Commit Graph

23138 Commits

Author SHA1 Message Date
Michael Haag dbdbaf8c30 Updated logic for SharePoint EOP
Added Web.status=200 Web.http_method=GET to keep it tight.  Based on exploit code available, this will work well.
2023-10-03 07:50:50 -06:00
srv-rr-gh-researchbt 88015b4e65 Branch was auto-updated. 2023-10-02 14:13:58 -07:00
Rod Soto 608438f223 Merge pull request #2860 from splunk/platform_security_20230919
Platform security 20230919
2023-10-02 14:13:37 -07:00
pyth0n1c d57b3f1fcf properly format times in risky command search 2023-10-02 12:56:00 -07:00
pyth0n1c 96c931eda9 use macro instead of using index and sourcetype directly. 2023-10-02 12:45:09 -07:00
pyth0n1c b16a497093 remove source= from search 2023-10-02 11:54:06 -07:00
pyth0n1c a00fce83db Update to new search after dynamic testing and refinement. 2023-10-02 11:49:57 -07:00
pyth0n1c aa366491e5 Merge branch 'platform_security_20230919' of https://github.com/splunk/security_content into platform_security_20230919 2023-10-02 11:37:32 -07:00
pyth0n1c de281dcdb6 First version of new detection for testing 2023-10-02 11:36:50 -07:00
Bhavin Patel e6ba0c14b4 adding to SPL 2023-10-02 11:33:51 -07:00
srv-rr-gh-researchbt b8df1501a3 Branch was auto-updated. 2023-10-02 11:19:55 -07:00
srv-rr-gh-researchbt a51faed2c5 Branch was auto-updated. 2023-10-02 11:19:54 -07:00
Bhavin Patel 3223d8fef9 Merge pull request #2864 from splunk/ws_ftp
WS_FTP
2023-10-02 11:19:36 -07:00
pyth0n1c 588ef14f0c Added fillnull to improve detection accuracy for all logs. 2023-10-02 11:03:24 -07:00
Gowthamaraj rajendran 05273c0b0e Merge branch 'themebleed_and_cve_2023_29357' of github.com:splunk/security_content into themebleed_and_cve_2023_29357 2023-10-02 09:58:04 -07:00
Gowthamaraj rajendran 4da628ca8a Edit ThemeBleed 2023-10-02 09:58:00 -07:00
srv-rr-gh-researchbt bc66334e86 Branch was auto-updated. 2023-10-02 09:12:48 -07:00
srv-rr-gh-researchbt ab5e3e2cf6 Branch was auto-updated. 2023-10-02 09:12:47 -07:00
srv-rr-gh-researchbt c7a52967fe Branch was auto-updated. 2023-10-02 09:12:45 -07:00
Bhavin Patel 6af27bff01 Merge pull request #2865 from splunk/teamcity
JetBrains TeamCity RCE
2023-10-02 09:12:25 -07:00
Bhavin Patel f3540a2da7 Update message 2023-10-02 08:57:56 -07:00
Bhavin Patel ca1758dee7 adding Attacker obs 2023-10-02 08:55:43 -07:00
Bhavin Patel 34252303f2 Adding POST 2023-10-02 08:52:40 -07:00
Gowthamaraj rajendran 315064fcb0 Update Theme bleed 2023-10-01 12:29:46 -07:00
Gowthamaraj rajendran 6e0397fc4c Update windows_theme_command_execution.yml 2023-10-01 11:29:58 -07:00
Gowthamaraj rajendran f7c411cfa2 Update windows_theme_command_execution.yml 2023-10-01 11:24:18 -07:00
Gowthamaraj rajendran 7ac5bba3df Update detections/endpoint/windows_theme_command_execution.yml 2023-10-01 11:22:25 -07:00
Gowthamaraj rajendran c3b03f288b Update 2023-10-01 11:17:59 -07:00
Michael Haag 36c15130f6 JetBrains TeamCity RCE 2023-10-01 10:59:09 -06:00
Michael Haag 5921fc0679 fix 2023-10-01 10:25:32 -06:00
Michael Haag 63c248fe02 Update ws_ftp_remote_code_execution.yml 2023-10-01 10:23:12 -06:00
Michael Haag 85ec2974bb Create ws_ftp_remote_code_execution.yml 2023-10-01 10:18:46 -06:00
Michael Haag a3d1907490 fixes 2023-10-01 09:42:31 -06:00
Michael Haag 17ca5971d3 WS_FTP 2023-10-01 09:39:59 -06:00
srv-rr-gh-researchbt 9b6c459a09 Branch was auto-updated. 2023-09-29 15:21:20 -07:00
Bhavin Patel 24b8573f65 Merge pull request #2859 from splunk/obs_fix_25
Fix issues with observables
2023-09-29 15:21:01 -07:00
pyth0n1c 31bc1a0820 Minor search fixes for
observables
2023-09-29 14:17:05 -07:00
pyth0n1c 56abb40647 More observable fixes, including renaming fields
in searchers.
2023-09-29 13:19:47 -07:00
Bhavin Patel 54ce1f7f1d Merge branch 'release_v4.13.0' into obs_fix_25 2023-09-28 17:47:52 -07:00
srv-rr-gh-researchbt e38e0bacc3 Branch was auto-updated. 2023-09-28 16:41:10 -07:00
Bhavin Patel 3d3631fba9 Merge pull request #2855 from splunk/sysmon_fix
Sysmon searches updated to use CIM fields
2023-09-28 16:40:50 -07:00
pyth0n1c f6dc49e1d3 add another filter so that we do not flag
scripts running out of c:
2023-09-28 16:18:50 -07:00
pyth0n1c 732aec3f95 Delete detection and migrate
logic and documentation to risky
command lookup file. Update macro
to point to new risky command csv.
Fiox some opservables.
2023-09-28 14:51:28 -07:00
pyth0n1c f76dfe4277 Minor updates to improve notables
and result rendering.
2023-09-28 13:37:36 -07:00
Bhavin Patel 1813ce39ac Merge branch 'release_v4.13.0' into sysmon_fix 2023-09-28 12:38:50 -07:00
srv-rr-gh-researchbt f11bec3047 Branch was auto-updated. 2023-09-28 12:27:36 -07:00
Bhavin Patel 83a2a59b34 Merge pull request #2858 from splunk/obs_fix_64
Observable fixes
2023-09-28 12:26:59 -07:00
Bhavin Patel e5a814e78e remove script block from message 2023-09-28 11:12:02 -07:00
Bhavin Patel 2270cac53c Update get_aduser_with_powershell_script_block.yml 2023-09-28 11:09:47 -07:00
Bhavin Patel 5bdfd1f170 Update get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml 2023-09-28 11:08:30 -07:00