mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
450 lines
26 KiB
Plaintext
450 lines
26 KiB
Plaintext
#############
|
|
# Automatically generated by generator.py in splunk/security_content
|
|
# On Date: 2021-09-13T10:57:27 UTC
|
|
# Author: Splunk Security Research
|
|
# Contact: research@splunk.com
|
|
#############
|
|
|
|
|
|
[aws_cloudwatchlogs_eks]
|
|
definition = sourcetype="aws:cloudwatchlogs:eks"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[aws_config]
|
|
definition = sourcetype=aws:config
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[aws_description]
|
|
definition = sourcetype="aws:description"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[aws_ecr_users]
|
|
definition = userName IN (user)
|
|
description = specify the user allowed to push Images to AWS ECR.
|
|
|
|
[aws_s3_accesslogs]
|
|
definition = sourcetype=aws:s3:accesslogs
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[aws_securityhub_finding]
|
|
definition = sourcetype="aws:securityhub:finding"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[aws_securityhub_firehose]
|
|
definition = sourcetype="aws:securityhub:firehose"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[brand_abuse_dns]
|
|
definition = lookup update=true brandMonitoring_lookup domain as query OUTPUT domain_abuse | search domain_abuse=true
|
|
description = This macro limits the output to only domains that are in the brand monitoring lookup file
|
|
|
|
[brand_abuse_email]
|
|
definition = lookup update=true brandMonitoring_lookup domain as src_user OUTPUT domain_abuse | search domain_abuse=true
|
|
description = This macro limits the output to only domains that are in the brand monitoring lookup file
|
|
|
|
[brand_abuse_web]
|
|
definition = lookup update=true brandMonitoring_lookup domain as urls OUTPUT domain_abuse | search domain_abuse=true
|
|
description = This macro limits the output to only domains that are in the brand monitoring lookup file
|
|
|
|
[circleci]
|
|
definition = sourcetype=circleci
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[cisco_networks]
|
|
definition = eventtype=cisco_ios
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[cloud_api_calls_from_previously_unseen_user_roles_activity_window]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far back you should be checking for new commands from user roles
|
|
|
|
[cloudtrail]
|
|
definition = sourcetype=aws:cloudtrail
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[cloudwatch_eks]
|
|
definition = sourcetype="aws:cloudwatchlogs:eks"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch eks logs. Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[cloudwatch_vpc]
|
|
definition = sourcetype=aws:cloudwatchlogs:vpcflow
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[cloudwatchlogs_vpcflow]
|
|
definition = sourcetype=aws:cloudwatchlogs:vpcflow
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[dynamic_dns_providers]
|
|
definition = lookup update=true dynamic_dns_providers_default dynamic_dns_domains as query OUTPUTNEW isDynDNS_default | lookup update=true dynamic_dns_providers_local dynamic_dns_domains as query OUTPUTNEW isDynDNS_local| eval isDynDNS = coalesce(isDynDNS_default, isDynDNS_local)|fields - isDynDNS_default, isDynDNS_local| search isDynDNS=True
|
|
description = This macro limits the output of the query field to dynamic dns domains. It looks up the domains in a file provided by Splunk and one intended to be updated by the end user.
|
|
|
|
[dynamic_dns_web_traffic]
|
|
definition = lookup update=true dynamic_dns_providers_default dynamic_dns_domains as url OUTPUTNEW isDynDNS_default | lookup update=true dynamic_dns_providers_local dynamic_dns_domains as url OUTPUTNEW isDynDNS_local| eval isDynDNS = coalesce(isDynDNS_default, isDynDNS_local)|fields - isDynDNS_default, isDynDNS_local| search isDynDNS=True
|
|
description = This is a description
|
|
|
|
[ec2_modification_api_calls]
|
|
definition = (eventName=AssociateAddress OR eventName=AssociateIamInstanceProfile OR eventName=AttachClassicLinkVpc OR eventName=AttachNetworkInterface OR eventName=AttachVolume OR eventName=BundleInstance OR eventName=DetachClassicLinkVpc OR eventName=DetachVolume OR eventName=ModifyInstanceAttribute OR eventName=ModifyInstancePlacement OR eventName=MonitorInstances OR eventName=RebootInstances OR eventName=ResetInstanceAttribute OR eventName=StartInstances OR eventName=StopInstances OR eventName=TerminateInstances OR eventName=UnmonitorInstances)
|
|
description = This is a list of AWS event names that have to do with modifying Amazon EC2 instances
|
|
|
|
[evilginx_phishlets_0365]
|
|
definition = (query=login* AND query=www*)
|
|
description = This limits the query fields to domains that are associated with evilginx masquerading as Office 365
|
|
|
|
[evilginx_phishlets_amazon]
|
|
definition = (query=fls-na* AND query = www* AND query=images*)
|
|
description = This limits the query fields to domains that are associated with evilginx masquerading as Amazon
|
|
|
|
[evilginx_phishlets_aws]
|
|
definition = (query=www* AND query=aws* AND query=console.aws* AND query=signin.aws* AND api-northeast-1.console.aws* AND query=fls-na* AND query=images-na*)
|
|
description = This limits the query fields to domains that are associated with evilginx masquerading as an AWS console
|
|
|
|
[evilginx_phishlets_facebook]
|
|
definition = (query=www* AND query = m* AND query=static*)
|
|
description = This limits the query fields to domains that are associated with evilginx masquerading as FaceBook
|
|
|
|
[evilginx_phishlets_github]
|
|
definition = (query=api* AND query = github*)
|
|
description = This limits the query fields to domains that are associated with evilginx masquerading as GitHub
|
|
|
|
[evilginx_phishlets_google]
|
|
definition = (query=accounts* AND query=ssl* AND query=www*)
|
|
description = This limits the query fields to domains that are associated with evilginx masquerading as Google
|
|
|
|
[evilginx_phishlets_outlook]
|
|
definition = (query=outlook* AND query=login* AND query=account*)
|
|
description = This limits the query fields to domains that are associated with evilginx masquerading as Outlook
|
|
|
|
[exchange]
|
|
definition = sourcetype="MSWindows:IIS"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[f5_bigip_rogue]
|
|
definition = index=netops sourcetype="f5:bigip:rogue"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[filter_rare_process_allow_list]
|
|
definition = lookup update=true lookup_rare_process_allow_list_default process as process OUTPUTNEW allow_list | where allow_list="false" | lookup update=true lookup_rare_process_allow_list_local process as process OUTPUT allow_list | where allow_list="false"
|
|
description = This macro is intended to allow_list processes that have been definied as rare
|
|
|
|
[github]
|
|
definition = sourcetype=aws:firehose:json
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[github_known_users]
|
|
definition = user IN (user_names_here)
|
|
description = specify the user allowed to create PRs in Github projects.
|
|
|
|
[google_gcp_pubnet_message]
|
|
definition = sourcetype="google:gcp:pubsub:message"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype) for Google GCP. Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[google_gcp_pubsub_message]
|
|
definition = sourcetype="google:gcp:pubsub:message"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[gsuite_drive]
|
|
definition = sourcetype=gsuite:drive:json
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[gsuite_gmail]
|
|
definition = sourcetype=gsuite:gmail:bigquery
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[is_windows_system_file]
|
|
definition = lookup update=true is_windows_system_file filename as process_name OUTPUT systemFile | search systemFile=true
|
|
description = This macro limits the output to process names that are in the Windows System directory
|
|
|
|
[kube_objects_events]
|
|
definition = sourcetype=kube:objects:events
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[kubernetes_azure]
|
|
definition = sourcetype=mscs:storage:blob:json
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data from Azure. Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[kubernetes_container_controller]
|
|
definition = sourcetype=kube:container:controller
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype) for Kubernetes data. Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[linux_hosts]
|
|
definition = index=*
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[netbackup]
|
|
definition = sourcetype="netbackup_logs"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[network_acl_events]
|
|
definition = (eventName = CreateNetworkAcl OR eventName = CreateNetworkAclEntry OR eventName = DeleteNetworkAcl OR eventName = DeleteNetworkAclEntry OR eventName = ReplaceNetworkAclEntry OR eventName = ReplaceNetworkAclAssociation)
|
|
description = This is a list of AWS event names that are associated with Network ACLs
|
|
|
|
[notable]
|
|
definition = index=notable
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[o365_management_activity]
|
|
definition = sourcetype=o365:management:activity
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[okta]
|
|
definition = eventtype=okta_log
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[osquery_process]
|
|
definition = eventtype="osquery-process"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[powershell]
|
|
definition = (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational")
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[previously_seen_cloud_api_calls_per_user_role_forget_window]
|
|
definition = "-90d@d"
|
|
description = Use this macro to determine how long to keep track of cloud api calls per user role
|
|
|
|
[previously_seen_cloud_compute_creations_by_user_search_window_begin_offset]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far into the past the window should be to determine if the user is new or not
|
|
|
|
[previously_seen_cloud_compute_image_search_window_begin_offset]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far into the past the window should be to determine if the image is new or not
|
|
|
|
[previously_seen_cloud_compute_images_forget_window]
|
|
definition = "-90d@d"
|
|
description = Use this macro to determine how long to keep track of cloud instance images
|
|
|
|
[previously_seen_cloud_compute_instance_type_forget_window]
|
|
definition = "-90d@d"
|
|
description = Use this macro to determine how long to keep track of cloud instance types
|
|
|
|
