Skip to content

Commit

Permalink
updating drilldowns
Browse files Browse the repository at this point in the history
  • Loading branch information
patel-bhavin committed Oct 24, 2024
1 parent 8b03f3d commit 0bb378b
Show file tree
Hide file tree
Showing 1,309 changed files with 5,236 additions and 5,236 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$dest$"
search: '%original_detection_search% | search dest = "$dest$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- CrushFTP Vulnerabilities
Expand Down
8 changes: 4 additions & 4 deletions detections/application/detect_password_spray_attempts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$sourcetype$"
search: '%original_detection_search% | search sourcetype = "$sourcetype$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$sourcetype$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$sourcetype$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Compromised User Account
Expand Down
8 changes: 4 additions & 4 deletions detections/application/ivanti_vtm_new_account_creation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$MODUSER$"
search: '%original_detection_search% | search MODUSER = "$MODUSER$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$MODUSER$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$MODUSER$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Ivanti Virtual Traffic Manager CVE-2024-7593
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
8 changes: 4 additions & 4 deletions detections/application/okta_idp_lifecycle_modifications.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Suspicious Okta Activity
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
8 changes: 4 additions & 4 deletions detections/application/okta_multiple_accounts_locked_out.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$src_user$"
search: '%original_detection_search% | search src_user = "$src_user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$src_user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
8 changes: 4 additions & 4 deletions detections/application/okta_new_api_token_created.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
8 changes: 4 additions & 4 deletions detections/application/okta_risk_threshold_exceeded.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$risk_object$"
search: '%original_detection_search% | search risk_object = "$risk_object$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$risk_object$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$risk_object$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
8 changes: 4 additions & 4 deletions detections/application/okta_suspicious_activity_reported.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Suspicious Okta Activity
Expand Down
8 changes: 4 additions & 4 deletions detections/application/okta_threatinsight_threat_detected.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$app$"
search: '%original_detection_search% | search app = "$app$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$app$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$app$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ references:
drilldown_searches:
- name: View the detection results for - "$user$"
search: '%original_detection_search% | search user = "$user$"'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: '"$info_min_time$"'
latest_offset: '"$info_max_time$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
tags:
analytic_story:
- Okta Account Takeover
Expand Down
Loading

0 comments on commit 0bb378b

Please sign in to comment.