diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index c40126191c..3e296551ac 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -1,8 +1,8 @@ name: ASL AWS CloudTrail id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898 -version: 3 +version: 9 creation_date: '2025-01-14' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Represents AWS API dataset data collection from Amazon Security Lake. mitre_components: @@ -24,7 +24,7 @@ separator: api.operation supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 output_fields: - dest - user diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml index dbe9bbafd8..12d7c54b8f 100644 --- a/data_sources/aws_cloudfront.yml +++ b/data_sources/aws_cloudfront.yml @@ -1,8 +1,8 @@ name: AWS Cloudfront id: 780086dc-2384-45b6-ade7-56cb00105464 -version: 3 +version: 9 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics. mitre_components: @@ -17,7 +17,7 @@ sourcetype: aws:cloudfront:accesslogs supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail.yml b/data_sources/aws_cloudtrail.yml index d80e70b155..22cc64c008 100644 --- a/data_sources/aws_cloudtrail.yml +++ b/data_sources/aws_cloudtrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail id: e8ace6db-1dbd-4c72-a1fb-334684619a38 -version: 2 +version: 8 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: All AWS CloudTrail events source: aws_cloudtrail @@ -11,4 +11,4 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml index efe8b33ddb..cf72e053ce 100644 --- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml +++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail AssumeRoleWithSAML id: 1e28f2a6-2db9-405f-b298-18734a293f77 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs attempts to assume roles via SAML authentication in AWS, including details of identity provider and role mapping. mitre_components: @@ -18,7 +18,7 @@ separator_value: AssumeRoleWithSAML supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml index 47f47f1900..9f053dd257 100644 --- a/data_sources/aws_cloudtrail_consolelogin.yml +++ b/data_sources/aws_cloudtrail_consolelogin.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ConsoleLogin id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events. mitre_components: @@ -18,7 +18,7 @@ separator_value: ConsoleLogin supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index afce3a4582..caa61e5cd5 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CopyObject id: 965083f4-64a8-403f-99cc-252e1a6bd3b6 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination. mitre_components: @@ -17,7 +17,7 @@ separator_value: CopyObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml index 55fa3c5e41..be51e37a77 100644 --- a/data_sources/aws_cloudtrail_createaccesskey.yml +++ b/data_sources/aws_cloudtrail_createaccesskey.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateAccessKey id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of new AWS access keys, including details of the associated user and permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateAccessKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml index a421c79763..4e0a8ea8bf 100644 --- a/data_sources/aws_cloudtrail_createkey.yml +++ b/data_sources/aws_cloudtrail_createkey.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateKey id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml index 3f8eab8b67..1164eb4fbf 100644 --- a/data_sources/aws_cloudtrail_createloginprofile.yml +++ b/data_sources/aws_cloudtrail_createloginprofile.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateLoginProfile id: 0024fdb1-0d62-4449-970a-746952cf80b6 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml index 1ad5447148..75b9c9fb3b 100644 --- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateNetworkAclEntry id: 45934028-10ec-4ab5-a7b1-a6349b833e67 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml index dfd4ba9321..3818645444 100644 --- a/data_sources/aws_cloudtrail_createpolicyversion.yml +++ b/data_sources/aws_cloudtrail_createpolicyversion.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreatePolicyVersion id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreatePolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml index e2a3e40ce3..7d58737dbd 100644 --- a/data_sources/aws_cloudtrail_createsnapshot.yml +++ b/data_sources/aws_cloudtrail_createsnapshot.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateSnapshot id: 514135a2-f4b2-4d32-8f31-d87824887f9f -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index 1a462fcf5d..b4ff68f5f1 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateTask id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateTask supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml index 1dd734b3c2..9c1e5ece3f 100644 --- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateVirtualMFADevice id: 13e6e952-0dad-4190-865c-fb5911725f7a -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml index bf04e2a317..f7086304d0 100644 --- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml +++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeactivateMFADevice id: 7397a10b-1150-4de9-8062-a96454ae53b2 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeactivateMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml index e08314d029..c0bae5d6a7 100644 --- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteAccountPasswordPolicy id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml index 44405c5e8b..c1f26e1b8d 100644 --- a/data_sources/aws_cloudtrail_deletealarms.yml +++ b/data_sources/aws_cloudtrail_deletealarms.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteAlarms id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f -version: 3 +version: 9 creation_date: '2024-08-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteAlarms supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml index 3d53d8c6c7..54cd996f45 100644 --- a/data_sources/aws_cloudtrail_deletedetector.yml +++ b/data_sources/aws_cloudtrail_deletedetector.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteDetector id: 5d8bd475-c8bc-4447-b27f-efa508728b90 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteDetector supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml index 67d95cdb65..1efdf5666d 100644 --- a/data_sources/aws_cloudtrail_deletegroup.yml +++ b/data_sources/aws_cloudtrail_deletegroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteGroup id: c95308a4-a943-42ca-b112-f90a05c21bd3 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteguardrail.yml b/data_sources/aws_cloudtrail_deleteguardrail.yml index c4f6cc2598..36c91acfcc 100644 --- a/data_sources/aws_cloudtrail_deleteguardrail.yml +++ b/data_sources/aws_cloudtrail_deleteguardrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteGuardrail id: 2f6e9d7a-1c53-48b1-be57-33a91e0f8c42 -version: 2 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Logs an event when a guardrail is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteGuardrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml index 010c2162c1..7665b843d4 100644 --- a/data_sources/aws_cloudtrail_deleteipset.yml +++ b/data_sources/aws_cloudtrail_deleteipset.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteIPSet id: ebdeeb63-77a0-4808-a6fe-549956731377 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations. mitre_components: @@ -16,7 +16,7 @@ separator_value: DeleteIPSet supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deleteknowledgebase.yml b/data_sources/aws_cloudtrail_deleteknowledgebase.yml index 8b13e8bdc2..129596a4e7 100644 --- a/data_sources/aws_cloudtrail_deleteknowledgebase.yml +++ b/data_sources/aws_cloudtrail_deleteknowledgebase.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteKnowledgeBase id: a8c47f25-5693-4d1a-9f8b-6e94d15ac2d9 -version: 2 +version: 8 creation_date: '2025-04-17' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Logs an event when a knowledge base is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteKnowledgeBase supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml b/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml index 55c95ea4ad..8821dd357c 100644 --- a/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml +++ b/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLoggingConfiguration id: 24a28726-28f3-4537-a953-71bfbbc3b831 -version: 2 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DeleteLoggingConfiguration source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time example_log: '' diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml index 3809b00a30..22920786a9 100644 --- a/data_sources/aws_cloudtrail_deleteloggroup.yml +++ b/data_sources/aws_cloudtrail_deleteloggroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLogGroup id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteLogGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml index 7270838ad1..d87a2a013e 100644 --- a/data_sources/aws_cloudtrail_deletelogstream.yml +++ b/data_sources/aws_cloudtrail_deletelogstream.