Nasreddine Bencherchali
731df609cf
fix auditd PATH type detections ( #3810 )
...
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-12-03 00:41:30 +01:00
Nasreddine Bencherchali
d8ddca1a2d
Merge branch 'develop' into fix_cwd_path_detections
2025-12-03 00:25:40 +01:00
Nasreddine Bencherchali
8cff5c05eb
update descriptions
2025-12-03 00:23:36 +01:00
Emil
064cbaef0d
Internal horizontal port scan nmap iteration ( #3802 )
...
* Running splunk auto format to structure SPL
* Simplifying query by doing more in initial tstats, adding additional information
Moving more logic to tstats in order to simplify and speed up query. Adding lastTime and fields, which should help with triage and tuning
* Adding in All_Traffic.rule in order to please validation
* rba to src_ip, remove threat_objects
* Update version and date in YAML configuration
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-12-02 14:51:03 -08:00
Nasreddine Bencherchali
572a93567f
add missing extension
2025-12-02 18:59:42 +01:00
Nasreddine Bencherchali
ff4fda6445
update indentations and logic
2025-12-02 18:58:56 +01:00
Nasreddine Bencherchali
4a5ab34b37
Merge pull request #3813 from splunk/inspect_5.19
...
updating versions
2025-12-02 10:50:13 +01:00
Bhavin Patel
121be41015
Merge branch 'develop' into inspect_5.19
2025-12-01 20:07:37 -08:00
Bhavin Patel
17f3101c03
updating versions
2025-12-01 18:10:06 -08:00
Thomas Macfarlane
59c872761b
chore: user_agent field fix in both the Azure AD authentication detections. Minor spelling mistake fixes. ( #3811 )
...
* chore: user_agent field fix in both the Azure AD authentication detections. Minor spelling mistake fixes.
* beautify
* remove rename
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-12-01 16:25:33 -08:00
Teoderick Contreras
ab35d310e8
fix_cwd_path_detections
2025-11-28 09:33:10 +01:00
Teoderick Contreras
0d47dd6127
fix_cwd_path_detections
2025-11-27 15:36:14 +01:00
Nasreddine Bencherchali
ac7dcfbb84
Merge pull request #3808 from splunk/auto-ta-update-462
...
Automated Splunk TA Update 462
2025-11-27 12:33:37 +01:00
patel-bhavin
9604770975
Updated TAs
2025-11-27 06:59:55 +00:00
Michael Haag
442e815dad
npm Supply Chain Compromise & Lifecycle Hook Abuse Detection ( #3806 )
...
* extra content
* 5 more extras
* Hunt 1
* story+extras
* Create linux_shai_hulud_2_exfiltration_artifacts.yml
* Create linux_shai_hulud_workflow_file_modification.yml
* Create linux_suspicious_github_workflow_file_modification.yml
* Create windows_github_workflow_file_creation_hunt.yml
* more
* last 3
* final pass
* Bump versions to resolve merge conflicts with develop branch
* Fix deprecated status for curl/wget bash execution detections
* Add npm Supply Chain Compromise story to file_download_or_read_to_pipe_execution (replacement for deprecated curl/wget bash detections)
* Fix version numbers to match previous build requirements
* Add all required Filesystem fields to windows_suspicious_github_workflow_file_modification search
* Update detections/endpoint/windows_curl_download_to_suspicious_path.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* small fixes
* apply updates
* more updates
* Update shai_hulud_2_exfiltration_artifact_files.yml
* Fix Windows path escaping - use single backslash in YAML block scalar
---------
Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-11-25 14:56:20 -08:00
dependabot[bot]
984e65062b
Bump actions/checkout from 5 to 6 ( #3804 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 5 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-11-24 15:56:11 -08:00
Rod Soto
b53280a5e9
Rod- Suspicious Local LLM Frameworks ( #3780 )
...
