Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DLUX 1 - Adding Misc New Detections #3024

Merged
merged 13 commits into from
Jul 17, 2024
Merged

DLUX 1 - Adding Misc New Detections #3024

merged 13 commits into from
Jul 17, 2024

Conversation

dluxtron
Copy link
Collaborator

@dluxtron dluxtron commented Jul 1, 2024

Adding a bunch of misc new detections across several security domains.

@dluxtron dluxtron changed the title Adding pwd spray detection DLUX Adding Misc New Detections Jul 2, 2024
@dluxtron dluxtron changed the title DLUX Adding Misc New Detections DLUX 1 - Adding Misc New Detections Jul 2, 2024
@patel-bhavin
Copy link
Contributor

overall results :
Failed
detections/application/detect_distributed_password_spray_attempts.yml - The dataset is does not work for the detection , the counts or the number of events are not enough

passed
detections/application/detect_password_spray_attempts.yml - pass
detections/application/windows_ad_add_self_to_group.yml - pass
detections/application/windows_increase_in_group_or_object_modification_activity.yml - pass
detections/application/windows_increase_in_user_modification_activity.yml - pass
detections/endpoint/windows_network_share_discovery_with_net.yml - pass
detections/endpoint/windows_vulnerable_driver_installed.yml - pass
detections/network/internal_horizontal_port_scan.yml - pass
detections/network/internal_vertical_port_scan.yml - pass
detections/network/internal_vulnerability_scan.yml - pass

@patel-bhavin
Copy link
Contributor

Made minor modifications and added data source fields

@patel-bhavin
Copy link
Contributor

Aweome work @dluxtron : will get this released in v.4.36.0

@patel-bhavin patel-bhavin reopened this Jul 17, 2024
@patel-bhavin patel-bhavin merged commit 16885f0 into develop Jul 17, 2024
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants