Skip to content

Commit aa23a18

Browse files
author
research bot
committed
removing CODEOWNERS
1 parent 65e5672 commit aa23a18

19 files changed

+3085
-789
lines changed

CODEOWNERS

Lines changed: 0 additions & 2 deletions
This file was deleted.

dist/DA-ESS-ContentUpdate/app.manifest

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
"id": {
66
"group": null,
77
"name": "DA-ESS-ContentUpdate",
8-
"version": "4.16.0"
8+
"version": "4.17.0"
99
},
1010
"author": [
1111
{

dist/DA-ESS-ContentUpdate/default/analyticstories.conf

Lines changed: 453 additions & 31 deletions
Large diffs are not rendered by default.

dist/DA-ESS-ContentUpdate/default/app.conf

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-16T20:58:41 UTC
3+
# On Date: 2023-12-06T21:36:36 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############
@@ -10,7 +10,7 @@
1010
is_configured = false
1111
state = enabled
1212
state_change_requires_restart = false
13-
build = 20231116205612
13+
build = 20231206213413
1414

1515
[triggers]
1616
reload.analytic_stories = simple
@@ -26,7 +26,7 @@ reload.es_investigations = simple
2626

2727
[launcher]
2828
author = Splunk
29-
version = 4.16.0
29+
version = 4.17.0
3030
description = Explore the Analytic Stories included with ES Content Updates.
3131

3232
[ui]

dist/DA-ESS-ContentUpdate/default/collections.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-16T20:58:41 UTC
3+
# On Date: 2023-12-06T21:36:36 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-16T20:58:41 UTC
3+
# On Date: 2023-12-06T21:36:36 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############
77
[content-version]
8-
version = 4.16.0
8+
version = 4.17.0

dist/DA-ESS-ContentUpdate/default/es_investigations.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-16T20:58:41 UTC
3+
# On Date: 2023-12-06T21:36:36 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############

dist/DA-ESS-ContentUpdate/default/macros.conf

Lines changed: 165 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security_content
3-
# On Date: 2023-11-16T20:58:41 UTC
3+
# On Date: 2023-12-06T21:36:36 UTC
44
# Author: Splunk Threat Research Team - Splunk
55
66
#############
@@ -233,6 +233,10 @@ description = Update this macro to limit the output results to filter out false
233233
definition = search *
234234
description = Update this macro to limit the output results to filter out false positives.
235235

236+
[splunk_rce_via_user_xslt_filter]
237+
definition = search *
238+
description = Update this macro to limit the output results to filter out false positives.
239+
236240
[splunk_reflected_xss_in_the_templates_lists_radio_filter]
237241
definition = search *
238242
description = Update this macro to limit the output results to filter out false positives.
@@ -965,6 +969,22 @@ description = Update this macro to limit the output results to filter out false
965969
definition = search *
966970
description = Update this macro to limit the output results to filter out false positives.
967971

972+
[o365_advanced_audit_disabled_filter]
973+
definition = search *
974+
description = Update this macro to limit the output results to filter out false positives.
975+
976+
[o365_application_registration_owner_added_filter]
977+
definition = search *
978+
description = Update this macro to limit the output results to filter out false positives.
979+
980+
[o365_applicationimpersonation_role_assigned_filter]
981+
definition = search *
982+
description = Update this macro to limit the output results to filter out false positives.
983+
984+
[o365_block_user_consent_for_risky_apps_disabled_filter]
985+
definition = search *
986+
description = Update this macro to limit the output results to filter out false positives.
987+
968988
[o365_bypass_mfa_via_trusted_ip_filter]
969989
definition = search *
970990
description = Update this macro to limit the output results to filter out false positives.
@@ -981,14 +1001,62 @@ description = Update this macro to limit the output results to filter out false
9811001
definition = search *
9821002
description = Update this macro to limit the output results to filter out false positives.
9831003

1004+
[o365_file_permissioned_application_consent_granted_by_user_filter]
1005+
definition = search *
1006+
description = Update this macro to limit the output results to filter out false positives.
1007+
1008+
[o365_high_number_of_failed_authentications_for_user_filter]
1009+
definition = search *
1010+
description = Update this macro to limit the output results to filter out false positives.
1011+
1012+
[o365_high_privilege_role_granted_filter]
1013+
definition = search *
1014+
description = Update this macro to limit the output results to filter out false positives.
1015+
1016+
[o365_mail_permissioned_application_consent_granted_by_user_filter]
1017+
definition = search *
1018+
description = Update this macro to limit the output results to filter out false positives.
1019+
1020+
[o365_mailbox_inbox_folder_shared_with_all_users_filter]
1021+
definition = search *
1022+
description = Update this macro to limit the output results to filter out false positives.
1023+
1024+
[o365_mailbox_read_access_granted_to_application_filter]
1025+
definition = search *
1026+
description = Update this macro to limit the output results to filter out false positives.
1027+
1028+
[o365_multi_source_failed_authentications_spike_filter]
1029+
definition = search *
1030+
description = Update this macro to limit the output results to filter out false positives.
1031+
1032+
[o365_multiple_appids_and_useragents_authentication_spike_filter]
1033+
definition = search *
1034+
description = Update this macro to limit the output results to filter out false positives.
1035+
1036+
[o365_multiple_failed_mfa_requests_for_user_filter]
1037+
definition = search *
1038+
description = Update this macro to limit the output results to filter out false positives.
1039+
1040+
[o365_multiple_users_failing_to_authenticate_from_ip_filter]
1041+
definition = search *
1042+
description = Update this macro to limit the output results to filter out false positives.
1043+
9841044
[o365_new_federated_domain_added_filter]
9851045
definition = search *
9861046
description = Update this macro to limit the output results to filter out false positives.
9871047

1048+
[o365_new_mfa_method_registered_filter]
1049+
definition = search *
1050+
description = Update this macro to limit the output results to filter out false positives.
1051+
9881052
[o365_pst_export_alert_filter]
9891053
definition = search *
9901054
description = Update this macro to limit the output results to filter out false positives.
9911055

1056+
[o365_service_principal_new_client_credentials_filter]
1057+
definition = search *
1058+
description = Update this macro to limit the output results to filter out false positives.
1059+
9921060
[o365_suspicious_admin_email_forwarding_filter]
9931061
definition = search *
9941062
description = Update this macro to limit the output results to filter out false positives.
@@ -1001,6 +1069,18 @@ description = Update this macro to limit the output results to filter out false
10011069
definition = search *
10021070
description = Update this macro to limit the output results to filter out false positives.
10031071

1072+
[o365_tenant_wide_admin_consent_granted_filter]
1073+
definition = search *
1074+
description = Update this macro to limit the output results to filter out false positives.
1075+
1076+
[o365_user_consent_blocked_for_risky_application_filter]
1077+
definition = search *
1078+
description = Update this macro to limit the output results to filter out false positives.
1079+
1080+
[o365_user_consent_denied_for_oauth_application_filter]
1081+
definition = search *
1082+
description = Update this macro to limit the output results to filter out false positives.
1083+
10041084
[risk_rule_for_dev_sec_ops_by_repository_filter]
10051085
definition = search *
10061086
description = Update this macro to limit the output results to filter out false positives.
@@ -3133,6 +3213,10 @@ description = Update this macro to limit the output results to filter out false
31333213
definition = search *
31343214
description = Update this macro to limit the output results to filter out false positives.
31353215

3216+
[powershell_remote_services_add_trustedhost_filter]
3217+
definition = search *
3218+
description = Update this macro to limit the output results to filter out false positives.
3219+
31363220
[powershell_remote_thread_to_known_windows_process_filter]
31373221
definition = search *
31383222
description = Update this macro to limit the output results to filter out false positives.
@@ -3949,6 +4033,10 @@ description = Update this macro to limit the output results to filter out false
39494033
definition = search *
39504034
description = Update this macro to limit the output results to filter out false positives.
39514035

