Commit Graph

  • 374fd54c26 Update and rename windows_modify_registry_disable_windows_security_center_notifs.yml to windows_modify_registry_disable_windows_security_center_notif.yml tccontre 2022-06-23 15:23:59 +02:00
  • 71e4bd8ebf Update windows_modify_registry_disable_toast_notifications.test.yml tccontre 2022-06-23 13:57:11 +02:00
  • 0478d292f4 Rename windows_modify_registry_suppress_win_defender_notifications.yml to windows_modify_registry_suppress_win_defender_notifs.yml tccontre 2022-06-23 13:36:47 +02:00
  • a259be3c32 azorult-bomb tccontre 2022-06-23 13:36:06 +02:00
  • 8321cf9c1d Update and rename windows_modify_registry_disable_windows_security_center_notifications.test.yml to windows_modify_registry_disable_windows_security_center_notifs.test.yml tccontre 2022-06-23 13:35:02 +02:00
  • 2e4eac9eaa Update windows_modify_registry_suppress_win_defender_notifs.test.yml tccontre 2022-06-23 13:28:26 +02:00
  • c4f248b11b azorult-bomb tccontre 2022-06-23 12:38:07 +02:00
  • 9d9b782b4e azorult-bomb tccontre 2022-06-23 12:27:43 +02:00
  • d858cd6875 included the --skip_enrichment flag pyth0n1c 2022-06-22 16:06:29 -07:00
  • 4f6d30dc51 Fixes to needs dependencies after updating job names pyth0n1c 2022-06-22 15:58:21 -07:00
  • 130f5e3c99 Simplified the build-and-validate workflow, collapsing several jobs into one. pyth0n1c 2022-06-22 15:49:56 -07:00
  • 28eefb325d adding 2 new detections for kerberoasting gowthamarajr 2022-06-22 17:35:37 -04:00
  • a74ebee88f Added the --skip_enrichment option to the contentctl tool. This can save a huge amount of time when generating an app. Also added a progress meter when the documentation is being generated. Finally, correctly initialized the default values of some class member fields in order to get all the contentctl steps working. pyth0n1c 2022-06-22 13:44:17 -07:00
  • 7ef25a98ec updating docs and package bits [ci skip] research bot 2022-06-22 17:56:19 +00:00
  • 7328ea1aa3 model to detect risky commands Kumar Sharad 2022-06-22 19:34:06 +02:00
  • e53e9cf232 Branch was auto-updated. pyth0n1c 2022-06-22 10:19:36 -07:00
  • af269b1bce Branch was auto-updated. pyth0n1c 2022-06-22 10:19:35 -07:00
  • ad2ae86220 Branch was auto-updated. pyth0n1c 2022-06-22 10:19:35 -07:00
  • 1033ae41ae Branch was auto-updated. pyth0n1c 2022-06-22 10:19:34 -07:00
  • cda681eb8b Merge pull request #2260 from splunk/DetectionFixes v3.43.1 Jose Enrique Hernandez 2022-06-22 13:19:16 -04:00
  • 6fa400f4f9 Update azorult.yml tccontre 2022-06-22 18:50:08 +02:00
  • 26d6664e7c model to detect risky commands Kumar Sharad 2022-06-22 17:41:34 +02:00
  • c35c786b09 model to detect risky commands Kumar Sharad 2022-06-22 17:39:17 +02:00
  • defa7b1bd0 model to detect risky commands Kumar Sharad 2022-06-22 16:57:52 +02:00
  • 4ace852c0b azorult-sfx-package tccontre 2022-06-22 16:55:51 +02:00
  • 629e5c2e5e model to detect risky commands Kumar Sharad 2022-06-22 16:47:07 +02:00
  • de7c604cd2 model to detect risky commands Kumar Sharad 2022-06-22 16:45:48 +02:00
  • f067ded253 model to detect risky commands Kumar Sharad 2022-06-22 16:38:22 +02:00
  • fe84f9fbf9 model to detect risky commands Kumar Sharad 2022-06-21 17:47:31 +02:00
  • 1120d578e5 model to detect risky commands Kumar Sharad 2022-06-21 17:43:49 +02:00
  • 96652af2bf model to detect risky commands Kumar Sharad 2022-06-21 15:39:48 +02:00