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLogStream id: 6f8bb808-89f8-465e-a34d-229df2f46402 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteLogStream supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml b/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml index 614f3fd068..6738fec292 100644 --- a/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml +++ b/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteModelInvocationLoggingConfiguration id: fe2b3a52-1c8d-4e17-9f74-76c531a87e21 -version: 2 +version: 8 creation_date: '2025-04-17' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Logs an event when a model invocation logging configuration is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteModelInvocationLoggingConfiguration supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml index 6562a321da..c8a03dda26 100644 --- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteNetworkAclEntry id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL. mitre_components: @@ -16,7 +16,7 @@ separator_value: DeleteNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml index 84c522f2f4..cd1301dc2d 100644 --- a/data_sources/aws_cloudtrail_deletepolicy.yml +++ b/data_sources/aws_cloudtrail_deletepolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeletePolicy id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeletePolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml index 4929e2e883..16d4bc368d 100644 --- a/data_sources/aws_cloudtrail_deleterule.yml +++ b/data_sources/aws_cloudtrail_deleterule.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteRule id: b5760623-f3ca-492d-a372-d5c2b3567dfc -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteRule supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deleterulegroup.yml b/data_sources/aws_cloudtrail_deleterulegroup.yml index b8105c4862..7a2fd06fe5 100644 --- a/data_sources/aws_cloudtrail_deleterulegroup.yml +++ b/data_sources/aws_cloudtrail_deleterulegroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteRuleGroup id: 21c9b538-fa11-4bdf-9138-0dfe06b4d730 -version: 2 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DeleteRuleGroup source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time example_log: '' diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml index c234e022e6..500eb880ba 100644 --- a/data_sources/aws_cloudtrail_deletesnapshot.yml +++ b/data_sources/aws_cloudtrail_deletesnapshot.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteSnapshot id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f -version: 3 +version: 9 creation_date: '2024-08-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml index e52c960d46..7be6532873 100644 --- a/data_sources/aws_cloudtrail_deletetrail.yml +++ b/data_sources/aws_cloudtrail_deletetrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteTrail id: a5af09ff-07b6-4df6-92a0-2146bfe402c8 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml index abcf17e438..783b378094 100644 --- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteVirtualMFADevice id: 84a08d6b-3d59-4260-8cab-84278ada262f -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml index c88017ac48..2a40ef10ce 100644 --- a/data_sources/aws_cloudtrail_deletewebacl.yml +++ b/data_sources/aws_cloudtrail_deletewebacl.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteWebACL id: 90da5f08-7961-4c29-8de8-01364982aadf -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteWebACL supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml index ee363cb8cd..5435659e2c 100644 --- a/data_sources/aws_cloudtrail_describeeventaggregates.yml +++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeEventAggregates id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when aggregate details about AWS events are queried, often for analysis. mitre_components: @@ -15,7 +15,7 @@ separator_value: DescribeEventAggregates supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml index d19da791f6..6ec56a6ee9 100644 --- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml +++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeImageScanFindings id: 688ea789-9ba2-4970-90a2-17e541e273c9 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail. mitre_components: @@ -16,7 +16,7 @@ separator_value: DescribeImageScanFindings supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_describesnapshotattribute.yml b/data_sources/aws_cloudtrail_describesnapshotattribute.yml index 2346b22494..7b7cbdaf92 100644 --- a/data_sources/aws_cloudtrail_describesnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_describesnapshotattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeSnapshotAttribute id: f054c99b-63b8-4236-8a62-b52fbbabacba -version: 2 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DescribeSnapshotAttribute source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - action - app diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml index 38d1565418..41dd514f85 100644 --- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetAccountPasswordPolicy id: 439bdc53-6e4b-4cd7-b326-86c7317fd396 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to get the account password policy in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: GetAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml index c39f7ca141..189da9dcf0 100644 --- a/data_sources/aws_cloudtrail_getobject.yml +++ b/data_sources/aws_cloudtrail_getobject.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetObject id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to access an object stored in an AWS S3 bucket. mitre_components: @@ -16,7 +16,7 @@ separator_value: GetObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml index 060a86c2dc..9b681d8553 100644 --- a/data_sources/aws_cloudtrail_getpassworddata.yml +++ b/data_sources/aws_cloudtrail_getpassworddata.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetPasswordData id: 6ff2ce99-85b1-4c17-888a-56dbc3570671 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance. mitre_components: @@ -15,7 +15,7 @@ separator_value: GetPasswordData supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_invokemodel.yml b/data_sources/aws_cloudtrail_invokemodel.yml index 924c2c1367..88b0c6b228 100644 --- a/data_sources/aws_cloudtrail_invokemodel.yml +++ b/data_sources/aws_cloudtrail_invokemodel.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail InvokeModel id: 5d92a1b6-3e78-4ff2-be83-7a4c01f9df6c -version: 2 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Logs an event when a model is invoked within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: InvokeModel supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml index 83b42f8449..02565ae6c8 100644 --- a/data_sources/aws_cloudtrail_jobcreated.yml +++ b/data_sources/aws_cloudtrail_jobcreated.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail JobCreated id: 6473289b-d097-4c86-a837-3cc5ae408155 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a new job is created in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: JobCreated supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_listfoundationmodels.yml b/data_sources/aws_cloudtrail_listfoundationmodels.yml index 06a7cd7584..889d180332 100644 --- a/data_sources/aws_cloudtrail_listfoundationmodels.yml +++ b/data_sources/aws_cloudtrail_listfoundationmodels.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ListFoundationModels id: e7f31c68-84b9-4d21-a8c5-ec9d2fb3a457 -version: 2 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Logs an event when a list of foundation models is requested within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: ListFoundationModels supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml index a6b0eeca89..02e630c64d 100644 --- a/data_sources/aws_cloudtrail_modifydbinstance.yml +++ b/data_sources/aws_cloudtrail_modifydbinstance.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifyDBInstance id: bfa2912d-1a33-4b05-be46-543874d68241 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations. mitre_components: @@ -16,7 +16,7 @@ separator_value: ModifyDBInstance supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml index 272e734d13..39c873b423 100644 --- a/data_sources/aws_cloudtrail_modifyimageattribute.yml +++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifyImageAttribute id: 667c2115-8082-419e-b541-8150066bda4d -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified. mitre_components: @@ -15,7 +15,7 @@ separator_value: ModifyImageAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml index afebb51c8f..46071c8e3e 100644 --- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifySnapshotAttribute id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: ModifySnapshotAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml index 172b11719d..a8eeb639e1 100644 --- a/data_sources/aws_cloudtrail_putbucketacl.yml +++ b/data_sources/aws_cloudtrail_putbucketacl.