-
Notifications
You must be signed in to change notification settings - Fork 430
New MacOS detections T1016 #3672
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: develop
Are you sure you want to change the base?
Conversation
|
Testing is failing - Testing environment does not currently have the osquery TA for this dataset, a new release hasn't been cut on that repo, and the app itself is archived from Splunkbase (don't think it'll be unarchived either due to changes in Splunk Works) - We'll need an actual release package of that TA and getting it into the config before testing can pass. |
|
@jwindley : You think we can get this TA unarchived by the Splunkbase folks or maybe we can consider shipping these detections as experimental and have detailed info in the how to implement section due to lack of supported TA? |
|
Hi @patel-bhavin . Regarding the TA - I have made updates to https://github.com/splunk/TA-osquery to bring it up-to-date. Not sure the process for getting this latest version on to Splunkbase. @josehelps owns the TA so perhaps he can help? Happy for you to ship as experimental if you wish. |
detections/endpoint/macos_system_network_configuration_discovery.yml
Outdated
Show resolved
Hide resolved
Does not make sense to ship these if there is no easy way for a customer to get this data imo. We should work to get the TA back on splunkbase or just keep this on hold |
14e7189 to
9240b85
Compare
Adding a couple of MacOS detections (first of many, hopefully), using data captured from TA-osquery.