Files
Michael Haag 442e815dad npm Supply Chain Compromise & Lifecycle Hook Abuse Detection (#3806)
* extra content

* 5 more extras

* Hunt 1

* story+extras

* Create linux_shai_hulud_2_exfiltration_artifacts.yml

* Create linux_shai_hulud_workflow_file_modification.yml

* Create linux_suspicious_github_workflow_file_modification.yml

* Create windows_github_workflow_file_creation_hunt.yml

* more

* last 3

* final pass

* Bump versions to resolve merge conflicts with develop branch

* Fix deprecated status for curl/wget bash execution detections

* Add npm Supply Chain Compromise story to file_download_or_read_to_pipe_execution (replacement for deprecated curl/wget bash detections)

* Fix version numbers to match previous build requirements

* Add all required Filesystem fields to windows_suspicious_github_workflow_file_modification search

* Update detections/endpoint/windows_curl_download_to_suspicious_path.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* small fixes

* apply updates

* more updates

* Update shai_hulud_2_exfiltration_artifact_files.yml

* Fix Windows path escaping - use single backslash in YAML block scalar

---------

Co-authored-by: Jose Enrique Hernandez <josehelps@gmail.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2025-11-25 14:56:20 -08:00
..
2025-11-21 14:50:18 -08:00
2025-10-21 14:08:57 -07:00