[previously_seen_cloud_compute_instance_types_search_window_begin_offset]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far into the past the window should be to determine if the instance type is new or not
|
|
|
|
[previously_seen_cloud_instance_modifications_by_user_search_window_begin_offset]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far into the past the window should be to determine if the user is new or not
|
|
|
|
[previously_seen_cloud_provisioning_activity_forget_window]
|
|
definition = "-90d@d"
|
|
description = Use this macro to determine how long to keep track of cloud provisioning locations
|
|
|
|
[previously_seen_cloud_region_forget_window]
|
|
definition = "-90d@d"
|
|
description = Use this macro to determine how long to keep track of cloud regions
|
|
|
|
[previously_seen_cloud_regions_search_window_begin_offset]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far into the past the window should be to determine if the region is new or not
|
|
|
|
[previously_seen_windows_services_forget_window]
|
|
definition = "-90d@d"
|
|
description = Use this macro to determine how long to keep track of Windows services
|
|
|
|
[previously_seen_windows_services_window]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far back you should be checking for new Windows services
|
|
|
|
[previously_seen_zoom_child_processes_forget_window]
|
|
definition = "-90d@d"
|
|
description = Use this macro to determine how long to keep track of zoom child processes
|
|
|
|
[previously_seen_zoom_child_processes_window]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far back you should be checking for new zoom child processes
|
|
|
|
[previously_unseen_cloud_provisioning_activity_window]
|
|
definition = "-70m@m"
|
|
description = Use this macro to determine how far back you should be checking for new provisioning activities
|
|
|
|
[printservice]
|
|
definition = source="wineventlog:microsoft-windows-printservice/operational" OR sourcetype="WinEventLog:Microsoft-Windows-PrintService/Admin"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[process_esentutl]
|
|
definition = (Processes.process_name=esentutl.exe OR Processes.original_file_name=esentutl.exe)
|
|
description = Matches the process with its original file name, data for this macro came from https://strontic.github.io/
|
|
|
|
[prohibited_apps_launching_cmd]
|
|
definition = | inputlookup prohibited_apps_launching_cmd | rename prohibited_applications as parent_process_name | eval parent_process_name="*" . parent_process_name | table parent_process_name
|
|
description = This macro outputs a list of process that should not be the parent process of cmd.exe
|
|
|
|
[prohibited_softwares]
|
|
definition = lookup prohibited_softwares app as process_name OUTPUT is_prohibited | search is_prohibited=True
|
|
description = This macro limits the output to process_names that have been marked as prohibited
|
|
|
|
[ransomware_extensions]
|
|
definition = lookup update=true ransomware_extensions_lookup Extensions AS file_extension OUTPUT Name | search Name !=False
|
|
description = This macro limits the output to files that have extensions associated with ransomware
|
|
|
|
[ransomware_notes]
|
|
definition = lookup ransomware_notes_lookup ransomware_notes as file_name OUTPUT status as "Known Ransomware Notes" | search "Known Ransomware Notes"=True
|
|
description = This macro limits the output to files that have been identified as a ransomware note
|
|
|
|
[remove_valid_domains]
|
|
definition = eval domain=trim(domain,"*") | search NOT[| inputlookup domains] NOT[ |inputlookup cim_corporate_email_domain_lookup] NOT[inputlookup cim_corporate_web_domain_lookup] | eval domain="*"+domain+"*"
|
|
description = This macro removes valid domains from the output
|
|
|
|
[s3_accesslogs]
|
|
definition = sourcetype=aws:s3:accesslogs
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype) for AWS cloudwatch vpc logs. Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[security_content_ctime(1)]
|
|
args = field
|
|
definition = convert timeformat="%Y-%m-%dT%H:%M:%S" ctime($field$)
|
|
description = convert epoch time to string
|
|
|
|
[security_content_summariesonly]
|
|
definition = summariesonly=false allow_old_summaries=true
|
|
description = search data model's summaries only
|
|
|
|
[security_group_api_calls]
|
|
definition = (eventName=AuthorizeSecurityGroupIngress OR eventName=CreateSecurityGroup OR eventName=DeleteSecurityGroup OR eventName=DescribeClusterSecurityGroups OR eventName=DescribeDBSecurityGroups OR eventName=DescribeSecurityGroupReferences OR eventName=DescribeSecurityGroups OR eventName=DescribeStaleSecurityGroups OR eventName=RevokeSecurityGroupIngress OR eventName=UpdateSecurityGroupRuleDescriptionsIngress)
|
|
description = This macro is a list of AWS event names associated with security groups
|
|
|
|
[signals]
|
|
definition = index=signals
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[stream_dns]
|
|
definition = sourcetype=stream:dns
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[stream_http]
|
|
definition = sourcetype=stream:http
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[stream_tcp]
|
|
definition = sourcetype=stream:tcp
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[suspicious_email_attachments]
|
|
