Jason Brewer
c06702a7f4
CRL-1725 - Added update to detections.spec.json to accomodate a new output entity parent_process_name.
2020-02-03 15:32:12 -08:00
divious1
0abf721c3f
introduced mitre technique id to detection spec
2020-01-06 13:31:43 -05:00
David Dorsey
5f30745b7c
Fixed issue in CRL-1387 where the check for executionpolicy bypass
...
was too broad.
Also, added investigation searches for file and registry activity
while I was here
2019-11-06 18:39:21 -08:00
bpatel
541b72fd71
merge with develop and testing
2019-11-05 12:22:01 -08:00
Patrick Bareiss
af66ed5fe3
Changed json to yml
2019-10-16 16:38:05 +02:00
Jose Enrique Hernandez
c9effaf169
Merge branch 'develop' into cloud_cryptominig
2019-10-08 08:40:51 -04:00
Jose Enrique Hernandez
9c6c794b81
Merge pull request #215 from splunk/drilldown
...
Added drilldown search and name to the detection spec.
2019-10-08 08:32:49 -04:00
David Dorsey
fb93597cfc
Merge branch 'macros' into cloud_cryptominig
2019-10-03 17:49:45 -07:00
David Dorsey
82e8b210a9
Files for new cloud cryptominig story.
...
It's a cloud infrastructure generic version of AWS Cryptomining
2019-10-03 17:42:40 -07:00
David Dorsey
24769e88c5
Added lookup to the search specs
2019-10-02 12:01:03 -07:00
David Dorsey
2a8b470241
Added drilldown search and name to the detection spec.
...
Added these fields to the suspicious wevtutil manifest
Updated validate to make sure both entries are there or neither are
Updated generate to output those fields if they are there
2019-10-01 17:31:11 -07:00
David Dorsey
575b766f09
Minor spec change to macro.spec.json
2019-09-30 16:08:08 -07:00
David Dorsey
3d25c40bf7
Updated macro definition in detections, investigations, and baselines to just be a list
...
Broke out macros definition into it's own manifest
Created macro manifests for all of current macros that we ship
Created lookup file manifest
Created lookup file manifests for all current lookup files that we ship
2019-09-30 13:53:25 -07:00
David Dorsey
6ee9d9962c
Added entry for macros in baseline, detections, and investigations spec.
2019-09-25 14:36:35 -05:00
bpatel
e1310d2192
adding ss.conf spec and example
2019-09-12 16:27:11 -07:00
bpatel
4d221f5d18
added entities field and updated spec files
2019-09-04 16:36:08 -07:00
divious1
bb0a440b62
removing example repo as all content is now v2
2019-09-04 12:44:43 -04:00
Rico Valdez
8eb0084ae0
re-applying some fixes for channel. Also, merging in develop broke the spec file, so fixed that.
2019-08-06 20:47:35 -06:00
divious1
b82eaa7750
fixing merge conflicts
2019-08-06 17:45:35 -04:00
Rico Valdez
5836446617
fixed channel in stories, minor tweaks to detections.
...
Also - updated spec to allow validation to pass for UBA detection, as well as updated validation script
2019-08-06 14:58:39 -06:00
Bhavin Patel
57118d085c
Merge pull request #167 from splunk/CRL-1580
...
CRL 1580 :UBA Anomaly
2019-07-26 12:26:53 -07:00
Rico Valdez
bfef6024fe
more tweaks/fixes to manifests - also adjustments to validation script and spec files. Successfully validates with exception of usecase in stories
2019-07-25 14:56:40 -06:00
bpatel
bfa2df0786
updated search and manifest content
2019-07-24 14:29:03 -07:00
divious1
06f5aa70fb
fixing stories that are using product_type
2019-07-18 12:35:45 -04:00
divious1
4c352b9bed
fixing error
2019-07-17 12:52:09 -04:00
divious1
3813882fae
doc generation skeleton
2019-06-19 00:03:14 -04:00
proyer
842e46f953
add missing providing_technologies to spec
2019-06-04 14:40:53 -04:00
bpatel
926298f6cd
validate errors
2019-04-22 13:51:30 -07:00
bpatel
7336624652
conflicts, merge spec update to this branch
2019-04-22 11:44:26 -07:00
bpatel
ce0eeade0f
spec updates, searches to 2.0
2019-04-18 14:39:01 -07:00
bpatel
3d43375341
fixes and udpates
2019-04-18 13:15:16 -07:00
divious1
bdfc72749a
updated validate script, included phantom in generator, fixed some stories to v2
2019-04-18 11:28:26 -04:00
bpatel
a449fbb8f7
updating Censys in providing technologies
2019-04-16 11:25:19 -07:00
bpatel
cff0563d28
phantom invesigation object
2019-04-16 11:20:37 -07:00
bpatel
86662c3c0a
CI errors
2019-04-15 13:37:49 -07:00
bpatel
018cd8256c
examples in spec files and docs
2019-04-02 17:00:32 -07:00
divious1
cfeccbd73e
removed example spec
2019-04-02 17:31:57 -05:00
divious1
87c1490320
Merge branch 'spec_update' of github.com:splunk/security-content into spec_update
2019-04-02 17:31:29 -05:00
divious1
6112fcc9e6
updating schedule field in specs, also corrected validation logic
2019-04-02 17:31:02 -05:00
divious1
d76848cb39
correct mistakes with the sub schema validation
2019-04-02 17:03:55 -05:00
bpatel
43093da142
story spec with example and docs
2019-04-02 14:28:20 -07:00
divious1
b923dc56c3
updated investigations
2019-04-02 14:47:10 -04:00
divious1
a9bb9bad0d
updated spec and examples to correct some def errors
2019-04-02 14:34:35 -04:00
bpatel
35f8c61e8c
oneOF example
2019-04-02 10:55:59 -07:00
divious1
e562cc1e37
updated with baseline searches
2019-04-01 16:36:17 -04:00
divious1
f05f011e6b
added investigative check functions
2019-03-29 22:59:27 -04:00
divious1
fd6a55d7f4
updated mitre mappings
2019-03-29 13:44:40 -04:00
bpatel
6c24bb91d9
spec omne enums and v2 examples
2019-03-29 12:45:15 -04:00
bpatel
a2f431b6cc
baseline update
2019-03-29 12:14:44 -04:00
bpatel
6ce4f809af
updates
2019-03-28 12:46:04 -04:00