Skip to content

Deprecated mapping yaml for detections#3297

Closed
patel-bhavin wants to merge 11 commits intodevelopfrom
deprecated_mapping
Closed

Deprecated mapping yaml for detections#3297
patel-bhavin wants to merge 11 commits intodevelopfrom
deprecated_mapping

Conversation

@patel-bhavin
Copy link
Contributor

adds a new mapping file for deprecated detections:

  • deprecated_name: Okta Two or More Rejected Okta Pushes
    deprecated_id: d93f785e-4c2c-4262-b8c7-12b77a13fd39
    replacement_name: Okta Multiple Failed MFA Requests For User
    replacement_id: 826dbaae-a1e6-4c8c-b384-d16898956e73
    date: '2025-01-28'
    escu_version: 5.0.0
    migration_guide: https://docs.splunk.com/Documentation/ESCU/5.0.0/user/DeprecatedAnalytics
    reason: Detections updated to use the new search logic and field names due to the
    TA update

@pyth0n1c
Copy link
Collaborator

pyth0n1c commented Feb 1, 2025

I have moved the deprecation information into each relevant YML file itself in line with some proposed contentctl updates.
I find this makes organization, parsing, etc much easier and more intuitive and explicit rather than keeping a separate file with mapping information.

Note that the following detections in the deprecated detections folder are still missing deprecation information in the YML and, as such, have not yet had their YMLs updated:

https://github.com/splunk/security_content/blob/deprecated_mapping/detections/deprecated/excel_spawning_windows_script_host.yml
https://github.com/splunk/security_content/blob/deprecated_mapping/detections/deprecated/windows_service_stop_via_net__and_sc_application.yml

We also lack deprecation information at this time for:

  • Baselines
  • Analytic Stories
  • Investigations

@patel-bhavin patel-bhavin added the WIP DO NOT MERGE Work in Progress label Feb 18, 2025
@josehelps josehelps added this to the v5.2.0 milestone Feb 20, 2025
@patel-bhavin
Copy link
Contributor Author

Closing this in favour of #3363

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

WIP DO NOT MERGE Work in Progress

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants