Skip to content

Commit bd1b475

Browse files
authored
Merge pull request #4088 from splunk/escu6_manual_review
ESCU 6 Manual Migrations
2 parents 81bdcbb + e84529f commit bd1b475

165 files changed

Lines changed: 4878 additions & 2093 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.vscode/settings.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@
1717
"./schemas/KVStoreLookup.schema.json": "lookups/kvstore/*.yml",
1818
"./schemas/FilebackedMacro.schema.json": "macros/*.yml",
1919
"./schemas/FilebackedSchedule.schema.json": "schedules/*.yml",
20+
"./schemas/Playbook.schema.json": "playbooks/*.yml",
2021
"./schemas/Story.schema.json": ["stories/*.yml", "!removed/stories/*.yml"]
2122
}
2223
}

baselines/baseline_of_network_acl_activity_by_arn.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,3 @@ product:
1616
- Splunk Cloud
1717
security_domain: network
1818
schedule: Default Baseline
19-
MANUAL_REVIEW:
20-
rba: {}
21-
manual_review_rationale: 'Baseline references detections that do not exist in the corpus: Detect Spike in Network ACL Activity'

baselines/baseline_of_security_group_activity_by_arn.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,3 @@ product:
1616
- Splunk Cloud
1717
security_domain: network
1818
schedule: Default Baseline
19-
MANUAL_REVIEW:
20-
rba: {}
21-
manual_review_rationale: 'Baseline references detections that do not exist in the corpus: Detect Spike in Security Group Activity'

baselines/create_a_list_of_approved_aws_service_accounts.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,3 @@ product:
1616
- Splunk Cloud
1717
security_domain: network
1818
schedule: Default Baseline
19-
MANUAL_REVIEW:
20-
rba: {}
21-
manual_review_rationale: 'Baseline references detections that do not exist in the corpus: Detect AWS API Activities From Unapproved Accounts'

baselines/discover_dns_records.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,3 @@ product:
1616
- Splunk Cloud
1717
security_domain: network
1818
schedule: Default Baseline
19-
MANUAL_REVIEW:
20-
rba: {}
21-
manual_review_rationale: 'Baseline references detections that do not exist in the corpus: DNS record changed'

baselines/dnstwist_domain_names.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,3 @@ product:
1616
- Splunk Cloud
1717
security_domain: network
1818
schedule: Default Baseline
19-
MANUAL_REVIEW:
20-
rba: {}
21-
manual_review_rationale: 'Baseline references detections that do not exist in the corpus: Monitor DNS For Brand Abuse'

baselines/previously_seen_command_line_arguments.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,3 @@ product:
1616
- Splunk Cloud
1717
security_domain: endpoint
1818
schedule: Default Baseline
19-
MANUAL_REVIEW:
20-
rba: {}
21-
manual_review_rationale: 'Baseline references detections that do not exist in the corpus: First time seen command line argument'

