Skip to content

Commit f2e7dbf

Browse files
committed
bump versions and dates on modified detections
1 parent 4c80dba commit f2e7dbf

11 files changed

+22
-22
lines changed

detections/application/windows_ad_dcshadow_privileges_acl_addition.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows AD DCShadow Privileges ACL Addition
22
id: ae915743-1aa8-4a94-975c-8062ebc8b723
3-
version: 3
4-
date: '2025-01-21'
3+
version: 4
4+
date: '2025-02-17'
55
author: Dean Luxton
66
status: production
77
type: TTP

detections/application/windows_ad_gpo_deleted.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows AD GPO Deleted
22
id: 0d41772b-35ab-4e1c-a2ba-d0b455481aee
3-
version: 3
4-
date: '2025-01-21'
3+
version: 4
4+
date: '2025-02-17'
55
author: Dean Luxton
66
status: production
77
type: TTP

detections/application/windows_ad_gpo_disabled.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows AD GPO Disabled
22
id: 72793bc0-c0cd-400e-9e60-fdf36f278917
3-
version: 3
4-
date: '2025-01-21'
3+
version: 4
4+
date: '2025-02-17'
55
author: Dean Luxton
66
status: production
77
type: TTP

detections/application/windows_ad_self_dacl_assignment.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows AD Self DACL Assignment
22
id: 16132445-da9f-4d03-ad44-56d717dcd67d
3-
version: 3
4-
date: '2025-01-21'
3+
version: 4
4+
date: '2025-02-17'
55
author: Dean Luxton
66
status: production
77
type: TTP

detections/endpoint/windows_archived_collected_data_in_temp_folder.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Archived Collected Data In TEMP Folder
22
id: cb56a1ea-e0b1-46d5-913f-e024cba40cbe
3-
version: 2
4-
date: '2024-11-13'
3+
version: 3
4+
date: '2025-02-17'
55
author: Teoderick Contreras, Splunk
66
data_source:
77
- Sysmon EventID 11

detections/endpoint/windows_bitlockertogo_with_network_activity.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows BitLockerToGo with Network Activity
22
id: 14e3a089-cc23-4f4d-a770-26e44a31fbac
3-
version: 2
4-
date: '2025-01-21'
3+
version: 3
4+
date: '2025-02-17'
55
author: Michael Haag, Nasreddine Bencherchali, Splunk
66
data_source:
77
- Sysmon EventID 22

detections/endpoint/windows_credentials_access_via_vaultcli_module.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Credentials Access via VaultCli Module
22
id: c0d89118-3f89-4cd7-8140-1f39e7210681
3-
version: 2
4-
date: '2025-01-21'
3+
version: 3
4+
date: '2025-02-17'
55
author: Teoderick Contreras, Splunk
66
data_source:
77
- Sysmon EventID 7

detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Obfuscated Files or Information via RAR SFX
22
id: 4ab6862b-ce88-4223-96c0-f6da2cffb898
3-
version: 1
4-
date: '2024-12-12'
3+
version: 2
4+
date: '2025-02-17'
55
author: Teoderick Contreras, Splunk
66
data_source:
77
- Sysmon EventID 11

detections/endpoint/windows_runmru_command_execution.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows RunMRU Command Execution
22
id: a15aa1ab-2b79-467f-8201-65e0f32d5b1a
3-
version: 2
4-
date: '2025-01-21'
3+
version: 3
4+
date: '2025-02-17'
55
author: Nasreddine Bencherchali, Michael Haag, Splunk
66
data_source:
77
- Sysmon EventID 11

detections/endpoint/windows_scheduled_tasks_for_compmgmtlauncher_or_eventvwr.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr
22
id: feb43b86-8c38-46cd-865e-20ce8a96c26c
3-
version: 4
4-
date: '2024-11-13'
3+
version: 5
4+
date: '2025-02-17'
55
author: Teoderick Contreras, Splunk
66
data_source:
77
- Windows Event Log Security 4698

0 commit comments

Comments
 (0)