Skip to content

added data source for new technique of attack#1019

Merged
patel-bhavin merged 4 commits intosplunk:masterfrom
CheraghiMilad:attack_data_forlinux_auditd_sysrq
Sep 3, 2025
Merged

added data source for new technique of attack#1019
patel-bhavin merged 4 commits intosplunk:masterfrom
CheraghiMilad:attack_data_forlinux_auditd_sysrq

Conversation

@CheraghiMilad
Copy link
Copy Markdown
Contributor

I am writing a detection rule for a specific attack technique in Splunk, and I need to include my data source here. The technique name is linux_auditd_magic_system_request_key

@patel-bhavin
Copy link
Copy Markdown
Collaborator

When the data is uploaded correctly, Github will show you that :
image

@CheraghiMilad
Copy link
Copy Markdown
Contributor Author

@patel-bhavin Thanks for guiding me.

@patel-bhavin
Copy link
Copy Markdown
Collaborator

patel-bhavin commented Aug 29, 2025

@CheraghiMilad : great! PR is looking good,. we will merge this so that we can run unit-testing in the security content repo

For now please ignore the failing validate-attack-data (pull_request)

@CheraghiMilad
Copy link
Copy Markdown
Contributor Author

great! PR is looking good,. we will merge this so that we can run unit-testing in the security content repo

For now please ignore the failing validate-attack-data (pull_request)

Sure, thanks! Please let me know if there’s anything I need to do.

@CheraghiMilad
Copy link
Copy Markdown
Contributor Author

@patel-bhavin
Security-Content PR is failed becuase this merge needed. Could you merge it?

@patel-bhavin
Copy link
Copy Markdown
Collaborator

ignoring the CI failure here since it is originating from a fork! file verified manually!

@patel-bhavin patel-bhavin merged commit 01a14ec into splunk:master Sep 3, 2025
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants