Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
f49bd31
update time 🚀
nasbench Jun 30, 2025
52d97d3
rename datasrouce files
nasbench Jun 30, 2025
c36a266
update dataset url
nasbench Jun 30, 2025
d66b88d
add new ta-cisco-nvm app to
pyth0n1c Jun 30, 2025
857d4da
Merge branch 'develop' into nvm-batch1
pyth0n1c Jun 30, 2025
1601ff7
small updates
nasbench Jun 30, 2025
8d10847
Merge branch 'develop' into nvm-batch1
nasbench Jun 30, 2025
75ec47e
add new detections, story and other cool things
nasbench Jul 1, 2025
544645b
Update suspicious_ports_list.csv
nasbench Jul 1, 2025
b90359f
fix rba and filter macro issue
nasbench Jul 1, 2025
6527190
up version for ci overlords
nasbench Jul 1, 2025
375dc32
oh wow, much detection
nasbench Jul 2, 2025
029b912
fix ci error with name and filter macro
nasbench Jul 2, 2025
b80d4fe
Update cisco_nvm___non_network_binary_making_network_connection.yml
nasbench Jul 2, 2025
0ab6a67
lemme add a couple more rules
nasbench Jul 3, 2025
6b72dcb
fix ci issues
nasbench Jul 3, 2025
e151b4e
Merge branch 'develop' into nvm-batch1
nasbench Jul 3, 2025
879259d
map existing rclone analytic and add a dedicated nvm one
nasbench Jul 4, 2025
e3bfb2d
the final countdown
nasbench Jul 6, 2025
afe0991
fix incorrect names and filter macros
nasbench Jul 6, 2025
8ffb683
Merge branch 'develop' into nvm-batch1
nasbench Jul 6, 2025
cb8f4bb
Update removed/deprecation_mapping.YML
nasbench Jul 7, 2025
fda81f6
Merge branch 'develop' into nvm-batch1
nasbench Jul 7, 2025
91c6bd2
Apply suggestion from @nasbench
nasbench Jul 7, 2025
584ed27
Update attacker_tools_on_endpoint.yml
nasbench Jul 7, 2025
61f6351
update by clause
nasbench Jul 7, 2025
80092ec
Merge branch 'develop' into nvm-batch1
nasbench Jul 7, 2025
9ba254c
Merge branch 'develop' into nvm-batch1
nasbench Jul 7, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions contentctl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -225,4 +225,12 @@ apps:
description: The Splunk Add-on for AppDynamics enables you to easily configure data
inputs to pull data from AppDynamics' REST APIs
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_314.tgz
- uid: 4221
title: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk
appid: TA-Cisco-NVM
version: 4.0.7
description: The Cisco Endpoint Security Analytics (CESA) Add-On for Splunk allows IT administrators to analyze and correlate user and endpoint behavior in Splunk Enterprise.
This Add-on provides configuration and collection of data from the Cisco AnyConnect Network Visibility Module IPFIX (nvzFlow) Collector.
This module collects additional context such as user, device, application, location and destination for flows both on and off premise.
