Skip to content

Commit

Permalink
Branch was auto-updated.
Browse files Browse the repository at this point in the history
  • Loading branch information
srv-rr-gh-researchbt committed Oct 4, 2023
2 parents dc8b1be + acaed15 commit 40f0e85
Show file tree
Hide file tree
Showing 17 changed files with 1,216 additions and 380 deletions.
2 changes: 1 addition & 1 deletion dist/api/detections.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/lookups.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/macros.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/stories.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/escu/app.manifest
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "4.12.0"
"version": "4.13.0"
},
"author": [
{
Expand Down
193 changes: 183 additions & 10 deletions dist/escu/default/analyticstories.conf

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions dist/escu/default/app.conf
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 17107
build = 17285

[triggers]
reload.analytic_stories = simple
Expand All @@ -20,7 +20,7 @@ reload.es_investigations = simple

[launcher]
author = Splunk
version = 4.12.0
version = 4.13.0
description = Explore the Analytic Stories included with ES Content Updates.

[ui]
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/collections.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-20T19:43:15 UTC
# On Date: 2023-10-04T21:15:36 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/content-version.conf
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
[content-version]
version = 4.12.0
version = 4.13.0
2 changes: 1 addition & 1 deletion dist/escu/default/es_investigations.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-20T19:43:15 UTC
# On Date: 2023-10-04T21:15:36 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down
58 changes: 57 additions & 1 deletion dist/escu/default/macros.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-09-20T19:43:15 UTC
# On Date: 2023-10-04T21:15:36 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down Expand Up @@ -109,6 +109,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[splunk_absolute_path_traversal_using_runshellscript_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[splunk_account_discovery_drilldown_dashboard_disclosure_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -145,6 +149,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[splunk_dos_using_malformed_saml_request_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[splunk_dos_via_dump_spl_command_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -213,6 +221,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[splunk_rce_via_serialized_session_payload_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[splunk_rce_via_splunk_secure_gateway__splunk_mobile_alerts_feature_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand All @@ -221,6 +233,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[splunk_reflected_xss_on_app_search_table_endpoint_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[splunk_risky_command_abuse_disclosed_february_2023_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3753,6 +3769,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_abused_web_services_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_access_token_manipulation_sedebugprivilege_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3841,6 +3861,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_admin_permission_discovery_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_administrative_shares_accessed_on_multiple_hosts_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3993,6 +4017,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_delete_or_modify_system_firewall_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_deleted_registry_by_a_non_critical_process_file_path_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand All @@ -4017,6 +4045,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_disable_or_modify_tools_via_taskkill_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_disable_shutdown_button_through_registry_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4109,6 +4141,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_executable_in_loaded_modules_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_execute_arbitrary_commands_with_msdt_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4137,6 +4173,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_njrat_fileless_storage_via_registry_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_files_and_dirs_access_rights_modification_via_icacls_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4441,6 +4481,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_modify_registry_with_md5_reg_key_name_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_modify_registry_wuserver_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -5013,6 +5057,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_time_based_evasion_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_unsigned_dll_side_loading_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -5393,6 +5441,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[jetbrains_teamcity_rce_attempt_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[juniper_networks_remote_code_execution_exploit_detection_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -5457,6 +5509,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[ws_ftp_remote_code_execution_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.


[admon]
definition = source=ActiveDirectory
Expand Down
Loading

0 comments on commit 40f0e85

Please sign in to comment.