-
Notifications
You must be signed in to change notification settings - Fork 173
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Threat-274 OCSF data model, CloudTrail #1238
base: develop
Are you sure you want to change the base?
Commits on Apr 11, 2024
-
Deprecate GreyNoise detections (#1205)
* Deprecate GreyNoise detections * Update rules/aws_cloudtrail_rules/aws_s3_activity_greynoise.yml * Update rules/cloudflare_rules/cloudflare_firewall_suspicious_event_greynoise.yml * Update cloudflare_httpreq_bot_high_volume_greynoise.yml --------- Co-authored-by: Ariel Ropek <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 8b4be20 - Browse repository at this point
Copy the full SHA 8b4be20View commit details
Commits on Apr 15, 2024
-
fix - Notion Login From New Location - NoneType error (#1206)
* fix - Notion Login From New Location - NoneType error * fix - Notion Login From New Location - NoneType error - linter fix
Configuration menu - View commit details
-
Copy full SHA for 319fd15 - Browse repository at this point
Copy the full SHA 319fd15View commit details
Commits on Apr 16, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 3fde677 - Browse repository at this point
Copy the full SHA 3fde677View commit details
Commits on Apr 23, 2024
-
fix - GCP rules - AttributeError (#1210)
* fix - GCP rules - AttributeError * fix - GCP rules - AttributeError - linter fix
Configuration menu - View commit details
-
Copy full SHA for 9239b29 - Browse repository at this point
Copy the full SHA 9239b29View commit details -
MITRE ATT&CK Mappings for MS Rules (#1209)
* added MITRE mappings for microsoft rules * fixed formatting on some helper files --------- Co-authored-by: Ariel Ropek <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for f1180d4 - Browse repository at this point
Copy the full SHA f1180d4View commit details -
traildiscover enrichment with managed schema (#1177)
* traildiscover enrichment with managed schema * Add npm install in dockerfile (#1172) * add npm install in dockerfile * Remove Python optimizations; add prettier to PATH --------- Co-authored-by: egibs <[email protected]> * schema name: TrailDiscover.CloudTrail * Fix Dockerfile; add Workflow to test image * updated data set * Add MongoDB.2FA.Disabled rule (#1190) Co-authored-by: Ariel Ropek <[email protected]> * lint and fmt * fmt * add OCSF selector * additional OCSF mappings * Fix Pipfile * Rebase changes --------- Co-authored-by: Panos Sakkos <[email protected]> Co-authored-by: egibs <[email protected]> Co-authored-by: Oleh Melenevskyi <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 6eeb515 - Browse repository at this point
Copy the full SHA 6eeb515View commit details -
Evan Gibler authored
Apr 23, 2024 Configuration menu - View commit details
-
Copy full SHA for e2e9b4f - Browse repository at this point
Copy the full SHA e2e9b4fView commit details
Commits on May 7, 2024
-
Replace panther_analysis_tool import with updated import (#1230)
Evan Gibler authoredMay 7, 2024 Configuration menu - View commit details
-
Copy full SHA for cd042d2 - Browse repository at this point
Copy the full SHA cd042d2View commit details -
Update Action versions; use SHAs (#1231)
* Update Action versions; use SHAs * Add dependabot.yml to keep Actions updated * Update PAT to 0.49.0
Evan Gibler authoredMay 7, 2024 Configuration menu - View commit details
-
Copy full SHA for 5e5f196 - Browse repository at this point
Copy the full SHA 5e5f196View commit details
Commits on May 8, 2024
-
migrates the gcp_storage_hmac_keys_create rule to (#1233)
python from sdyaml
Configuration menu - View commit details
-
Copy full SHA for 0f28285 - Browse repository at this point
Copy the full SHA 0f28285View commit details -
Configuration menu - View commit details
-
Copy full SHA for 83e6d74 - Browse repository at this point
Copy the full SHA 83e6d74View commit details
Commits on May 13, 2024
-
* consistency nit fixes * - somethings -> some things
Configuration menu - View commit details
-
Copy full SHA for 575cf47 - Browse repository at this point
Copy the full SHA 575cf47View commit details
Commits on May 14, 2024
-
AppOmni Alert passthrough (#1211)
* alert passthrough * Deprecate GreyNoise detections (#1205) * Deprecate GreyNoise detections * Update rules/aws_cloudtrail_rules/aws_s3_activity_greynoise.yml * Update rules/cloudflare_rules/cloudflare_firewall_suspicious_event_greynoise.yml * Update cloudflare_httpreq_bot_high_volume_greynoise.yml --------- Co-authored-by: Ariel Ropek <[email protected]> * fix - Notion Login From New Location - NoneType error (#1206) * fix - Notion Login From New Location - NoneType error * fix - Notion Login From New Location - NoneType error - linter fix * remove codeowners (#1208) * linting * fix - GCP rules - AttributeError (#1210) * fix - GCP rules - AttributeError * fix - GCP rules - AttributeError - linter fix * MITRE ATT&CK Mappings for MS Rules (#1209) * added MITRE mappings for microsoft rules * fixed formatting on some helper files --------- Co-authored-by: Ariel Ropek <[email protected]> * traildiscover enrichment with managed schema (#1177) * traildiscover enrichment with managed schema * Add npm install in dockerfile (#1172) * add npm install in dockerfile * Remove Python optimizations; add prettier to PATH --------- Co-authored-by: egibs <[email protected]> * schema name: TrailDiscover.CloudTrail * Fix Dockerfile; add Workflow to test image * updated data set * Add MongoDB.2FA.Disabled rule (#1190) Co-authored-by: Ariel Ropek <[email protected]> * lint and fmt * fmt * add OCSF selector * additional OCSF mappings * Fix Pipfile * Rebase changes --------- Co-authored-by: Panos Sakkos <[email protected]> Co-authored-by: egibs <[email protected]> Co-authored-by: Oleh Melenevskyi <[email protected]> * Update PAT to 0.46.0 (#1216) * add file/host state to msft graph alert context (#1220) * fix timestamps (#1219) * Update PAT to 0.46.1 (#1222) * pack for traildiscover LUT (#1221) * use event.deep_get and remove InlineFilters * add pack --------- Co-authored-by: Oleh Melenevskyi <[email protected]> Co-authored-by: Ariel Ropek <[email protected]> Co-authored-by: akozlovets098 <[email protected]> Co-authored-by: Panos Sakkos <[email protected]> Co-authored-by: ben-githubs <[email protected]> Co-authored-by: egibs <[email protected]> Co-authored-by: Evan Gibler <[email protected]> Co-authored-by: Nick Hakmiller <[email protected]> Co-authored-by: Ariel Ropek <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for c8b6ad9 - Browse repository at this point
Copy the full SHA c8b6ad9View commit details
Commits on May 15, 2024
-
Merge remote-tracking branch 'origin/release' into release
# Conflicts: # .github/CODEOWNERS # Pipfile # Pipfile.lock
Configuration menu - View commit details
-
Copy full SHA for 1cb6695 - Browse repository at this point
Copy the full SHA 1cb6695View commit details
Commits on May 21, 2024
-
* Deprecate GreyNoise detections (#1205) * Deprecate GreyNoise detections * Update rules/aws_cloudtrail_rules/aws_s3_activity_greynoise.yml * Update rules/cloudflare_rules/cloudflare_firewall_suspicious_event_greynoise.yml * Update cloudflare_httpreq_bot_high_volume_greynoise.yml --------- Co-authored-by: Ariel Ropek <[email protected]> * fix - Notion Login From New Location - NoneType error (#1206) * fix - Notion Login From New Location - NoneType error * fix - Notion Login From New Location - NoneType error - linter fix * Push Security rules * remove codeowners (#1208) * fix - GCP rules - AttributeError (#1210) * fix - GCP rules - AttributeError * fix - GCP rules - AttributeError - linter fix * MITRE ATT&CK Mappings for MS Rules (#1209) * added MITRE mappings for microsoft rules * fixed formatting on some helper files --------- Co-authored-by: Ariel Ropek <[email protected]> * traildiscover enrichment with managed schema (#1177) * traildiscover enrichment with managed schema * Add npm install in dockerfile (#1172) * add npm install in dockerfile * Remove Python optimizations; add prettier to PATH --------- Co-authored-by: egibs <[email protected]> * schema name: TrailDiscover.CloudTrail * Fix Dockerfile; add Workflow to test image * updated data set * Add MongoDB.2FA.Disabled rule (#1190) Co-authored-by: Ariel Ropek <[email protected]> * lint and fmt * fmt * add OCSF selector * additional OCSF mappings * Fix Pipfile * Rebase changes --------- Co-authored-by: Panos Sakkos <[email protected]> Co-authored-by: egibs <[email protected]> Co-authored-by: Oleh Melenevskyi <[email protected]> * Update PAT to 0.46.0 (#1216) * add file/host state to msft graph alert context (#1220) * fix timestamps (#1219) * Update PAT to 0.46.1 (#1222) * pack for traildiscover LUT (#1221) * pack, fmt lint, event.deep_get * pack update --------- Co-authored-by: Oleh Melenevskyi <[email protected]> Co-authored-by: Ariel Ropek <[email protected]> Co-authored-by: akozlovets098 <[email protected]> Co-authored-by: Panos Sakkos <[email protected]> Co-authored-by: ben-githubs <[email protected]> Co-authored-by: egibs <[email protected]> Co-authored-by: Evan Gibler <[email protected]> Co-authored-by: Nick Hakmiller <[email protected]> Co-authored-by: Ariel Ropek <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 8012f11 - Browse repository at this point
Copy the full SHA 8012f11View commit details -
Configuration menu - View commit details
-
Copy full SHA for 1252a70 - Browse repository at this point
Copy the full SHA 1252a70View commit details -
* created pack and updated event.deep_get * update logtype
Configuration menu - View commit details
-
Copy full SHA for 63db6ce - Browse repository at this point
Copy the full SHA 63db6ceView commit details
Commits on May 22, 2024
-
Remove Node/NPM/Prettier (#1241)
* Remove Node/NPM/Prettier Signed-off-by: egibs <[email protected]> * Update README; add removal notes Signed-off-by: egibs <[email protected]> --------- Signed-off-by: egibs <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 442849c - Browse repository at this point
Copy the full SHA 442849cView commit details
Commits on May 27, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 309c401 - Browse repository at this point
Copy the full SHA 309c401View commit details
Commits on May 29, 2024
-
Configuration menu - View commit details
-
Copy full SHA for c8b23bd - Browse repository at this point
Copy the full SHA c8b23bdView commit details -
Use harden-runner Action for all Workflows (#1244)
* Use harden-runner Action for all Workflows Signed-off-by: egibs <[email protected]> * Run Docker Workflow Signed-off-by: egibs <[email protected]> * Add blocking policy for docker.yml Signed-off-by: egibs <[email protected]> * Add permissions to Workflow Signed-off-by: egibs <[email protected]> * More permissions Signed-off-by: egibs <[email protected]> --------- Signed-off-by: egibs <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for dc7070c - Browse repository at this point
Copy the full SHA dc7070cView commit details
Commits on May 30, 2024
-
Threat 319 Replace geoinfo_from_ip with new version (#1242)
* Deprecate GreyNoise detections (#1205) * Deprecate GreyNoise detections * Update rules/aws_cloudtrail_rules/aws_s3_activity_greynoise.yml * Update rules/cloudflare_rules/cloudflare_firewall_suspicious_event_greynoise.yml * Update cloudflare_httpreq_bot_high_volume_greynoise.yml --------- Co-authored-by: Ariel Ropek <[email protected]> * fix - Notion Login From New Location - NoneType error (#1206) * fix - Notion Login From New Location - NoneType error * fix - Notion Login From New Location - NoneType error - linter fix * remove codeowners (#1208) * fix - GCP rules - AttributeError (#1210) * fix - GCP rules - AttributeError * fix - GCP rules - AttributeError - linter fix * MITRE ATT&CK Mappings for MS Rules (#1209) * added MITRE mappings for microsoft rules * fixed formatting on some helper files --------- Co-authored-by: Ariel Ropek <[email protected]> * traildiscover enrichment with managed schema (#1177) * traildiscover enrichment with managed schema * Add npm install in dockerfile (#1172) * add npm install in dockerfile * Remove Python optimizations; add prettier to PATH --------- Co-authored-by: egibs <[email protected]> * schema name: TrailDiscover.CloudTrail * Fix Dockerfile; add Workflow to test image * updated data set * Add MongoDB.2FA.Disabled rule (#1190) Co-authored-by: Ariel Ropek <[email protected]> * lint and fmt * fmt * add OCSF selector * additional OCSF mappings * Fix Pipfile * Rebase changes --------- Co-authored-by: Panos Sakkos <[email protected]> Co-authored-by: egibs <[email protected]> Co-authored-by: Oleh Melenevskyi <[email protected]> * Update PAT to 0.46.0 (#1216) * THREAT-319 Replace geoinfo_from_ip with new version --------- Co-authored-by: Oleh Melenevskyi <[email protected]> Co-authored-by: Ariel Ropek <[email protected]> Co-authored-by: Panos Sakkos <[email protected]> Co-authored-by: ben-githubs <[email protected]> Co-authored-by: egibs <[email protected]> Co-authored-by: Evan Gibler <[email protected]> Co-authored-by: Evan Gibler <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 736c250 - Browse repository at this point
Copy the full SHA 736c250View commit details -
Use full Action SHAs rather than versioned releases (#1245)
Signed-off-by: egibs <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for cec5c8c - Browse repository at this point
Copy the full SHA cec5c8cView commit details -
Configuration menu - View commit details
-
Copy full SHA for ca6f7de - Browse repository at this point
Copy the full SHA ca6f7deView commit details
Commits on Jun 3, 2024
-
Merge branch 'main' into release
Signed-off-by: egibs <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 7eed675 - Browse repository at this point
Copy the full SHA 7eed675View commit details -
Update panther-core to 0.10.1 via PAT (#1249)
Signed-off-by: egibs <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 12ff27b - Browse repository at this point
Copy the full SHA 12ff27bView commit details
Commits on Jun 4, 2024
-
Configuration menu - View commit details
-
Copy full SHA for c331931 - Browse repository at this point
Copy the full SHA c331931View commit details -
Configuration menu - View commit details
-
Copy full SHA for 88becd1 - Browse repository at this point
Copy the full SHA 88becd1View commit details -
Configuration menu - View commit details
-
Copy full SHA for 63439fc - Browse repository at this point
Copy the full SHA 63439fcView commit details -
Configuration menu - View commit details
-
Copy full SHA for 40e9e64 - Browse repository at this point
Copy the full SHA 40e9e64View commit details -
Configuration menu - View commit details
-
Copy full SHA for 1ddcd0e - Browse repository at this point
Copy the full SHA 1ddcd0eView commit details -
Tweak Snowflake queries (#1250)
* Tweak Snowflake queries Signed-off-by: egibs <[email protected]> * Remove configuration drift query from Pack Signed-off-by: egibs <[email protected]> * Threat Hunting queries are okay Signed-off-by: egibs <[email protected]> * Fix comment Workflow Signed-off-by: egibs <[email protected]> * 12 hours -> 1 day Signed-off-by: egibs <[email protected]> * Update queries/snowflake_queries/snowflake_0108977_configuration_drift.yml --------- Signed-off-by: egibs <[email protected]> Co-authored-by: Ariel Ropek <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for aa5ae8b - Browse repository at this point
Copy the full SHA aa5ae8bView commit details -
Configuration menu - View commit details
-
Copy full SHA for a854c16 - Browse repository at this point
Copy the full SHA a854c16View commit details