Skip to content

Commit d13e377

Browse files
patel-bhavinresearch botljstella
authored
Bump contentctl.yml to 5.22.0 (#3894)
* chore: bump contentctl.yml to 5.22.0 * remove detections --------- Co-authored-by: research bot <research@splunk.com> Co-authored-by: Lou Stella <ljstella@gmail.com>
1 parent 84c0519 commit d13e377

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

contentctl.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ app:
33
uid: 3449
44
title: ES Content Updates
55
appid: DA-ESS-ContentUpdate
6-
version: 5.21.0
6+
version: 5.22.0
77
description: Explore the Analytic Stories included with ES Content Updates.
88
prefix: ESCU
99
label: ESCU

detections/deprecated/cobalt_strike_named_pipes.yml renamed to removed/detections/cobalt_strike_named_pipes.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 5876d429-0240-4709-8b93-ea8330b411b5
33
version: 13
44
date: '2025-12-04'
55
author: Michael Haag, Splunk
6-
status: deprecated
6+
status: removed
77
type: TTP
88
description: The following analytic detects the use of default or publicly known named
99
pipes associated with Cobalt Strike. It leverages Sysmon EventID 17 and 18 to identify

detections/deprecated/http_suspicious_tool_user_agent.yml renamed to removed/detections/http_suspicious_tool_user_agent.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 1ca76190-4997-4d19-b5bc-9e220b70c7d3
33
version: 2
44
date: '2025-10-09'
55
author: Raven Tait, Splunk
6-
status: deprecated
6+
status: removed
77
type: Anomaly
88
description: This Splunk query analyzes web access logs to identify and categorize
99
non-browser user agents, detecting various types of security tools, scripting languages,

0 commit comments

Comments
 (0)