Skip to content

Commit

Permalink
Update dist/escu, dist/ssa, and dist/api folders with the latest cont…
Browse files Browse the repository at this point in the history
…ent associated with this tag
  • Loading branch information
research bot committed Nov 29, 2022
1 parent f7f7946 commit eb124fb
Show file tree
Hide file tree
Showing 19 changed files with 789 additions and 123 deletions.
2 changes: 1 addition & 1 deletion dist/api/detections.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/macros.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/api/stories.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion dist/escu/app.manifest
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"id": {
"group": null,
"name": "DA-ESS-ContentUpdate",
"version": "3.53.0"
"version": "3.54.0"
},
"author": [
{
Expand Down
118 changes: 108 additions & 10 deletions dist/escu/default/analyticstories.conf

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions dist/escu/default/app.conf
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 11110
build = 11194

[triggers]
reload.analytic_stories = simple
Expand All @@ -20,7 +20,7 @@ reload.es_investigations = simple

[launcher]
author = Splunk
version = 3.53.0
version = 3.54.0
description = Explore the Analytic Stories included with ES Content Updates.

[ui]
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/collections.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-11-15T20:45:39 UTC
# On Date: 2022-11-29T22:43:40 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down
2 changes: 1 addition & 1 deletion dist/escu/default/content-version.conf
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
[content-version]
version = 3.53.0
version = 3.54.0
2 changes: 1 addition & 1 deletion dist/escu/default/es_investigations.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-11-15T20:45:39 UTC
# On Date: 2022-11-29T22:43:40 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down
30 changes: 29 additions & 1 deletion dist/escu/default/macros.conf
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2022-11-15T20:45:39 UTC
# On Date: 2022-11-29T22:43:40 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
Expand Down Expand Up @@ -2501,6 +2501,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_load_module_in_meterpreter_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[powershell_loading_dotnet_into_memory_via_reflection_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3141,6 +3145,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_apache_benchmark_binary_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_app_layer_protocol_qakbot_namedpipe_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3453,6 +3461,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_mimikatz_binary_execution_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_modify_registry_disable_toast_notifications_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3493,6 +3505,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_msexchange_management_mailbox_cmdlet_usage_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_mshta_execution_in_registry_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -3521,6 +3537,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_ngrok_reverse_proxy_usage_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[windows_nirsoft_advancedrun_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4309,6 +4329,10 @@ description = Update this macro to limit the output results to filter out false
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[ngrok_reverse_proxy_on_network_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.

[plain_http_post_exfiltrated_data_filter]
definition = search *
description = Update this macro to limit the output results to filter out false positives.
Expand Down Expand Up @@ -4574,6 +4598,10 @@ description = customer specific splunk configurations(eg- index, source, sourcet
definition = (Processes.process_name IN ("sh", "ksh", "zsh", "bash", "dash", "rbash", "fish", "csh", "tcsh", "ion", "eshell"))
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.

[msexchange_management]
definition = sourcetype=MSExchange:management
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.

[netbackup]
definition = sourcetype="netbackup_logs"
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
Expand Down
Loading

0 comments on commit eb124fb

Please sign in to comment.