4036+
[windows_archive_collected_data_via_rar_filter]
4037+
definition = search *
4038+
description = Update this macro to limit the output results to filter out false positives.
4039+
39524040
[windows_autoit3_execution_filter]
39534041
definition = search *
39544042
description = Update this macro to limit the output results to filter out false positives.
@@ -4049,6 +4137,14 @@ description = Update this macro to limit the output results to filter out false
40494137
definition = search *
40504138
description = Update this macro to limit the output results to filter out false positives.
40514139

4140+
[windows_credentials_from_password_stores_creation_filter]
4141+
definition = search *
4142+
description = Update this macro to limit the output results to filter out false positives.
4143+
4144+
[windows_credentials_from_password_stores_deletion_filter]
4145+
definition = search *
4146+
description = Update this macro to limit the output results to filter out false positives.
4147+
40524148
[windows_credentials_from_password_stores_query_filter]
40534149
definition = search *
40544150
description = Update this macro to limit the output results to filter out false positives.
@@ -4081,6 +4177,26 @@ description = Update this macro to limit the output results to filter out false
40814177
definition = search *
40824178
description = Update this macro to limit the output results to filter out false positives.
40834179

4180+
[windows_defender_asr_audit_events_filter]
4181+
definition = search *
4182+
description = Update this macro to limit the output results to filter out false positives.
4183+
4184+
[windows_defender_asr_block_events_filter]
4185+
definition = search *
4186+
description = Update this macro to limit the output results to filter out false positives.
4187+
4188+
[windows_defender_asr_registry_modification_filter]
4189+
definition = search *
4190+
description = Update this macro to limit the output results to filter out false positives.
4191+
4192+
[windows_defender_asr_rule_disabled_filter]
4193+
definition = search *
4194+
description = Update this macro to limit the output results to filter out false positives.
4195+
4196+
[windows_defender_asr_rules_stacking_filter]
4197+
definition = search *
4198+
description = Update this macro to limit the output results to filter out false positives.
4199+
40844200
[windows_defender_exclusion_registry_entry_filter]
40854201
definition = search *
40864202
description = Update this macro to limit the output results to filter out false positives.
@@ -4357,6 +4473,10 @@ description = Update this macro to limit the output results to filter out false
43574473
definition = search *
43584474
description = Update this macro to limit the output results to filter out false positives.
43594475

4476+
[windows_indicator_removal_via_rmdir_filter]
4477+
definition = search *
4478+
description = Update this macro to limit the output results to filter out false positives.
4479+
43604480
[windows_indirect_command_execution_via_forfiles_filter]
43614481
definition = search *
43624482
description = Update this macro to limit the output results to filter out false positives.
@@ -4453,6 +4573,10 @@ description = Update this macro to limit the output results to filter out false
44534573
definition = search *
44544574
description = Update this macro to limit the output results to filter out false positives.
44554575

4576+
[windows_masquerading_msdtc_process_filter]
4577+
definition = search *
4578+
description = Update this macro to limit the output results to filter out false positives.
4579+
44564580
[windows_mimikatz_binary_execution_filter]
44574581
definition = search *
44584582
description = Update this macro to limit the output results to filter out false positives.
@@ -4461,6 +4585,10 @@ description = Update this macro to limit the output results to filter out false
44614585
definition = search *
44624586
description = Update this macro to limit the output results to filter out false positives.
44634587

4588+
[windows_modify_registry_authenticationleveloverride_filter]
4589+
definition = search *
4590+
description = Update this macro to limit the output results to filter out false positives.
4591+
44644592
[windows_modify_registry_auto_minor_updates_filter]
44654593
definition = search *
44664594
description = Update this macro to limit the output results to filter out false positives.
@@ -4489,6 +4617,14 @@ description = Update this macro to limit the output results to filter out false
44894617
definition = search *
44904618
description = Update this macro to limit the output results to filter out false positives.
44914619

