Commit Graph

168 Commits

Author SHA1 Message Date
pyth0n1c dc13c17d7a improve specificity 2023-06-08 13:16:51 -07:00
pyth0n1c 84af2e0f6b Update splunk_http_response_splitting_via_rest_spl_command.yml 2023-06-08 12:19:11 -07:00
pyth0n1c 7831c8ae20 Revert to previous version in develop. This ammends an unintentional commit directly to develop. 2023-06-08 12:12:11 -07:00
pyth0n1c 431918df8d Minor update to increase
specificity of search
2023-06-08 12:07:46 -07:00
pyth0n1c c42c086a0a Fix detection 2023-06-01 11:10:39 -07:00
patel-bhavin 95cc544ca1 audit 2023-06-01 10:25:12 -07:00
patel-bhavin f7cabb74bb update yml 2023-06-01 10:18:58 -07:00
Bhavin Patel 553ecb9478 Update splunk_dos_via_dump_spl_command.yml 2023-06-01 09:58:45 -07:00
pyth0n1c 087a29c857 fixing mitre ids 2023-06-01 09:45:20 -07:00
pyth0n1c 4bfd0c1277 content for June2023. 2023-06-01 08:18:50 -07:00
P4T12ICK 97a1ec3bd5 bug fix validation 2023-04-28 13:53:52 +02:00
srv-rr-gh-researchbt 5f5f0aa76b Branch was auto-updated. 2023-04-17 16:53:09 -07:00
Bhavin Patel 69296ac7d1 Update okta_threatinsight_suspected_passwordspray_attack.yml 2023-04-17 16:46:08 -07:00
srv-rr-gh-researchbt 73f0a8dc50 Branch was auto-updated. 2023-04-17 16:26:21 -07:00
patel-bhavin fc34672ca4 updates to ymls 2023-04-17 15:23:53 -07:00
srv-rr-gh-researchbt 02803d91be Branch was auto-updated. 2023-04-17 13:11:16 -07:00
Lou Stella ed394e2ce1 Removing extra 11186 around field name 2023-04-17 15:00:52 -05:00
tccontre f276d22e6c data_destruction_wiper_story 2023-04-14 10:50:14 +02:00
pyth0n1c 67d09a1c52 Fixing some syntactic errors with a number of detections. 2023-04-12 10:09:43 -07:00
patel-bhavin 080e429c01 manual flag for 1 detection 2023-04-10 11:20:41 -07:00
patel-bhavin 6126674761 updated all yml, remove kc,nist,cis, updaated with 3.64.0 new content 2023-04-04 17:15:38 -05:00
P4T12ICK 8b990a6ea6 merged with develop 2023-03-23 10:35:34 +01:00
Rod Soto a4b8c67f8b firstfix 2023-03-21 12:25:11 -07:00
P4T12ICK 78909f6429 merged with develop 2023-03-03 12:40:16 +01:00
pyth0n1c 0640489c50 Fixed filter macro name 2023-02-14 09:17:16 -08:00
pyth0n1c eb124998c7 fixed name 2023-02-14 08:46:33 -08:00
pyth0n1c 9d595cf451 added dataset links 2023-02-14 08:21:48 -08:00
pyth0n1c e6c5fbd101 added all detections for release, still need to update dataset links 2023-02-14 06:46:13 -08:00
srv-rr-gh-researchbt 8583fe64f8 Branch was auto-updated. 2023-02-06 15:57:35 -08:00
pyth0n1c 60ea283f53 Moving failing tests to experimental 2023-02-02 16:32:24 -08:00
pyth0n1c 0daa31c481 Updated the macro in another
search whose test file was changed.
2023-02-01 18:01:19 -08:00
pyth0n1c 9cf9d1d3f7 Fixing incorrect macro in a detection
whose test file was updated.
2023-02-01 17:59:02 -08:00
P4T12ICK fd0c8b349f updated tags 2023-01-09 09:33:30 +01:00
P4T12ICK 5ae53c9368 Migrated all detections to v4 2023-01-03 13:42:10 +01:00
pyth0n1c 5e911193bd Merge branch 'security_updates' of https://github.com/splunk/security_content into security_updates 2022-11-02 10:05:40 -07:00
pyth0n1c 4351d385d0 Moved detection and test files from production to experimental 2022-11-02 10:02:17 -07:00
Bhavin Patel c76f6c1ce0 Update splunk_xss_in_save_table_dialog_header_in_search_page.yml 2022-11-02 09:14:58 -07:00
pyth0n1c f5eaa40534 Changed media.githubusercontent
to raw.githubusercontent links
2022-11-02 09:02:30 -07:00
Bhavin Patel 79e8b40a67 Update splunk_xss_in_save_table_dialog_header_in_search_page.yml 2022-11-02 08:40:23 -07:00
pyth0n1c 844df50ee5 Fixed format of CVE tag 2022-11-01 08:41:14 -07:00
pyth0n1c a80f89e32c Replaced index= and sourcetype= with appropriate macro. Added that macro as well. 2022-11-01 08:38:04 -07:00
pyth0n1c 689277d6ee Added a number of macros, tests, and detections in support of release of Splunk vulnerabilities and patches. 2022-11-01 08:12:14 -07:00
Michael Haag c8c64150bd updates 2022-10-03 09:20:17 -06:00
Michael Haag d359e51e9e Create okta_risk_threshold_exceeded.yml 2022-09-29 15:08:47 -06:00
Rod Soto 537c13d063 addedwords 2022-08-30 11:56:41 -07:00
d1vious b6e2ff6278 adding updated url 2022-08-16 15:01:17 -04:00
d1vious b7e1a5fe94 adding new detections 2022-08-16 11:30:24 -04:00
Kumar Sharad 4cdbe51506 model to detect risky commands 2022-07-14 16:37:47 +02:00
Kumar Sharad 28c799e829 model to detect risky commands 2022-06-29 23:45:27 +02:00
patel-bhavin cb150c258e minor edits for yml validation and test file name update 2022-06-23 15:21:30 -07:00