Files
splunk-security_content/lookups/browser_process_and_path.yml
Br3akp0int 27aeb7d95d Add BlankGrabber Stealer Related Analytics and Tagging (#3943)
---------

Co-authored-by: Teoderick Contreras <tcontreras@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-03-16 18:09:57 +01:00

13 lines
393 B
YAML

name: browser_process_and_path
date: 2025-03-09
version: 1
id: c35eb14c-2a12-4556-8c9d-d11e31c8915f
author: Splunk Threat Research Team
lookup_type: csv
description: Legitimate browser process executable paths; used to filter out known browsers e.g. when detecting hosts file access.
default_match: false
match_type:
- WILDCARD(browser_process_path)
min_matches: 1
case_sensitive_match: false