mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
bc1b413923
* Fix #3961 * Fix #3909 * Fix output fields * Remove duplicate process_name entry * Update outbound_network_connection_from_java_using_default_ports.yml * Update detect_computer_changed_with_anonymous_account.yml * Update detect_computer_changed_with_anonymous_account.yml * Fix #3969 * update palo alto TA and beautify analytics * Update vmware_aria_operations_exploit_attempt.yml * fix source * enhance metadata and fp info * beautify spl for ease of reading * add some missing attack techniques * remove unnecessary usage of regex * Update windows_uac_bypass_suspicious_escalation_behavior.yml * small fix * Refine description and improve regex * Update windows_uac_bypass_suspicious_escalation_behavior.yml * Update possible_lateral_movement_powershell_spawn.yml * Update possible_lateral_movement_powershell_spawn.yml * Update windows_event_log_security_4756.yml * description update --------- Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>