Commit Graph

  • 72f7bb0676 Added detection testing service results inLinux Service Started Or Enabled root 2022-01-03 10:35:34 +00:00
  • 00521f06a5 Added detection testing service results inLinux Setuid Using Setcap Utility root 2022-01-03 10:04:59 +00:00
  • 780aa81877 Update linux_setuid_using_setcap_utility.yml tccontre 2022-01-03 10:40:56 +01:00
  • 733abea5da Bump filelock from 3.4.0 to 3.4.2 dependabot[bot] 2022-01-01 23:00:54 +00:00
  • d4063a48cf Bump platformdirs from 2.4.0 to 2.4.1 dependabot[bot] 2022-01-01 23:00:51 +00:00
  • 2c803e1c6f Bump virtualenv from 20.10.0 to 20.12.1 dependabot[bot] 2022-01-01 23:00:48 +00:00
  • d7b159aea3 test: fixed a typo Arjun Khunti 2021-12-29 13:27:38 +05:30
  • 500986bfb4 Update README.md truptilangalia-crest 2021-12-28 18:00:14 +05:30
  • 9da1778b53 Update README.md truptilangalia-crest 2021-12-28 17:57:15 +05:30
  • 2f34f7d03c Merge branch 'develop' of github.com:splunk/security-content into tf23 Xiao Lin 2021-12-27 11:20:35 -08:00
  • c13428f57b Update README.md truptilangalia-crest 2021-12-27 17:10:22 +05:30
  • 8f4c7ea68f test: encoded git token Detection Testing Service 2021-12-27 16:03:28 +05:30
  • a5dcbab86c test: updated code with some minor fixes Detection Testing Service 2021-12-24 13:31:15 +05:30
  • 2723fab278 WIP P4T12ICK 2021-12-23 15:30:35 +01:00
  • e21247f2d2 linux_persist_priv_batch_2 tccontre 2021-12-23 12:31:05 +01:00
  • eb48e000a8 Updated default app loadout for splunkbase. Added splunk_ta_for_nginz, splunk_security_essentials, and ta_for_zeek. pyth0n1c 2021-12-22 14:05:55 -08:00
  • 2574fb2fea Hardcoding the branch to develop for CI testing. pyth0n1c 2021-12-22 13:19:05 -08:00
  • dc3fc8296d Added a config file to run tests against latest splunkbase apps. Also, added slightly better error output for certain types of test failures. Finally updated splunkbase app defaults in validate_args, but they are commented out for now while we use the S3 versions. pyth0n1c 2021-12-22 13:02:21 -08:00
  • f300a6c4a6 Merge branch 'splunk:develop' into test/enrich_detections truptilangalia-crest 2021-12-22 18:42:07 +05:30
  • 77f963cd11 test:updated detection-ta-mapping.yml Detection Testing Service 2021-12-22 18:30:21 +05:30
  • 0d62a0f22c Merge branch 'linux_persist_priv_batch_1' of https://github.com/splunk/security_content into linux_persist_priv_batch_1 Detection Testing Service 2021-12-22 10:54:27 +00:00
  • ae6cca1cf4 Added detection testing service results inLinux Add Files In Known Crontab Directories root 2021-12-22 10:54:26 +00:00
  • 9b3ecff018 Update linux_possible_append_command_to_at_allow_config_file.test.yml tccontre 2021-12-22 11:51:16 +01:00
  • 24431a7891 Merge branch 'linux_persist_priv_batch_1' of https://github.com/splunk/security_content into linux_persist_priv_batch_1 Detection Testing Service 2021-12-22 10:25:23 +00:00
  • d708418dd8 Added detection testing service results inLinux At Allow Config File Creation root 2021-12-22 10:25:23 +00:00
  • 9a6806ce75 Added detection testing service results inLinux At Application Execution root 2021-12-22 10:22:07 +00:00
  • b38beadde2 Added detection testing service results inLinux Edit Cron Table Parameter root 2021-12-22 10:03:26 +00:00
  • 3a68d044ef Update linux_possible_append_cronjob_entry_on_existing_cronjob_file.test.yml tccontre 2021-12-22 10:46:27 +01:00
  • 7549ae7c7b Update ssa___hiding_files_and_directories_with_attrib_exe.yml tccontre 2021-12-22 10:22:49 +01:00
  • d1c95a44ad Added detection testing service results inLinux Possible Cronjob Modification With Editor root 2021-12-22 09:02:46 +00:00
  • 05821f4303 Fixed some parts of the CI that don't give a descriptive error message in the output files when a search generates certain types of errors. For example, an error where it cannot reach the Splunk endpoint server. These are rare, but good to have. pyth0n1c 2021-12-21 14:46:44 -08:00
  • 47e155b747 Changed back to one container per GH Action Machine config with the mock option. Also, shuffling detections after they are put into a list to distribute runtime and load as much as possible. pyth0n1c 2021-12-21 14:22:33 -08:00
  • 94130345ab Branch was auto-updated. Bhavin Patel 2021-12-21 11:22:20 -08:00
  • 0ff1e78f11 Branch was auto-updated. Bhavin Patel 2021-12-21 11:22:19 -08:00
  • 5b820c2af9 Branch was auto-updated. Bhavin Patel 2021-12-21 11:22:17 -08:00
  • 930a6db140 Merge pull request #1901 from splunk/AD_Privilege_Escalation_CVE-2021-42278 Jose Enrique Hernandez 2021-12-21 14:21:54 -05:00
  • 04c526ba6d Changed the wrong line to trigger a test of everything. Trying again. pyth0n1c 2021-12-21 11:17:09 -08:00
  • 9243038c09 Added detection testing service results inSuspicious Ticket Granting Ticket Request root 2021-12-21 19:06:04 +00:00
  • 5f972f734f Re-push to test everything with 2 containers per GH Actions machine. pyth0n1c 2021-12-21 11:00:11 -08:00
  • 9ba7abd0e8 Fixed a small error. If you specified a PR number and a branch that did not exist, then it would create a branch and that would be bad. Now, when you specify a branch and a PR number, the branch MUST exist. If not, we fail and bail. pyth0n1c 2021-12-21 10:44:50 -08:00
  • bb8ae58f84 adding new detection mvelazco 2021-12-21 13:44:17 -05:00
  • 11dbcdf473 Update ssa___hiding_files_and_directories_with_attrib_exe.yml tccontre 2021-12-21 15:13:54 +01:00
  • fb087ea8b3 linux_persist_priv_batch_1 tccontre 2021-12-21 11:02:15 +01:00
  • da634d5c25 Added detection testing service results inSuspicious Kerberos Service Ticket Request root 2021-12-21 03:57:17 +00:00
  • 4631c84a60 updating logic mvelazco 2021-12-20 22:38:27 -05:00
  • 122d403d6c Added detection testing service results inSuspicious Kerberos Service Ticket Request root 2021-12-21 03:34:17 +00:00
  • d5d7e0ce1a Update suspicious_computer_account_name_change.yml mvelazco 2021-12-20 22:11:09 -05:00
  • 6fa0f9b30b adding new detection mvelazco 2021-12-20 22:08:19 -05:00
  • 653a7755e8 Added detection testing service results inSuspicious Computer Account Name Change root 2021-12-20 22:50:20 +00:00
  • 63555bc531 Added some more robust error handling to the high level test runner. It looks like we were getting errors pulling the image from docker hub - was it down... pyth0n1c 2021-12-20 14:45:01 -08:00
  • d4aae32b3d Removed Python 2 which was previously used for splunk packaging toolkit. Replaced with python3 pyth0n1c 2021-12-20 14:26:57 -08:00
  • af31bdb3ec updating observable mvelazco 2021-12-20 17:20:58 -05:00
  • 243e60a3cc minor fix mvelazco 2021-12-20 17:04:58 -05:00
  • 264dbfb7f4 Fixed up and error that could occur where the environment is not properly set up if the users requested PERSIST_SECURITY_CONTENT, but the directory did not exist. Also fixed the default argument for this on GitHub Actions., pyth0n1c 2021-12-20 13:58:58 -08:00
  • 82a4a63093 creating analytic story and first detection mvelazco 2021-12-20 16:58:34 -05:00
  • d26032b912 Updated the github_actions config with S3 binary paths.Updated the default args to include web and experimental as possible folders with Web being a default. pyth0n1c 2021-12-20 13:38:51 -08:00
  • 0e26dc76ff Changed so that we no longer start a container if we know that we will not have a test for it. For example, if we try to start 4 containers by have only 2 tests at the beginning we will only start 2 containers. This saves a lot of startup time and resources. There is a descriptive printout for this as well. Also, bumped the maximum startup time for 6 minutes to 10 minutes. This, combined with the system info from the previous commit should let us determine if we can bump the number of containers per GitHub Actions VM from 1 to 2 or more. pyth0n1c 2021-12-20 13:17:46 -08:00
  • 2a15f8b170 Branch was auto-updated. Bhavin Patel 2021-12-20 12:42:51 -08:00
  • d60bcec3a4 Branch was auto-updated. Bhavin Patel 2021-12-20 12:42:50 -08:00
  • 59b9068998 Merge pull request #1894 from splunk/Fix_Log4j_detection mvelazco 2021-12-20 15:42:26 -05:00
  • 7230b5c63d Print out some system usage information on each update. This will help users dianose if their systems are overburdend and also helps us figure out what the appropriate number of containers to run on cloud infrastructure, like GitHub Actions, may be without logging directly into the machine doing the testing. In some cases, we can't log into those machines by design. If you're running tests at home, you can also just listen to the volume of your computer's fans. pyth0n1c 2021-12-20 12:02:11 -08:00
  • cc8113ec86 Fixed output of manifest for detection_failure_manifest.json. Previously, it contained mostly default settings and most notably did not container the proper apps configuration. Also updated a few documentation strings. pyth0n1c 2021-12-20 08:34:54 -08:00
  • e1261b36ca Update ssa___hiding_files_and_directories_with_attrib_exe.yml tccontre 2021-12-20 17:18:44 +01:00
  • b61311f72b new_ssa_info_sabotage tccontre 2021-12-20 13:44:02 +01:00
  • f144fc5df3 new_ssa_info_sabotage tccontre 2021-12-20 12:37:12 +01:00
  • c53510c42a new_ssa_info_sabotage tccontre 2021-12-20 12:31:21 +01:00
  • 9cf834a5f1 new_ssa_info_sabotage tccontre 2021-12-20 12:25:34 +01:00
  • d6581e728b new_ssa_info_sabotage tccontre 2021-12-20 12:21:04 +01:00
  • cdab1e8c74 new_ssa_ifo_sabotage tccontre 2021-12-20 12:17:04 +01:00
  • 76364bf1c0 Updated the default configuration to use attack_range apps stored on S3. Pointed at the PATCHED linux_sysmon. Added a slight delay in between starts of containers for performance reasons. Enabled better handling and ability to download http_path local apps to a folder instead of passing them in as string for the container to download. pyth0n1c 2021-12-17 20:06:42 -08:00
  • 2ebb9f8c40 Updated Log4shell hunt mhaag-spl 2021-12-17 11:43:40 -07:00
  • c8082984f0 A large number of changes and fixes to make everything smoother. The largest differences are improving detection of containers that take too long to start (or that crash while) they are starting by adding a timeout. That timeout is set to 360 seconds and might need to be tuned in the future to a larger number since this was tested on a fast machine with fast network. The other large change is an initial pass at updating and committing detections that have passed the test back to the repo. This still needs a lot of testing and refinement. pyth0n1c 2021-12-17 10:13:49 -08:00
  • 422a0f5b9d add builder design pattern instead of repository P4T12ICK 2021-12-17 18:08:12 +01:00
  • 9cd2e9c0ab Merge branch 'develop' of github.com:splunk/security-content into tf23 Xiao Lin 2021-12-17 08:41:39 -08:00
  • d7a71ec90b pex-43: add sse filtered detections Danny Leung 2021-12-16 15:04:57 -08:00
  • 6e12b4f2ad Branch was auto-updated. Bhavin Patel 2021-12-16 12:55:23 -08:00
  • 3eb630b220 Branch was auto-updated. Bhavin Patel 2021-12-16 12:55:22 -08:00
  • eff3306f89 Merge pull request #1897 from splunk/ssa_descriptive_branch_name peter 2021-12-16 14:55:05 -06:00
  • 55fd63fe2f Caps fix peter-cg 2021-12-16 14:53:54 -06:00
  • 3aa223a948 Adding sourcetype to sysproc_unexpected_location test peter-cg 2021-12-16 10:44:05 -06:00
  • ba83011191 Adding addl humvee runner and fixing macro def peter-cg 2021-12-16 10:42:01 -06:00
  • 4a1b55931b WIP P4T12ICK 2021-12-16 09:42:36 +01:00
  • 366dd6bf78 Merge branch 'develop' of github.com:splunk/security-content into tf23 Xiao Lin 2021-12-15 17:13:17 -08:00
  • 46c4c874d3 Branch was auto-updated. Bhavin Patel 2021-12-15 15:52:05 -08:00
  • ab3eb94c83 Branch was auto-updated. Bhavin Patel 2021-12-15 15:52:04 -08:00
  • 7431dabd65 Merge pull request #1896 from splunk/doc_updates pyth0n1c 2021-12-15 15:51:51 -08:00
  • 2f8de77b7c Docs Update for playbook changes Lou Stella 2021-12-15 17:42:47 -06:00
  • 72a04655d0 Branch was auto-updated. Bhavin Patel 2021-12-15 15:20:37 -08:00
  • ae3484780a Branch was auto-updated. Bhavin Patel 2021-12-15 15:20:36 -08:00
  • 9c21e7f869 Merge pull request #1895 from splunk/The_Day_After_The_Day_After_log4shell Lou Stella 2021-12-15 17:20:18 -06:00
  • 01bc5757b6 removed married parent playbook Lou Stella 2021-12-15 17:06:02 -06:00
  • fbf15c3424 Final copy from phantomcyber/playbooks Lou Stella 2021-12-15 16:58:31 -06:00
  • 872ea4b55c Standardized type Lou Stella 2021-12-15 15:52:40 -06:00
  • 496f97a0ee Added detection testing service results inOutbound Network Connection from Java Using Default Ports root 2021-12-15 21:19:25 +00:00
  • ca0aaa46c5 divorced parent playbook Lou Stella 2021-12-15 15:03:21 -06:00
  • 3bb9712286 updating detection to use data models mvelazco 2021-12-15 15:53:06 -05:00
  • 337e077224 Merge pull request #1892 from splunk/bug_with_playbook_detection Lou Stella 2021-12-15 14:16:09 -06:00
  • 0df62338c9 bug with playbooks detection page d1vious 2021-12-15 15:01:27 -05:00
  • 9eea4ded41 It's Raining Haags mhaag-spl 2021-12-15 13:01:04 -07:00
  • 8566c56a0e Merge pull request #1889 from splunk/minor_api_gen_bug Jose Enrique Hernandez 2021-12-15 14:56:09 -05:00