Skip to content

Commit 9240b85

Browse files
committed
Address PR review comments
1 parent 7effc6f commit 9240b85

File tree

3 files changed

+6
-67
lines changed

3 files changed

+6
-67
lines changed

detections/endpoint/linux_system_network_discovery.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ description: The following analytic identifies potential enumeration of local ne
1515
movement within the environment.
1616
data_source:
1717
- Sysmon for Linux EventID 1
18+
- osquery
1819
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
1920
as lastTime values(Processes.action) as action values(Processes.dest) as dest values(Processes.original_file_name)
2021
as original_file_name values(Processes.parent_process) as parent_process values(Processes.parent_process_exec)
@@ -85,3 +86,6 @@ tests:
8586
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/atomic_red_team/linux_net_discovery/sysmon_linux.log
8687
source: Syslog:Linux-Sysmon/Operational
8788
sourcetype: sysmon:linux
89+
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/atomic_red_team/macos_net_discovery/macos_network_discovery.log
90+
sourcetype: osquery:results
91+
source: local_vm

detections/endpoint/macos_list_firewall_rules.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ drilldown_searches:
3737
earliest_offset: $info_min_time$
3838
latest_offset: $info_max_time$
3939
rba:
40-
message: MacOS firewall rules listed
40+
message: MacOS firewall rules listed by $user$ on $dest$
4141
risk_objects:
4242
- field: dest
4343
type: system
@@ -61,6 +61,6 @@ tags:
6161
tests:
6262
- name: True Positive Test
6363
attack_data:
64-
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1016/atomic_red_team/macos_net_discovery/macos_network_discovery.log
64+
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1016/atomic_red_team/macos_net_discovery/macos_list_firewall_rules.log
6565
sourcetype: osquery:results
6666
source: local_vm

detections/endpoint/macos_system_network_configuration_discovery.yml

Lines changed: 0 additions & 65 deletions
This file was deleted.

0 commit comments

Comments
 (0)