Skip to content

Commit 1f16d12

Browse files
committed
416 files
1 parent 27003e1 commit 1f16d12

File tree

93 files changed

+1234
-246
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

93 files changed

+1234
-246
lines changed

dist/DA-ESS-ContentUpdate/app.manifest

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"id": {
66
"group": null,
77
"name": "DA-ESS-ContentUpdate",
8-
"version": "4.15.0"
8+
"version": "4.16.0"
99
},
1010
"author": [
1111
{

dist/DA-ESS-ContentUpdate/default/analyticstories.conf

Lines changed: 234 additions & 29 deletions
Large diffs are not rendered by default.

dist/DA-ESS-ContentUpdate/default/app.conf

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-01T20:44:08 UTC
3+
# On Date: 2023-11-16T22:15:55 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############
@@ -10,7 +10,7 @@
1010
is_configured = false
1111
state = enabled
1212
state_change_requires_restart = false
13-
build = 20231101204321
13+
build = 20231116221053
1414

1515
[triggers]
1616
reload.analytic_stories = simple
@@ -26,7 +26,7 @@ reload.es_investigations = simple
2626

2727
[launcher]
2828
author = Splunk
29-
version = 4.15.0
29+
version = 4.16.0
3030
description = Explore the Analytic Stories included with ES Content Updates.
3131

3232
[ui]

dist/DA-ESS-ContentUpdate/default/collections.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-01T20:44:08 UTC
3+
# On Date: 2023-11-16T22:15:55 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-01T20:44:08 UTC
3+
# On Date: 2023-11-16T22:15:55 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############
77
[content-version]
8-
version = 4.15.0
8+
version = 4.16.0

dist/DA-ESS-ContentUpdate/default/es_investigations.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-01T20:44:08 UTC
3+
# On Date: 2023-11-16T22:15:55 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############

dist/DA-ESS-ContentUpdate/default/macros.conf

Lines changed: 85 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-01T20:44:08 UTC
3+
# On Date: 2023-11-16T22:15:55 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############
@@ -117,6 +117,10 @@ description = Update this macro to limit the output results to filter out false
117117
definition = search *
118118
description = Update this macro to limit the output results to filter out false positives.
119119

120+
[splunk_app_for_lookup_file_editing_rce_via_user_xslt_filter]
121+
definition = search *
122+
description = Update this macro to limit the output results to filter out false positives.
123+
120124
[splunk_code_injection_via_custom_dashboard_leading_to_rce_filter]
121125
definition = search *
122126
description = Update this macro to limit the output results to filter out false positives.
@@ -257,6 +261,10 @@ description = Update this macro to limit the output results to filter out false
257261
definition = search *
258262
description = Update this macro to limit the output results to filter out false positives.
259263

264+
[splunk_xss_in_highlighted_json_events_filter]
265+
definition = search *
266+
description = Update this macro to limit the output results to filter out false positives.
267+
260268
[splunk_xss_in_monitoring_console_filter]
261269
definition = search *
262270
description = Update this macro to limit the output results to filter out false positives.
@@ -593,10 +601,18 @@ description = Update this macro to limit the output results to filter out false
593601
definition = search *
594602
description = Update this macro to limit the output results to filter out false positives.
595603

604+
[azure_ad_block_user_consent_for_risky_apps_disabled_filter]
605+
definition = search *
606+
description = Update this macro to limit the output results to filter out false positives.
607+
596608
[azure_ad_concurrent_sessions_from_different_ips_filter]
597609
definition = search *
598610
description = Update this macro to limit the output results to filter out false positives.
599611

612+
[azure_ad_device_code_authentication_filter]
613+
definition = search *
614+
description = Update this macro to limit the output results to filter out false positives.
615+
600616
[azure_ad_external_guest_user_invited_filter]
601617
definition = search *
602618
description = Update this macro to limit the output results to filter out false positives.
@@ -617,6 +633,18 @@ description = Update this macro to limit the output results to filter out false
617633
definition = search *
618634
description = Update this macro to limit the output results to filter out false positives.
619635

636+
[azure_ad_multi_source_failed_authentications_spike_filter]
637+
definition = search *
638+
description = Update this macro to limit the output results to filter out false positives.
639+
640+
[azure_ad_multiple_appids_and_useragents_authentication_spike_filter]
641+
definition = search *
642+
description = Update this macro to limit the output results to filter out false positives.
643+
644+
[azure_ad_multiple_denied_mfa_requests_for_user_filter]
645+
definition = search *
646+
description = Update this macro to limit the output results to filter out false positives.
647+
620648
[azure_ad_multiple_failed_mfa_requests_for_user_filter]
621649
definition = search *
622650
description = Update this macro to limit the output results to filter out false positives.
@@ -633,10 +661,18 @@ description = Update this macro to limit the output results to filter out false
633661
definition = search *
634662
description = Update this macro to limit the output results to filter out false positives.
635663

664+
[azure_ad_new_mfa_method_registered_filter]
665+
definition = search *
666+
description = Update this macro to limit the output results to filter out false positives.
667+
636668
[azure_ad_new_mfa_method_registered_for_user_filter]
637669
definition = search *
638670
description = Update this macro to limit the output results to filter out false positives.
639671

672+
[azure_ad_oauth_application_consent_granted_by_user_filter]
673+
definition = search *
674+
description = Update this macro to limit the output results to filter out false positives.
675+
640676
[azure_ad_pim_role_assigned_filter]
641677
definition = search *
642678
description = Update this macro to limit the output results to filter out false positives.
@@ -681,10 +717,22 @@ description = Update this macro to limit the output results to filter out false
681717
definition = search *
682718
description = Update this macro to limit the output results to filter out false positives.
683719

