Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dlux 5 - AAD detection #3266

Merged
merged 18 commits into from
Jan 14, 2025
Merged

Dlux 5 - AAD detection #3266

merged 18 commits into from
Jan 14, 2025

Conversation

dluxtron
Copy link
Collaborator

@dluxtron dluxtron commented Jan 6, 2025

1x new Macro
8x new AAD focused detections based on the midnight blizzard attack & the BOTS scenario

Pending attack data PR for datasets to be approved: https://github.com/splunk/attack_data/pull/933/files#diff-ac74827b10a6cce5d71e749afd683657adacaa005f3a7fe926eeb78e9cac10b8

@patel-bhavin patel-bhavin added the WIP DO NOT MERGE Work in Progress label Jan 6, 2025
@patel-bhavin patel-bhavin removed the WIP DO NOT MERGE Work in Progress label Jan 8, 2025
@patel-bhavin patel-bhavin changed the title Dlux 5 - WIP Dlux 5 - AAD detection Jan 8, 2025
@patel-bhavin
Copy link
Contributor

@dluxtron :Thank you for this PR , made some minor fixes to the yamls and added a data source object! We should be good with merging this PR!

@patel-bhavin patel-bhavin merged commit fb66f8c into develop Jan 14, 2025
6 checks passed
@patel-bhavin patel-bhavin deleted the dlux_5 branch January 14, 2025 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants