Commit Graph

10362 Commits

Author SHA1 Message Date
pyth0n1c ba78e372e2 Changed a port back to the original since it's run inside the docker container as part of a playbook 2021-09-17 18:12:02 -07:00
pyth0n1c 2a3e220249 Made the splunk management port dynamic for uploading replay data. 2021-09-17 17:51:27 -07:00
pyth0n1c 5588eeabe1 Fixed ugly multi line comment 2021-09-17 17:35:50 -07:00
pyth0n1c 94f05e573c Added some error handling so that the show can go on while we debug. Fixed another bad variable naming error 2021-09-17 17:33:20 -07:00
pyth0n1c ebb00af725 Forgot to declare results_queue before using it. 2021-09-17 16:58:14 -07:00
pyth0n1c 4d1c456a33 Removed some aws calls which should no longer be made 2021-09-17 16:49:05 -07:00
pyth0n1c e5c87027c1 Lots more changes building out the skeleton of the docker testing framework. Needs testing, breakup into simpler files, documentation, etc. But a good start. 2021-09-17 16:45:05 -07:00
pyth0n1c dc8b704332 Initial changes and testing for local dockerized detection testing service 2021-09-17 15:14:17 -07:00
Michael Haag b6db6f357b Merge pull request #1667 from splunk/add_dataset_url
adding dataset url
2021-09-17 06:24:41 -06:00
Jose Enrique Hernandez aec4f7c772 adding dataset url 2021-09-15 17:34:51 -04:00
pyth0n1c 3f5b996824 Merge pull request #1664 from splunk/TR-851
removed submodule, no need for additonal detection testing run. Semgrep error is due to issue in semgrep repo
2021-09-15 11:36:01 -07:00
Lou Stella e3a84e4840 removed submodule 2021-09-15 12:54:05 -05:00
mvelazco 1fde288203 Merge pull request #1662 from splunk/AD_Discovery_TR-789_5
May The Haag Be With You
2021-09-14 15:34:29 -04:00
root 575377d312 Added detection testing service results inPowerShell Get LocalGroup Discovery 2021-09-14 18:46:53 +00:00
Detection Testing Service 6bed1bdc71 Merge branch 'AD_Discovery_TR-789_5' of https://github.com/splunk/security_content into AD_Discovery_TR-789_5 2021-09-14 18:20:58 +00:00
root 70dfb3b5d1 Added detection testing service results inWmic Group Discovery 2021-09-14 18:20:57 +00:00
Detection Testing Service 1a5e50fbec Merge branch 'AD_Discovery_TR-789_5' of https://github.com/splunk/security_content into AD_Discovery_TR-789_5 2021-09-14 18:14:29 +00:00
root eaacec47db Added detection testing service results inPowershell Get LocalGroup Discovery with Script Block Logging 2021-09-14 18:14:29 +00:00
Detection Testing Service 84f5346fdf Merge branch 'AD_Discovery_TR-789_5' of https://github.com/splunk/security_content into AD_Discovery_TR-789_5 2021-09-14 18:02:07 +00:00
root c514bf1361 Added detection testing service results inNet Localgroup Discovery 2021-09-14 18:02:07 +00:00
Detection Testing Service 5cf90f60b2 Merge branch 'AD_Discovery_TR-789_5' of https://github.com/splunk/security_content into AD_Discovery_TR-789_5 2021-09-14 17:55:42 +00:00
root 7ccd84ccfd Added detection testing service results inGet WMIObject Group Discovery with Script Block Logging 2021-09-14 17:55:41 +00:00
root 9836d8c263 Added detection testing service results inGet WMIObject Group Discovery 2021-09-14 17:52:46 +00:00