definition = lookup update=true is_suspicious_file_extension_lookup file_name OUTPUT suspicious | search suspicious=true
|
|
description = This macro limits the output to email attachments that have suspicious extensions
|
|
|
|
[suspicious_writes]
|
|
definition = lookup suspicious_writes_lookup file as file_name OUTPUT note as "Reference" | search "Reference" != False
|
|
description = This macro limites the output to file names that have been marked as suspicious
|
|
|
|
[sysmon]
|
|
definition = sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[system_network_configuration_discovery_tools]
|
|
definition = (process_name= "arp.exe" OR process_name= "at.exe" OR process_name= "attrib.exe" OR process_name= "cscript.exe" OR process_name= "dsquery.exe" OR process_name= "hostname.exe" OR process_name= "ipconfig.exe" OR process_name= "mimikatz.exe" OR process_name= "nbstat.exe" OR process_name= "net.exe" OR process_name= "netsh.exe" OR process_name= "nslookup.exe" OR process_name= "ping.exe" OR process_name= "quser.exe" OR process_name= "qwinsta.exe" OR process_name= "reg.exe" OR process_name= "runas.exe" OR process_name= "sc.exe" OR process_name= "schtasks.exe" OR process_name= "ssh.exe" OR process_name= "systeminfo.exe" OR process_name= "taskkill.exe" OR process_name= "telnet.exe" OR process_name= "tracert.exe" OR process_name="wscript.exe" OR process_name= "xcopy.exe")
|
|
description = This macro is a list of process that can be used to discover the network configuration
|
|
|
|
[uncommon_processes]
|
|
definition = lookup update=true lookup_uncommon_processes_default process_name as process_name outputnew uncommon_default,category_default,analytic_story_default,kill_chain_phase_default,mitre_attack_default | lookup update=true lookup_uncommon_processes_local process_name as process_name outputnew uncommon_local,category_local,analytic_story_local,kill_chain_phase_local,mitre_attack_local | eval uncommon = coalesce(uncommon_default, uncommon_local), analytic_story = coalesce(analytic_story_default, analytic_story_local), category=coalesce(category_default, category_local), kill_chain_phase=coalesce(kill_chain_phase_default, kill_chain_phase_local), mitre_attack=coalesce(mitre_attack_default, mitre_attack_local) | fields - analytic_story_default, analytic_story_local, category_default, category_local, kill_chain_phase_default, kill_chain_phase_local, mitre_attack_default, mitre_attack_local, uncommon_default, uncommon_local | search uncommon=true
|
|
description = This macro limits the output to processes that have been marked as uncommon
|
|
|
|
[wineventlog_security]
|
|
definition = eventtype=wineventlog_security
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[wineventlog_system]
|
|
definition = eventtype=wineventlog_system
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[wmi]
|
|
definition = sourcetype="wineventlog:microsoft-windows-wmi-activity/operational"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[zeek_rpc]
|
|
definition = index=zeek sourcetype="zeek:rpc:json"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[zeek_ssl]
|
|
definition = index=zeek sourcetype="zeek:ssl:json"
|
|
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
|
|
|
[aws_ecr_container_scanning_findings_high_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[aws_ecr_container_scanning_findings_low_informational_unknown_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[aws_ecr_container_scanning_findings_medium_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[aws_ecr_container_upload_outside_business_hours_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[aws_ecr_container_upload_unknown_user_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[circle_ci_disable_security_job_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[circle_ci_disable_security_step_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[correlation_by_repository_and_risk_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[correlation_by_user_and_risk_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[gsuite_email_suspicious_attachment_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[github_dependabot_alert_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[github_pull_request_from_unknown_user_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[github_commit_changes_in_master_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[github_commit_in_develop_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[gsuite_drive_share_in_external_email_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[gsuite_email_suspicious_subject_with_attachment_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[gsuite_email_with_known_abuse_web_service_link_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[gsuite_outbound_email_with_attachment_to_external_domain_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[gsuite_suspicious_shared_file_name_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[kubernetes_nginx_ingress_lfi_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[kubernetes_nginx_ingress_rfi_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|
|
[kubernetes_scanner_image_pulling_filter]
|
|
definition = search *
|
|
description = Update this macro to limit the output results to filter out false positives.
|
|
|