Files
jwindley c5e9d4a573 Fixed two detections, and improved macos keychain dumping for more coverage of the technique (#4034)
* Fix and improve azure high-risk sign-in, curl percent-encoded URL, and macOS keychain dump detections

* Apply suggestions from code review

* Update azure_active_directory_high_risk_sign_in.yml

* Update curl_execution_with_percent_encoded_url.yml

* beautify spl

* Update macos_keychains_dumped.yml

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
2026-04-29 15:20:25 +02:00
..