Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove extra fields from YMLs #3062

Open
wants to merge 29 commits into
base: develop
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
66d9355
set extra='forbid' to catch erroneously included fields in high level…
pyth0n1c Jul 27, 2024
bcb3eee
remove risk_score, update_timestamp, and some unused tags from baselines
pyth0n1c Jul 27, 2024
d5e60e5
remove more extra keys from detections
pyth0n1c Jul 27, 2024
fdf6bb6
Branch was auto-updated.
patel-bhavin Jul 29, 2024
62ca4f6
Branch was auto-updated.
patel-bhavin Jul 29, 2024
63add27
Branch was auto-updated.
patel-bhavin Jul 29, 2024
4f2d6d2
Branch was auto-updated.
patel-bhavin Jul 29, 2024
97afee6
Branch was auto-updated.
patel-bhavin Jul 30, 2024
bd927ca
Branch was auto-updated.
patel-bhavin Jul 30, 2024
ee90b28
Branch was auto-updated.
patel-bhavin Jul 30, 2024
5e04f5c
update contentctl.yml format
pyth0n1c Jul 30, 2024
b2d4fd3
merged
pyth0n1c Jul 30, 2024
96572cd
Remove some more extra fields from new ymls
pyth0n1c Jul 30, 2024
73014b4
Branch was auto-updated.
patel-bhavin Jul 31, 2024
5d461d3
Branch was auto-updated.
patel-bhavin Aug 1, 2024
4b1e814
Branch was auto-updated.
patel-bhavin Aug 5, 2024
97e2f36
Branch was auto-updated.
patel-bhavin Aug 5, 2024
21444b4
Branch was auto-updated.
patel-bhavin Aug 5, 2024
e5938c1
Branch was auto-updated.
patel-bhavin Aug 6, 2024
7d401f2
remove build_ssa as it is no longer used in contentctl
pyth0n1c Aug 21, 2024
f172d78
fix merge conflict in contentctl.yml. remove risk_score field from ma…
pyth0n1c Aug 21, 2024
fbf0881
Branch was auto-updated.
patel-bhavin Aug 22, 2024
d5228e5
Branch was auto-updated.
patel-bhavin Aug 22, 2024
eabf78a
Branch was auto-updated.
patel-bhavin Aug 22, 2024
5ec368b
Branch was auto-updated.
patel-bhavin Aug 22, 2024
60706e6
Branch was auto-updated.
patel-bhavin Aug 22, 2024
b617f1c
Branch was auto-updated.
patel-bhavin Aug 22, 2024
cb715a2
Branch was auto-updated.
patel-bhavin Aug 22, 2024
01c4f01
Branch was auto-updated.
patel-bhavin Aug 23, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,6 @@ tags:
- Emotet Malware DHS Report TA18-201A
- Monitor for Unauthorized Software
- SamSam Ransomware
asset_type: Endpoint
detections:
- Prohibited Software On Endpoint
product:
Expand All @@ -29,17 +28,4 @@ tags:
- Splunk Cloud
required_fields:
- _time
security_domain: endpoint
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: endpoint
15 changes: 1 addition & 14 deletions baselines/deprecated/baseline_of_api_calls_per_user_arn.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,17 +32,4 @@ tags:
- _time
- eventType
- userIdentity.arn
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
Original file line number Diff line number Diff line change
Expand Up @@ -44,17 +44,4 @@ tags:
- eventName
- errorCode
- src_user
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
Original file line number Diff line number Diff line change
Expand Up @@ -44,17 +44,4 @@ tags:
- eventName
- errorCode
- src_user
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
Original file line number Diff line number Diff line change
Expand Up @@ -35,17 +35,4 @@ tags:
- userIdentity.type
- userName
- eventName
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
Original file line number Diff line number Diff line change
Expand Up @@ -33,17 +33,4 @@ tags:
- _time
- eventName
- sourceIPAddress
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
15 changes: 1 addition & 14 deletions baselines/deprecated/previously_seen_ec2_amis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,17 +29,4 @@ tags:
- eventName
- errorCode
- requestParameters.instancesSet.items{}.imageId
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
15 changes: 1 addition & 14 deletions baselines/deprecated/previously_seen_ec2_instance_types.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,17 +29,4 @@ tags:
- eventName
- errorCode
- requestParameters.instanceType
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
15 changes: 1 addition & 14 deletions baselines/deprecated/previously_seen_ec2_launches_by_user.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,17 +30,4 @@ tags:
- eventName
- errorCode
- requestParameters.instanceType
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
15 changes: 1 addition & 14 deletions baselines/deprecated/previously_seen_users_in_cloudtrail.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,17 +37,4 @@ tags:
- eventName
- userIdentity.arn
- src
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
Original file line number Diff line number Diff line change