720+
[azure_ad_tenant_wide_admin_consent_granted_filter]
721+
definition = search *
722+
description = Update this macro to limit the output results to filter out false positives.
723+
684724
[azure_ad_unusual_number_of_failed_authentications_from_ip_filter]
685725
definition = search *
686726
description = Update this macro to limit the output results to filter out false positives.
687727

728+
[azure_ad_user_consent_blocked_for_risky_application_filter]
729+
definition = search *
730+
description = Update this macro to limit the output results to filter out false positives.
731+
732+
[azure_ad_user_consent_denied_for_oauth_application_filter]
733+
definition = search *
734+
description = Update this macro to limit the output results to filter out false positives.
735+
688736
[azure_ad_user_enabled_and_password_reset_filter]
689737
definition = search *
690738
description = Update this macro to limit the output results to filter out false positives.
@@ -753,14 +801,6 @@ description = Update this macro to limit the output results to filter out false
753801
definition = search *
754802
description = Update this macro to limit the output results to filter out false positives.
755803

756-
[correlation_by_repository_and_risk_filter]
757-
definition = search *
758-
description = Update this macro to limit the output results to filter out false positives.
759-
760-
[correlation_by_user_and_risk_filter]
761-
definition = search *
762-
description = Update this macro to limit the output results to filter out false positives.
763-
764804
[detect_aws_console_login_by_new_user_filter]
765805
definition = search *
766806
description = Update this macro to limit the output results to filter out false positives.
@@ -961,6 +1001,10 @@ description = Update this macro to limit the output results to filter out false
9611001
definition = search *
9621002
description = Update this macro to limit the output results to filter out false positives.
9631003

1004+
[risk_rule_for_dev_sec_ops_by_repository_filter]
1005+
definition = search *
1006+
description = Update this macro to limit the output results to filter out false positives.
1007+
9641008
[abnormally_high_aws_instances_launched_by_user_filter]
9651009
definition = search *
9661010
description = Update this macro to limit the output results to filter out false positives.
@@ -1005,6 +1049,14 @@ description = Update this macro to limit the output results to filter out false
10051049
definition = search *
10061050
description = Update this macro to limit the output results to filter out false positives.
10071051

1052+
[correlation_by_repository_and_risk_filter]
1053+
definition = search *
1054+
description = Update this macro to limit the output results to filter out false positives.
1055+
1056+
[correlation_by_user_and_risk_filter]
1057+
definition = search *
1058+
description = Update this macro to limit the output results to filter out false positives.
1059+
10081060
[detect_activity_related_to_pass_the_hash_attacks_filter]
10091061
definition = search *
10101062
description = Update this macro to limit the output results to filter out false positives.
@@ -3897,6 +3949,10 @@ description = Update this macro to limit the output results to filter out false
38973949
definition = search *
38983950
description = Update this macro to limit the output results to filter out false positives.
38993951

3952+
[windows_autoit3_execution_filter]
3953+
definition = search *
3954+
description = Update this macro to limit the output results to filter out false positives.
3955+
39003956
[windows_autostart_execution_lsass_driver_registry_modification_filter]
39013957
definition = search *
39023958
description = Update this macro to limit the output results to filter out false positives.
@@ -3917,6 +3973,10 @@ description = Update this macro to limit the output results to filter out false
39173973
definition = search *
39183974
description = Update this macro to limit the output results to filter out false positives.
39193975

3976+
[windows_cab_file_on_disk_filter]
3977+
definition = search *
3978+
description = Update this macro to limit the output results to filter out false positives.
3979+
39203980
[windows_cached_domain_credentials_reg_query_filter]
39213981
definition = search *
39223982
description = Update this macro to limit the output results to filter out false positives.
@@ -3965,6 +4025,10 @@ description = Update this macro to limit the output results to filter out false
39654025
definition = search *
39664026
description = Update this macro to limit the output results to filter out false positives.
39674027

4028+
[windows_conhost_with_headless_argument_filter]
4029+
definition = search *
4030+
description = Update this macro to limit the output results to filter out false positives.
4031+
39684032
[windows_create_local_account_filter]
39694033
definition = search *
39704034
description = Update this macro to limit the output results to filter out false positives.
@@ -4533,6 +4597,10 @@ description = Update this macro to limit the output results to filter out false
45334597
definition = search *
45344598
description = Update this macro to limit the output results to filter out false positives.
45354599

4600+
[windows_msiexec_spawn_windbg_filter]
4601+
definition = search *
4602+
description = Update this macro to limit the output results to filter out false positives.
4603+
45364604
[windows_msiexec_unregister_dllregisterserver_filter]
45374605
definition = search *
45384606
description = Update this macro to limit the output results to filter out false positives.
@@ -5137,6 +5205,10 @@ description = Update this macro to limit the output results to filter out false
51375205
definition = search *
51385206
description = Update this macro to limit the output results to filter out false positives.
51395207

5208+
[windows_windbg_spawning_autoit3_filter]
5209+
definition = search *
5210+
description = Update this macro to limit the output results to filter out false positives.
5211+
51405212
[windows_winlogon_with_public_network_connection_filter]
51415213
definition = search *
51425214
description = Update this macro to limit the output results to filter out false positives.
@@ -5610,6 +5682,10 @@ description = customer specific splunk configurations(eg- index, source, sourcet
56105682
definition = sourcetype=mscs:azure:audit
56115683
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
56125684

5685+
[azure_monitor_aad]
5686+
definition = sourcetype=azure:monitor:aad
5687+
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
5688+
56135689
[azuread]
56145690
definition = sourcetype=mscs:azure:eventhub
56155691
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.

0 commit comments

Comments
 (0)