Commit Graph

  • bdedd41b34 removing bad reference, dead link v1.0.50 divious1 2020-02-07 14:15:32 -05:00
  • 456f68131d Merge pull request #355 from splunk/jwindley-splunk/T1164 rvaldez617 2020-02-07 12:07:25 -07:00
  • 6caea176a6 corrected a few bugs with the spec divious1 2020-02-07 13:51:31 -05:00
  • 096234f417 Merge pull request #354 from splunk/fix_convert_bug_issue_343 Bhavin Patel 2020-02-07 10:38:14 -08:00
  • 6b2c9e4172 Merge pull request #327 from splunk/supicious_email_updates Bhavin Patel 2020-02-07 10:35:35 -08:00
  • 556efc4a78 Merge pull request #325 from splunk/dns_query_updates Bhavin Patel 2020-02-07 10:33:05 -08:00
  • 3336663726 fixes issue 343 divious1 2020-02-07 13:32:56 -05:00
  • ff7a6fef59 update mod dates of stories: bpatel 2020-02-07 10:30:32 -08:00
  • 77ca56ce19 Merge pull request #347 from splunk/CRL-1725_Processes.parent_process.Correction Bhavin Patel 2020-02-07 10:28:07 -08:00
  • 6896cf9b58 removing incorrect mitre id bpatel 2020-02-07 10:27:21 -08:00
  • f682a22461 Merge branch 'develop' into CRL-1725_Processes.parent_process.Correction Bhavin Patel 2020-02-07 10:18:17 -08:00
  • 1c97742fed macros node bpatel 2020-02-07 10:17:14 -08:00
  • 98195728fc Merge pull request #324 from splunk/first_time_seen_cmd_updates Bhavin Patel 2020-02-07 10:07:18 -08:00
  • 0432161688 Merge pull request #326 from splunk/smb_detection_updates Bhavin Patel 2020-02-07 10:05:44 -08:00
  • 44761d1106 Merge pull request #348 from splunk/CRL-1723 Bhavin Patel 2020-02-07 10:04:22 -08:00
  • 7d61248099 Merge branch 'develop' into CRL-1725_Processes.parent_process.Correction Bhavin Patel 2020-02-07 10:03:49 -08:00
  • 382d0d719d Merge pull request #351 from splunk/issue_336 Jose Enrique Hernandez 2020-02-07 13:02:48 -05:00
  • 9849b76aff Merge branch 'develop' into first_time_seen_cmd_updates Bhavin Patel 2020-02-07 10:02:26 -08:00
  • f307274f95 story mod updates bpatel 2020-02-07 10:00:28 -08:00
  • 11e67aefb4 Merge pull request #352 from splunk/fixing_external_pr_ci Bhavin Patel 2020-02-07 09:54:05 -08:00
  • 108865f3b5 WIP: spec 3_0 POC Patrick Bareiss 2020-02-07 13:36:50 +01:00
  • 08d7ba3900 Merge pull request #346 from splunk/CRL-1726_lookups_csv_ci Jose Enrique Hernandez 2020-02-06 23:49:33 -05:00
  • 345858c83b updating docs and package bits [ci skip] research bot 2020-02-06 22:47:39 +00:00
  • 537f51434e Merge branch 'develop' of github.com:splunk/security-content into develop Rico Valdez 2020-02-05 16:28:45 -07:00
  • ac7bd7cfee changed the file name of the .csv file and updated the associated yml file Rico Valdez 2020-02-05 16:27:57 -07:00
  • 7d33b5c36c Merge pull request #350 from splunk/issue_323 CRL-1721_fix_lookup_name_mismatch rvaldez617 2020-02-05 16:06:17 -07:00
  • 2fb2d880f0 Merge pull request #344 from smalloy2/develop Jose Enrique Hernandez 2020-02-04 17:07:13 -05:00
  • caa5437fad fixing issue with seans PR divious1 2020-02-04 16:31:56 -05:00
  • dbbc58fb43 renaming lookup file in package/lookup bpatel 2020-02-04 09:46:22 -08:00
  • 8b0f74c34d updating mod dates and version bpatel 2020-02-04 09:21:52 -08:00
  • 92768472e0 updating files as per Dons feedback bpatel 2020-02-04 09:15:39 -08:00
  • e134fb24c8 Merge pull request #349 from splunk/dependabot/pip/nodeenv-1.3.5 lookup_cleanup dependabot-preview[bot] 2020-02-04 08:35:32 +00:00
  • 6ac73bb183 Bump nodeenv from 1.3.4 to 1.3.5 dependabot-preview[bot] 2020-02-04 08:31:13 +00:00
  • e18a1402f4 CRL-1723 : corrected field name in SPL Filesystem.filepath [which does not exist] to Filesystem.file_path. Jason Brewer 2020-02-03 21:00:55 -08:00
  • c06702a7f4 CRL-1725 - Added update to detections.spec.json to accomodate a new output entity parent_process_name. Jason Brewer 2020-02-03 15:32:12 -08:00