* newstory
* firstdet
* fixeddatasets
* 4688locallmdiscovery
* sys1
* sysmon
* secsys
* llmdns
* suspdownfix
* Update detections/endpoint/suspicious_local_llm_framework_download_and_execution_via_sysmon.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* localdnstosuspicious
* windowsexecutionoflocallllmdet
* fixeddetections
* deletedold
* fixedsearch
* fixedsuspiciouslocalllmframeworkprocessexecnospath
* fixedhowtoimplement
* fixhowtoimp
* fixdescription
* moredetails
* update detections
* small fixes
* updates
* small change
* various fixes
* remove dd for hunting detections
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-11-24 13:06:41 -08:00
Nasreddine Bencherchali
515d736c62
Add New ASA Analytics ( #3794 )
...
* first batch
* more updates
* update tags and filter
* more fixes
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* Update cisco_asa___reconnaissance_command_activity.yml
* update to production
* fixes and updates
* update date and fix typos
* apply suggestion
* Update cisco_asa___reconnaissance_command_activity.yml
* add explicit message ids
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-11-21 14:50:18 -08:00
Br3akp0int
888c2249e8
netsupport ( #3798 )
...
* netsupport
* netsupport
* netsupport
* netsupport
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update data_sources/sysmon_eventid_29.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update data_sources/sysmon_eventid_29.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_executable_masquerading_as_benign_file_types.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* netsupport
* netsupport
* netsupport
* netsupport
* updates
* small fixes
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-11-21 13:27:52 -08:00
Bhavin Patel
19d3c489fe
CIM App name and Switch sourcetypes ( #3799 )
...
* fix app issue
* splunkbase_file_name
* updating detections
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-11-21 08:33:33 -08:00
Nasreddine Bencherchali
c3aaf7147b
Merge pull request #3800 from splunk/auto-ta-update-456
...
Automated Splunk TA Update 456
2025-11-21 16:31:43 +01:00
patel-bhavin
50989c2650
Updated TAs
2025-11-21 06:59:48 +00:00
Nasreddine Bencherchali
902d2cf325
Merge pull request #3797 from splunk/auto-ta-update-455
...
Automated Splunk TA Update 455
2025-11-20 17:05:14 +01:00
patel-bhavin
1bd5621d23
Updated TAs
2025-11-20 06:58:48 +00:00
Nasreddine Bencherchali
4610e52c6e
Add @nasbench as code owner ( #3795 )
2025-11-18 14:43:17 -08:00
Raven Tait
001a152933
NTLM Reflection via DNS Object SPN Spoofing ( #3789 )
...
* NTLM Reflection via DNS Object SPN Spoofing
* Update to user field
* update data source
* Adding fields manadated in the output fields of Sysmon EventID 22 data source
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-11-18 12:59:34 -08:00
Bhavin Patel
8e3a86dbea
Appinspect on develop ( #3792 )
...
* add push condition
* remove on develop
2025-11-17 14:32:47 -08:00
Bhavin Patel
a03c06aaa9
Testing CI ( #3791 )
...
* testing
* setting runner to 22.02
* last months version
* testing verbose
* change to one container
* one more test
* Update access_lsass_memory_for_dump_creation.yml
2025-11-17 12:28:49 -08:00
Emil
6bf3fa8979
Suspicious mshta child process minor fixes ( #3787 )
...
* Removing duplicate process_name, adding process_name to risk_message
Powershell.exe was written twice, removing duplicate value
Adding proccess_name to risk message allows for better understanding of impact
* Bump version to 11 and update date
Updated version and date for suspicious mshta child process detection.
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-11-14 08:49:56 -08:00
James Hodgkinson
206f28f1c7
Fixing typo in suspicious_ollama_activities.yml ( #3783 )
2025-11-13 17:14:15 -08:00
Bhavin Patel
637e44267d
Updated TAs ( #3782 )
...
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
2025-11-13 12:31:49 -08:00
Lou Stella
e932cf6f89
Merge pull request #3781 from splunk/ctl_519
...
updating package version to 5.19
2025-11-13 08:14:17 -06:00
Bhavin Patel
ff1fa9987d
Merge branch 'develop' into ctl_519
2025-11-12 17:59:33 -08:00
Bhavin Patel
075bd54bcf
updating contentctl to 5.19
2025-11-12 17:02:24 -08:00
Bhavin Patel
45c49654bc
switching source and sourcetype ( #3779 )
2025-11-12 16:54:27 -08:00
Jake Enea
bde912d439
execution of file with multiple extensions: fixing rtf.exe ( #3778 )
2025-11-12 16:32:08 -08:00
Bhavin Patel
e42da6eaf3
Automated Splunk TA Update 440 ( #3761 )
...
