############# # Automatically generated by generator.py in splunk/security_content # On Date: 2021-12-15T02:51:23 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# [aws_cloudwatchlogs_eks] definition = sourcetype="aws:cloudwatchlogs:eks" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [aws_config] definition = sourcetype=aws:config description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [aws_description] definition = sourcetype="aws:description" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [aws_ecr_users] definition = userName IN (user) description = specify the user allowed to push Images to AWS ECR. [aws_s3_accesslogs] definition = sourcetype=aws:s3:accesslogs description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [aws_securityhub_finding] definition = sourcetype="aws:securityhub:finding" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [aws_securityhub_firehose] definition = sourcetype="aws:securityhub:firehose" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [brand_abuse_dns] definition = lookup update=true brandMonitoring_lookup domain as query OUTPUT domain_abuse | search domain_abuse=true description = This macro limits the output to only domains that are in the brand monitoring lookup file [brand_abuse_email] definition = lookup update=true brandMonitoring_lookup domain as src_user OUTPUT domain_abuse | search domain_abuse=true description = This macro limits the output to only domains that are in the brand monitoring lookup file [brand_abuse_web] definition = lookup update=true brandMonitoring_lookup domain as urls OUTPUT domain_abuse | search domain_abuse=true description = This macro limits the output to only domains that are in the brand monitoring lookup file [circleci] definition = sourcetype=circleci description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [cisco_networks] definition = eventtype=cisco_ios description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [cloud_api_calls_from_previously_unseen_user_roles_activity_window] definition = "-70m@m" description = Use this macro to determine how far back you should be checking for new commands from user roles [cloudtrail] definition = sourcetype=aws:cloudtrail description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [cloudwatch_eks] definition = sourcetype="aws:cloudwatchlogs:eks" description = customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environmnent. [cloudwatch_vpc] definition = sourcetype=aws:cloudwatchlogs:vpcflow description = customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent. [cloudwatchlogs_vpcflow] definition = sourcetype=aws:cloudwatchlogs:vpcflow description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [dynamic_dns_providers] definition = lookup update=true dynamic_dns_providers_default dynamic_dns_domains as query OUTPUTNEW isDynDNS_default | lookup update=true dynamic_dns_providers_local dynamic_dns_domains as query OUTPUTNEW isDynDNS_local| eval isDynDNS = coalesce(isDynDNS_default, isDynDNS_local)|fields - isDynDNS_default, isDynDNS_local| search isDynDNS=True description = This macro limits the output of the query field to dynamic dns domains. It looks up the domains in a file provided by Splunk and one intended to be updated by the end user. [dynamic_dns_web_traffic] definition = lookup update=true dynamic_dns_providers_default dynamic_dns_domains as url OUTPUTNEW isDynDNS_default | lookup update=true dynamic_dns_providers_local dynamic_dns_domains as url OUTPUTNEW isDynDNS_local| eval isDynDNS = coalesce(isDynDNS_default, isDynDNS_local)|fields - isDynDNS_default, isDynDNS_local| search isDynDNS=True description = This is a description [ec2_modification_api_calls] definition = (eventName=AssociateAddress OR eventName=AssociateIamInstanceProfile OR eventName=AttachClassicLinkVpc OR eventName=AttachNetworkInterface OR eventName=AttachVolume OR eventName=BundleInstance OR eventName=DetachClassicLinkVpc OR eventName=DetachVolume OR eventName=ModifyInstanceAttribute OR eventName=ModifyInstancePlacement OR eventName=MonitorInstances OR eventName=RebootInstances OR eventName=ResetInstanceAttribute OR eventName=StartInstances OR eventName=StopInstances OR eventName=TerminateInstances OR eventName=UnmonitorInstances) description = This is a list of AWS event names that have to do with modifying Amazon EC2 instances [evilginx_phishlets_0365] definition = (query=login* AND query=www*) description = This limits the query fields to domains that are associated with evilginx masquerading as Office 365 [evilginx_phishlets_amazon] definition = (query=fls-na* AND query = www* AND query=images*) description = This limits the query fields to domains that are associated with evilginx masquerading as Amazon [evilginx_phishlets_aws] definition = (query=www* AND query=aws* AND query=console.aws* AND query=signin.aws* AND api-northeast-1.console.aws* AND query=fls-na* AND query=images-na*) description = This limits the query fields to domains that are associated with evilginx masquerading as an AWS console [evilginx_phishlets_facebook] definition = (query=www* AND query = m* AND query=static*) description = This limits the query fields to domains that are associated with evilginx masquerading as FaceBook [evilginx_phishlets_github] definition = (query=api* AND query = github*) description = This limits the query fields to domains that are associated with evilginx masquerading as GitHub [evilginx_phishlets_google] definition = (query=accounts* AND query=ssl* AND query=www*) description = This limits the query fields to domains that are associated with evilginx masquerading as Google [evilginx_phishlets_outlook] definition = (query=outlook* AND query=login* AND query=account*) description = This limits the query fields to domains that are associated with evilginx masquerading as Outlook [exchange] definition = sourcetype="MSWindows:IIS" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [f5_bigip_rogue] definition = index=netops sourcetype="f5:bigip:rogue" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [filter_rare_process_allow_list] definition = lookup update=true lookup_rare_process_allow_list_default process as process OUTPUTNEW allow_list | where allow_list="false" | lookup update=true lookup_rare_process_allow_list_local process as process OUTPUT allow_list | where allow_list="false" description = This macro is intended to allow_list processes that have been definied as rare [github] definition = sourcetype=aws:firehose:json description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [github_known_users] definition = user IN (user_names_here) description = specify the user allowed to create PRs in Github projects. [google_gcp_pubnet_message] definition = sourcetype="google:gcp:pubsub:message" description = customer specific splunk configurations(eg- index, source, sourcetype) for Google GCP. Replace the macro definition with configurations for your Splunk Environmnent. [google_gcp_pubsub_message] definition = sourcetype="google:gcp:pubsub:message" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [gsuite_calendar] definition = sourcetype=gsuite:calendar:json description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [gsuite_drive] definition = sourcetype=gsuite:drive:json description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [gsuite_gmail] definition = sourcetype=gsuite:gmail:bigquery description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [is_windows_system_file] definition = lookup update=true is_windows_system_file filename as process_name OUTPUT systemFile | search systemFile=true description = This macro limits the output to process names that are in the Windows System directory [kube_objects_events] definition = sourcetype=kube:objects:events description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [kubernetes_azure] definition = sourcetype=mscs:storage:blob:json description = customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data from Azure. Replace the macro definition with configurations for your Splunk Environmnent. [kubernetes_container_controller] definition = sourcetype=kube:container:controller description = customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data. Replace the macro definition with configurations for your Splunk Environmnent. [linux_hosts] definition = index=* description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [linux_shells] definition = (Processes.process_name IN ("sh", "ksh", "zsh", "bash", "dash", "rbash", "fish", "csh', "tcsh', "ion", "eshell")) description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [netbackup] definition = sourcetype="netbackup_logs" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [network_acl_events] definition = (eventName = CreateNetworkAcl OR eventName = CreateNetworkAclEntry OR eventName = DeleteNetworkAcl OR eventName = DeleteNetworkAclEntry OR eventName = ReplaceNetworkAclEntry OR eventName = ReplaceNetworkAclAssociation) description = This is a list of AWS event names that are associated with Network ACLs [notable] definition = index=notable description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [o365_management_activity] definition = sourcetype=o365:management:activity description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [okta] definition = eventtype=okta_log description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [osquery_process] definition = eventtype="osquery-process" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [powershell] definition = (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational") description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [previously_seen_cloud_api_calls_per_user_role_forget_window] definition = "-90d@d" description = Use this macro to determine how long to keep track of cloud api calls per user role [previously_seen_cloud_compute_creations_by_user_search_window_begin_offset] definition = "-70m@m" description = Use this macro to determine how far into the past the window should be to determine if the user is new or not [previously_seen_cloud_compute_image_search_window_begin_offset] definition = "-70m@m" description = Use this macro to determine how far into the past the window should be to determine if the image is new or not [previously_seen_cloud_compute_images_forget_window] definition = "-90d@d" description = Use this macro to determine how long to keep track of cloud instance images [previously_seen_cloud_compute_instance_type_forget_window] definition = "-90d@d" description = Use this macro to determine how long to keep track of cloud instance types [previously_seen_cloud_compute_instance_types_search_window_begin_offset] definition = "-70m@m" description = Use this macro to determine how far into the past the window should be to determine if the instance type is new or not [previously_seen_cloud_instance_modifications_by_user_search_window_begin_offset] definition = "-70m@m" description = Use this macro to determine how far into the past the window should be to determine if the user is new or not [previously_seen_cloud_provisioning_activity_forget_window] definition = "-90d@d" description = Use this macro to determine how long to keep track of cloud provisioning locations [previously_seen_cloud_region_forget_window] definition = "-90d@d" description = Use this macro to determine how long to keep track of cloud regions [previously_seen_cloud_regions_search_window_begin_offset] definition = "-70m@m" description = Use this macro to determine how far into the past the window should be to determine if the region is new or not [previously_seen_windows_services_forget_window] definition = "-90d@d" description = Use this macro to determine how long to keep track of Windows services [previously_seen_windows_services_window] definition = "-70m@m" description = Use this macro to determine how far back you should be checking for new Windows services [previously_seen_zoom_child_processes_forget_window] definition = "-90d@d" description = Use this macro to determine how long to keep track of zoom child processes [previously_seen_zoom_child_processes_window] definition = "-70m@m" description = Use this macro to determine how far back you should be checking for new zoom child processes [previously_unseen_cloud_provisioning_activity_window] definition = "-70m@m" description = Use this macro to determine how far back you should be checking for new provisioning activities [printservice] definition = source="wineventlog:microsoft-windows-printservice/operational" OR sourcetype="WinEventLog:Microsoft-Windows-PrintService/Admin" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [process_bitsadmin] definition = (Processes.process_name=bitsadmin.exe OR Processes.original_file_name=bitsadmin.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_certutil] definition = (Processes.process_name=certutil.exe OR Processes.original_file_name=CertUtil.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_cmd] definition = (Processes.process_name=cmd.exe OR Processes.original_file_name=Cmd.Exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_copy] definition = (Processes.process_name=copy.exe OR Processes.original_file_name=copy.exe OR Processes.process_name=xcopy.exe OR Processes.original_file_name=xcopy.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_csc] definition = (Processes.process_name=csc.exe OR Processes.original_file_name=csc.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_curl] definition = (Processes.process_name=curl.exe OR Processes.original_file_name=Curl.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_dllhost] definition = (Processes.process_name=dllhost.exe OR Processes.original_file_name=dllhost.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_dsquery] definition = (Processes.process_name=dsquery.exe OR Processes.original_file_name=dsquery.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_dxdiag] definition = (Processes.process_name=dxdiag.exe OR Processes.original_file_name=dxdiag.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_esentutl] definition = (Processes.process_name=esentutl.exe OR Processes.original_file_name=esentutl.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_fodhelper] definition = (Processes.process_name=fodhelper.exe OR Processes.original_file_name=FodHelper.EXE) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_gpupdate] definition = (Processes.process_name=gpupdate.exe OR Processes.original_file_name=GPUpdate.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_hh] definition = (Processes.process_name=hh.exe OR Processes.original_file_name=HH.EXE) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_installutil] definition = (Processes.process_name=installutil.exe OR Processes.original_file_name=InstallUtil.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_microsoftworkflowcompiler] definition = (Processes.process_name=microsoft.workflow.compiler.exe OR Processes.original_file_name=Microsoft.Workflow.Compiler.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_msbuild] definition = (Processes.process_name=msbuild.exe OR Processes.original_file_name=MSBuild.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_mshta] definition = (Processes.process_name=mshta.exe OR Processes.original_file_name=MSHTA.EXE) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_net] definition = (Processes.process_name="net.exe" OR Processes.original_file_name="net.exe" OR Processes.process_name="net1.exe" OR Processes.original_file_name="net1.exe") description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_netsh] definition = (Processes.process_name=netsh.exe OR Processes.original_file_name=netsh.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_nltest] definition = (Processes.process_name=nltest.exe OR Processes.original_file_name=nltestrk.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_ntdsutil] definition = (Processes.process_name=ntdsutil.exe OR Processes.original_file_name=ntdsutil.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_powershell] definition = (Processes.process_name=pwsh.exe OR Processes.process_name=sqlps.exe OR Processes.process_name=sqltoolsps.exe OR Processes.process_name=powershell.exe OR Processes.process_name=powershell_ise.exe OR Processes.original_file_name=pwsh.dll OR Processes.original_file_name=PowerShell.EXE OR Processes.original_file_name=powershell_ise.EXE) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_procdump] definition = (Processes.process_name=procdump.exe OR Processes.process_name=procdump64.exe OR Processes.original_file_name=procdump) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_psexec] definition = (Processes.process_name=psexec.exe OR Processes.process_name=psexec64.exe OR Processes.original_file_name=psexec.c) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_rclone] definition = (Processes.original_file_name=rclone.exe OR Processes.process_name=rclone.exe) description = Matches the process with its original file name. [process_reg] definition = (Processes.process_name=reg.exe OR Processes.original_file_name=reg.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_regasm] definition = (Processes.process_name=regasm.exe OR Processes.original_file_name=RegAsm.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_regsvcs] definition = (Processes.process_name=regsvcs.exe OR Processes.original_file_name=RegSvcs.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_regsvr32] definition = (Processes.process_name=regsvr32.exe OR Processes.original_file_name=REGSVR32.EXE) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_route] definition = (Processes.process_name=route.exe OR Processes.original_file_name=route.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_runas] definition = (Processes.process_name=runas.exe OR Processes.original_file_name=runas.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_rundll32] definition = (Processes.process_name=rundll32.exe OR Processes.original_file_name=RUNDLL32.EXE) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_schtasks] definition = (Processes.process_name=schtasks.exe OR Processes.original_file_name=schtasks.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_sdelete] definition = (Processes.process_name=sdelete.exe OR Processes.original_file_name=sdelete.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_setspn] definition = (Processes.process_name=setspn.exe OR Processes.original_file_name=setspn.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_verclsid] definition = (Processes.process_name=verclsid.exe OR Processes.original_file_name=verclsid.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_vssadmin] definition = (Processes.process_name=vssadmin.exe OR Processes.original_file_name=VSSADMIN.EXE) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_wbadmin] definition = (Processes.process_name=wbadmin.exe OR Processes.original_file_name=WBADMIN.EXE) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [process_wmic] definition = (Processes.process_name=wmic.exe OR Processes.original_file_name=wmic.exe) description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/ [prohibited_apps_launching_cmd] definition = | inputlookup prohibited_apps_launching_cmd | rename prohibited_applications as parent_process_name | eval parent_process_name="*" . parent_process_name | table parent_process_name description = This macro outputs a list of process that should not be the parent process of cmd.exe [prohibited_softwares] definition = lookup prohibited_softwares app as process_name OUTPUT is_prohibited | search is_prohibited=True description = This macro limits the output to process_names that have been marked as prohibited [ransomware_extensions] definition = lookup update=true ransomware_extensions_lookup Extensions AS file_extension OUTPUT Name | search Name !=False description = This macro limits the output to files that have extensions associated with ransomware [ransomware_notes] definition = lookup ransomware_notes_lookup ransomware_notes as file_name OUTPUT status as "Known Ransomware Notes" | search "Known Ransomware Notes"=True description = This macro limits the output to files that have been identified as a ransomware note [remove_valid_domains] definition = eval domain=trim(domain,"*") | search NOT[| inputlookup domains] NOT[ |inputlookup cim_corporate_email_domain_lookup] NOT[inputlookup cim_corporate_web_domain_lookup] | eval domain="*"+domain+"*" description = This macro removes valid domains from the output [s3_accesslogs] definition = sourcetype=aws:s3:accesslogs description = customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent. [security_content_ctime(1)] args = field definition = convert timeformat="%Y-%m-%dT%H:%M:%S" ctime($field$) description = convert epoch time to string [security_content_summariesonly] definition = summariesonly=false allow_old_summaries=true description = search data model's summaries only [security_group_api_calls] definition = (eventName=AuthorizeSecurityGroupIngress OR eventName=CreateSecurityGroup OR eventName=DeleteSecurityGroup OR eventName=DescribeClusterSecurityGroups OR eventName=DescribeDBSecurityGroups OR eventName=DescribeSecurityGroupReferences OR eventName=DescribeSecurityGroups OR eventName=DescribeStaleSecurityGroups OR eventName=RevokeSecurityGroupIngress OR eventName=UpdateSecurityGroupRuleDescriptionsIngress) description = This macro is a list of AWS event names associated with security groups [signals] definition = index=signals description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [stream_dns] definition = sourcetype=stream:dns description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [stream_http] definition = sourcetype=stream:http description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [stream_tcp] definition = sourcetype=stream:tcp description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [suspicious_email_attachments] definition = lookup update=true is_suspicious_file_extension_lookup file_name OUTPUT suspicious | search suspicious=true description = This macro limits the output to email attachments that have suspicious extensions [suspicious_writes] definition = lookup suspicious_writes_lookup file as file_name OUTPUT note as "Reference" | search "Reference" != False description = This macro limites the output to file names that have been marked as suspicious [sysmon] definition = sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=Syslog:Linux-Sysmon/Operational description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [system_network_configuration_discovery_tools] definition = (process_name= "arp.exe" OR process_name= "at.exe" OR process_name= "attrib.exe" OR process_name= "cscript.exe" OR process_name= "dsquery.exe" OR process_name= "hostname.exe" OR process_name= "ipconfig.exe" OR process_name= "mimikatz.exe" OR process_name= "nbstat.exe" OR process_name= "net.exe" OR process_name= "netsh.exe" OR process_name= "nslookup.exe" OR process_name= "ping.exe" OR process_name= "quser.exe" OR process_name= "qwinsta.exe" OR process_name= "reg.exe" OR process_name= "runas.exe" OR process_name= "sc.exe" OR process_name= "schtasks.exe" OR process_name= "ssh.exe" OR process_name= "systeminfo.exe" OR process_name= "taskkill.exe" OR process_name= "telnet.exe" OR process_name= "tracert.exe" OR process_name="wscript.exe" OR process_name= "xcopy.exe") description = This macro is a list of process that can be used to discover the network configuration [uncommon_processes] definition = lookup update=true lookup_uncommon_processes_default process_name as process_name outputnew uncommon_default,category_default,analytic_story_default,kill_chain_phase_default,mitre_attack_default | lookup update=true lookup_uncommon_processes_local process_name as process_name outputnew uncommon_local,category_local,analytic_story_local,kill_chain_phase_local,mitre_attack_local | eval uncommon = coalesce(uncommon_default, uncommon_local), analytic_story = coalesce(analytic_story_default, analytic_story_local), category=coalesce(category_default, category_local), kill_chain_phase=coalesce(kill_chain_phase_default, kill_chain_phase_local), mitre_attack=coalesce(mitre_attack_default, mitre_attack_local) | fields - analytic_story_default, analytic_story_local, category_default, category_local, kill_chain_phase_default, kill_chain_phase_local, mitre_attack_default, mitre_attack_local, uncommon_default, uncommon_local | search uncommon=true description = This macro limits the output to processes that have been marked as uncommon [windows_shells] definition = (Processes.process_name=cmd.exe OR Processes.process_name=powershell.exe) description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [wineventlog_security] definition = eventtype=wineventlog_security description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [wineventlog_system] definition = eventtype=wineventlog_system description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [wineventlog_task_scheduler] definition = source="WinEventLog:Microsoft-Windows-TaskScheduler/Operational" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [wmi] definition = sourcetype="wineventlog:microsoft-windows-wmi-activity/operational" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [zeek_rpc] definition = index=zeek sourcetype="zeek:rpc:json" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [zeek_ssl] definition = index=zeek sourcetype="zeek:ssl:json" description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. [abnormally_high_number_of_cloud_infrastructure_api_calls_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [abnormally_high_number_of_cloud_security_group_api_calls_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [amazon_eks_kubernetes_activity_by_src_ip_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_create_policy_version_to_allow_all_resources_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_createaccesskey_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_createloginprofile_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_cross_account_activity_from_previously_unseen_account_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_detect_users_with_kms_keys_performing_encryption_s3_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_excessive_security_scanning_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_iam_accessdenied_discovery_events_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_iam_assume_role_policy_brute_force_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_iam_delete_policy_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_iam_failure_group_deletion_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_iam_successful_group_deletion_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_investigate_security_hub_alerts_by_dest_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_investigate_user_activities_by_accesskeyid_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_investigate_user_activities_by_arn_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_network_access_control_list_created_with_all_open_ports_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_network_access_control_list_deleted_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_network_acl_details_from_id_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_network_interface_details_via_resourceid_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_s3_bucket_details_via_bucketname_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_saml_access_by_provider_user_and_principal_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_saml_update_identity_provider_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_setdefaultpolicyversion_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [aws_updateloginprofile_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [baseline_of_cloud_infrastructure_api_calls_per_user_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [baseline_of_cloud_instances_destroyed_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [baseline_of_cloud_instances_launched_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [baseline_of_cloud_security_group_api_calls_per_user_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_api_calls_from_previously_unseen_user_roles_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_compute_instance_created_by_previously_unseen_user_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_compute_instance_created_in_previously_unused_region_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_compute_instance_created_with_previously_unseen_image_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_compute_instance_created_with_previously_unseen_instance_type_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_instance_modified_by_previously_unseen_user_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_provisioning_activity_from_previously_unseen_city_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_provisioning_activity_from_previously_unseen_country_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_provisioning_activity_from_previously_unseen_ip_address_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [cloud_provisioning_activity_from_previously_unseen_region_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [detect_aws_console_login_by_new_user_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [detect_aws_console_login_by_user_from_new_city_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [detect_aws_console_login_by_user_from_new_country_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [detect_aws_console_login_by_user_from_new_region_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [detect_new_open_s3_buckets_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [detect_new_open_s3_buckets_over_aws_cli_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [detect_shared_ec2_snapshot_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [detect_spike_in_aws_security_hub_alerts_for_ec2_instance_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [get_all_aws_activity_from_city_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [get_all_aws_activity_from_country_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [get_all_aws_activity_from_ip_address_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [get_all_aws_activity_from_region_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [get_ec2_instance_details_by_instanceid_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [get_ec2_launch_details_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [investigate_aws_activities_via_region_name_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [investigate_aws_user_activities_by_user_field_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_add_app_role_assignment_grant_user_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_added_service_principal_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_bypass_mfa_via_trusted_ip_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_disable_mfa_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_excessive_authentication_failures_alert_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_excessive_sso_logon_errors_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_new_federated_domain_added_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_pst_export_alert_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_suspicious_admin_email_forwarding_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_suspicious_rights_delegation_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [o365_suspicious_user_email_forwarding_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_aws_cross_account_activity___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_aws_cross_account_activity___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_api_calls_per_user_role___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_api_calls_per_user_role___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_compute_creations_by_user___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_compute_creations_by_user___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_compute_images___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_compute_images___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_compute_instance_types___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_compute_instance_types___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_instance_modifications_by_user___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_instance_modifications_by_user___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_provisioning_activity_sources___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_provisioning_activity_sources___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_regions___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_cloud_regions___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_users_in_cloudtrail___initial_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [previously_seen_users_in_cloudtrail___update_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [abnormally_high_number_of_cloud_instances_destroyed_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. [abnormally_high_number_of_cloud_instances_launched_filter] definition = search * description = Update this macro to limit the output results to filter out false positives.