Skip to content

Commit

Permalink
Update dist/escu, dist/ssa, and dist/api folders with the latest cont…
Browse files Browse the repository at this point in the history
…ent associated with this tag
  • Loading branch information
research bot committed Sep 20, 2023
1 parent c81a487 commit 3a6638d
Show file tree
Hide file tree
Showing 15 changed files with 1,777 additions and 1,316 deletions.
2 changes: 1 addition & 1 deletion dist/api/baselines.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/detections.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/macros.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/stories.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/escu/app.manifest
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "4.11.1"
"version": "4.12.0"
},
"author": [
{
Expand Down
1,130 changes: 606 additions & 524 deletions dist/escu/default/analyticstories.conf

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions dist/escu/default/app.conf
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 16958
build = 17107

[triggers]
reload.analytic_stories = simple
Expand All @@ -20,7 +20,7 @@ reload.es_investigations = simple

[launcher]
author = Splunk
version = 4.11.1
version = 4.12.0
description = Explore the Analytic Stories included with ES Content Updates.

[ui]
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/collections.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/content-version.conf
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
[content-version]
version = 4.11.1
version = 4.12.0
2 changes: 1 addition & 1 deletion dist/escu/default/es_investigations.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down
34 changes: 33 additions & 1 deletion dist/escu/default/macros.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down Expand Up @@ -2237,6 +2237,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[headless_browser_mockbin_or_mocky_request_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[headless_browser_usage_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[hide_user_account_from_sign_in_screen_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3757,6 +3765,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_ad_abnormal_object_access_activity_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_ad_adminsdholder_acl_modified_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3789,6 +3801,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_ad_privileged_object_access_activity_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_ad_replication_request_initiated_by_user_account_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4125,10 +4141,22 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_find_domain_organizational_units_with_getdomainou_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_find_interesting_acl_with_findinterestingdomainacl_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_findstr_gpp_discovery_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_forest_discovery_with_getforestdomain_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_gather_victim_host_information_camera_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand All @@ -4145,6 +4173,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_get_local_admin_with_findlocaladminaccess_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_group_policy_object_created_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down
1,892 changes: 1,117 additions & 775 deletions dist/escu/default/savedsearches.conf

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/escu/default/transforms.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/workflow_actions.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-05T22:20:53 UTC
# On Date: 2023-09-20T19:43:15 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down
Loading

0 comments on commit 3a6638d

Please sign in to comment.