Skip to content

Analytic Updates & Tunings #3377

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 12 commits into from
May 1, 2025
Merged

Analytic Updates & Tunings #3377

merged 12 commits into from
May 1, 2025

Conversation

nasbench
Copy link
Contributor

@nasbench nasbench commented Mar 3, 2025

The following PR introduces the following updates

Deprecated Analytics

  • CertUtil Download With URLCache and Split Arguments
  • CertUtil Download With VerifyCtl and Split Arguments
  • Windows CertUtil Download With URL Argument

New Analytics

  • Windows File Download Via CertUtil - This new analytic merges the 3 deprecated.

Updated Analytics

  • CHCP Command Execution - Removed the CommandLine condition to make it more generic. Also switched it to an Anomaly.
  • Check Elevated CMD using whoami - Updated FP section
  • Detection of tools built by NirSoft - Updated to an Anomaly
  • System Processes Run From Unexpected Locations - Added new locations to tune FP

Updated Lookups

  • is_nirsoft_software - Added additional nirsoft tooling

@patel-bhavin
Copy link
Contributor

Since this has new deprecated content : Lets make sure this PR passes the new validation check : splunk/contentctl#355

@patel-bhavin patel-bhavin added the Deprecated PRs where content is moved to deprecated label Mar 25, 2025
@patel-bhavin patel-bhavin modified the milestone: v5.5.0 Apr 17, 2025
@nasbench nasbench added this to the v5.5.0 milestone Apr 24, 2025
@nasbench nasbench marked this pull request as ready for review April 24, 2025 19:34
@patel-bhavin patel-bhavin merged commit a26bfc0 into develop May 1, 2025
4 checks passed
@patel-bhavin patel-bhavin deleted the small-tuning branch May 1, 2025 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Deprecated PRs where content is moved to deprecated Detections Lookups
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants