github splunk/security_content v3.62.0

latest releases: v4.40.0, v4.39.1, v4.39.0...
18 months ago

New Analytic Story

New Analytics

  • Okta Mismatch Between Source and Response for Okta Verify Push Request
  • Okta Multiple Failed Requests to Access Applications
  • Okta Suspicious Use of a Session Cookie
  • Okta Phishing Detection with FastPass Origin Check
  • Okta ThreatInsight Login Failure with High Unknown users
  • Okta ThreatInsight Suspected PasswordSpray Attack
  • Windows Rundll32 WebDAV Request
  • Windows Rundll32 WebDav With Network Connection

Other Updates

  • Updated ransomware_notes.csv and ransomware_extensions.csv files and transforms definition (thanks to @VatsalJagani )
  • Updated playbook name to CrowdStrike OAuth API Device Attribute Lookup
  • Updated several analytics to integrate better with Enterprise Security

Don't miss a new security_content release

NewReleases is sending notifications on new releases.