You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
700
-
- content: Github Commit Changes In Master
701
-
removed_in_version: 5.4.0
702
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
703
-
- content: Github Commit In Develop
704
-
removed_in_version: 5.4.0
705
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
706
-
- content: GitHub Dependabot Alert
707
-
removed_in_version: 5.4.0
708
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
709
-
- content: GitHub Pull Request from Unknown User
710
-
removed_in_version: 5.4.0
711
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
712
-
- content: Known Services Killed by Ransomware
713
-
removed_in_version: 5.4.0
714
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
715
-
- content: Remote Desktop Network Bruteforce
716
-
removed_in_version: 5.4.0
717
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
718
-
- content: Suspicious Driver Loaded Path
719
-
removed_in_version: 5.4.0
720
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
721
-
- content: Suspicious Event Log Service Behavior
722
-
removed_in_version: 5.4.0
723
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
724
-
- content: Suspicious Process File Path
725
-
removed_in_version: 5.4.0
726
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
727
-
- content: AWS Cross Account Activity From Previously Unseen Account
728
-
removed_in_version: 5.4.0
729
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
730
-
- content: aws detect attach to role policy
731
-
removed_in_version: 5.4.0
732
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
733
-
- content: aws detect permanent key creation
734
-
removed_in_version: 5.4.0
735
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
736
-
- content: aws detect role creation
737
-
removed_in_version: 5.4.0
738
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
739
-
- content: aws detect sts assume role abuse
740
-
removed_in_version: 5.4.0
741
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
742
-
- content: aws detect sts get session token abuse
743
-
removed_in_version: 5.4.0
744
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
745
-
- content: AWS SAML Access by Provider User and Principal
746
-
removed_in_version: 5.4.0
747
-
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
748
770
baselines:
749
771
- content: Add Prohibited Processes to Enterprise Security
750
772
removed_in_version: 5.2.0
@@ -943,6 +965,16 @@ investigations:
943
965
removed_in_version: 5.2.0
944
966
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
945
967
stories:
968
+
- content: Nexus APT Threat Activity
969
+
removed_in_version: 5.4.0
970
+
reason: Analytic Story has been replaced by a new analytic story with a more specific name
971
+
replacement_content:
972
+
- China-Nexus Threat Activity
973
+
- content: Earth Estries
974
+
removed_in_version: 5.4.0
975
+
reason: Analytic Story has been replaced by a new analytic story with a more specific name
976
+
replacement_content:
977
+
- Salt Typhoon
946
978
- content: AWS Cryptomining
947
979
removed_in_version: 5.2.0
948
980
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
@@ -1000,9 +1032,4 @@ stories:
1000
1032
- Suspicious Cloud Instance Activities
1001
1033
- content: Web Fraud Detection
1002
1034
removed_in_version: 5.2.0
1003
-
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
1004
-
- content: Nexus APT Threat Activity
1005
-
removed_in_version: 5.4.0
1006
-
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
1007
-
replacement_content:
1008
-
- China-Nexus Threat Activity
1035
+
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
0 commit comments