Skip to content

Commit

Permalink
Update dist/escu, dist/ssa, and dist/api folders with the latest cont…
Browse files Browse the repository at this point in the history
…ent associated with this tag
  • Loading branch information
research bot committed Apr 4, 2023
1 parent 79d2736 commit f6eefe8
Show file tree
Hide file tree
Showing 13 changed files with 676 additions and 43 deletions.
2 changes: 1 addition & 1 deletion dist/api/detections.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/stories.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/escu/app.manifest
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "3.63.0"
"version": "3.64.0"
},
"author": [
{
Expand Down
126 changes: 118 additions & 8 deletions dist/escu/default/analyticstories.conf

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions dist/escu/default/app.conf
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 12686
build = 12838

[triggers]
reload.analytic_stories = simple
Expand All @@ -20,7 +20,7 @@ reload.es_investigations = simple

[launcher]
author = Splunk
version = 3.63.0
version = 3.64.0
description = Explore the Analytic Stories included with ES Content Updates.

[ui]
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/collections.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-03-30T20:08:38 UTC
# On Date: 2023-04-04T18:54:41 UTC
# Author: Splunk Security Research
# Contact: [email protected]
#############
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/content-version.conf
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
[content-version]
version = 3.63.0
version = 3.64.0
2 changes: 1 addition & 1 deletion dist/escu/default/es_investigations.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-03-30T20:08:38 UTC
# On Date: 2023-04-04T18:54:41 UTC
# Author: Splunk Security Research
# Contact: [email protected]
#############
Expand Down
46 changes: 45 additions & 1 deletion dist/escu/default/macros.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2023-03-30T20:08:38 UTC
# On Date: 2023-04-04T18:54:41 UTC
# Author: Splunk Security Research
# Contact: [email protected]
#############
Expand Down Expand Up @@ -2533,6 +2533,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_enable_powershell_remoting_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_enable_smb1protocol_feature_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand All @@ -2557,6 +2561,14 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_invoke_cimmethod_cimsession_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_invoke_wmiexec_usage_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_load_module_in_meterpreter_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand All @@ -2581,6 +2593,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_start_or_stop_service_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_using_memory_as_backing_store_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3445,6 +3461,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_enable_win32_scheduledjob_via_registry_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_event_for_service_disabled_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3613,6 +3633,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_lateral_tool_transfer_remcom_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_linked_policies_in_adsi_discovery_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3813,6 +3837,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_powershell_get_ciminstance_remote_computer_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_powershell_iis_components_webglobalmodule_usage_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand All @@ -3821,6 +3849,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_powershell_wmi_win32_scheduledjob_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_powerview_constrained_delegation_discovery_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3925,6 +3957,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_remote_create_service_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_remote_service_rdpwinst_tool_execution_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3977,10 +4013,18 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_service_create_remcomsvc_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_service_create_sliverc2_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_service_create_with_tscon_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_service_created_with_suspicious_service_path_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down
Loading

0 comments on commit f6eefe8

Please sign in to comment.