contentctl.yml

Lines changed: 268 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,268 @@
1+
path: .
2+
app:
3+
uid: 3449
4+
title: ES Content Updates
5+
appid: DA-ESS-ContentUpdate
6+
version: 6.0.0
7+
description: Explore the Analytic Stories included with ES Content Updates.
8+
prefix: ESCU
9+
label: ESCU
10+
author_name: Splunk Threat Research Team
11+
author_email: research@splunk.com
12+
author_company: Splunk
13+
enrichments: false
14+
build_app: true
15+
build_api: true
16+
build_ssa: false
17+
build_path: dist
18+
test_instance:
19+
splunk_app_username: admin
20+
instance_address: localhost
21+
hec_port: 8088
22+
web_ui_port: 8000
23+
api_port: 8089
24+
container_settings:
25+
full_image_path: registry.hub.docker.com/splunk/splunk:9.3
26+
leave_running: true
27+
num_containers: 1
28+
mode: {}
29+
splunk_api_username: null
30+
post_test_behavior: pause_on_failure
31+
apps:
32+
- uid: 1621
33+
title: Splunk_SA_CIM
34+
appid: Splunk_SA_CIM
35+
version: 8.5.0
36+
description: description of app
37+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-common-information-model-cim_850.tgz
38+
- uid: 6553
39+
title: Splunk Add-on for Okta Identity Cloud
40+
appid: Splunk_TA_okta_identity_cloud
41+
version: 5.0.2
42+
description: description of app
43+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-okta-identity-cloud_502.tgz
44+
- uid: 7404
45+
title: Cisco Security Cloud
46+
appid: CiscoSecurityCloud
47+
version: 3.6.5
48+
description: description of app
49+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-security-cloud_365.tgz
50+
- uid: 7569
51+
title: Cisco Secure Access Add-on for Splunk
52+
appid: TA-cisco-cloud-security-addon
53+
version: 1.0.50
54+
description: description of app
55+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-secure-access-add-on-for-splunk_1050.tar.gz
56+
- uid: 6652
57+
title: Add-on for Linux Sysmon
58+
appid: Splunk_TA_linux_sysmon
59+
version: 1.0.0
60+
description: description of app
61+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-sysmon-for-linux_100.tgz
62+
- uid: null
63+
title: Splunk Fix XmlWinEventLog HEC Parsing
64+
appid: Splunk_FIX_XMLWINEVENTLOG_HEC_PARSING
65+
version: '0.1'
66+
description: This TA is required for replaying Windows Data into the Test Environment.
67+
The Default TA does not include logic for properly splitting multiple log events
68+
in a single file. In production environments, this logic is applied by the Universal
69+
Forwarder.
70+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz
71+
- uid: 742
72+
title: Splunk Add-on for Microsoft Windows
73+
appid: SPLUNK_ADD_ON_FOR_MICROSOFT_WINDOWS
74+
version: 10.0.1
75+
description: description of app
76+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-windows_1001.tgz
77+
- uid: 5709
78+
title: Splunk Add-on for Sysmon
79+
appid: Splunk_TA_microsoft_sysmon
80+
version: 5.0.0
81+
description: description of app
82+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-sysmon_500.tgz
83+
- uid: 833
84+
title: Splunk Add-on for Unix and Linux
85+
appid: Splunk_TA_nix
86+
version: 10.2.0
87+
description: description of app
88+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-unix-and-linux_1020.tgz
89+
- uid: 5579
90+
title: Splunk Add-on for CrowdStrike FDR
91+
appid: Splunk_TA_CrowdStrike_FDR
92+
version: 2.0.5
93+
description: description of app
94+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-crowdstrike-fdr_205.tgz
95+
- uid: 3185
96+
title: Splunk Add-on for Microsoft IIS
97+
appid: SPLUNK_TA_FOR_IIS
98+
version: 1.3.0
99+
description: description of app
100+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-iis_130.tgz
101+
- uid: 6994
102+
title: CCX Add-on for Suricata
103+
appid: SPLUNK_TA_FOR_SURICATA
104+
version: 1.0.1
105+
description: description of app
106+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/ccx-add-on-for-suricata_101.tgz
107+
- uid: 5466
108+
title: TA for Zeek
109+
appid: SPLUNK_TA_FOR_ZEEK
110+
version: 1.0.11
111+
description: description of app
112+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/ta-for-zeek_1011.tgz
113+
- uid: 3258
114+
title: Splunk Add-on for NGINX
115+
appid: SPLUNK_ADD_ON_FOR_NGINX
116+
version: 3.3.0
117+
description: description of app
118+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-nginx_330.tgz
119+
- uid: 5238
120+
title: Splunk Add-on for Stream Forwarders
121+
appid: SPLUNK_ADD_ON_FOR_STREAM_FORWARDERS
122+
version: 8.1.3
123+
description: description of app
124+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-stream-forwarders_813.tgz
125+
- uid: 5234
126+
title: Splunk Add-on for Stream Wire Data
127+
appid: SPLUNK_ADD_ON_FOR_STREAM_WIRE_DATA
128+
version: 8.1.6
129+
description: description of app
130+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-stream-wire-data_816.tgz
131+
- uid: 2757
132+
title: Splunk Add-on for Palo Alto Networks
133+
appid: SPLUNK_ADD_ON_FOR_PALO_ALTO_NETWORKS
134+
version: 3.0.1
135+
description: description of app
136+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-palo-alto-networks_301.tgz
137+
- uid: 3865
138+
title: Zscaler Technical Add-On for Splunk
139+
appid: Zscaler_CIM
140+
version: 4.0.16
141+
description: description of app
142+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/zscaler-technical-add-on-for-splunk_4016.tgz
143+
- uid: 3719
144+
title: Splunk Add-on for Amazon Kinesis Firehose
145+
appid: SPLUNK_ADD_ON_FOR_AMAZON_KINESIS_FIREHOSE
146+
version: 1.3.2
147+
description: description of app
148+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-kinesis-firehose_132.tgz
149+
- uid: 1876
150+
title: Splunk Add-on for AWS
151+
appid: Splunk_TA_aws
152+
version: 8.1.1
153+
description: description of app
154+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-amazon-web-services-aws_811.tgz
155+
- uid: 3088
156+
title: Splunk Add-on for Google Cloud Platform
157+
appid: SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM
158+
version: 4.7.0
159+
description: description of app
160+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-cloud-platform_470.tgz
161+
- uid: 5556
162+
title: Splunk Add-on for Google Workspace
163+
appid: SPLUNK_ADD_ON_FOR_GOOGLE_WORKSPACE
164+
version: 3.1.1
165+
description: description of app
166+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-workspace_311.tgz
167+
- uid: 3110
168+
title: Splunk Add-on for Microsoft Cloud Services
169+
appid: SPLUNK_TA_MICROSOFT_CLOUD_SERVICES
170+
version: 6.1.1
171+
description: description of app
172+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-cloud-services_611.tgz
173+
- uid: 4055
174+
title: Splunk Add-on for Microsoft Office 365
175+
appid: SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365
176+
version: 6.0.2
177+
description: description of app
178+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-office-365_602.tgz
179+
- uid: 5518
180+
title: Splunk add on for Microsoft Defender Advanced Hunting
181+
appid: SPLUNK_ADD_ON_FOR_MICROSOFT_DEFENDER_ADVANCED_HUNTING
182+
version: 1.4.2
183+
description: description of app
184+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/microsoft-defender-advanced-hunting-add-on-for-splunk_142.tgz
185+
- uid: 6207
186+
title: Splunk Add-on for Microsoft Security
187+
appid: Splunk_TA_MS_Security
188+
version: 3.0.0
189+
description: description of app
190+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-microsoft-security_300.tgz
191+
- uid: 2734
192+
title: URL Toolbox
193+
appid: URL_TOOLBOX
194+
version: 1.9.4
195+
description: description of app
196+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/url-toolbox_194.tgz
197+
- uid: 6853
198+
title: Splunk Add-on for Admon Enrichment
199+
appid: SA-admon
200+
version: 1.1.2
201+
description: description of app
202+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-admon-enrichment_112.tgz
203+
- uid: 5082
204+
title: CrowdStrike Falcon Event Streams Technical Add-On
205+
appid: TA-crowdstrike-falcon-event-streams
206+
version: 3.2.1
207+
description: description of app
208+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/crowdstrike-falcon-event-streams-technical-add-on_321.tgz
209+
- uid: 6254
210+
title: Splunk Add-on for Github
211+
appid: Splunk_TA_github
212+
version: 3.2.0
213+
description: description of app
214+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-github_320.tgz
215+
- uid: 3471
216+
title: Splunk Add-on for AppDynamics
217+
appid: Splunk_TA_AppDynamics
218+
version: 3.2.1
219+
description: The Splunk Add-on for AppDynamics enables you to easily configure data
220+
inputs to pull data from AppDynamics' REST APIs
221+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_321.tgz
222+
- uid: 4221
223+
title: Cisco NVM Add-on for Splunk
224+
appid: TA-Cisco-NVM
225+
version: 4.0.7
226+
description: The Cisco Endpoint Security Analytics (CESA) Add-On for Splunk allows
227+
IT administrators to analyze and correlate user and endpoint behavior in Splunk
228+
Enterprise. This Add-on provides configuration and collection of data from the
229+
Cisco AnyConnect Network Visibility Module IPFIX (nvzFlow) Collector. This module
230+
collects additional context such as user, device, application, location and destination
231+
for flows both on and off premise.
232+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-endpoint-security-analytics-cesa-add-on-for-splunk_407.tgz
233+
- uid: 5603
234+
title: Add-on for VMware ESXi Logs
235+
appid: Splunk_TA_esxilogs
236+
version: 4.2.2
237+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-vmware-esxi-logs_422.tgz
238+
- uid: 5640
239+
title: Splunk Add-on for VMware Indexes
240+
appid: SPLUNK_ADD_ON_FOR_VMWARE_INDEXES
241+
version: 4.0.3
242+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-vmware-indexes_403.tgz
243+
- uid: 1467
244+
title: Cisco Networks Add-on
245+
appid: TA-cisco_ios
246+
version: 2.7.9
247+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/add-on-for-cisco-network-data_279.tgz
248+
- uid: 8024
249+
title: TA-ollama
250+
appid: ta-ollama
251+
version: 0.1.5
252+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/ta-ollama_015.tgz
253+
- uid: 8377
254+
title: MCP TA
255+
appid: mcp-ta
256+
version: 0.1.2
257+
description: description of app
258+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/mcp-ta_012.tgz
259+
- uid: 8574
260+
title: TA-osquery
261+
appid: ta-osquery
262+
version: 1.0.4
263+
description: description of app
264+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/ta-osquery_104.tgz
265+
githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
266+
test_data_caches:
267+
- base_url: https://media.githubusercontent.com/media/splunk/attack_data/master/
268+
base_directory_name: external_repos/attack_data

