Skip to content

Releases: dlamspl/splunk_attack_range_reporting

Version 1.0.9

22 Nov 17:00
d2b2bf6

Choose a tag to compare

  • Update some visualizations (punchcard) to use Treemap instead
  • Add PurpleSharp information to the Navigator dashboard
  • Add new dashboard to make it easier for users to map ATT&CK techniques to Splunk Detections and/or Atomic Red Team/PurpleSharp tests available
  • Fix an issue displaying the SanKey diagram for "Executed Simulations" on the main dashboard

Version 1.0.8

08 Sep 15:45
29e102e

Choose a tag to compare

  • Update MITRE & Atomic Red Tests Lookups
  • Update contributor link
  • Fix AppInspect failed tests

v1.0.7 - Fixed Links, additional detection viz and cosmetic improvements

11 Mar 19:50
2de413b

Choose a tag to compare

  • Fixed the links for Analytic Stories to ES and documentation (as that was moved to research.splunk.com)
  • Added a Sankey visualization to display the executed simulations/atomic tests
  • Minor cosmetic improvements to table column headers
  • Documentation update (README)

v1.0.6

14 Jul 17:44
7cd8380

Choose a tag to compare

splunk_attack_range_reporting-1.0.6.tar.gz

  • Fix "The Attack Range Dashboard, Potential detections panel does not show expected Detections" issue
  • Fix "View [ESCU] link is broken with latest ESCU version bug" issue

v1.0.5

19 Aug 19:54

Choose a tag to compare

Updates to support sub-techniques

v1.0.4

26 Apr 10:48

Choose a tag to compare

Updated versions

v1.0.3: Updated dashboards with deetections

26 Apr 09:16

Choose a tag to compare

This version of Splunk attack range reporting provides the following:

  1. Attack range main dashboard - Added detections
  2. Attack range navigator - Added more precise detection view

Known issues:
On attack range navigator token is not unset on removing Tactic filter

Dependencies:
Make sure sseidenrcihment from SSE is available to system

Good enough !

16 Apr 12:25

Choose a tag to compare

Added macro for index data and removed offending IDs

Minor update

16 Apr 12:11

Choose a tag to compare

Minor csv update to avoid SSE issues.

First release !

15 Apr 17:31

Choose a tag to compare

This is the initial release of the Splunk attack range reporting app. Provides the following two dashboards

  • Attack Range Dashboard
  • Attack Range Navigator