Skip to content

Conversation

@patel-bhavin
Copy link
Contributor

This PR contains updates to Splunk TAs made by GitHub Actions workflow.

@ljstella
Copy link
Contributor

ljstella commented Nov 6, 2025

Unit testing timed out because of the number of detections- spun up a test harness with attack_data archive and these two failures occurred. Recommend additional testing of just those two to confirm:

Windows Kerberos Local Successful Logon
detections/endpoint/windows_kerberos_local_successful_logon.yml

Windows Svchost.exe Parent Process Anomaly
detections/endpoint/windows_svchost_exe_parent_process_anomaly.yml

@patel-bhavin
Copy link
Contributor Author

patel-bhavin commented Nov 6, 2025

Windows Kerberos Local Successful Logon - Passes after removal of : process_name process_path from the search
Old :
image

New
image

@patel-bhavin
Copy link
Contributor Author

Windows Svchost.exe Parent Process Anomaly- Doesnt get mapped to datamodel ?
Old
image

New
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants