github splunk/security_content v3.11.0

latest releases: v4.31.1, v4.31.0, v4.30.0...
3 years ago

New Detections:

  • Multi-factor authentication disabled (o365)
  • Excessive Authentication Failures Alert (o365)
  • PST Export Alert (o365)
  • Detect high number of login failures from a single source
  • Detect Supernova Webshell (used in SUNBURST)

Updates:

  • High number of login failures from a single source detection
  • Deprecated AWS Searches that have been translated.
    Other
  • Circle CI Config updates
  • Increase in testing coverage

Don't miss a new security_content release

NewReleases is sending notifications on new releases.