Expand Up @@ -39,17 +39,4 @@ tags:
- eventName
- userIdentity.arn
- src
security_domain: network
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
security_domain: network
16 changes: 1 addition & 15 deletions baselines/dnstwist_domain_names.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,6 @@ tags:
analytic_story:
- Brand Monitoring
- Suspicious Emails
asset_type: Endpoint
detections:
- Monitor Email For Brand Abuse
- Monitor DNS For Brand Abuse
Expand All @@ -28,19 +27,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
kill_chain_phases:
- Exploitation
required_fields:
- _time
security_domain: network
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: dest
type: Other
role:
- Other
security_domain: network
12 changes: 5 additions & 7 deletions contentctl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,10 +13,10 @@ app:
enrichments: false
build_app: true
build_api: true
build_ssa: false
build_path: dist
test_instance:
splunk_app_username: admin
test_instances:
- splunk_app_username: admin
instance_name: test_instance
instance_address: localhost
hec_port: 8088
web_ui_port: 8000
Expand All @@ -32,9 +32,9 @@ apps:
# - uid: 263
# title: Splunk Enterprise Security
# appid: SplunkEnterpriseSecuritySuite
# version: 7.3.1
# version: 7.3.2
# description: description of app
# hardcoded_path: apps/splunk-enterprise-security_731.spl
# hardcoded_path: apps/splunk-enterprise-security_7312.spl
- uid: 1621
title: Splunk Common Information Model (CIM)
appid: Splunk_SA_CIM
Expand Down Expand Up @@ -194,5 +194,3 @@ apps:
version: 3.2.1
description: description of app
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/crowdstrike-falcon-event-streams-technical-add-on_321.tgz

githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,6 @@ tags:
- user
- action
- message
risk_score: 64
security_domain: network
cve:
- CVE-2024-4040
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 49
required_fields:
- Authentication.action
- Authentication.user
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -49,5 +49,4 @@ tags:
- Authentication.dest_category
- Authentication.dest
- Authentication.user
risk_score: 25
security_domain: network
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 49
required_fields:
- Authentication.action
- Authentication.user
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -64,5 +64,4 @@ tags:
- All_Email.src_user
- All_Email.file_name
- All_Email.message_id
risk_score: 25
security_domain: network
Original file line number Diff line number Diff line change
Expand Up @@ -58,5 +58,4 @@ tags:
- Filesystem.action
- Filesystem.process_id
- Filesystem.dest
risk_score: 25
security_domain: endpoint
Original file line number Diff line number Diff line change
Expand Up @@ -63,5 +63,4 @@ tags:
- All_Traffic.bytes_out
- All_Traffic.src_category
- All_Traffic.dest_ip
risk_score: 25
security_domain: network
1 change: 0 additions & 1 deletion detections/application/monitor_email_for_brand_abuse.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,5 +48,4 @@ tags:
- All_Email.recipient
- All_Email.src_user
- All_Email.message_id
risk_score: 25
security_domain: network
Original file line number Diff line number Diff line change
Expand Up @@ -50,5 +50,4 @@ tags:
- Updates.status
- Updates.vendor_product
- Updates.dest
risk_score: 25
security_domain: endpoint
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,6 @@ tags:
- Authentication.signature
- Authentication.method
- Authentication.src
risk_score: 48
security_domain: identity
tests:
- name: True Positive Test
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,6 @@ tags:
- user_agent
- command
- description
risk_score: 81
security_domain: identity
tests:
- name: True Positive Test
Expand Down
1 change: 0 additions & 1 deletion detections/application/okta_mfa_exhaustion_hunt.yml
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,6 @@ tags:
- src_ip
- eventType
- status
risk_score: 18
security_domain: access
tests:
- name: True Positive Test
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -74,5 +74,4 @@ tags:
- client.userAgent.rawUserAgent
- debugContext.debugData.behaviors
- group_push_time
risk_score: 64
security_domain: access
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,6 @@ tags:
- All_Changes.result
- All_Changes.src
- sourcetype
risk_score: 30
security_domain: identity
tests:
- name: True Positive Test
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,6 @@ tags:
- All_Changes.result
- All_Changes.src
- sourcetype
risk_score: 49
security_domain: identity
tests:
- name: True Positive Test
Expand Down
Loading
Loading