Skip to content

Commit 3d646fa

Browse files
committed
updating version
1 parent f1ca83e commit 3d646fa

File tree

75 files changed

+150
-150
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

75 files changed

+150
-150
lines changed

detections/application/crushftp_server_side_template_injection.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: CrushFTP Server Side Template Injection
22
id: ccf6b7a3-bd39-4bc9-a949-143a8d640dbc
3-
version: 2
4-
date: '2024-09-30'
3+
version: 3
4+
date: '2025-01-21'
55
author: Michael Haag, Splunk
66
data_source:
77
- CrushFTP

detections/application/detect_distributed_password_spray_attempts.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect Distributed Password Spray Attempts
22
id: b1a82fc8-8a9f-4344-9ec2-bde5c5331b57
3-
version: 2
4-
date: '2024-10-17'
3+
version: 3
4+
date: '2025-01-21'
55
author: Dean Luxton
66
status: production
77
type: Hunting

detections/application/detect_new_login_attempts_to_routers.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect New Login Attempts to Routers
22
id: bce3ed7c-9b1f-42a0-abdf-d8b123a34836
3-
version: 3
4-
date: '2024-10-17'
3+
version: 4
4+
date: '2025-01-21'
55
author: Bhavin Patel, Splunk
66
status: experimental
77
type: TTP

detections/application/detect_password_spray_attempts.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect Password Spray Attempts
22
id: 086ab581-8877-42b3-9aee-4a7ecb0923af
3-
version: 4
4-
date: '2024-10-17'
3+
version: 5
4+
date: '2025-01-21'
55
author: Dean Luxton
66
status: production
77
type: TTP

detections/application/email_attachments_with_lots_of_spaces.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Email Attachments With Lots Of Spaces
22
id: 56e877a6-1455-4479-ada6-0550dc1e22f8
3-
version: 4
4-
date: '2024-10-17'
3+
version: 5
4+
date: '2025-01-21'
55
author: David Dorsey, Splunk
66
status: experimental
77
type: Anomaly

detections/application/email_files_written_outside_of_the_outlook_directory.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Email files written outside of the Outlook directory
22
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
3-
version: 5
4-
date: '2024-10-17'
3+
version: 6
4+
date: '2025-01-21'
55
author: Bhavin Patel, Splunk
66
status: experimental
77
type: TTP

detections/application/email_servers_sending_high_volume_traffic_to_hosts.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Email servers sending high volume traffic to hosts
22
id: 7f5fb3e1-4209-4914-90db-0ec21b556378
3-
version: 4
4-
date: '2024-10-17'
3+
version: 5
4+
date: '2025-01-21'
55
author: Bhavin Patel, Splunk
66
status: experimental
77
type: Anomaly

detections/application/ivanti_vtm_new_account_creation.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Ivanti VTM New Account Creation
22
id: b04be6e5-2002-4349-8742-52285635b8f5
3-
version: 2
4-
date: '2024-09-30'
3+
version: 3
4+
date: '2025-01-21'
55
author: Michael Haag, Splunk
66
data_source:
77
- Ivanti VTM Audit

detections/application/monitor_email_for_brand_abuse.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Monitor Email For Brand Abuse
22
id: b2ea1f38-3a3e-4b8a-9cf1-82760d86a6b8
3-
version: 4
4-
date: '2024-10-17'
3+
version: 5
4+
date: '2025-01-21'
55
author: David Dorsey, Splunk
66
status: experimental
77
type: TTP

detections/application/no_windows_updates_in_a_time_frame.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: No Windows Updates in a time frame
22
id: 1a77c08c-2f56-409c-a2d3-7d64617edd4f
3-
version: 3
4-
date: '2024-10-17'
3+
version: 4
4+
date: '2025-01-21'
55
author: Bhavin Patel, Splunk
66
status: experimental
77
type: Hunting

0 commit comments

Comments
 (0)