Skip to content

Commit b4cd414

Browse files
committed
updating detection file
1 parent 17a4e1e commit b4cd414

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

detections/network/cisco_secure_firewall___intrusion_events_by_threat_activity.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco Secure Firewall - Intrusion Events by Threat Activity
22
id: b71e57e8-c571-4ff1-ae13-bc4384a9e891
3-
version: 3
4-
date: '2025-08-21'
3+
version: 4
4+
date: '2025-09-25'
55
author: Bhavin Patel, Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly
@@ -16,6 +16,7 @@ description: |
1616
events that occur in close temporal proximity.
1717
1818
Currently, this detection will alert on the following threat actors or malware families as defined in the cisco_snort_ids_to_threat_mapping lookup:
19+
* ArcaneDoor
1920
* Static Tundra
2021
* AgentTesla
2122
* Amadey

0 commit comments

Comments
 (0)