Bhavin Patel
157a434a53
Merge pull request #2335 from yaleman/patch-1
...
Grammar correction in documentation template
2022-08-23 15:02:11 -05:00
pyth0n1c
82f771dc08
Branch was auto-updated.
2022-08-22 14:51:12 -07:00
mvelazco
b0c3232991
adding microsoft cloud services ta
2022-08-22 17:38:49 -04:00
James Hodgkinson
729574b236
grammar correction in template
2022-08-18 13:32:34 +10:00
d1vious
799bdbae5b
we do not use it
2022-08-16 15:45:06 -04:00
Lou Stella
bc331db06c
Print error instead of bailing out on enrichment failure
2022-08-16 11:04:24 -05:00
pyth0n1c
4f6c1f20d3
Fixed template files that were modified in error
2022-08-12 13:15:41 -07:00
pyth0n1c
a17b44daf7
Remove lookups from copied ESCU directory.
2022-08-12 12:09:17 -07:00
pyth0n1c
f632813720
Changes to a number of files to make them suitable for use in an app by a different name.
2022-08-11 16:54:05 -07:00
pyth0n1c
f8e3fb6d4a
code to update templates files that must change for an app with different name to work
2022-08-11 15:14:17 -07:00
pyth0n1c
2c0888a090
Merge branch 'develop' into Clean_and_Deploy
2022-08-11 11:12:49 -07:00
P4T12ICK
97bc95f773
bug fix
2022-08-04 14:55:21 +02:00
pyth0n1c
1ee1b76968
Branch was auto-updated.
2022-08-04 00:42:05 -07:00
P4T12ICK
0fb17dd617
bug fix
2022-08-04 09:28:56 +02:00
d1vious
939493337d
adding research site links
2022-08-03 17:34:32 -04:00
pyth0n1c
87a8bc0442
Merged develop into this branch and resolved merge conflicts.
2022-08-03 06:47:22 -07:00
P4T12ICK
9dac698c46
solve merge conflicts
2022-08-01 11:39:02 +02:00
P4T12ICK
bcb943d150
fix tests
2022-08-01 11:31:23 +02:00
tccontre
b21d754be3
attack_data_helper
2022-07-20 10:54:59 +02:00
pyth0n1c
d5d7725afe
JSON file contained the words None, which is correctly for Python code, instead of null which is valid JSON
2022-07-19 13:47:05 -07:00
pyth0n1c
dc95a7fbfb
Branch was auto-updated.
2022-07-19 13:09:36 -07:00
pyth0n1c
93cf4d1d3f
Merge branch 'develop' into 20220715_app_baseline
2022-07-19 12:57:52 -07:00
pyth0n1c
72c1153383
Branch was auto-updated.
2022-07-19 12:40:38 -07:00
pyth0n1c
236f0ce71f
Branch was auto-updated.
2022-07-19 12:36:12 -07:00
pyth0n1c
bf4c565f79
Branch was auto-updated.
2022-07-19 12:36:08 -07:00
pyth0n1c
d4779f44ad
Branch was auto-updated.
2022-07-19 11:16:25 -07:00
pyth0n1c
03ccafe319
Branch was auto-updated.
2022-07-19 11:16:21 -07:00
pyth0n1c
d04c5e49f5
Branch was auto-updated.
2022-07-19 11:16:17 -07:00
pyth0n1c
ad975d46c2
Updating a few more links in test files from Fireeye
...
to Mandiant to match the source files.
2022-07-19 10:14:21 -07:00
pyth0n1c
7554992aa0
Updates to reduce duplication in the check_references code. Other updates to fix a number of issues introduced which cause Pytests to fail
2022-07-18 15:58:12 -07:00
Michael Haag
b71e570891
Update cobalt_strike_named_pipes.yml
...
Updated to Hunting
2022-07-15 10:16:14 -06:00
pyth0n1c
9a3302512a
Update Office 365 AddOn to 4.0
2022-07-15 09:13:10 -07:00
pyth0n1c
ea70270940
Update CIM and MS Sysmon as well
2022-07-15 09:04:21 -07:00
pyth0n1c
e993ff1dce
Updating baseline to latest apps as of
...
20220715. Apps have already been
uploaded to S3.
2022-07-15 08:48:32 -07:00
pyth0n1c
1cdfb1916f
Fixed paths in content generation to use the input path instead of hardcoded relative paths.
2022-07-15 08:02:17 -07:00
pyth0n1c
97ad9beaa2
Fixed the pathing issue for reporting.
2022-07-15 06:44:25 -07:00
pyth0n1c
20ab9f27ce
Moved id collision checking into
...
the Utils module since it will
be used by the Factory and the
BA Factory. Updated a duplicate
UUID to mitigate the collision
issue raised on GitHub.
2022-07-12 15:06:35 -07:00
pyth0n1c
9b21029bea
Added logic for checking to
...
see if there are duplicate ids
for any/all kinds of content that
have an ID associated with it.
2022-07-12 14:26:34 -07:00
pyth0n1c
46d152a0c1
Branch was auto-updated.
2022-07-12 12:14:21 -07:00
pyth0n1c
bf127dc0c0
Updating authorize.conf to allow us to delete from internal indexes. Reordering how delete works.
2022-07-12 08:39:08 -07:00
pyth0n1c
71b7c5d45c
Forgot to specify the host that data
...
was being uploaded from. This means
that delete does not work as expected,
causing a large number of tests to fail
and slower searches.
2022-07-11 14:06:01 -07:00
pyth0n1c
1e6f2d79b0
Don't modify the original search variable.
...
This can cause problems if we need to run
the search again.
2022-07-11 12:48:25 -07:00
pyth0n1c
b2aae73265
Branch was auto-updated.
2022-07-07 17:12:27 -07:00
pyth0n1c
8f0e5be32d
Merge pull request #2279 from splunk/retry_failed_detections_in_cicd
...
Small changes to CI/CD detection testing system. We merge these in now so that we can examine the results of the nightly scheduled run.
2022-07-07 17:11:56 -07:00
pyth0n1c
b1ba36517e
Updated wait time
...
and fixed typo in print
statement.
2022-07-07 17:09:51 -07:00
pyth0n1c
0c41f0a2f8
Branch was auto-updated.
2022-07-07 17:08:03 -07:00
pyth0n1c
81324ddb00
A number of detections are passing locally
...
but failing in CI/CD. I believe this is because
they are not being given enough time to finish
their data ingest completely. If a search fails,
wait some time and run it a few more times to
see if it will complete.
2022-07-07 15:58:46 -07:00
pyth0n1c
f2b7f155eb
Faster container startup when launching
...
a single container. Same wait time
between containers when launching
multiple containers. This gets us
to startup much faster for the most
common testing case, a single
container.
2022-07-07 15:30:24 -07:00
pyth0n1c
8ed9372401
On CVESearch API failure, added a
...
brief sleep to allow the API to
begin working again before trying
to resolve it again.
2022-07-07 14:40:39 -07:00
pyth0n1c
80af56d397
Fixing the rare case where enrichment fails
...
due to CVESearch API failure, causing the
entire workflow to fail. Now, we will retry
enrichment up to a total of 3 times. This should
virtually eliminate all CVE Enrichment failures.
If they do still occur, we will receive a
descriptive message indicating why there was
a failure instead of the cryptic message
that we were getting before.
2022-07-07 14:33:57 -07:00