Skip to content

Commit 3272e09

Browse files
author
research bot
committed
updating docs and package bits [ci skip]
1 parent 8401886 commit 3272e09

File tree

7 files changed

+43
-43
lines changed

7 files changed

+43
-43
lines changed

package/default/analytic_stories.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security-content
3-
# On Date: 2019-10-31T17:15:19 UTC
3+
# On Date: 2019-10-31T20:26:18 UTC
44
# Author: Splunk Security Research
55
66
#############

package/default/analyticstories.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security-content
3-
# On Date: 2019-10-31T17:15:19 UTC
3+
# On Date: 2019-10-31T20:26:18 UTC
44
# Author: Splunk Security Research
55
66
#############

package/default/app.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
is_configured = false
55
state = enabled
66
state_change_requires_restart = false
7-
build = 2705
7+
build = 2729
88

99
[triggers]
1010
reload.analytic_stories = simple

package/default/macros.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security-content
3-
# On Date: 2019-10-31T17:15:19 UTC
3+
# On Date: 2019-10-31T20:26:18 UTC
44
# Author: Splunk Security Research
55
66
#############

package/default/savedsearches.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security-content
3-
# On Date: 2019-10-31T17:15:19 UTC
3+
# On Date: 2019-10-31T20:26:18 UTC
44
# Author: Splunk Security Research
55
66
#############

package/default/transforms.conf

Lines changed: 37 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -1,196 +1,196 @@
11
#############
22
# Automatically generated by generator.py in splunk/security-content
3-
# On Date: 2019-10-31T17:15:19 UTC
3+
# On Date: 2019-10-31T20:26:18 UTC
44
# Author: Splunk Security Research
55
66
#############
77

88
[api_call_by_user_baseline]
99
filename = api_call_by_user_baseline.csv
10-
description = A lookup file that will contain the baseline information for number of AWS API calls per user
10+
# description = A lookup file that will contain the baseline information for number of AWS API calls per user
1111

1212
[aws_service_accounts]
1313
filename = aws_service_accounts.csv
14-
description = A lookup file that will contain AWS Service accounts
14+
# description = A lookup file that will contain AWS Service accounts
1515

1616
[baseline_blocked_outbound_connections]
1717
filename = baseline_blocked_outbound_connections.csv
18-
description = A lookup file that will contain the baseline information for number of blocked outbound connections
18+
# description = A lookup file that will contain the baseline information for number of blocked outbound connections
1919

2020
[brandMonitoring_lookup]
2121
filename = brand_monitoring.csv
2222
default_match = false
23-
description = A file that contains look-a-like domains for brands that you want to monitor
23+
# description = A file that contains look-a-like domains for brands that you want to monitor
2424
match_type = WILDCARD(domain)
2525
min_matches = 1
2626

2727
[csc_lookup]
2828
filename = csc_lookup.csv
29-
description = The CSC control numbers and names
29+
# description = The CSC control numbers and names
3030
min_matches = 1
3131

3232
[domains]
3333
filename = domains.csv
34-
description = A list of domains that can be whitelisted
34+
# description = A list of domains that can be whitelisted
3535

3636
[dynamic_dns_providers_default]
3737
filename = dynamic_dns_providers_default.csv
3838
case_sensitive_match = false
39-
description = A list of dynammic dns providers that should not be modified
39+
# description = A list of dynammic dns providers that should not be modified
4040
match_type = WILDCARD(dynamic_dns_domains)
4141

4242
[dynamic_dns_providers_local]
4343
filename = dynamic_dns_providers_local.csv
4444
case_sensitive_match = false
45-
description = A list of dynammic dns providers that can be modified
45+
# description = A list of dynammic dns providers that can be modified
4646
match_type = WILDCARD(dynamic_dns_domains)
4747

4848
[escu_search_id_lookup]
4949
filename = escu_search_id.csv
50-
description = A placeholder lookup file to hold information for ESCU Usage dashboard
50+
# description = A placeholder lookup file to hold information for ESCU Usage dashboard
5151

5252
[isSuspiciousFileExtension_lookup]
5353
filename = suspicious_email_attachments.csv
54-
description = A list of suspicious extensions for email attachments
54+
# description = A list of suspicious extensions for email attachments
5555
match_type = WILDCARD(file_name)
5656

5757
[isWindowsSystemFile_lookup]
5858
filename = system32_executables.csv
5959
default_match = false
60-
description = A list of executable files in Windows\System32
60+
# description = A list of executable files in Windows\System32
6161
min_matches = 1
6262

6363
[legit_domains]
6464
filename = legit_domains.csv
65-
description = A list of legit domains to be used to whitelist possible phishing sites
65+
# description = A list of legit domains to be used to whitelist possible phishing sites
6666

6767
[lookup_rare_process_whitelist_default]
6868
filename = rare_process_whitelist_default.csv
6969
default_match = false
7070
case_sensitive_match = false
71-
description = A list of rare processes that are legitimate provided by Splunk
71+
# description = A list of rare processes that are legitimate provided by Splunk
7272
match_type = WILDCARD(process)
7373
min_matches = 1
7474

7575
[lookup_rare_process_whitelist_local]
7676
filename = rare_process_whitelist_local.csv
7777
default_match = false
7878
case_sensitive_match = false
79-
description = A list of rare processes that are legitimate provided by the end user
79+
# description = A list of rare processes that are legitimate provided by the end user
8080
match_type = WILDCARD(process)
8181
min_matches = 1
8282

8383
[lookup_uncommon_processes_default]
8484
filename = uncommon_processes_default.csv
8585
case_sensitive_match = false
86-
description = A list of processes that are not common
86+
# description = A list of processes that are not common
8787
match_type = WILDCARD(process)
8888

8989
[lookup_uncommon_processes_local]
9090
filename = uncommon_processes_local.csv
9191
case_sensitive_match = false
92-
description = A list of processes that are not common
92+
# description = A list of processes that are not common
9393
match_type = WILDCARD(process)
9494

9595
[network_acl_activity_baseline]
9696
filename = network_acl_activity_baseline.csv
97-
description = A lookup file that will contain the baseline information for number of AWS Network ACL Activity
97+
# description = A lookup file that will contain the baseline information for number of AWS Network ACL Activity
9898

9999
[previously_seen_S3_access_from_remote_ip]
100100
filename = previously_seen_S3_access_from_remote_ip.csv
101-
description = A placeholder for a list of IPs that have access S3
101+
# description = A placeholder for a list of IPs that have access S3
102102

103103
[previously_seen_api_calls_from_user_roles]
104104
filename = previously_seen_api_calls_from_user_roles.csv
105-
description = A placeholder for a list of AWS API calls for each user role
105+
# description = A placeholder for a list of AWS API calls for each user role
106106

107107
[previously_seen_aws_cross_account_activity]
108108
filename = previously_seen_aws_cross_account_activity.csv
109-
description = A placeholder for a list of AWS accounts and assumed roles
109+
# description = A placeholder for a list of AWS accounts and assumed roles
110110

111111
[previously_seen_aws_regions]
112112
filename = previously_seen_aws_regions.csv
113113
default_match = false
114-
description = A place holder for a list of used AWS regions
114+
# description = A place holder for a list of used AWS regions
115115
min_matches = 1
116116

117117
[previously_seen_cloud_compute_creations_by_user]
118118
filename = previously_seen_cloud_compute_creations_by_user.csv
119119
default_match = false
120-
description = A place holder for a list of users that have created cloud compute instances
120+
# description = A place holder for a list of users that have created cloud compute instances
121121
min_matches = 1
122122

123123
[previously_seen_cloud_compute_images]
124124
filename = previously_seen_cloud_compute_images.csv
125125
default_match = false
126-
description = A place holder for a list of used cloud compute images
126+
# description = A place holder for a list of used cloud compute images
127127
min_matches = 1
128128

129129
[previously_seen_cloud_compute_instance_types]
130130
filename = previously_seen_cloud_compute_instance_types.csv
131131
default_match = false
132-
description = A place holder for a list of used cloud compute instance types
132+
# description = A place holder for a list of used cloud compute instance types
133133
min_matches = 1
134134

135135
[previously_seen_cloud_regions]
136136
filename = previously_seen_cloud_regions.csv
137137
default_match = false
138-
description = A place holder for a list of used cloud compute images
138+
# description = A place holder for a list of used cloud compute images
139139
min_matches = 1
140140

141141
[previously_seen_cmd_line_arguments]
142142
filename = previously_seen_cmd_line_arguments.csv
143-
description = A placeholder for a list of cmd line arugments that been seen before
143+
# description = A placeholder for a list of cmd line arugments that been seen before
144144

145145
[previously_seen_ec2_modifications_by_user]
146146
filename = previously_seen_ec2_modifications_by_user.csv
147-
description = A place holder for a list of AWS EC2 modifications done by each user
147+
# description = A place holder for a list of AWS EC2 modifications done by each user
148148

149149
[previously_seen_running_windows_services]
150150
filename = previously_seen_running_windows_services.csv
151-
description = A placeholder for the list of Windows Services running
151+
# description = A placeholder for the list of Windows Services running
152152

153153
[prohibitedProcesses_lookup]
154154
filename = prohibited_processes.csv
155-
description = A list of processes that have been marked as prohibited
155+
# description = A list of processes that have been marked as prohibited
156156

157157
[prohibited_apps_launching_cmd]
158158
filename = prohibited_apps_launching_cmd.csv
159-
description = A list of processes that should not be launching cmd.exe
159+
# description = A list of processes that should not be launching cmd.exe
160160
match_type = WILDCARD(prohibited_applications)
161161

162162
[ransomware_extensions_lookup]
163163
filename = ransomware_extensions.csv
164164
default_match = false
165-
description = A list of file extensions that are associated with ransomware
165+
# description = A list of file extensions that are associated with ransomware
166166
min_matches = 1
167167

168168
[ransomware_notes_lookup]
169169
filename = ransomware_notes.csv
170170
default_match = false
171-
description = A list of file names that are ransomware note files
171+
# description = A list of file names that are ransomware note files
172172
match_type = WILDCARD(ransomware_notes)
173173
min_matches = 1
174174

175175
[s3_deletion_baseline]
176176
filename = s3_deletion_baseline.csv
177-
description = A placeholder for the baseline information for AWS S3 deletions
177+
# description = A placeholder for the baseline information for AWS S3 deletions
178178

179179
[security_group_activity_baseline]
180180
filename = security_group_activity_baseline.csv
181-
description = A placeholder for the baseline information for AWS security groups
181+
# description = A placeholder for the baseline information for AWS security groups
182182

183183
[security_services_lookup]
184184
filename = security_services.csv
185185
default_match = false
186-
description = A list of services that deal with security
186+
# description = A list of services that deal with security
187187
match_type = WILDCARD(service)
188188
min_matches = 1
189189

190190
[suspicious_writes_lookup]
191191
filename = suspicious_files.csv
192192
default_match = false
193-
description = A list of suspicious file names
193+
# description = A list of suspicious file names
194194
match_type = WILDCARD(file)
195195
min_matches = 1
196196

package/default/use_case_library.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#############
22
# Automatically generated by generator.py in splunk/security-content
3-
# On Date: 2019-10-31T17:15:19 UTC
3+
# On Date: 2019-10-31T20:26:18 UTC
44
# Author: Splunk Security Research
55
66
#############

0 commit comments

Comments
 (0)