4620+
[windows_modify_registry_disableremotedesktopantialias_filter]
4621+
definition = search *
4622+
description = Update this macro to limit the output results to filter out false positives.
4623+
4624+
[windows_modify_registry_disablesecuritysettings_filter]
4625+
definition = search *
4626+
description = Update this macro to limit the output results to filter out false positives.
4627+
44924628
[windows_modify_registry_disabling_wer_settings_filter]
44934629
definition = search *
44944630
description = Update this macro to limit the output results to filter out false positives.
@@ -4501,6 +4637,10 @@ description = Update this macro to limit the output results to filter out false
45014637
definition = search *
45024638
description = Update this macro to limit the output results to filter out false positives.
45034639

4640+
[windows_modify_registry_dontshowui_filter]
4641+
definition = search *
4642+
description = Update this macro to limit the output results to filter out false positives.
4643+
45044644
[windows_modify_registry_enablelinkedconnections_filter]
45054645
definition = search *
45064646
description = Update this macro to limit the output results to filter out false positives.
@@ -4521,6 +4661,14 @@ description = Update this macro to limit the output results to filter out false
45214661
definition = search *
45224662
description = Update this macro to limit the output results to filter out false positives.
45234663

4664+
[windows_modify_registry_proxyenable_filter]
4665+
definition = search *
4666+
description = Update this macro to limit the output results to filter out false positives.
4667+
4668+
[windows_modify_registry_proxyserver_filter]
4669+
definition = search *
4670+
description = Update this macro to limit the output results to filter out false positives.
4671+
45244672
[windows_modify_registry_qakbot_binary_data_registry_filter]
45254673
definition = search *
45264674
description = Update this macro to limit the output results to filter out false positives.
@@ -4681,6 +4829,10 @@ description = Update this macro to limit the output results to filter out false
46814829
definition = search *
46824830
description = Update this macro to limit the output results to filter out false positives.
46834831

4832+
[windows_parent_pid_spoofing_with_explorer_filter]
4833+
definition = search *
4834+
description = Update this macro to limit the output results to filter out false positives.
4835+
46844836
[windows_password_managers_discovery_filter]
46854837
definition = search *
46864838
description = Update this macro to limit the output results to filter out false positives.
@@ -5617,6 +5769,10 @@ description = Update this macro to limit the output results to filter out false
56175769
definition = search *
56185770
description = Update this macro to limit the output results to filter out false positives.
56195771

5772+
[web_remote_shellservlet_access_filter]
5773+
definition = search *
5774+
description = Update this macro to limit the output results to filter out false positives.
5775+
56205776
[web_spring4shell_http_request_class_module_filter]
56215777
definition = search *
56225778
description = Update this macro to limit the output results to filter out false positives.
@@ -5878,6 +6034,10 @@ description = customer specific splunk configurations(eg- index, source, sourcet
58786034
definition = (Processes.process_name IN ("sh", "ksh", "zsh", "bash", "dash", "rbash", "fish", "csh", "tcsh", "ion", "eshell"))
58796035
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
58806036

6037+
[ms_defender]
6038+
definition = source="WinEventLog:Microsoft-Windows-Windows Defender/Operational"
6039+
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
6040+
58816041
[msexchange_management]
58826042
definition = sourcetype=MSExchange:management
58836043
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
@@ -5894,6 +6054,10 @@ description = This is a list of AWS event names that are associated with Network
58946054
definition = index=notable
58956055
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
58966056

6057+
[o365_graph]
6058+
definition = sourcetype=o365:graph:api
6059+
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
6060+
58976061
[o365_management_activity]
58986062
definition = sourcetype=o365:management:activity
58996063
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.

0 commit comments

Comments
 (0)