Commit Graph

12668 Commits

Author SHA1 Message Date
pyth0n1c 7effe85ae2 Previous commit overwrote things we did not want to, like fields besides required_fields in the tags section. Now we are more careful. 2022-01-10 15:50:17 -08:00
pyth0n1c 3df196b43d Updated code to make changes to files after scanning. 2022-01-10 15:43:23 -08:00
pyth0n1c 97e9cda0ca We now properly complete the required_fields under tags. We just need to write this data back out to the relevant files. 2022-01-10 14:52:02 -08:00
pyth0n1c d9ed887036 Fixed a bad submodel name in one of the datamodels for a search. 2022-01-10 12:56:29 -08:00
pyth0n1c 795ef776ef Moved old baseline search to experimental. It is also using a datamodel that is included in Enterprise Security, but is not present in Splunk_CIM. That was causing some issues/warning in validation of datamodels/submodels/fields. 2022-01-10 12:54:44 -08:00
pyth0n1c 4a34f4445d Updated a large number of searches which uses datamodels from 'datamodel=datamodel' to 'datamodel=datamodel.submodel'. This is more explicit and allows us to better enumerate and check required_fields and declared datamodels 2022-01-10 12:52:16 -08:00
pyth0n1c af3c38d10b Progress towards matching tokens with datamodels. still a number of false positive misses that we need to work through. 2022-01-10 10:09:42 -08:00
pyth0n1c fb91aaaa68 Progress on cleaning up the required fields. We can now pull out the datamodel fields, but it includes the datamodel itself too. 2022-01-06 17:48:30 -08:00
pyth0n1c 1ca0ffa3ea Update datamodel=MODEL fields to datamodel=Model.Submodel 2022-01-06 13:45:29 -08:00
tccontre fa843067da Merge pull request #1917 from splunk/remocs_desc_update
remcos_desc_update
2022-01-05 09:41:08 +01:00
pyth0n1c e10f55348c Updated Detection Text
Updated Text of Detection "Suspicious Process DNS Query Known Abuse Web Services"
2022-01-04 08:47:13 -08:00
pyth0n1c 8891384376 Small Text Update
Small Text Update to "Loading Of Dynwrapx Module"
2022-01-04 08:42:39 -08:00
tccontre 7420f730d4 Update suspicious_process_dns_query_known_abuse_web_services.yml 2022-01-04 17:39:17 +01:00
pyth0n1c 249c784daf Small Text Updates
Small Text Updates to "Loading Of Dynwrapx Module"
2022-01-04 08:38:05 -08:00
pyth0n1c 5702bf9c7d Minor Text Updates
Minor Text Updates to "System Info Gathering Using Dxdiag Application"
2022-01-04 08:36:46 -08:00
pyth0n1c 54e6931e48 Minor Text Updates
Minor updates to the text of  "Suspicious Process DNS Query Known Abuse Web Services"
2022-01-04 08:31:04 -08:00
pyth0n1c cff1c5dd74 Update Text of Detection
Minor update to text of "Possible Browser Pass View Parameter"
2022-01-04 08:23:36 -08:00
pyth0n1c 3c6c0dc575 Minor Text Update
Minor update to text of "Loading Of Dynwrapx Module"
2022-01-04 08:21:15 -08:00
tccontre 9c96e69754 remcos_desc_update 2022-01-04 10:25:11 +01:00
Lou Stella 94f903d685 Merge pull request #1916 from splunk/adding_not_supported
modify experimental detections to say not supported
2022-01-03 13:46:45 -06:00
d1vious 8f0518b5af spelling fix 2022-01-03 14:39:48 -05:00
d1vious 7c1025425a fixed spelling 2022-01-03 14:35:49 -05:00
d1vious 50ba793358 fixing formatting 2022-01-03 12:20:42 -05:00
d1vious 1e731ee7af modify experimental detections to say not supported 2022-01-03 12:03:34 -05:00
Jose Enrique Hernandez 930a6db140 Merge pull request #1901 from splunk/AD_Privilege_Escalation_CVE-2021-42278 2021-12-21 14:21:54 -05:00
root 9243038c09 Added detection testing service results inSuspicious Ticket Granting Ticket Request 2021-12-21 19:06:04 +00:00
mvelazco bb8ae58f84 adding new detection 2021-12-21 13:44:17 -05:00
root da634d5c25 Added detection testing service results inSuspicious Kerberos Service Ticket Request 2021-12-21 03:57:17 +00:00
mvelazco 4631c84a60 updating logic 2021-12-20 22:38:27 -05:00
root 122d403d6c Added detection testing service results inSuspicious Kerberos Service Ticket Request 2021-12-21 03:34:17 +00:00
mvelazco d5d7e0ce1a Update suspicious_computer_account_name_change.yml 2021-12-20 22:11:09 -05:00
mvelazco 6fa0f9b30b adding new detection 2021-12-20 22:08:19 -05:00
root 653a7755e8 Added detection testing service results inSuspicious Computer Account Name Change 2021-12-20 22:50:20 +00:00
mvelazco af31bdb3ec updating observable 2021-12-20 17:20:58 -05:00
mvelazco 243e60a3cc minor fix 2021-12-20 17:04:58 -05:00
mvelazco 82a4a63093 creating analytic story and first detection 2021-12-20 16:58:34 -05:00
mvelazco 59b9068998 Merge pull request #1894 from splunk/Fix_Log4j_detection
Update Log4J Detection to use data models
2021-12-20 15:42:26 -05:00
Bhavin Patel 3eb630b220 Branch was auto-updated. 2021-12-16 12:55:22 -08:00
peter eff3306f89 Merge pull request #1897 from splunk/ssa_descriptive_branch_name
SSA descriptive branch name
2021-12-16 14:55:05 -06:00
peter-cg 55fd63fe2f Caps fix 2021-12-16 14:53:54 -06:00
peter-cg 3aa223a948 Adding sourcetype to sysproc_unexpected_location test 2021-12-16 10:44:05 -06:00
peter-cg ba83011191 Adding addl humvee runner and fixing macro def 2021-12-16 10:42:01 -06:00
Bhavin Patel ab3eb94c83 Branch was auto-updated. 2021-12-15 15:52:04 -08:00
pyth0n1c 7431dabd65 Merge pull request #1896 from splunk/doc_updates
Docs Update for playbook changes
2021-12-15 15:51:51 -08:00
Lou Stella 2f8de77b7c Docs Update for playbook changes 2021-12-15 17:42:47 -06:00
Bhavin Patel ae3484780a Branch was auto-updated. 2021-12-15 15:20:36 -08:00
Lou Stella 9c21e7f869 Merge pull request #1895 from splunk/The_Day_After_The_Day_After_log4shell
The Day After The Day After log4shell
2021-12-15 17:20:18 -06:00
Lou Stella 01bc5757b6 removed married parent playbook 2021-12-15 17:06:02 -06:00
Lou Stella fbf15c3424 Final copy from phantomcyber/playbooks 2021-12-15 16:58:31 -06:00
Lou Stella 872ea4b55c Standardized type 2021-12-15 15:52:40 -06:00