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketAcl id: 28fffbfd-d98d-4a42-990b-b04ab47422eb -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutBucketAcl supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml index c24c6c2417..ba801b9754 100644 --- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml +++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketLifecycle id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutBucketLifecycle supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml index ac76f2f355..f0977d5e6d 100644 --- a/data_sources/aws_cloudtrail_putbucketreplication.yml +++ b/data_sources/aws_cloudtrail_putbucketreplication.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketReplication id: 0e1362eb-e592-419f-8fa5-556d3a122417 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when replication configurations are added or modified for an S3 bucket. mitre_components: @@ -14,7 +14,7 @@ separator_value: PutBucketReplication supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml index 9f834c10ce..6f9a354dc0 100644 --- a/data_sources/aws_cloudtrail_putbucketversioning.yml +++ b/data_sources/aws_cloudtrail_putbucketversioning.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketVersioning id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket. mitre_components: @@ -14,7 +14,7 @@ separator_value: PutBucketVersioning supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml index 22e5498275..8a5630e104 100644 --- a/data_sources/aws_cloudtrail_putimage.yml +++ b/data_sources/aws_cloudtrail_putimage.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutImage id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutImage supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml index 37d43a3286..3eb5ea087c 100644 --- a/data_sources/aws_cloudtrail_putkeypolicy.yml +++ b/data_sources/aws_cloudtrail_putkeypolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutKeyPolicy id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs changes made to AWS Key Management Service (KMS) key policies, including updates and permission assignments. mitre_components: @@ -13,7 +13,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml index 34e190129c..34e7637ce2 100644 --- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ReplaceNetworkAclEntry id: db0c240e-3754-40e4-86ef-cde018ee9f65 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: ReplaceNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml index c3264444c1..cb3b21aba7 100644 --- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml +++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail SetDefaultPolicyVersion id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when the default version of a resource policy in AWS is set or changed. mitre_components: @@ -15,7 +15,7 @@ separator_value: SetDefaultPolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml index 7858189b11..1f35f46609 100644 --- a/data_sources/aws_cloudtrail_stoplogging.yml +++ b/data_sources/aws_cloudtrail_stoplogging.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail StopLogging id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped. mitre_components: @@ -14,7 +14,7 @@ separator_value: StopLogging supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml index 9790a74d67..45ba97d223 100644 --- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateAccountPasswordPolicy id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when an AWS account's password policy is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml index 2e58b10a33..8cac3d8d5c 100644 --- a/data_sources/aws_cloudtrail_updateloginprofile.yml +++ b/data_sources/aws_cloudtrail_updateloginprofile.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateLoginProfile id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when an IAM user's login profile is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml index 755e03f508..37fc12a87a 100644 --- a/data_sources/aws_cloudtrail_updatesamlprovider.yml +++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateSAMLProvider id: e5eb628d-711e-499c-87d9-8fa5dee419ec -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a SAML provider is updated in AWS. mitre_components: @@ -16,7 +16,7 @@ separator_value: UpdateSAMLProvider supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml index cd980da894..b7872a1a8f 100644 --- a/data_sources/aws_cloudtrail_updatetrail.yml +++ b/data_sources/aws_cloudtrail_updatetrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateTrail id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939 -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - app diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml index eb0cdc7ecf..779a16f389 100644 --- a/data_sources/aws_cloudwatchlogs_vpcflow.yml +++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml @@ -1,8 +1,8 @@ name: AWS CloudWatchLogs VPCflow id: 38a34fc4-e128-4478-a8f4-7835d51d5135 -version: 3 +version: 9 creation_date: '2024-07-31' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Logs an event when network traffic flow information such as source and destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS. mitre_components: @@ -12,7 +12,7 @@ source: aws_cloudwatchlogs_vpcflow sourcetype: aws:cloudwatchlogs:vpcflow supported_TA: - name: Splunk Add-on for AWS - version: 8.1.2 + version: 8.2.2 url: https://splunkbase.splunk.com/app/1876 fields: - _raw diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml index b2bda6430e..c02d27ce9d 100644 --- a/data_sources/aws_security_hub.yml +++ b/data_sources/aws_security_hub.yml @@ -1,8 +1,8 @@ name: AWS Security Hub id: b02bfbf3-294f-478e-99a1-e24b8c692d7e -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts. mitre_components: @@ -15,7 +15,7 @@ sourcetype: aws:securityhub:finding supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.2 fields: - _time - AwsAccountId diff --git a/data_sources/azure_active_directory.yml b/data_sources/azure_active_directory.yml index 4b353862ea..9c74b2e8cd 100644 --- a/data_sources/azure_active_directory.yml +++ b/data_sources/azure_active_directory.yml @@ -1,8 +1,8 @@ name: Azure Active Directory id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c -version: 2 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: All Azure Active Directory events source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 output_fields: - dest - user diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml index 182d512dca..7b532fd756 100644 --- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml +++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add app role assignment to service principal id: 8b2e84cd-6db0-47e9-badc-75c17df1995f -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs the addition of an application role assignment to a service principal in Azure Active Directory, including details about the role, service principal, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add app role assignment to service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml index 5031b5cd33..6e5c0f39d3 100644 --- a/data_sources/azure_active_directory_add_member_to_role.yml +++ b/data_sources/azure_active_directory_add_member_to_role.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add member to role id: 1660d196-127f-4678-81b2-472d51711b07 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add member to role supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml index f0c01197f6..54c61af015 100644 --- a/data_sources/azure_active_directory_add_owner_to_application.yml +++ b/data_sources/azure_active_directory_add_owner_to_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add owner to application id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add owner to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml index c5e2c3a4e5..2ab6a70a6f 100644 --- a/data_sources/azure_active_directory_add_service_principal.yml +++ b/data_sources/azure_active_directory_add_service_principal.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add service principal id: fd89d337-e4c0-4162-ad13-bca36f096fe6 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml index 7b4411afbd..7ac41daa4c 100644 --- a/data_sources/azure_active_directory_add_unverified_domain.yml +++ b/data_sources/azure_active_directory_add_unverified_domain.