1
1
#############
2
2
# Automatically generated by generator.py in splunk/security_content
3
- # On Date: 2023-11-01T20:44:08 UTC
3
+ # On Date: 2023-11-16T22:15:55 UTC
4
4
# Author: Splunk Threat Research Team - Splunk
5
5
6
6
#############
@@ -117,6 +117,10 @@ description = Update this macro to limit the output results to filter out false
117
117
definition = search *
118
118
description = Update this macro to limit the output results to filter out false positives.
119
119
120
+ [splunk_app_for_lookup_file_editing_rce_via_user_xslt_filter]
121
+ definition = search *
122
+ description = Update this macro to limit the output results to filter out false positives.
123
+
120
124
[splunk_code_injection_via_custom_dashboard_leading_to_rce_filter]
121
125
definition = search *
122
126
description = Update this macro to limit the output results to filter out false positives.
@@ -257,6 +261,10 @@ description = Update this macro to limit the output results to filter out false
257
261
definition = search *
258
262
description = Update this macro to limit the output results to filter out false positives.
259
263
264
+ [splunk_xss_in_highlighted_json_events_filter]
265
+ definition = search *
266
+ description = Update this macro to limit the output results to filter out false positives.
267
+
260
268
[splunk_xss_in_monitoring_console_filter]
261
269
definition = search *
262
270
description = Update this macro to limit the output results to filter out false positives.
@@ -593,10 +601,18 @@ description = Update this macro to limit the output results to filter out false
593
601
definition = search *
594
602
description = Update this macro to limit the output results to filter out false positives.
595
603
604
+ [azure_ad_block_user_consent_for_risky_apps_disabled_filter]
605
+ definition = search *
606
+ description = Update this macro to limit the output results to filter out false positives.
607
+
596
608
[azure_ad_concurrent_sessions_from_different_ips_filter]
597
609
definition = search *
598
610
description = Update this macro to limit the output results to filter out false positives.
599
611
612
+ [azure_ad_device_code_authentication_filter]
613
+ definition = search *
614
+ description = Update this macro to limit the output results to filter out false positives.
615
+
600
616
[azure_ad_external_guest_user_invited_filter]
601
617
definition = search *
602
618
description = Update this macro to limit the output results to filter out false positives.
@@ -617,6 +633,18 @@ description = Update this macro to limit the output results to filter out false
617
633
definition = search *
618
634
description = Update this macro to limit the output results to filter out false positives.
619
635
636
+ [azure_ad_multi_source_failed_authentications_spike_filter]
637
+ definition = search *
638
+ description = Update this macro to limit the output results to filter out false positives.
639
+
640
+ [azure_ad_multiple_appids_and_useragents_authentication_spike_filter]
641
+ definition = search *
642
+ description = Update this macro to limit the output results to filter out false positives.
643
+
644
+ [azure_ad_multiple_denied_mfa_requests_for_user_filter]
645
+ definition = search *
646
+ description = Update this macro to limit the output results to filter out false positives.
647
+
620
648
[azure_ad_multiple_failed_mfa_requests_for_user_filter]
621
649
definition = search *
622
650
description = Update this macro to limit the output results to filter out false positives.
@@ -633,10 +661,18 @@ description = Update this macro to limit the output results to filter out false
633
661
definition = search *
634
662
description = Update this macro to limit the output results to filter out false positives.
635
663
664
+ [azure_ad_new_mfa_method_registered_filter]
665
+ definition = search *
666
+ description = Update this macro to limit the output results to filter out false positives.
667
+
636
668
[azure_ad_new_mfa_method_registered_for_user_filter]
637
669
definition = search *
638
670
description = Update this macro to limit the output results to filter out false positives.
639
671
672
+ [azure_ad_oauth_application_consent_granted_by_user_filter]
673
+ definition = search *
674
+ description = Update this macro to limit the output results to filter out false positives.
675
+
640
676
[azure_ad_pim_role_assigned_filter]
641
677
definition = search *
642
678
description = Update this macro to limit the output results to filter out false positives.
@@ -681,10 +717,22 @@ description = Update this macro to limit the output results to filter out false
681
717
definition = search *
682
718
description = Update this macro to limit the output results to filter out false positives.
683
719
720
+ [azure_ad_tenant_wide_admin_consent_granted_filter]
721
+ definition = search *
722
+ description = Update this macro to limit the output results to filter out false positives.
723
+
684
724
[azure_ad_unusual_number_of_failed_authentications_from_ip_filter]
685
725
definition = search *
686
726
description = Update this macro to limit the output results to filter out false positives.
687
727
728
+ [azure_ad_user_consent_blocked_for_risky_application_filter]
729
+ definition = search *
730
+ description = Update this macro to limit the output results to filter out false positives.
731
+
732
+ [azure_ad_user_consent_denied_for_oauth_application_filter]
733
+ definition = search *
734
+ description = Update this macro to limit the output results to filter out false positives.
735
+
688
736
[azure_ad_user_enabled_and_password_reset_filter]
689
737
definition = search *
690
738
description = Update this macro to limit the output results to filter out false positives.
@@ -753,14 +801,6 @@ description = Update this macro to limit the output results to filter out false
753
801
definition = search *
754
802
description = Update this macro to limit the output results to filter out false positives.
755
803
756
- [correlation_by_repository_and_risk_filter]
757
- definition = search *
758
- description = Update this macro to limit the output results to filter out false positives.
759
-
760
- [correlation_by_user_and_risk_filter]
761
- definition = search *
762
- description = Update this macro to limit the output results to filter out false positives.
763
-
764
804
[detect_aws_console_login_by_new_user_filter]
765
805
definition = search *
766
806
description = Update this macro to limit the output results to filter out false positives.
@@ -961,6 +1001,10 @@ description = Update this macro to limit the output results to filter out false
961
1001
definition = search *
962
1002
description = Update this macro to limit the output results to filter out false positives.
963
1003
1004
+ [risk_rule_for_dev_sec_ops_by_repository_filter]
1005
+ definition = search *
1006
+ description = Update this macro to limit the output results to filter out false positives.
1007
+
964
1008
[abnormally_high_aws_instances_launched_by_user_filter]
965
1009
definition = search *
966
1010
description = Update this macro to limit the output results to filter out false positives.
@@ -1005,6 +1049,14 @@ description = Update this macro to limit the output results to filter out false
1005
1049
definition = search *
1006
1050
description = Update this macro to limit the output results to filter out false positives.
1007
1051
1052
+ [correlation_by_repository_and_risk_filter]
1053
+ definition = search *
1054
+ description = Update this macro to limit the output results to filter out false positives.
1055
+
1056
+ [correlation_by_user_and_risk_filter]
1057
+ definition = search *
1058
+ description = Update this macro to limit the output results to filter out false positives.
1059
+
1008
1060
[detect_activity_related_to_pass_the_hash_attacks_filter]
1009
1061
definition = search *
1010
1062
description = Update this macro to limit the output results to filter out false positives.
@@ -3897,6 +3949,10 @@ description = Update this macro to limit the output results to filter out false
3897
3949
definition = search *
3898
3950
description = Update this macro to limit the output results to filter out false positives.
3899
3951
3952
+ [windows_autoit3_execution_filter]
3953
+ definition = search *
3954
+ description = Update this macro to limit the output results to filter out false positives.
3955
+
3900
3956
[windows_autostart_execution_lsass_driver_registry_modification_filter]
3901
3957
definition = search *
3902
3958
description = Update this macro to limit the output results to filter out false positives.
@@ -3917,6 +3973,10 @@ description = Update this macro to limit the output results to filter out false
3917
3973
definition = search *
3918
3974
description = Update this macro to limit the output results to filter out false positives.
3919
3975
3976
+ [windows_cab_file_on_disk_filter]
3977
+ definition = search *
3978
+ description = Update this macro to limit the output results to filter out false positives.
3979
+
3920
3980
[windows_cached_domain_credentials_reg_query_filter]
3921
3981
definition = search *
3922
3982
description = Update this macro to limit the output results to filter out false positives.
@@ -3965,6 +4025,10 @@ description = Update this macro to limit the output results to filter out false
3965
4025
definition = search *
3966
4026
description = Update this macro to limit the output results to filter out false positives.
3967
4027
4028
+ [windows_conhost_with_headless_argument_filter]
4029
+ definition = search *
4030
+ description = Update this macro to limit the output results to filter out false positives.
4031
+
3968
4032
[windows_create_local_account_filter]
3969
4033
definition = search *
3970
4034
description = Update this macro to limit the output results to filter out false positives.
@@ -4533,6 +4597,10 @@ description = Update this macro to limit the output results to filter out false
4533
4597
definition = search *
4534
4598
description = Update this macro to limit the output results to filter out false positives.
4535
4599
4600
+ [windows_msiexec_spawn_windbg_filter]
4601
+ definition = search *
4602
+ description = Update this macro to limit the output results to filter out false positives.
4603
+
4536
4604
[windows_msiexec_unregister_dllregisterserver_filter]
4537
4605
definition = search *
4538
4606
description = Update this macro to limit the output results to filter out false positives.
@@ -5137,6 +5205,10 @@ description = Update this macro to limit the output results to filter out false
5137
5205
definition = search *
5138
5206
description = Update this macro to limit the output results to filter out false positives.
5139
5207
5208
+ [windows_windbg_spawning_autoit3_filter]
5209
+ definition = search *
5210
+ description = Update this macro to limit the output results to filter out false positives.
5211
+
5140
5212
[windows_winlogon_with_public_network_connection_filter]
5141
5213
definition = search *
5142
5214
description = Update this macro to limit the output results to filter out false positives.
@@ -5610,6 +5682,10 @@ description = customer specific splunk configurations(eg- index, source, sourcet
5610
5682
definition = sourcetype=mscs:azure:audit
5611
5683
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
5612
5684
5685
+ [azure_monitor_aad]
5686
+ definition = sourcetype=azure:monitor:aad
5687
+ description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
5688
+
5613
5689
[azuread]
5614
5690
definition = sourcetype=mscs:azure:eventhub
5615
5691
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
0 commit comments