detections/application/esxi_external_root_login_activity.yml

Lines changed: 2 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -26,11 +26,11 @@ intermediate_findings:
2626
- field: dest
2727
type: system
2828
score: 20
29-
message: Root logged in on ESXi host $dest$ from $SrcIpAddr.
29+
message: Root logged in on ESXi host $dest$ from $SrcIpAddr$.
3030
- field: SrcIpAddr
3131
type: system
3232
score: 20
33-
message: Root logged in on ESXi host $dest$ from $SrcIpAddr.
33+
message: Root logged in on ESXi host $dest$ from $SrcIpAddr$.
3434
analytic_story:
3535
- ESXi Post Compromise
3636
- Black Basta Ransomware
@@ -50,15 +50,3 @@ tests:
5050
source: vmware:esxlog
5151
sourcetype: vmw-syslog
5252
test_type: unit
53-
MANUAL_REVIEW:
54-
rba:
55-
message: Root logged in on ESXi host $dest$ from $SrcIpAddr.
56-
risk_objects:
57-
- field: dest
58-
type: system
59-
score: 20
60-
- field: SrcIpAddr
61-
type: system
62-
score: 20
63-
threat_objects: []
64-
manual_review_rationale: "The following error was found while validating the intermediate finding message: 1 validation error for EsTokenString\n Value error, Unbalanced $ delimiter in token string: 'Root logged in on ESXi host $dest$ from $SrcIpAddr.'. Each $ must be part of a $field_name$ token pair. [type=value_error, input_value='Root logged in on ESXi h...$dest$ from $SrcIpAddr.', input_type=str]\n For further information visit https://errors.pydantic.dev/2.13/v/value_error"

detections/application/monitor_email_for_brand_abuse.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,3 @@ category: application
4343
security_domain: network
4444
baselines:
4545
- DNSTwist Domain Names
46-
MANUAL_REVIEW:
47-
rba: {}
48-
manual_review_rationale: 'Detection references baseline(s) flagged for manual review: DNSTwist Domain Names'

0 commit comments

Comments
 (0)