* Updated TAs
* Applink
* Fix - Windows Kerberos Local Successful Logon (#3763 )
* fixes?
* Update windows_svchost_exe_parent_process_anomaly.yml
revert
* manual test
* unicode
---------
Co-authored-by: patel-bhavin <7771446+patel-bhavin@users.noreply.github.com >
v5.18.0
2025-11-10 12:24:06 -08:00
Br3akp0int
fcf1275e96
castlerat ( #3750 )
...
* castlerat
* castlerat
* castlerat
* castlerat
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-11-07 11:08:44 -08:00
lyonheart14
5b8befee38
Removed grouping by dest ( #3759 )
...
* Removed grouping by dest
Grouping by the 'dest' field causes the search to filter out alerts where dest is empty (which doesn't make sense with the base search stipulating user="*" or dest="*"). Filtering out alerts where dest doesn't contain a value can be done with the filter macro.
* adding values(dest) before by clause
* version, date, author update
---------
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-11-05 11:17:48 -08:00
Bhavin Patel
d1a15f9e91
Ollama TA ( #3757 )
...
* updating ta
* updating weird things
2025-11-05 09:50:50 -08:00
Bhavin Patel
d401d3a33b
updating raw log ( #3756 )
2025-11-04 13:17:53 -08:00
Bhavin Patel
bd66e7a1d3
remove TA ( #3755 )
2025-11-04 11:05:19 -08:00
Lou Stella
c664c282b9
Merge pull request #3748 from splunk/dependabot/github_actions/actions/upload-artifact-5
...
Bump actions/upload-artifact from 4 to 5
2025-10-30 12:36:44 -05:00
dependabot[bot]
6f3c42cac5
Bump actions/upload-artifact from 4 to 5
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 4 to 5.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2025-10-30 17:30:15 +00:00
Bhavin Patel
c5413e93f2
updating version and removing detections ( #3749 )
2025-10-30 10:29:04 -07:00
Bhavin Patel
437a5cdf62
revert - Splunk Add-on for Microsoft Security ( #3747 )
...
* revert this app
* revert versions
v5.17.0
2025-10-27 15:38:58 -07:00
Br3akp0int
d2ca19aab5
detection_fixed ( #3746 )
...
* detection_fixed
* detection_fixed
* detection_fixed
* Update deprecation_mapping.YML
---------
Co-authored-by: Teoderick Contreras <tcontreras@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
2025-10-27 10:23:56 -07:00
Michael Haag
58bf9a1bc8
WSUSpect in Custody: CVE-2025-59287 ( #3743 )
...
* WSUSpect in Custody: CVE-2025-59287
* WSUS and Updates
* :jt_stare:
* Update windows_wsus_spawning_shell.yml
* Update w3wp_spawning_shell.yml
* deprecate rules and map analytic stories
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
2025-10-27 09:48:44 -07:00
Nasreddine Bencherchali
9fc8942993
New Rules & Updates - Oct 25 ( #3726 )
...
* new rules and updates
* fix issues with ci
* rename for accurate macro
* update description and logic
* new wbadmin rule and fix pwsh dataset
* more updates for the weekend
* update network rules filters
* downgrade versions
* Update windows_file_transfer_protocol_in_non_common_process_path.yml
* add missing DS for some rules
* update nirsoft lookup and add new rules
* update more nirsoft stuff
* update snort message
* Update cisco_secure_firewall_filetype_lookup.yml
* new analytic and updates / incl. fix #3730
* Update detect_new_local_admin_account.yml
* add lnx dataset and fix wildcards
2025-10-24 14:19:48 -07:00
Nasreddine Bencherchali
0227a4f5f1
Add Oracle Exploitation Snort Coverage ( #3742 )
...
* add oracle snort coverage
* fix refs
* Update cisco_secure_firewall___oracle_e_business_suite_exploitation.yml
2025-10-23 14:49:04 -07:00