  • 67f35bba10 model to detect risky commands Kumar Sharad 2022-06-21 14:40:19 +02:00
  • 0de66753a1 Branch was auto-updated. pyth0n1c 2022-06-22 07:17:51 -07:00
  • 8d67c4f0a2 Branch was auto-updated. pyth0n1c 2022-06-22 07:17:50 -07:00
  • afc1e9afeb Branch was auto-updated. pyth0n1c 2022-06-22 07:17:49 -07:00
  • b6fbbcfe7c Branch was auto-updated. pyth0n1c 2022-06-22 07:17:48 -07:00
  • 52fa6467a9 Updated per customer feedback Lou Stella 2022-06-22 09:17:14 -05:00
  • a7868fc25e Merge branch 'azorult-sfx-package' of github.com:splunk/security_content into azorult-sfx-package tccontre 2022-06-22 15:04:35 +02:00
  • 07ef9a215e azorult-sfx-package tccontre 2022-06-22 15:04:13 +02:00
  • d2c419e596 azorult-bomb tccontre 2022-06-22 13:31:48 +02:00
  • 54203d6858 Fixing detection to conform to new sysmon behavior. pyth0n1c 2022-06-21 17:21:30 -07:00
  • b73ea9e5ae Added another custom_index to a test file that was failing because it did not have one. pyth0n1c 2022-06-21 16:59:44 -07:00
  • ff0a57e526 Branch was auto-updated. pyth0n1c 2022-06-21 16:45:18 -07:00
  • 70e9066273 Branch was auto-updated. pyth0n1c 2022-06-21 16:45:17 -07:00
  • ee7dd5f7e9 Branch was auto-updated. pyth0n1c 2022-06-21 16:45:16 -07:00
  • 07a13ca16b Merge pull request #2240 from splunk/more-defense-evasion Bhavin Patel 2022-06-21 16:44:59 -07:00
  • 8d04037125 Update windows_impair_defenses_disable_win_defender_auto_logging.yml Bhavin Patel 2022-06-21 16:28:05 -07:00
  • 35908f5a30 Removed user from the stats call of this search since it does not exist and the field userName does exist. And it is likely to have captured the same data. pyth0n1c 2022-06-21 16:25:20 -07:00
  • 0634828d94 Branch was auto-updated. pyth0n1c 2022-06-21 16:07:18 -07:00
  • cc03d129c3 Branch was auto-updated. pyth0n1c 2022-06-21 16:07:17 -07:00
  • 62ed8fe817 Branch was auto-updated. pyth0n1c 2022-06-21 16:07:16 -07:00
  • e225958248 Branch was auto-updated. pyth0n1c 2022-06-21 16:07:15 -07:00
  • 471ee2b8a5 Merge pull request #2220 from splunk/inspired_2194 Jose Enrique Hernandez 2022-06-21 19:06:53 -04:00
  • b5c79b6db8 Added a custom index for a detection test that was created when custom_index support did not yet exist. pyth0n1c 2022-06-21 15:53:26 -07:00
  • cf7f30111e Branch was auto-updated. pyth0n1c 2022-06-21 15:47:25 -07:00
  • 88ce513e8e Branch was auto-updated. pyth0n1c 2022-06-21 15:47:24 -07:00
  • 6e989d1e07 Branch was auto-updated. pyth0n1c 2022-06-21 15:47:23 -07:00
  • d231e4e7fd Branch was auto-updated. pyth0n1c 2022-06-21 15:47:22 -07:00
  • 349551a98f Branch was auto-updated. inspired_2194 pyth0n1c 2022-06-21 15:47:21 -07:00
  • 7f38d4e78e Merge pull request #2252 from splunk/fixing_incorrect_story Bhavin Patel 2022-06-21 15:47:05 -07:00
  • 7816778eae Removed the field "user" from the stats line. It does not appear to exist in the raw data and is not pulled into any field(s). However, there is a field called userName which, presumably, represents the same data. pyth0n1c 2022-06-21 15:45:00 -07:00
  • 056969eaae Branch was auto-updated. pyth0n1c 2022-06-21 15:28:42 -07:00
  • d671db062d Branch was auto-updated. pyth0n1c 2022-06-21 15:28:41 -07:00
  • b44da42de6 Branch was auto-updated. pyth0n1c 2022-06-21 15:28:40 -07:00
  • 6616463196 Branch was auto-updated. pyth0n1c 2022-06-21 15:28:39 -07:00