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-endpoint-security-analytics-cesa-add-on-for-splunk_407.tgz
githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
149 changes: 149 additions & 0 deletions data_sources/cisco_network_visibility_module_flow_data.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,149 @@
name: Cisco Network Visibility Module Flow Data
id: d49bcd3c-da06-41c6-b33e-8b8d23078f68
version: 1
date: '2025-06-30'
author: Nasreddine Bencherchali, Splunk
description: Data source object for Netflow events from Cisco Network Visibility Module
source: not_applicable
sourcetype: cisco:nvm:flowdata
supported_TA:
- name: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk
url: https://splunkbase.splunk.com/app/4221
version: 4.0.7
fields:
- action
- aditional_logged_in_user_list
- aliul
- bytes
- bytes_in
- bytes_out
- da
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- deserialize
- dest
- dest_hostname
- dest_ip
- dest_ipv6
- dest_port
- dh
- direction
- dp
- dps
- ds
- eventtype
- fd
- fems
- fes
- fet
- field
- flow_dns_suffix
- flow_end_msec
- flow_end_sec
- flow_end_time
- flow_report_stage
- flow_start_msec
- flow_start_sec
- flow_start_time
- flow_version
- fsg
- fsms
- fss
- fst
- fv
- hh
- hm
- host
- ht
- http_host
- http_method
- ibc
- iid
- index
- linecount
- liuat
- liuid
- liuida
- liuidp
- logged_in_user
- logged_in_user_account_type
- logged_in_user_authority
- logged_in_user_principal
- mhl
- mnl
- module_hash_list
- module_name_list
- obc
- pa
- paa
- pap
- parent_process
- parent_process_account
- parent_process_arguments
- parent_process_hash
- parent_process_id
- parent_process_integrity_level
- parent_process_name
- parent_process_path
- parent_process_user_account_type
- parg
- ph
- pid
- pil
- pn
- ppa
- pparg
- ppath
- pph
- ppid
- ppil
- ppn
- pppath
- ppuat
- pr
- process
- process_account_authority
- process_account_principal
- process_arguments
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- process_user_account_type
- protocol_identifier
- puat
- puid
- punct
- sa
- source
- sourcetype
- sp
- splunk_server
- splunk_server_group
- sps
- src
- src_interface
- src_ip
- src_ipv6
- src_port
- tag
- tag::action
- tag::eventtype
- timeendpos
- timestamp
- timestartpos
- transport
- udid
- uri_path
- user
output_fields:
- dest
Comment thread
patel-bhavin marked this conversation as resolved.
example_log: 'Jun 26 16:09:18 127.0.0.1 Jun 26 16:09:18 ip-172-31-30-201 fv="nvzFlow_v9" pr="6" sa="172.16.3.110" sp="5203" da="140.82.112.3" dp="443" fd="1" fss="1750954134" fst="Thu Jun 26 16:08:54 2025" fes="1750954134" fet="Thu Jun 26 16:08:54 2025" hh="''" hm="''" ht="''" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" liuid="EC2AMAZ-E56LIG5\Administrator" liuida="EC2AMAZ-E56LIG5" liuidp="Administrator" liuat="2" pa="EC2AMAZ-E56LIG5\Administrator" paa="EC2AMAZ-E56LIG5" pap="Administrator" puat="8194" pn="msiexec.exe" ph="23EC37A4DF21893A1B3B6F5F72B2D78918E86C3A90F9664F8248A2C8219F889A" ppa="EC2AMAZ-E56LIG5\Administrator" ppuat="8194" ppn="cmd.exe" pph="41871DADE953D9F40F4AA445FC19982AB59D263C8AA93D7F67A1451663A09A57" ibc="0" obc="0" ds="us-east-2.compute.internal" dh="github.com" iid="4" mnl="''" mhl="''" fsms="1750954134331" fems="1750954134340" pid="8496" ppath="C:\Windows\system32\msiexec.exe" parg=" /i \"https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1218.007/src/T1218.007_JScript.msi\"" ppid="9232" pppath="C:\Windows\system32\cmd.exe" aliul="''" pil="12288" ppil="12288" fsg="1" puid="071161F29663831BB4A1C0FADA9805E0"'
51 changes: 51 additions & 0 deletions data_sources/cisco_network_visibility_module_osquery.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
name: Cisco Network Visibility Module OSquery
id: d59bcd3c-da06-41c6-b33e-8b8d23078f68
version: 1
date: '2025-06-30'
author: Nasreddine Bencherchali, Splunk
description: Data source object for OSquery events from Cisco Network Visibility Module
source: not_applicable
sourcetype: cisco:nvm:osquery
supported_TA:
- name: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk
url: https://splunkbase.splunk.com/app/4221
version: 4.0.7
fields:
- current_page
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- eventtype
- fv
- host
- index
- linecount
- osquery_version
- punct
- qid
- qjr
- qpi
- qpn
- qt
- query_id
- query_json_response
- query_timestamp
- qv
- source
- sourcetype
- splunk_server
- splunk_server_group
- tag
- tag::eventtype
- timeendpos
- timestartpos
- total_pages
- udid
output_fields:
- query_json_response