mhaag-spl 358917d733 May The Haag Be With You 2021-09-14 11:05:59 -06:00
Michael Haag cd5bbf6cca Merge pull request #1660 from splunk/AD_Discovery_TR-789_9
AD_Discovery_TR-789_9
2021-09-14 10:02:13 -06:00
mvelazco 47e3c2bf9e fixing message field 2021-09-14 11:54:58 -04:00
mvelazco 2e6bb4886b Merge branch 'AD_Discovery_TR-789_9' of github.com:splunk/security_content into AD_Discovery_TR-789_9 2021-09-14 10:01:54 -04:00
mvelazco 379f8e82c1 adding required_fields 2021-09-14 10:01:52 -04:00
Detection Testing Service 042f7e0c74 Merge branch 'AD_Discovery_TR-789_9' of https://github.com/splunk/security_content into AD_Discovery_TR-789_9 2021-09-14 13:35:29 +00:00
root 31a0177b31 Added detection testing service results inGetCurrent User with PowerShell Script Block 2021-09-14 13:35:28 +00:00
root 4abb769c46 Added detection testing service results inGetCurrent User with PowerShell 2021-09-14 13:33:53 +00:00
Detection Testing Service 893822a9c9 Merge branch 'AD_Discovery_TR-789_9' of https://github.com/splunk/security_content into AD_Discovery_TR-789_9 2021-09-13 22:58:59 +00:00
root a51106c70d Added detection testing service results inUser Discovery With Env Vars PowerShell 2021-09-13 22:58:58 +00:00
Detection Testing Service d953fb05b1 Merge branch 'AD_Discovery_TR-789_9' of https://github.com/splunk/security_content into AD_Discovery_TR-789_9 2021-09-13 22:58:57 +00:00
root 137aa7a5e5 Added detection testing service results inUser Discovery With Env Vars PowerShell Script Block 2021-09-13 22:58:57 +00:00
root e4719b9437 Added detection testing service results inSystem User Discovery With Whoami 2021-09-13 22:56:08 +00:00
root 07e27ba6ae Added detection testing service results inSystem User Discovery With Query 2021-09-13 22:03:33 +00:00
mvelazco 2959c2edb7 Merge branch 'AD_Discovery_TR-789_9' of github.com:splunk/security_content into AD_Discovery_TR-789_9 2021-09-13 17:22:33 -04:00
mvelazco 687fb1745c adding 4 detections 2021-09-13 17:22:30 -04:00
Bhavin Patel 9522b364c5 Branch was auto-updated. 2021-09-13 11:10:27 -07:00
Bhavin Patel 70dc4c3414 Merge pull request #1658 from splunk/AD_Discovery_TR-789_8
AD_Discovery_TR-789_8
2021-09-13 11:10:10 -07:00
Bhavin Patel eca9191516 Branch was auto-updated. 2021-09-13 11:09:36 -07:00
Bhavin Patel b94510f831 Merge pull request #1624 from splunk/AD_Discovery_TR-789_3
AD_Discovery_TR-789_3
2021-09-13 11:09:16 -07:00
Bhavin Patel 5cd91c53c2 Branch was auto-updated. 2021-09-13 11:07:52 -07:00
Bhavin Patel 2a06605804 Merge pull request #1596 from splunk/AD_Discovery_TR-789_6
AD_Discovery_TR-789_6
2021-09-13 11:07:33 -07:00
Bhavin Patel 20913cd362 Branch was auto-updated. 2021-09-13 11:06:38 -07:00
Bhavin Patel 361c57dfc7 Merge pull request #1620 from splunk/AD_Discovery_TR-789_7
AD_Discovery_TR-789_7
2021-09-13 11:06:16 -07:00
mvelazco ce3b5cadfd initial 2 detections 2021-09-13 12:08:42 -04:00
mhaag-spl fd34f91dcd Update create_or_delete_windows_shares_using_net_exe.yml 2021-09-13 07:34:37 -06:00
mvelazco 9d694d78a6 Merge pull request #1659 from splunk/cab-in-the-inf
Haag With the Wind: CVE-2021-40444 Edition
2021-09-10 15:08:29 -04:00