  • 346709b58f CRL-1725 - Changed prohibited_apps_spawning_cmdprompt.yml to use parent_process_name as entity. Changed supress field to add user. Bumped detection version number and story version numbers on stories/suspicious_cmd_line_executions.yml and stories/suspicious_mshta_activities.yml. Jason Brewer 2020-02-03 15:24:49 -08:00
  • 667ac3ffa3 Merge pull request #345 from splunk/CRL-1727_detection_bug_issue_343 Jose Enrique Hernandez 2020-02-03 17:36:49 -05:00
  • 6730dbefd8 adding logic to copy over lookups divious1 2020-02-03 17:35:06 -05:00
  • 2b6db17c99 fixing issue #343 divious1 2020-02-03 17:10:15 -05:00
  • 6a3c1d4988 Making color contrast changes for 508 compliance seanmalloy 2020-02-03 10:31:13 -08:00
  • 70a3aa3841 Merge pull request #342 from splunk/dependabot/pip/jinja2-2.11.1 dependabot-preview[bot] 2020-01-30 18:28:52 +00:00
  • a696b13961 Bump jinja2 from 2.11.0 to 2.11.1 dependabot-preview[bot] 2020-01-30 18:23:29 +00:00
  • 5e88f84ba5 Merge pull request #341 from splunk/dependabot/pip/pre-commit-2.0.1 dependabot-preview[bot] 2020-01-30 02:14:17 +00:00
  • d0d0772679 Bump pre-commit from 2.0.0 to 2.0.1 dependabot-preview[bot] 2020-01-30 02:09:24 +00:00
  • 90cdbe7ef0 Merge pull request #340 from splunk/dependabot/pip/more-itertools-8.2.0 dependabot-preview[bot] 2020-01-29 13:09:31 +00:00
  • 0b110b541a Bump more-itertools from 8.1.0 to 8.2.0 dependabot-preview[bot] 2020-01-29 13:05:09 +00:00
  • c0ef423eef Merge pull request #339 from splunk/dependabot/pip/importlib-metadata-1.5.0 dependabot-preview[bot] 2020-01-29 05:15:01 +00:00
  • 503dbe5e40 Bump importlib-metadata from 1.4.0 to 1.5.0 dependabot-preview[bot] 2020-01-29 05:10:30 +00:00
  • a7baf3fcc2 Merge pull request #338 from splunk/dependabot_automerge Jose Enrique Hernandez 2020-01-28 22:24:32 -05:00
  • d4fbe656d6 adding github workflow to auto approve dependabot PRs that passed CI this is to circumvent branch protection divious1 2020-01-28 22:12:14 -05:00
  • 94664241b6 Merge pull request #337 from splunk/dependabot/pip/pre-commit-2.0.0 dependabot-preview[bot] 2020-01-29 03:07:41 +00:00
  • 992eedfecc Bump pre-commit from 1.21.0 to 2.0.0 dependabot-preview[bot] 2020-01-29 02:51:57 +00:00
  • 5d49e31f16 Merge pull request #328 from splunk/dependabot/pip/identify-1.4.11 dependabot-preview[bot] 2020-01-29 00:35:23 +00:00
  • 8caa037cc6 Merge pull request #329 from splunk/dependabot/pip/zipp-2.1.0 dependabot-preview[bot] 2020-01-28 21:38:59 +00:00
  • b155dd6d4b Bump identify from 1.4.10 to 1.4.11 dependabot-preview[bot] 2020-01-28 16:13:32 +00:00
  • 453183cbff Merge pull request #332 from splunk/dependabot/pip/jinja2-2.11.0 dependabot-preview[bot] 2020-01-28 16:12:24 +00:00
  • cf78269d29 Merge pull request #335 from splunk/dependabot_automerge Jose Enrique Hernandez 2020-01-28 11:06:49 -05:00
  • 8b3447c016 merge all divious1 2020-01-28 11:06:24 -05:00
  • 78bffbf8d5 Merge pull request #334 from splunk/dependabot_automerge Jose Enrique Hernandez 2020-01-28 10:29:56 -05:00
  • d9f7c09eac no need to specify path divious1 2020-01-28 10:29:16 -05:00
  • 23174e7c99 Merge pull request #330 from splunk/dependabot_automerge Jose Enrique Hernandez 2020-01-28 10:21:42 -05:00
  • 7bec484354 Bump jinja2 from 2.10.3 to 2.11.0 dependabot-preview[bot] 2020-01-28 14:13:11 +00:00
  • 656b66cd71 Merge pull request #331 from splunk/develop Bhavin Patel 2020-01-27 14:00:48 -08:00
  • 0da53bb353 Bump zipp from 2.0.0 to 2.1.0 dependabot-preview[bot] 2020-01-27 14:13:08 +00:00
  • c92d097eac updating boiler plate, detection not working out of box against T1193 but this may be due to error loading lookup table for supicious file extensions. jzsplunk 2020-01-27 03:04:55 -08:00
  • d4aa6bc9ea update smb related content. The outbound_smb_connections detection works out of the box against attack ID T1110 when testing in the attack range. jzsplunk 2020-01-27 02:33:26 -08:00
