Skip to content

Commit 78f52c4

Browse files
authored
Merge pull request #3437 from splunk/fix_bad_attack_data_paths
fix weird attack data links
2 parents fe42046 + d996056 commit 78f52c4

File tree

1,764 files changed

+4734
-4740
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

1,764 files changed

+4734
-4740
lines changed

detections/application/cisco_ai_defense_security_alerts_by_application_name.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco AI Defense Security Alerts by Application Name
22
id: 105e4a69-ec55-49fc-be1f-902467435ea8
3-
version: 2
4-
date: '2025-03-21'
3+
version: 3
4+
date: '2025-05-02'
55
author: Bhavin Patel, Splunk
66
status: production
77
type: Anomaly

detections/application/cisco_secure_application_alerts.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco Secure Application Alerts
22
id: 9982bff4-fc5d-49a3-ab9e-2dbbab2a711b
3-
version: 1
4-
date: '2025-02-04'
3+
version: 2
4+
date: '2025-05-02'
55
author: Ryan Long, Bhavin Patel, Splunk
66
status: production
77
type: Anomaly

detections/application/crushftp_server_side_template_injection.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: CrushFTP Server Side Template Injection
22
id: ccf6b7a3-bd39-4bc9-a949-143a8d640dbc
3-
version: 3
4-
date: '2025-01-21'
3+
version: 4
4+
date: '2025-05-02'
55
author: Michael Haag, Splunk
66
data_source:
77
- CrushFTP

detections/application/detect_distributed_password_spray_attempts.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect Distributed Password Spray Attempts
22
id: b1a82fc8-8a9f-4344-9ec2-bde5c5331b57
3-
version: 4
4-
date: '2025-02-10'
3+
version: 5
4+
date: '2025-05-02'
55
author: Dean Luxton
66
status: production
77
type: Hunting

detections/application/detect_html_help_spawn_child_process.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect HTML Help Spawn Child Process
22
id: 723716de-ee55-4cd4-9759-c44e7e55ba4b
3-
version: 10
4-
date: '2025-02-10'
3+
version: 11
4+
date: '2025-05-02'
55
author: Michael Haag, Splunk
66
status: production
77
type: TTP

detections/application/detect_new_login_attempts_to_routers.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect New Login Attempts to Routers
22
id: bce3ed7c-9b1f-42a0-abdf-d8b123a34836
3-
version: 4
4-
date: '2025-01-21'
3+
version: 5
4+
date: '2025-05-02'
55
author: Bhavin Patel, Splunk
66
status: experimental
77
type: TTP

detections/application/detect_password_spray_attempts.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect Password Spray Attempts
22
id: 086ab581-8877-42b3-9aee-4a7ecb0923af
3-
version: 7
4-
date: '2025-02-10'
3+
version: 8
4+
date: '2025-05-02'
55
author: Dean Luxton
66
status: production
77
type: TTP

detections/application/email_attachments_with_lots_of_spaces.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Email Attachments With Lots Of Spaces
22
id: 56e877a6-1455-4479-ada6-0550dc1e22f8
3-
version: 5
4-
date: '2025-01-21'
3+
version: 6
4+
date: '2025-05-02'
55
author: David Dorsey, Splunk
66
status: experimental
77
type: Anomaly

detections/application/email_files_written_outside_of_the_outlook_directory.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Email files written outside of the Outlook directory
22
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
3-
version: 8
4-
date: '2025-02-10'
3+
version: 9
4+
date: '2025-05-02'
55
author: Bhavin Patel, Splunk
66
status: experimental
77
type: TTP

detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Email servers sending high volume traffic to hosts
22
id: 7f5fb3e1-4209-4914-90db-0ec21b556378
3-
version: 6
4-
date: '2025-02-10'
3+
version: 7
4+
date: '2025-05-02'
55
author: Bhavin Patel, Splunk
66
status: experimental
77
type: Anomaly

0 commit comments

Comments
 (0)