Issues
- 1
[community request] Update Ransomware Extensions Lookup
#3131 opened by ljstella - 0
- 4
- 1
- 2
AppLocker Dashboard Issue - No Policy Review Data
#3021 opened by matchstickboy - 0
[BUG] Missing Wildcards in Splunk Rule for Detecting Known Services Killed by Ransomware
#2996 opened by shimonShouei - 2
pre trained Deep Learning models for ESCU - Support for DSDL Version 5.1.1
#2939 opened by atgithub11 - 2
[BUG] Azure MFA failure detections logic flaw
#3134 opened by 0xC0FFEEEE - 2
- 2
[BUG] research.splunk.com not showing datasources correctly when looking at a specific detection
#3195 opened by isakhansson - 1
Expand CIM Web Datamodel
#3141 opened by dluxtron - 0
[BUG] Missing wildcard for -type parameter detection 2452e632-9e0d-11eb-bacd-acde48001122
#3171 opened by Wouter-Jansen - 1
[BUG] Datasource is set incorrectly on this detection
#2962 opened by josehelps - 2
[BUG] Whitespace `\t` in several YAML rule files causing YAML load errors
#3098 opened by brokensound77 - 1
- 2
- 1
- 2
- 1
- 1
- 1
- 1
[BUG] - Windows AD Domain Replication ACL Addition has unnecessary escape chars in SPL causing errors
#3039 opened by livehybrid - 1
[BUG] browser_app_list lookup doesn't exist in indexers, causing query to fail in "Windows Credential Access From Browser Password Store"
#3014 opened by iso-rgomez - 1
Custom Content Development
#3019 opened by lluked - 1
[BUG] please, fix links in wiki: https://github.com/splunk/security_content/wiki/Detection-Analytic-Types
#3011 opened by yaroslav-nakonechnikov - 4
Add custom annotation for versioning
#2907 opened by TheLawsOfChaos - 0
Azure AD Multi-Source Failed Authentications Spike - Missing ADFSSignInLogs category
#2980 opened by atgithub11 - 3
[BUG] ESCU - Get ADUser with PowerShell - Rule has no Adaptive Reponse Actions
#2965 opened by albertenc13 - 1
[BUG] DNS Query Length With High Standard Deviation
#2958 opened by josehelps - 3
[BUG] Windows Excessive Disabled Services Event uses ComputerName instead of src field (CIM issue)
#2825 opened by iso-rgomez - 3
- 1
Consider adding Scope for search Azure AD Tenant Wide Admin Consent Granted
#2950 opened by atgithub11 - 2
- 6
[BUG] Build is not working
#2948 opened by yaroslav-nakonechnikov - 2
- 1
[BUG] O365 Mailbox Inbox Folder Shared with All Users. Field "object" doesn't exist.
#2937 opened by atgithub11 - 2
CMD Carry Out String Command Parameter - false negatives due to trailing space before wildcard in search [BUG]
#2928 opened by cxosmo - 1
[BUG] "Kerberos TGT Request Using RC4 Encryption" using non-CIM field "Account_Name"
#2920 opened by iso-rgomez - 1
[BUG] Active_Directory_Disable_Account_Dispatch
#2769 opened by kelby-shelton - 2
[BUG] System Processes Run From Unexpected Locations - missing field for Risk Message
#2871 opened by ccl0utier - 3
[BUG] ESCU CS fields LogonType and TargetUserName
#2869 opened by cp-sn - 2
[BUG] VirusTotal v3 Identifier Reputation Playbook failing with math domain error
#2772 opened by gdollasigns - 1
Build constraints based on tags
#2767 opened by schimpy - 1
- 4
[BUG] - Build Failing Everytime
#2894 opened by abhinavkakku - 1
- 2
- 1
[BUG] `Unusually Long Command Line` Detection has incorrect Risk Message and Threat Object
#2806 opened by ccl0utier - 1
When trying to build attack range I get the following error 'No module named 'azure.mgmt.resource'[BUG]
#2762 opened by Cybertooth34 - 1
Hi All, I am facing an issue when trying to configure the attack range locally.... The error I am getting is 'configuration.py, line 150, answers = questionary.prompt(questions) NameError: name 'questionary' is not defined. Did you mean: 'questions''... I cant find any answers online from people having the same issue.[BUG]
#2761 opened by Cybertooth34