 22 data source

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-11-18 12:59:34 -08:00
Bhavin Patel 8e3a86dbea Appinspect on develop (#3792)
* add push condition

* remove on develop
2025-11-17 14:32:47 -08:00
Bhavin Patel a03c06aaa9 Testing CI (#3791)
* testing

* setting runner to 22.02

* last months version

* testing verbose

* change to one container

* one more test

* Update access_lsass_memory_for_dump_creation.yml
2025-11-17 12:28:49 -08:00
Emil 6bf3fa8979 Suspicious mshta child process minor fixes (#3787)
* Removing duplicate process_name, adding process_name to risk_message

Powershell.exe was written twice, removing duplicate value

Adding proccess_name to risk message allows for better understanding of impact

* Bump version to 11 and update date

Updated version and date for suspicious mshta child process detection.

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-11-14 08:49:56 -08:00
James Hodgkinson 206f28f1c7 Fixing typo in suspicious_ollama_activities.yml (#3783) 2025-11-13 17:14:15 -08:00
Bhavin Patel 637e44267d Updated TAs (#3782)
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
2025-11-13 12:31:49 -08:00
Lou Stella e932cf6f89 Merge pull request #3781 from splunk/ctl_519
updating package version to 5.19
2025-11-13 08:14:17 -06:00
Bhavin Patel ff1fa9987d Merge branch 'develop' into ctl_519 2025-11-12 17:59:33 -08:00
Bhavin Patel 075bd54bcf updating contentctl to 5.19 2025-11-12 17:02:24 -08:00
Bhavin Patel 45c49654bc switching source and sourcetype (#3779) 2025-11-12 16:54:27 -08:00
Jake Enea bde912d439 execution of file with multiple extensions: fixing rtf.exe (#3778) 2025-11-12 16:32:08 -08:00
Bhavin Patel e42da6eaf3 Automated Splunk TA Update 440 (#3761)
* Updated TAs

* Applink

* Fix - Windows Kerberos Local Successful Logon (#3763)

* fixes?

* Update windows_svchost_exe_parent_process_anomaly.yml

revert

* manual test

* unicode

---------

Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com>
v5.18.0
2025-11-10 12:24:06 -08:00
Br3akp0int fcf1275e96 castlerat (#3750)
* castlerat

* castlerat

* castlerat

* castlerat

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-11-07 11:08:44 -08:00
lyonheart14 5b8befee38 Removed grouping by dest (#3759)
* Removed grouping by dest

Grouping by the 'dest' field causes the search to filter out alerts where dest is empty (which doesn't make sense with the base search stipulating user="*" or dest="*"). Filtering out alerts where dest doesn't contain a value can be done with the filter macro.

* adding values(dest) before by clause

* version, date, author update

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-11-05 11:17:48 -08:00
Bhavin Patel d1a15f9e91 Ollama TA (#3757)
* updating ta

* updating weird things
2025-11-05 09:50:50 -08:00
Bhavin Patel d401d3a33b updating raw log (#3756) 2025-11-04 13:17:53 -08:00
Bhavin Patel bd66e7a1d3 remove TA (#3755) 2025-11-04 11:05:19 -08:00
Lou Stella c664c282b9 Merge pull request #3748 from splunk/dependabot/github_actions/actions/upload-artifact-5
Bump actions/upload-artifact from 4 to 5
2025-10-30 12:36:44 -05:00
dependabot[bot] 6f3c42cac5 Bump actions/upload-artifact from 4 to 5
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 5.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v5)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-30 17:30:15 +00:00
Bhavin Patel c5413e93f2 updating version and removing detections (#3749) 2025-10-30 10:29:04 -07:00
Bhavin Patel 437a5cdf62 revert - Splunk Add-on for Microsoft Security (#3747)
* revert this app

* revert versions
v5.17.0
2025-10-27 15:38:58 -07:00
Br3akp0int d2ca19aab5 detection_fixed (#3746)
* detection_fixed

* detection_fixed

* detection_fixed

* Update deprecation_mapping.YML

---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-10-27 10:23:56 -07:00
Michael Haag 58bf9a1bc8 WSUSpect in Custody: CVE-2025-59287 (#3743)
* WSUSpect in Custody: CVE-2025-59287

* WSUS and Updates

* :jt_stare:

* Update windows_wsus_spawning_shell.yml

* Update w3wp_spawning_shell.yml

* deprecate rules and map analytic stories

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-10-27 09:48:44 -07:00
Nasreddine Bencherchali 9fc8942993 New Rules & Updates - Oct 25 (#3726)
* new rules and updates

* fix issues with ci

* rename for accurate macro

* update description and logic

* new wbadmin rule and fix pwsh dataset

* more updates for the weekend

* update network rules filters

* downgrade versions

* Update windows_file_transfer_protocol_in_non_common_process_path.yml

* add missing DS for some rules

* update nirsoft lookup and add new rules

* update more nirsoft stuff

* update snort message

* Update cisco_secure_firewall_filetype_lookup.yml

* new analytic and updates / incl. fix #3730

* Update detect_new_local_admin_account.yml

* add lnx dataset and fix wildcards
2025-10-24 14:19:48 -07:00
Nasreddine Bencherchali 0227a4f5f1 Add Oracle Exploitation Snort Coverage (#3742)
* add oracle snort coverage

* fix refs

* Update cisco_secure_firewall___oracle_e_business_suite_exploitation.yml
2025-10-23 14:49:04 -07:00