Skip to content

Commit 36f3b6e

Browse files
committed
shipping as experimental
1 parent 441ba47 commit 36f3b6e

File tree

2 files changed

+2
-10
lines changed

2 files changed

+2
-10
lines changed

detections/network/detect_dns_query_to_decommissioned_s3_bucket.yml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,8 +47,7 @@ tags:
4747
- Splunk Enterprise Security
4848
- Splunk Cloud
4949
security_domain: network
50-
manual_test: This search needs a lookup table to be populated in decommissioned_buckets KVStore Lookup by running a baseline search `Baseline Of Open S3 Bucket Decommissioning` prior to running this detection.
51-
tests:
50+
tests:
5251
- name: Baseline Dataset Test
5352
attack_data:
5453
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/decommissioned_buckets/cloudtrail.json

detections/web/detect_web_access_to_decommissioned_s3_bucket.yml

Lines changed: 1 addition & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -51,21 +51,14 @@ tags:
5151
- Splunk Enterprise Security
5252
- Splunk Cloud
5353
security_domain: network
54-
manual_test: This search needs a lookup table to be populated the decommissioned_buckets KVStore Lookup by running a baseline search `Baseline Of Open S3 Bucket Decommissioning` prior to running this detection.
55-
tests:
54+
tests:
5655
- name: Baseline Dataset Test
5756
attack_data:
5857
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/decommissioned_buckets/cloudtrail.json
5958
source: cloudtrail
6059
sourcetype: aws:cloudtrail
6160
- name: True Positive Test
6261
attack_data:
63-
<<<<<<< HEAD
64-
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/s3_bucket_deletion/s3_bucket_deletion.csv
65-
source: s3*
66-
sourcetype: aws:cloudtrail
67-
=======
6862
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/decommissioned_buckets/web_cloudfront_access.log
6963
source: aws_cloudfront_accesslogs
7064
sourcetype: aws:cloudfront:accesslogs
71-
>>>>>>> 7907bd82d87c9792b191ce11addb3e1397053f67

0 commit comments

Comments
 (0)