Skip to content

Commit

Permalink
Update dist/escu, dist/ssa, and dist/api folders with the latest cont…
Browse files Browse the repository at this point in the history
…ent associated with this tag
  • Loading branch information
research bot committed Oct 18, 2023
1 parent ba0e12c commit 7df57b0
Show file tree
Hide file tree
Showing 81 changed files with 1,029 additions and 406 deletions.
2 changes: 1 addition & 1 deletion dist/api/detections.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/lookups.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/macros.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/stories.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/escu/app.manifest
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "4.13.0"
"version": "4.14.0"
},
"author": [
{
Expand Down
285 changes: 216 additions & 69 deletions dist/escu/default/analyticstories.conf

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions dist/escu/default/app.conf
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 17306
build = 17448

[triggers]
reload.analytic_stories = simple
Expand All @@ -20,7 +20,7 @@ reload.es_investigations = simple

[launcher]
author = Splunk
version = 4.13.0
version = 4.14.0
description = Explore the Analytic Stories included with ES Content Updates.

[ui]
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/collections.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-10-04T22:36:05 UTC
# On Date: 2023-10-18T20:29:18 UTC
# Author: Splunk Security Research
# Contact: [email protected]
#############
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/content-version.conf
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
[content-version]
version = 4.13.0
version = 4.14.0
2 changes: 1 addition & 1 deletion dist/escu/default/es_investigations.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-10-04T22:36:05 UTC
# On Date: 2023-10-18T20:29:18 UTC
# Author: Splunk Security Research
# Contact: [email protected]
#############
Expand Down
46 changes: 45 additions & 1 deletion dist/escu/default/macros.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-10-04T22:36:05 UTC
# On Date: 2023-10-18T20:29:18 UTC
# Author: Splunk Security Research
# Contact: [email protected]
#############
Expand Down Expand Up @@ -1573,6 +1573,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[detect_certipy_file_modifications_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[detect_computer_changed_with_anonymous_account_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4105,6 +4109,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_domain_admin_impersonation_indicator_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_dotnet_binary_in_non_standard_path_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4793,6 +4801,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_registry_sip_provider_modification_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_regsvr32_renamed_binary_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4933,6 +4945,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_sip_provider_inventory_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_sip_winverifytrust_failed_trust_validation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_snake_malware_file_modification_crmlog_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4989,6 +5009,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_steal_authentication_certificates___esc1_abuse_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_steal_authentication_certificates_export_certificate_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -5389,6 +5413,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[cisco_ios_xe_implant_access_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[citrix_adc_exploitation_cve_2023_3519_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand All @@ -5397,6 +5425,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[confluence_cve_2023_22515_trigger_vulnerability_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[confluence_data_center_and_server_privilege_escalation_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[confluence_unauthenticated_remote_code_execution_cve_2022_26134_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -5457,6 +5493,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[microsoft_sharepoint_server_elevation_of_privilege_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[monitor_web_traffic_for_brand_abuse_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -6131,6 +6171,10 @@ description = customer specific splunk configurations(eg- index, source, sourcet
definition = sourcetype=stream:tcp
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.

[subjectinterfacepackage]
definition = sourcetype="PwSh:SubjectInterfacePackage"
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.

[suspicious_email_attachments]
definition = lookup update=true is_suspicious_file_extension_lookup file_name OUTPUT suspicious | search suspicious=true
description = This macro limits the output to email attachments that have suspicious extensions
Expand Down
Loading

0 comments on commit 7df57b0

Please sign in to comment.