example_log: 'Jun 30 09:20:43 127.0.0.1 Jun 30 09:20:43 ip-172-31-30-201 fv="nvzFlow_v8" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" qv="5.5.1-dirty" qid="38654705666" qt="1751275242" qpi="1" qpn="1" qjr="[{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"addons-search-detection@mozilla.com\",\"location\":\"app-builtin\",\"name\":\"Add-ons Search Detection\",\"native\":\"\",\"path\":\"null\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.0.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Mozilla <screenshots-feedback@mozilla.com>\",\"description\":\"Take clips and screenshots from the Web and save them temporarily or permanently.\",\"disabled\":\"1\",\"identifier\":\"screenshots@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Firefox Screenshots\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\screenshots@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"39.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"formautofill@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Form Autofill\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\formautofill@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Fixes for web compatibility with Picture-in-Picture\",\"disabled\":\"0\",\"identifier\":\"pictureinpicture@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Picture-In-Picture\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\pictureinpicture@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.0\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Urgent post-release fixes for web compatibility.\",\"disabled\":\"0\",\"identifier\":\"webcompat@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Web Compatibility Interventions\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"137.7.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Thomas Wisniewski <twisniewski@mozilla.com>\",\"description\":\"Report site compatibility issues on webcompat.com\",\"disabled\":\"1\",\"identifier\":\"webcompat-reporter@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"WebCompat Reporter\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat-reporter@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.1.0\",\"visible\":\"1\"}]"'
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
name: Any Powershell DownloadFile
id: 1a93b7ea-7af7-11eb-adb5-acde48001122
version: '15'
date: '2025-05-06'
version: '16'
date: '2025-06-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: TTP
description: The following analytic detects the use of PowerShell's `DownloadFile`
method to download files. It leverages data from Endpoint Detection and Response
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
name: Any Powershell DownloadString
id: 4d015ef2-7adf-11eb-95da-acde48001122
version: '12'
date: '2025-05-06'
version: '13'
date: '2025-06-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: TTP
description: The following analytic detects the use of PowerShell's `DownloadString`
method to download files. It leverages data from Endpoint Detection and Response
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
name: Windows InstallUtil Uninstall Option with Network
id: 1a52c836-43ef-11ec-a36c-acde48001122
version: 12
date: '2025-05-02'
version: 13
date: '2025-06-26'
author: Michael Haag, Splunk
status: production
status: deprecated
type: TTP
description: The following analytic identifies the use of Windows InstallUtil.exe
making a remote network connection using the `/u` (uninstall) switch. This detection
Expand Down
11 changes: 9 additions & 2 deletions detections/endpoint/attacker_tools_on_endpoint.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
name: Attacker Tools On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
version: 12
date: '2025-07-03'
date: '2025-07-07'
author: Bhavin Patel, Splunk, sventec, Github Community
status: production
type: TTP
Expand All @@ -17,6 +17,7 @@ data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
- Cisco Network Visibility Module Flow Data
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime values(Processes.process) as process values(Processes.parent_process)
as parent_process from datamodel=Endpoint.Processes where
Expand Down Expand Up @@ -77,6 +78,7 @@ tags:
- CISA AA22-264A
- Compromised Windows Host
- PHP-CGI RCE Attack on Japanese Organizations
- Cisco Network Visibility Module Analytics
asset_type: Endpoint
mitre_attack_id:
- T1003
Expand All @@ -88,8 +90,13 @@ tags:
- Splunk Cloud
security_domain: endpoint
tests:
- name: True Positive Test
- name: True Positive Test - Sysmon
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/attacker_scan_tools/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
- name: True Positive Test - Cisco NVM
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log
source: not_applicable
sourcetype: cisco:nvm:flowdata
8 changes: 4 additions & 4 deletions detections/endpoint/bitsadmin_download_file.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
name: BITSAdmin Download File
id: 80630ff4-8e4c-11eb-aab5-acde48001122
version: 10
date: '2025-05-02'
version: 11
date: '2025-06-24'
author: Michael Haag, Sittikorn S
status: production
type: TTP
Expand Down Expand Up @@ -90,12 +90,12 @@ tags:
- Splunk Cloud
security_domain: endpoint
tests:
- name: True Positive Test
- name: True Positive Test - Sysmon
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
- name: True Positive Test
- name: True Positive Test - CrowdStrike
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log
source: crowdstrike
Expand Down
Loading