Skip to content

Commit ccc2587

Browse files
authored
Merge pull request #1000 from splunk/cisco_isovalent
Cisco Isovalent 1
2 parents 7b5103d + 1440db8 commit ccc2587

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:a3b686ab456637b24d559663913862b9962c7a3ccbc0f64d8a53010f9a59ecb2
3+
size 15566
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
author: Bhavin Patel, Splunk
2+
id: 1fc537db-5e0b-4a2e-a768-27e08eff0c70
3+
date: '2025-08-15'
4+
description: |
5+
Generated datasets for Cisco Isovalent Process Exec EventType. Contains simulations for the following detections:
6+
* Cisco Isovalent - Detect Shell Execution
7+
* Cisco Isovalent - Curl Execution With Insecure Flags
8+
environment: manual simulations in a K8s cluster running Tetragon
9+
mitre_technique: []
10+
datasets:
11+
- name: cisco_isovalent
12+
path: /datasets/cisco_isovalent/cisco_isovalent.log
13+
sourcetype: cisco:isovalent
14+
source: cisco_isovalent

0 commit comments

Comments
 (0)