  • b762034a4b update version info and macros, attack range freezing on testing detection against attack ID T1071 so query is untested against atomic red team test for now jzsplunk 2020-01-27 01:44:53 -08:00
  • 6406cfbc32 update version info, add macros for first time seen cmd line detection jzsplunk 2020-01-27 01:08:53 -08:00
  • d73c378321 automatically merge deps divious1 2020-01-24 18:16:26 -08:00
  • 814c7bb023 updating docs and package bits [ci skip] research bot 2020-01-23 21:58:19 +00:00
  • f2702a6e10 Merge pull request #322 from splunk/CRL-1720 v1.0.49 Bhavin Patel 2020-01-23 13:48:36 -08:00
  • 9e6becda1f adding definitions bpatel 2020-01-23 13:31:43 -08:00
  • cbd0c380d3 updating docs and package bits [ci skip] research bot 2020-01-23 01:33:05 +00:00
  • 2fd12b9155 Merge pull request #320 from splunk/don_young_bug Jose Enrique Hernandez 2020-01-22 17:26:54 -08:00
  • 75485ef666 Merge pull request #316 from splunk/CRL-1717_addMacroDefinitionsWhereMissing Bhavin Patel 2020-01-22 14:59:44 -08:00
  • dd5b1ee344 Merge pull request #319 from splunk/dns_hijack_story_update Bhavin Patel 2020-01-22 14:58:40 -08:00
  • 03f4b9a8b7 Merge pull request #309 from splunk/dependabot/pip/more-itertools-8.1.0 dependabot-preview[bot] 2020-01-22 21:31:37 +00:00
  • 0ba1b4c30d fixing mispelling divious1 2020-01-22 13:31:09 -08:00
  • c3b04375c9 CRL-1719 - Fixing reference to https://attack.mitre.org/wiki/Privilege_Escalation >>> https://attack.mitre.org/tactics/TA0004/ Jason Brewer 2020-01-22 12:17:24 -08:00
  • 38b84113bf Merge pull request #318 from splunk/CRL-1495-update_share_creation_and_deletion Bhavin Patel 2020-01-22 09:19:43 -08:00
  • 0cef2e73b1 Merge pull request #315 from splunk/CRL-1716-FixPowerShellObfusc Bhavin Patel 2020-01-22 09:18:42 -08:00
  • 5d6ef5ce60 renaming files bpatel 2020-01-22 09:14:51 -08:00
  • b85543e0b5 CRL-1717 - Addressing comments by removing unnecessary output_filter macros from investigation searches and removing references to those in the investigation definitions. Jason Brewer 2020-01-22 08:40:30 -08:00
  • b62ce205b8 CRL-1716 - Updating per code review requests. Adding output macro file and reference within the detection search. Jason Brewer 2020-01-22 08:26:16 -08:00
  • f196179eee Merge pull request #317 from splunk/dependabot/pip/zipp-2.0.0 dependabot-preview[bot] 2020-01-22 02:17:12 +00:00
  • bfa7317668 removing comments Jose Enrique Hernandez 2020-01-21 18:14:24 -08:00
  • 3bf8cf26de updating the manifest to reflect correct details bpatel 2020-01-21 18:05:33 -08:00
  • 14f54a12e8 removing incorrect macro file bpatel 2020-01-21 17:29:55 -08:00
  • bccc500554 Bump more-itertools from 8.0.2 to 8.1.0 dependabot-preview[bot] 2020-01-21 19:44:25 +00:00
  • 593798dfb3 Merge pull request #304 from splunk/dependabot/pip/nodeenv-1.3.4 dependabot-preview[bot] 2020-01-21 19:43:03 +00:00
  • c6a904b36f Merge pull request #314 from splunk/CRL-1712_netsh_abuse Jose Enrique Hernandez 2020-01-21 11:42:42 -08:00
  • 7b976f25f7 Update investigate_user_activities_in_all_cloud_region_output_filter.yml Jose Enrique Hernandez 2020-01-21 11:34:38 -08:00
  • 11a1b68979 bumping version Jose Enrique Hernandez 2020-01-21 11:28:26 -08:00
  • c007d41844 remove comments to get search working, clean up detection jzsplunk 2020-01-21 02:23:15 -08:00
  • 82d00df489 Drop comments to get search working, change file name to reflect generic case of detecting any type of share deletion or creation. jzsplunk 2020-01-21 02:07:30 -08:00
  • 6eed922214 testing commented search jzsplunk 2020-01-21 01:58:30 -08:00
  • 0a006f7b04 Add IDEA IDE ignores jzsplunk 2020-01-21 00:51:29 -08:00
  • 2f81672bbb Bump zipp from 1.0.0 to 2.0.0 dependabot-preview[bot] 2020-01-20 14:12:06 +00:00
  • 0ac15cb563 updated fields and added macros and lookup entries divious1 2020-01-19 21:37:45 -05:00
  • 8eddded385 Bump nodeenv from 1.3.3 to 1.3.4 dependabot-preview[bot] 2020-01-18 02:47:21 +00:00