  • 6cbace8412 Branch was auto-updated. pyth0n1c 2022-06-21 15:28:38 -07:00
  • 72cf29295c Branch was auto-updated. pyth0n1c 2022-06-21 15:28:37 -07:00
  • e470e2b6d8 Merge pull request #2257 from splunk/2253_fix Jose Enrique Hernandez 2022-06-21 18:28:11 -04:00
  • aa228e84be hunting patel-bhavin 2022-06-21 14:55:19 -07:00
  • d5d0868005 merge from develop patel-bhavin 2022-06-21 14:53:25 -07:00
  • de30c530eb Branch was auto-updated. pyth0n1c 2022-06-21 14:46:29 -07:00
  • 25e4a180b1 Branch was auto-updated. pyth0n1c 2022-06-21 14:46:28 -07:00
  • 88f26544e2 Branch was auto-updated. pyth0n1c 2022-06-21 14:46:26 -07:00
  • e57a4a33b3 Branch was auto-updated. pyth0n1c 2022-06-21 14:46:25 -07:00
  • c42c8acce2 Branch was auto-updated. pyth0n1c 2022-06-21 14:46:22 -07:00
  • 1f897f43c0 Branch was auto-updated. pyth0n1c 2022-06-21 14:46:20 -07:00
  • 6fc1b95369 Merge pull request #2258 from splunk/properly_detected_failed_attack_data_downloads Bhavin Patel 2022-06-21 14:46:03 -07:00
  • 26f6bbfc92 Adding the URL_TOOLBOX app to the application baseline. pyth0n1c 2022-06-21 14:29:11 -07:00
  • 6554d4a42b Moved ssa___ test file from the tests/network directory to the tests/experimental/endpoint directory because that's where the corresponding detection resides. pyth0n1c 2022-06-21 13:59:50 -07:00
  • 5762b4e373 Updated the app baseline as well as the python code for generating the default config. Also updated the print behavior for when files are downloaded. App baseline is now current, and files are hosted on S3, as of 06/21/2022. pyth0n1c 2022-06-21 13:53:26 -07:00
  • 575cd80e01 Updated observable & asset_type Lou Stella 2022-06-21 15:17:25 -05:00
  • 6b06ab718b Fixing a link to a dataset that has been moved. pyth0n1c 2022-06-21 13:13:50 -07:00
  • e681b766c2 Fixing field name Lou Stella 2022-06-21 14:59:48 -05:00
  • c98d7b6855 Fix an issue where trying to download a file from attack_data that returns a 404 fails too late in the process, giving a nondescriptive error message and resulting in a bad filename being included in the detection failure manifest. pyth0n1c 2022-06-21 12:52:32 -07:00
  • 85f4f107a3 Changed to anomaly Lou Stella 2022-06-21 14:45:43 -05:00
  • a92a6f2546 map filter patel-bhavin 2022-06-21 12:24:04 -07:00
  • 8ca9ac7b57 adding urltoolbox and spl updates patel-bhavin 2022-06-21 12:05:52 -07:00
  • 2ea683be87 Merge branch 'develop' into inspired_2194 patel-bhavin 2022-06-21 11:04:27 -07:00
  • 7bb299490f model to detect risky commands Kumar Sharad 2022-06-21 17:47:31 +02:00
  • f45aadfb8e model to detect risky commands Kumar Sharad 2022-06-21 17:43:49 +02:00
  • 951517fc63 WIP P4T12ICK 2022-06-21 16:30:00 +02:00
  • 8228c36d18 model to detect risky commands Kumar Sharad 2022-06-21 15:39:48 +02:00
  • dc22c28425 azorult-sfx-package tccontre 2022-06-21 15:08:26 +02:00
  • 693ee6c03d model to detect risky commands Kumar Sharad 2022-06-21 14:40:19 +02:00
  • 53bc5dcda4 fixing incorrect story pointer d1vious 2022-06-20 16:33:35 -04:00
  • 79e7a23cd8 azorult-sfx-package tccontre 2022-06-20 16:40:54 +02:00
  • 2cf31f78d7 azorult-sfx-package tccontre 2022-06-20 16:12:39 +02:00
  • 56394444ce fix mhaag-spl 2022-06-17 13:09:37 -06:00
  • 2788e8e63c path fix mhaag-spl 2022-06-17 10:22:24 -06:00
  • 9a25da4387 T1218.007 - MSIExec mhaag-spl 2022-06-17 09:36:34 -06:00