Skip to content

Commit d6f03a2

Browse files
committed
Bumped versions
1 parent 8d0935f commit d6f03a2

22 files changed

+44
-44
lines changed

detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Curl Execution With Insecure Flags
22
id: cc695238-3117-4e60-aa83-4beac2a42c69
3-
version: 1
4-
date: '2025-07-01'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
22
id: f2a9df84-9b01-4a21-9e3a-7aa1a217f69e
3-
version: 1
4-
date: '2025-07-03'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Non-Network Binary Making Network Connection
22
id: c6db35af-8a0e-4b61-88ed-738e66f15715
3-
version: 1
4-
date: '2025-07-01'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Outbound Connection to Suspicious Port
22
id: fc32a8d5-bc79-4437-b48f-4646ab7bed9d
3-
version: 1
4-
date: '2025-07-01'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Rclone Execution With Network Activity
22
id: 719f8c78-b20d-4bb9-8c33-6d1a762e7a9a
3-
version: 1
4-
date: '2025-07-03'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download
22
id: 18f0d27d-569e-4bc4-96e1-09b214fa73c0
3-
version: 1
4-
date: '2025-07-03'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Susp Script From Archive Triggering Network Activity
22
id: 8b07c2c9-0cde-4c44-9fa6-59dcf2b25777
3-
version: 1
4-
date: '2025-07-01'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Suspicious Download From File Sharing Website
22
id: 94ebc001-35e7-4ae8-9b0e-52766b2f99c7
3-
version: 1
4-
date: '2025-07-01'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Suspicious File Download via Headless Browser
22
id: cd0e816f-f67d-4dbe-a153-480b546e867e
3-
version: 1
4-
date: '2025-07-02'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: TTP

detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Cisco NVM - Suspicious Network Connection From Process With No Args
22
id: 54fa06c5-96a2-4406-a4a7-44d93ddbd173
3-
version: 1
4-
date: '2025-07-02'
3+
version: 2
4+
date: '2025-09-09'
55
author: Nasreddine Bencherchali, Splunk
66
status: production
77
type: Anomaly

0 commit comments

Comments
 (0)