github splunk/security_content v3.25.2

latest releases: v4.43.0, v4.42.0, v4.41.0...
3 years ago

This is a GitHub-only release and will not be uploaded to SplunkBase

Bug Fixes

SSA

System Process Running from Unexpected Location

Splunk Security Analytics for AWS

AWS CreateAccessKey
AWS UpdateLoginProfile
AWS CreateLoginProfile
Detect New Open S3 buckets
Detect New Open S3 Buckets over AWS CLI

New Analytics

  • Attacker Tools On Endpoint

Other

Adding new tags to support multi risk entities and threat objects in Risk Analysis Framework

Don't miss a new security_content release

NewReleases is sending notifications on new releases.