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add unverified domain id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add unverified domain supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml index 1461a8eaa6..692b1a0dee 100644 --- a/data_sources/azure_active_directory_consent_to_application.yml +++ b/data_sources/azure_active_directory_consent_to_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Consent to application id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the consenting user or process. mitre_components: @@ -17,7 +17,7 @@ separator_value: Consent to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml index 177b30e212..956f101489 100644 --- a/data_sources/azure_active_directory_disable_strong_authentication.yml +++ b/data_sources/azure_active_directory_disable_strong_authentication.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Disable Strong Authentication id: 8f31966d-c496-496d-8837-f7fd11f31255 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when strong authentication methods are disabled in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Disable Strong Authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml index b7fd87116e..75c9715e12 100644 --- a/data_sources/azure_active_directory_enable_account.yml +++ b/data_sources/azure_active_directory_enable_account.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Enable account id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Active Directory account is enabled. mitre_components: @@ -16,7 +16,7 @@ separator_value: Enable account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml index 22983a3d9f..0c08b76a54 100644 --- a/data_sources/azure_active_directory_invite_external_user.yml +++ b/data_sources/azure_active_directory_invite_external_user.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Invite external user id: d3818bd5-f283-4518-8b67-df19240c3e40 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when an external user is invited to join an Azure Active Directory tenant. mitre_components: @@ -16,7 +16,7 @@ separator_value: Invite external user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml b/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml index 65cb093d4f..ef58407d12 100644 --- a/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml +++ b/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml @@ -1,8 +1,8 @@ name: Azure Active Directory MicrosoftGraphActivityLogs id: 63ff93ba-2bbb-4542-8773-239bf5266367 -version: 2 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Bhavin Patel, Splunk description: Data source object for Azure Active Directory MicrosoftGraphActivityLogs source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time example_log: '{"time": "2024-04-30T01:22:46.4948958Z", "resourceId": "/TENANTS/225E05A1-5914-4688-A404-7030E60F3143/PROVIDERS/MICROSOFT.AADIAM", "operationName": "Microsoft Graph Activity", "operationVersion": "beta", "category": "MicrosoftGraphActivityLogs", "resultSignature": "200", "durationMs": "948894", "callerIpAddress": "45.83.145.6", "correlationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "level": "Informational", "location": "East US 2", "properties": {"__UDI_RequiredFields_TenantId": "225e05a1-5914-4688-a404-7030e60f3143", "__UDI_RequiredFields_UniqueId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "__UDI_RequiredFields_EventTime": 638500369660000000, "__UDI_RequiredFields_RegionScope": "NA", "timeGenerated": "2024-04-30T01:22:46.4948958Z", "location": "East US 2", "requestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "operationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "clientRequestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "apiVersion": "beta", "requestMethod": "GET", "responseStatusCode": 200, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143", "durationMs": 948894, "responseSizeBytes": 91, "signInActivityId": "KRsphQ_4s0-oHv_Br8qSAQ", "roles": "", "appId": "1950a258-227b-4e31-a9cf-717495945fc2", "UserPrincipalObjectID": "7b934539-7366-494e-a8ac-3517694d32db", "scopes": "AuditLog.Read.All Directory.AccessAsUser.All email openid profile", "identityProvider": "", "clientAuthMethod": "0", "wids": "b79fbf4d-3ef9-4689-8143-76b194e85509", "C_Idtyp": "user", "C_Iat": "1714439850", "ipAddress": "45.83.145.6", "userAgent": "azurehound/v2.1.8", "requestUri": "https://graph.microsoft.com/beta/servicePrincipals/ffe3e001-d8cf-43a4-89ab-bfce35fd7786/owners?%24top=999", "userId": "7b934539-7366-494e-a8ac-3517694d32db", "tokenIssuedAt": "2024-04-30T01:17:30.0000000Z"}, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143"}' diff --git a/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml b/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml index 8c5adbf8ae..a082741c14 100644 --- a/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml +++ b/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml @@ -1,8 +1,8 @@ name: Azure Active Directory NonInteractiveUserSignInLogs id: 11fe8a43-164d-47e4-b542-afc2f242068b -version: 2 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Bhavin Patel, Splunk description: Data source object for Azure Active Directory NonInteractiveUserSignInLogs source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - action - additional_details diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml index da60f90a28..eb5dadd4ca 100644 --- a/data_sources/azure_active_directory_reset_password_(by_admin).yml +++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml @@ -1,8 +1,8 @@ name: Azure Active Directory Reset password (by admin) id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when an admin resets a user's password in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Reset password (by admin) supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml index 9a0c666f20..adbec33a63 100644 --- a/data_sources/azure_active_directory_set_domain_authentication.yml +++ b/data_sources/azure_active_directory_set_domain_authentication.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Set domain authentication id: e7bcdab9-908c-40ab-ba38-5db54fa87750 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified. mitre_components: @@ -16,7 +16,7 @@ separator_value: Set domain authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml index d6888c0dee..61bf71a5d1 100644 --- a/data_sources/azure_active_directory_sign_in_activity.yml +++ b/data_sources/azure_active_directory_sign_in_activity.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Sign-in activity id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes. mitre_components: @@ -16,7 +16,7 @@ separator_value: Sign-in activity supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml index b0ae6b37c9..2972241e3e 100644 --- a/data_sources/azure_active_directory_update_application.yml +++ b/data_sources/azure_active_directory_update_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update application id: 2c08188a-ba25-496e-87c7-803cf28b6c90 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions. mitre_components: @@ -16,7 +16,7 @@ separator_value: Update application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml index 7a086791e4..a1dc4ee7e1 100644 --- a/data_sources/azure_active_directory_update_authorization_policy.yml +++ b/data_sources/azure_active_directory_update_authorization_policy.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update authorization policy id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when an authorization policy is updated in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Update authorization policy supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml index f0ca04a229..d123e60f5e 100644 --- a/data_sources/azure_active_directory_update_user.yml +++ b/data_sources/azure_active_directory_update_user.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update user id: 5495c90a-047c-4b8e-b2fe-1db6282d3872 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when a user account is updated in Azure Active Directory. mitre_components: @@ -15,7 +15,7 @@ separator_value: Update user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml index ce39762a76..2787f6c0e8 100644 --- a/data_sources/azure_active_directory_user_registered_security_info.yml +++ b/data_sources/azure_active_directory_user_registered_security_info.yml @@ -1,8 +1,8 @@ name: Azure Active Directory User registered security info id: b63240de-8a01-4ba8-8987-89d18d4b375d -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when a user registers or updates their security information in Azure Active Directory. mitre_components: @@ -15,7 +15,7 @@ separator_value: User registered security info supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - Level diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml index fb083554f3..f455daad97 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation account id: 2ab182e7-feda-4249-9418-32710b55a885 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Automation account is created or updated. mitre_components: @@ -16,7 +16,7 @@ separator_value: Create or Update an Azure Automation account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - authorization.action diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml index 1c61b96dac..28df5f57ce 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation Runbook id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: Create or Update an Azure Automation Runbook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - authorization.action diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml index c1d309bda9..638977dfdc 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation webhook id: 575faeb2-09d0-4849-b1f6-eae241f26ff2 -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs an event when a webhook is created or updated in Azure Automation. mitre_components: @@ -16,7 +16,7 @@ separator_value: Create or Update an Azure Automation webhook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - _time - authorization.action diff --git a/data_sources/azure_monitor_activity.yml b/data_sources/azure_monitor_activity.yml index 5b89633bdb..35b62eb940 100644 --- a/data_sources/azure_monitor_activity.yml +++ b/data_sources/azure_monitor_activity.yml @@ -1,8 +1,8 @@ name: Azure Monitor Activity id: 1997a515-a61a-4f78-ada9-54af34c764f2 -version: 2 +version: 7 creation_date: '2025-01-13' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Bhavin Patel, Splunk description: Data source object for Azure Monitor Activity. The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub. source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.3 fields: - column - action diff --git a/data_sources/cisco_ai_defense_alerts.yml b/data_sources/cisco_ai_defense_alerts.yml index aa3e7c95cb..9798563cec 100644 --- a/data_sources/cisco_ai_defense_alerts.yml +++ b/data_sources/cisco_ai_defense_alerts.yml @@ -1,8 +1,8 @@ name: Cisco AI Defense Alerts id: cbb06880-9dd9-4542-ac60-bd6e1d3c3e4e -version: 2 +version: 9 creation_date: '2025-02-14' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Bhavin Patel description: Data source object for Cisco AI Defense Alerts source: cisco_ai_defense @@ -11,5 +11,5 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: diff --git a/data_sources/cisco_asa_logs.yml b/data_sources/cisco_asa_logs.yml index 04a92090d7..528817446d 100644 --- a/data_sources/cisco_asa_logs.yml +++ b/data_sources/cisco_asa_logs.yml @@ -1,8 +1,8 @@ name: Cisco ASA Logs id: 3f2a9b6d-1c8e-4f7b-a2d3-8b7f1c2a9d4e -version: 3 +version: 10 creation_date: '2025-09-25' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Bhavin Patel, Splunk description: "Data source object for Cisco ASA system logs. Cisco ASA logs provide firewall operational and security telemetry (connection events, ACL denies, VPN events, NAT translations, and device health). Deploy the Splunk Add-on for Cisco ASA (TA-cisco_asa) on indexers/heavy forwarders and the Cisco ASA App on search heads for best parsing, CIM mapping, and dashboards. This data is ingested via SYSLOG. You must be ingesting Cisco ASA syslog data into your Splunk environment. To ensure all detections work, configure your ASA and FTD devices to generate and forward both debug and informational level syslog messages before they are sent to Splunk. A few analytics are designed to be used with comprehensive logging enabled, as it relies on the presence of specific message IDs. You can find specific instructions on how to set this up here : https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/63884-config-asa-00.html#toc-hId--1451069880. \n" source: not_applicable @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - Cisco_ASA_action - Cisco_ASA_message_id diff --git a/data_sources/cisco_duo_activity.yml b/data_sources/cisco_duo_activity.yml index 3bea5f94aa..dadfd55b2f 100644 --- a/data_sources/cisco_duo_activity.yml +++ b/data_sources/cisco_duo_activity.yml @@ -1,8 +1,8 @@ name: Cisco Duo Activity id: 83f727f6-8754-41f8-b9f7-8226886a659e -version: 2 +version: 9 creation_date: '2025-07-10' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Activity source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - access_device.browser - access_device.browser_version diff --git a/data_sources/cisco_duo_administrator.yml b/data_sources/cisco_duo_administrator.yml index b3fa5fb6d7..e7cc388dfb 100644 --- a/data_sources/cisco_duo_administrator.yml +++ b/data_sources/cisco_duo_administrator.yml @@ -1,8 +1,8 @@ name: Cisco Duo Administrator id: 38e22de6-8b6b-449c-ae26-a640c88ff7f9 -version: 2 +version: 9 creation_date: '2025-07-10' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Administrator source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - action - actionlabel diff --git a/data_sources/cisco_isovalent_process_connect.yml b/data_sources/cisco_isovalent_process_connect.yml index d0c47aadec..dbce70823b 100644 --- a/data_sources/cisco_isovalent_process_connect.yml +++ b/data_sources/cisco_isovalent_process_connect.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Connect id: bf8c76a1-6066-4759-ab77-d3f0a375519e -version: 2 +version: 9 creation_date: '2026-01-05' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Bhavin Patel, Splunk description: "Captures detailed process connection events—including source and destination process metadata, execution lineage (ancestry), and Kubernetes workload context—generated by Cisco Isovalent instrumentation. Enables technical analysis of inter-process communications, container-level activity, and workload-specific network flows in cloud-native environments." source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processConnect supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - _time - app diff --git a/data_sources/cisco_isovalent_process_exec.yml b/data_sources/cisco_isovalent_process_exec.yml index 5c86c068fd..cd572c1aee 100644 --- a/data_sources/cisco_isovalent_process_exec.yml +++ b/data_sources/cisco_isovalent_process_exec.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Exec id: 87654321-dcba-4321-00fe-0987654321ba -version: 2 +version: 9 creation_date: '2026-01-05' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Bhavin Patel, Splunk description: Logs process execution events within Cisco Isovalent environments, providing visibility into process exec ancestry and Kubernetes workload identity. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processExec supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - _time - cluster_name diff --git a/data_sources/cisco_isovalent_process_kprobe.yml b/data_sources/cisco_isovalent_process_kprobe.yml index 8487727aad..23b05e30e8 100644 --- a/data_sources/cisco_isovalent_process_kprobe.yml +++ b/data_sources/cisco_isovalent_process_kprobe.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Kprobe id: b2620ef2-fac6-467f-bdc8-253d65db1cb9 -version: 2 +version: 9 creation_date: '2026-01-05' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Bhavin Patel, Splunk description: Captures kernel probe (kprobe) telemetry from Cisco Isovalent Runtime Security, including function name, arguments, and process context, enabling visibility into low-level kernel interactions that may indicate container escape attempts or system tampering. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - _time - app diff --git a/data_sources/cisco_secure_access_dns.yml b/data_sources/cisco_secure_access_dns.yml index bdf4c50c56..b072d38cea 100644 --- a/data_sources/cisco_secure_access_dns.yml +++ b/data_sources/cisco_secure_access_dns.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access DNS id: 5673dba3-cae9-449e-8991-03832d79f729 -version: 1 +version: 5 creation_date: '2026-05-06' -modification_date: '2026-05-06' +modification_date: '2026-09-10' author: Bhavin Patel, Splunk description: | Captures DNS security events from Cisco Secure Access (including Umbrella-style DNS policy and roaming client telemetry) with client identity, query and response metadata, resolved domain, and URL/content categorization. @@ -12,7 +12,7 @@ sourcetype: cisco:cloud_security:dns supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.50 + version: 1.0.55 fields: - RecordType - ReplyCode diff --git a/data_sources/cisco_secure_access_firewall.yml b/data_sources/cisco_secure_access_firewall.yml index 5b1c49627c..4ea63b3462 100644 --- a/data_sources/cisco_secure_access_firewall.yml +++ b/data_sources/cisco_secure_access_firewall.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access Firewall id: 5dc07487-f834-4850-b6a7-4cc09e56549b -version: 2 +version: 6 creation_date: '2026-04-29' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Bhavin Patel, Splunk description: Captures firewall connection events from Cisco Secure Access including user identity, source and destination metadata, protocol details, and session statistics. Enables analysis of network traffic patterns, access policy enforcement, brute force attempts, and anomalous connection behavior across cloud-managed network access infrastructure. source: cisco_secure_access:firewall @@ -10,7 +10,7 @@ sourcetype: cisco:cloud_security:firewall supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.50 + version: 1.0.55 fields: - _time - action diff --git a/data_sources/cisco_secure_access_proxy.yml b/data_sources/cisco_secure_access_proxy.yml index 3b981bad63..2356b32b7a 100644 --- a/data_sources/cisco_secure_access_proxy.yml +++ b/data_sources/cisco_secure_access_proxy.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access Proxy id: 2dc95ec2-8964-4ddb-8714-8d7dfe264922 -version: 1 +version: 5 creation_date: '2026-05-08' -modification_date: '2026-05-08' +modification_date: '2026-09-10' author: Bhavin Patel, Splunk description: | Captures HTTP/HTTPS proxy access events from Cisco Secure Access, including requesting source, user identity, URL, HTTP method, response status, and user-agent metadata. @@ -12,7 +12,7 @@ sourcetype: cisco:cloud_security:proxy supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.50 + version: 1.0.55 fields: - _time - action diff --git a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml index ed96cbbe2d..55f7162d1e 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Connection Event id: 18878597-8f8a-4bca-a805-bfbe35e00032 -version: 3 +version: 10 creation_date: '2025-04-03' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Nasreddine Bencherchali, Splunk description: Data source object for raw connection events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - AC_RuleAction - action diff --git a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml index fdfd338ddb..e124406309 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense File Event id: 19878597-8f8a-4bca-a805-bfbe35e00032 -version: 2 +version: 9 creation_date: '2025-04-09' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Nasreddine Bencherchali, Splunk description: Data source object for raw file events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - app - Application diff --git a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml index 309b325466..e8406ad7c5 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Intrusion Event id: d11b67ec-1cb2-4f6f-a2d8-a099c7e15b29 -version: 2 +version: 9 creation_date: '2025-04-16' -modification_date: '2026-05-13' +modification_date: '2026-09-17' author: Nasreddine Bencherchali, Splunk description: Data source object for raw intrusion events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.7.2 fields: - Application - Classification diff --git a/data_sources/crowdstrike_falcon_stream_alert.yml b/data_sources/crowdstrike_falcon_stream_alert.yml index 32b048111d..92eb12dc5a 100644 --- a/data_sources/crowdstrike_falcon_stream_alert.yml +++ b/data_sources/crowdstrike_falcon_stream_alert.yml @@ -1,8 +1,8 @@ name: CrowdStrike Falcon Stream Alert id: 52b38751-b0db-4965-a800-ebaabd1fd7d5 -version: 2 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-05-13' +modification_date: '2026-09-15' author: Bhavin Patel, Bryan Pluta, Splunk description: Logs of CrowdStrike Falcon Stream Alerts mitre_components: @@ -17,7 +17,7 @@ separator: event.DetectName supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 2.0.5 + version: 3.2.0 fields: - action - description diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml index 05c7e2f476..9b88a02e50 100644 --- a/data_sources/crowdstrike_processrollup2.yml +++ b/data_sources/crowdstrike_processrollup2.yml @@ -1,8 +1,8 @@ name: CrowdStrike ProcessRollup2 id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e -version: 3 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-15' author: Patrick Bareiss, Splunk description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments. mitre_components: @@ -18,7 +18,7 @@ separator_value: ProcessRollup2 supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 2.0.5 + version: 3.2.0 fields: - AuthenticationId - AuthenticationId_meaning diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml index a9b1f66987..a8101ca4d3 100644 --- a/data_sources/g_suite_drive.yml +++ b/data_sources/g_suite_drive.yml @@ -1,8 +1,8 @@ name: G Suite Drive id: 5f79120f-a235-4468-bd0d-55203758ac22 -version: 3 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-28' author: Patrick Bareiss, Splunk description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details. mitre_components: @@ -16,7 +16,7 @@ sourcetype: gsuite:drive:json supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 5.0.1 fields: - _time - email diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml index 5e9526e61b..6a437de347 100644 --- a/data_sources/g_suite_gmail.yml +++ b/data_sources/g_suite_gmail.yml @@ -1,8 +1,8 @@ name: G Suite Gmail id: 706c3978-41de-406b-b6e0-75bd01e12a5d -version: 3 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-28' author: Patrick Bareiss, Splunk description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events. mitre_components: @@ -15,7 +15,7 @@ sourcetype: gsuite:gmail:bigquery supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 5.0.1 fields: - _time - action_type diff --git a/data_sources/github_enterprise_audit_logs.yml b/data_sources/github_enterprise_audit_logs.yml index 893b9b4e98..08c255aa2e 100644 --- a/data_sources/github_enterprise_audit_logs.yml +++ b/data_sources/github_enterprise_audit_logs.yml @@ -1,8 +1,8 @@ name: GitHub Enterprise Audit Logs id: 8a4d656f-8801-4a2c-ae10-553d2696a59f -version: 2 +version: 6 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-09-11' author: Patrick Bareiss, Splunk description: Data source object for GitHub Enterprise logs using Audit log streaming as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk using a Splunk HTTP Event Collector. source: http:github @@ -10,7 +10,7 @@ sourcetype: httpevent supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.2.0 + version: 4.0.1 fields: - _document_id - action diff --git a/data_sources/github_organizations_audit_logs.yml b/data_sources/github_organizations_audit_logs.yml index e6e106f4a1..f44638d1ad 100644 --- a/data_sources/github_organizations_audit_logs.yml +++ b/data_sources/github_organizations_audit_logs.yml @@ -1,8 +1,8 @@ name: GitHub Organizations Audit Logs id: ce520b1c-79fe-48ef-a0f9-71fbbd4837b0 -version: 2 +version: 6 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-09-11' author: Patrick Bareiss, Splunk description: Data source object for GitHub Organizations logs using the Splunk Add-on for Github using a Personal Access Token. source: github @@ -10,7 +10,7 @@ sourcetype: github:cloud:audit supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.2.0 + version: 4.0.1 fields: - _document_id - action diff --git a/data_sources/google_workspace.yml b/data_sources/google_workspace.yml index acd5970dd5..223c2dc17c 100644 --- a/data_sources/google_workspace.yml +++ b/data_sources/google_workspace.yml @@ -1,8 +1,8 @@ name: Google Workspace id: f1a044e3-113a-4e4d-84f2-b153ade83087 -version: 2 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-08-28' author: Bhavin Patel, Splunk description: Data source object for Google Workspace source: google_workspace @@ -10,7 +10,7 @@ sourcetype: gws:reports:login supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 5.0.1 fields: - action - actor.callerType diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml index ed05961581..cdb11ed95d 100644 --- a/data_sources/google_workspace_login_failure.yml +++ b/data_sources/google_workspace_login_failure.yml @@ -1,8 +1,8 @@ name: Google Workspace login_failure id: cabec7cf-4008-4899-b47e-39c34a9a1255 -version: 3 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-28' author: Patrick Bareiss, Splunk description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure. mitre_components: @@ -17,7 +17,7 @@ separator_value: login_failure supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 5.0.1 fields: - _time - actor.email diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml index 4b61dd8b5f..518f833ed9 100644 --- a/data_sources/google_workspace_login_success.yml +++ b/data_sources/google_workspace_login_success.yml @@ -1,8 +1,8 @@ name: Google Workspace login_success id: bffe8013-9cdf-4fe6-9c1b-6784391a4951 -version: 3 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-28' author: Patrick Bareiss, Splunk description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: login_success supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 5.0.1 fields: - _time - actor.email diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index 164e9aefb7..1302ff3cc0 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -1,8 +1,8 @@ name: Linux Auditd Add User id: 30f79353-e1d2-4585-8735-1e0359559f3f -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - msg - type diff --git a/data_sources/linux_auditd_cwd.yml b/data_sources/linux_auditd_cwd.yml index afbe0ec701..e8624ad5a7 100644 --- a/data_sources/linux_auditd_cwd.yml +++ b/data_sources/linux_auditd_cwd.yml @@ -1,8 +1,8 @@ name: Linux Auditd Cwd id: a9ef851b-d864-478b-b1b3-76535d7ff7fc -version: 2 +version: 8 creation_date: '2025-12-02' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Nasreddine Bencherchali, Splunk description: This type is used to record the working directory from which the process that invoked the system call specified in the first record was executed. The purpose of this record is to record the current process's location in case a relative path winds up being captured in the associated PATH record. This way the absolute path can be reconstructed. source: auditd @@ -13,7 +13,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - cwd - date_hour diff --git a/data_sources/linux_auditd_daemon_abort.yml b/data_sources/linux_auditd_daemon_abort.yml index 9b83e49dc1..eb8fb9160f 100644 --- a/data_sources/linux_auditd_daemon_abort.yml +++ b/data_sources/linux_auditd_daemon_abort.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Abort id: cc8b3bb0-0fae-4236-9c61-fe2d7138bd63 -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_end.yml b/data_sources/linux_auditd_daemon_end.yml index f7b4fcf4dd..130add532b 100644 --- a/data_sources/linux_auditd_daemon_end.yml +++ b/data_sources/linux_auditd_daemon_end.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon End id: 15135c45-e302-4d5a-a38a-3e8279f2ebd8 -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_start.yml b/data_sources/linux_auditd_daemon_start.yml index 9f96075a6e..f2cfded310 100644 --- a/data_sources/linux_auditd_daemon_start.yml +++ b/data_sources/linux_auditd_daemon_start.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Start id: f1b97407-ddf0-41a5-8685-ada05aae3555 -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - type - op diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 1d5c039877..50fd781380 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -1,8 +1,8 @@ name: Linux Auditd Execve id: 9ef6364d-cc67-480e-8448-3306829a6a24 -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - msg - type diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index 6f0953cec0..6b9ed55249 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -1,8 +1,8 @@ name: Linux Auditd Path id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - msg - type diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index 44e2a8935b..d6c9418e10 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -1,8 +1,8 @@ name: Linux Auditd Proctitle id: 5a25984a-2789-400a-858b-d75c923e06b1 -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - proctitle - msg diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index 1db5103e14..71b9cc1c35 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -1,8 +1,8 @@ name: Linux Auditd Service Stop id: 0643483c-bc62-455c-8d6e-1630e5f0e00d -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - msg - type diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index b5d9647033..61e2af7581 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -1,8 +1,8 @@ name: Linux Auditd Syscall id: 4dff7047-0d43-4096-bb3f-b756c889bbad -version: 3 +version: 9 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Teoderick Contreras, Splunk description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - msg - type diff --git a/data_sources/linux_messages_syslog.yml b/data_sources/linux_messages_syslog.yml index 090a768534..424a284dd2 100644 --- a/data_sources/linux_messages_syslog.yml +++ b/data_sources/linux_messages_syslog.yml @@ -1,8 +1,8 @@ name: Linux Messages Syslog id: c9e3bbb5-e0a2-4bac-8457-227e71841bda -version: 1 +version: 7 creation_date: '2025-05-06' -modification_date: '2025-05-06' +modification_date: '2026-09-01' author: Ravent Tait, Splunk description: Logs kernel events on a Linux system, including service starts/stops, hardware events, authentication notices, and other OS-level activity. @@ -16,7 +16,7 @@ sourcetype: linux_messages_syslog supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - _time - action diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index b8dd8ae5ba..9141e0c365 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -1,8 +1,8 @@ name: Linux Secure id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb -version: 3 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-01' author: Patrick Bareiss, Splunk description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. mitre_components: @@ -16,7 +16,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.4 fields: - _time - action diff --git a/data_sources/m365_copilot_graph_api.yml b/data_sources/m365_copilot_graph_api.yml index 33aec6362d..aa283c0518 100644 --- a/data_sources/m365_copilot_graph_api.yml +++ b/data_sources/m365_copilot_graph_api.yml @@ -1,8 +1,8 @@ name: M365 Copilot Graph API id: 30dd2202-869c-47fb-ad37-4f4d4c93c6b7 -version: 2 +version: 4 creation_date: '2025-10-13' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Rod Soto, Splunk description: Access Logs from M365 Copilot access via Graph API source: AuditLogs.SignIns @@ -10,7 +10,7 @@ sourcetype: o365:graph:api supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - appDisplayName - appId diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml index 7d33235198..5e2f25797f 100644 --- a/data_sources/ms365_defender_incident_alerts.yml +++ b/data_sources/ms365_defender_incident_alerts.yml @@ -1,8 +1,8 @@ name: MS365 Defender Incident Alerts id: 12345678-90ab-cdef-1234-567890abcdef -version: 3 +version: 4 creation_date: '2024-10-29' -modification_date: '2026-05-13' +modification_date: '2026-07-21' author: Bhavin Patel, Splunk description: Logs security incidents and correlated alerts in Microsoft 365 Defender, including details about affected assets, threat types, and remediation steps. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ms365:defender:incident:alerts supported_TA: - name: Splunk Add-on for Microsoft Security url: https://splunkbase.splunk.com/app/6207 - version: 3.0.0 + version: 4.0.0 fields: - actorName - alertId diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml index a38abee6a2..3263b1edaa 100644 --- a/data_sources/ms_defender_atp_alerts.yml +++ b/data_sources/ms_defender_atp_alerts.yml @@ -1,8 +1,8 @@ name: MS Defender ATP Alerts id: 38f034ed-1598-46c8-95e8-14edf01fdf5d -version: 3 +version: 4 creation_date: '2024-11-07' -modification_date: '2026-05-13' +modification_date: '2026-07-21' author: Bryan Pluta, Bhavin Patel, Splunk description: Logs security alerts generated by Microsoft Defender for Endpoint, including information about detected threats, impacted devices, and recommended actions. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ms:defender:atp:alerts supported_TA: - name: Splunk Add-on for Microsoft Security url: https://splunkbase.splunk.com/app/6207 - version: 3.0.0 + version: 4.0.0 fields: - column - accountName diff --git a/data_sources/nginx_access.yml b/data_sources/nginx_access.yml index 8c249409e4..b3a886aba7 100644 --- a/data_sources/nginx_access.yml +++ b/data_sources/nginx_access.yml @@ -1,8 +1,8 @@ name: Nginx Access id: c716a418-eab3-4df5-9dff-5420174e3068 -version: 3 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-09-10' author: Patrick Bareiss, Splunk description: Logs HTTP/S access events on an Nginx server, including details such as client IP, request method, URI, response status, and user agent. mitre_components: @@ -16,7 +16,7 @@ sourcetype: nginx:plus:kv supported_TA: - name: Splunk Add-on for NGINX url: https://splunkbase.splunk.com/app/3258 - version: 3.3.0 + version: 3.3.2 fields: - _time - action diff --git a/data_sources/ntlm_operational_8004.yml b/data_sources/ntlm_operational_8004.yml index 141ebdf0de..a85fabf459 100644 --- a/data_sources/ntlm_operational_8004.yml +++ b/data_sources/ntlm_operational_8004.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8004 id: fd08cb77-c26e-464c-a43e-2867e232127e -version: 2 +version: 11 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8004 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8005.yml b/data_sources/ntlm_operational_8005.yml index da24c4688c..2261e0892b 100644 --- a/data_sources/ntlm_operational_8005.yml +++ b/data_sources/ntlm_operational_8005.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8005 id: ad15a1cf-4b21-43de-81e4-6307c69172fb -version: 2 +version: 11 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8005 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8006.yml b/data_sources/ntlm_operational_8006.yml index e4ec349eb5..9921037957 100644 --- a/data_sources/ntlm_operational_8006.yml +++ b/data_sources/ntlm_operational_8006.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8006 id: 9f50a672-6f7d-4621-a3bd-69468c6b7a7f -version: 2 +version: 11 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8006 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/o365.yml b/data_sources/o365.yml index a19cd4ad78..211a5c71a3 100644 --- a/data_sources/o365.yml +++ b/data_sources/o365.yml @@ -1,8 +1,8 @@ name: O365 id: b32de97d-0074-4cca-853c-db22c392b6c0 -version: 3 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs management activities in Microsoft 365, including administrative actions, user activities, and configuration changes across various services. mitre_components: @@ -17,4 +17,4 @@ separator: Operation supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml index 7723ded61a..55a56c64ea 100644 --- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml +++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml @@ -1,8 +1,8 @@ name: O365 Add app role assignment grant to user. id: ce1d7849-a1d2-47fd-b6eb-d7ef854a860c -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs the assignment of an application role grant to a user in Microsoft 365, including details about the role, user, and application involved. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add app role assignment grant to user. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml index 8654f39dbd..9f8b16ac37 100644 --- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml +++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml @@ -1,8 +1,8 @@ name: O365 Add app role assignment to service principal. id: 785ba57a-ba7b-474e-97c8-9474e6e00b3a -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs the assignment of an application role to a service principal in Microsoft 365, including details about the role, service principal, and application involved. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add app role assignment to service principal. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml index 39b8cabf1c..9c1f50e8c0 100644 --- a/data_sources/o365_add_mailboxpermission.yml +++ b/data_sources/o365_add_mailboxpermission.yml @@ -1,8 +1,8 @@ name: O365 Add-MailboxPermission id: 9c0babdb-bb15-449e-abba-0a9cdb3fc061 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs the addition of mailbox permissions in Microsoft 365, including details about the mailbox, granted permissions, and the user or administrator performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add-MailboxPermission supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - AccessRights diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml index 203e698796..607824d5d9 100644 --- a/data_sources/o365_add_member_to_role_.yml +++ b/data_sources/o365_add_member_to_role_.yml @@ -1,8 +1,8 @@ name: O365 Add member to role. id: 8b949f7c-4b5d-404f-9694-d7403c4ec096 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs the addition of a member to a role in Microsoft 365, including details about the role, the added member, and the user or administrator performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add member to role. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml index 78a3be49c4..5b18c91a03 100644 --- a/data_sources/o365_add_owner_to_application_.yml +++ b/data_sources/o365_add_owner_to_application_.yml @@ -1,8 +1,8 @@ name: O365 Add owner to application. id: da012cbf-af6e-40ee-a1ba-32a5f8da8f8a -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs the addition of an owner to an application in Microsoft 365, including details about the application, the new owner, and the user or administrator performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add owner to application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml index 3f55630da5..ce9e844147 100644 --- a/data_sources/o365_add_service_principal_.yml +++ b/data_sources/o365_add_service_principal_.yml @@ -1,8 +1,8 @@ name: O365 Add service principal. id: 9c1ef9f5-bc30-4a47-a1bd-cb34484ee778 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs the addition of a new service principal in Microsoft 365, including details about the associated application and the action initiator. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add service principal. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml index 63af5c5dce..ae948aa580 100644 --- a/data_sources/o365_change_user_license_.yml +++ b/data_sources/o365_change_user_license_.yml @@ -1,8 +1,8 @@ name: O365 Change user license. id: 1029a20d-3d0d-4fb9-b5e2-22ac5380b20a -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs changes to user licenses in Microsoft 365, including additions, removals, or updates to service plans associated with a user account. mitre_components: @@ -17,7 +17,7 @@ separator_value: Change user license. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_consent_to_application_.yml b/data_sources/o365_consent_to_application_.yml index d4a327cfbe..07ca716ad8 100644 --- a/data_sources/o365_consent_to_application_.yml +++ b/data_sources/o365_consent_to_application_.yml @@ -1,8 +1,8 @@ name: O365 Consent to application. id: 0a15a464-ef51-4614-9a07-a216eb9817db -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs user or administrator consent to an application's permissions in Microsoft 365, including details about the application, granted permissions, and the consenting user or process. mitre_components: @@ -17,7 +17,7 @@ separator_value: Consent to application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_disable_strong_authentication_.yml b/data_sources/o365_disable_strong_authentication_.yml index 65923c1c80..4ec66cfb32 100644 --- a/data_sources/o365_disable_strong_authentication_.yml +++ b/data_sources/o365_disable_strong_authentication_.yml @@ -1,8 +1,8 @@ name: O365 Disable Strong Authentication. id: 235381c4-382a-4183-b818-a51c3ce12187 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs the disabling of strong authentication (e.g., multi-factor authentication) for a user or group in Microsoft 365, including details about the affected accounts and the action initiator. mitre_components: @@ -17,7 +17,7 @@ separator_value: Disable Strong Authentication. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_mailitemsaccessed.yml b/data_sources/o365_mailitemsaccessed.yml index 8174ccfa10..176979c6dd 100644 --- a/data_sources/o365_mailitemsaccessed.yml +++ b/data_sources/o365_mailitemsaccessed.yml @@ -1,8 +1,8 @@ name: O365 MailItemsAccessed id: 3d5188eb-341a-4b46-9caa-aade4047d027 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs access to mailbox items in Microsoft 365, including details about the user accessing the items, the accessed content, and the method of access. mitre_components: @@ -17,7 +17,7 @@ separator_value: MailItemsAccessed supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - AppId diff --git a/data_sources/o365_modifyfolderpermissions.yml b/data_sources/o365_modifyfolderpermissions.yml index 94b626b468..fcd131bf2e 100644 --- a/data_sources/o365_modifyfolderpermissions.yml +++ b/data_sources/o365_modifyfolderpermissions.yml @@ -1,8 +1,8 @@ name: O365 ModifyFolderPermissions id: 0a8c1080-68c2-46d7-8324-2e7d97bb6e2f -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs modifications to folder permissions in Microsoft 365, including updates to access levels, user assignments, and sharing settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: ModifyFolderPermissions supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - AppId diff --git a/data_sources/o365_set_company_information_.yml b/data_sources/o365_set_company_information_.yml index b093098610..214a0e409a 100644 --- a/data_sources/o365_set_company_information_.yml +++ b/data_sources/o365_set_company_information_.yml @@ -1,8 +1,8 @@ name: O365 Set Company Information. id: 06c6d576-f032-41e3-b15d-80a434ce13d8 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs updates to organizational settings and company information in Microsoft 365, including changes to contact details, branding, and configuration policies. mitre_components: @@ -17,7 +17,7 @@ separator_value: Set Company Information. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_set_mailbox.yml b/data_sources/o365_set_mailbox.yml index 96c5ad2283..40d68897a6 100644 --- a/data_sources/o365_set_mailbox.yml +++ b/data_sources/o365_set_mailbox.yml @@ -1,8 +1,8 @@ name: O365 Set-Mailbox id: db798c5c-928c-4972-bb42-e5f90e35865f -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs changes to mailbox properties in Microsoft 365, including updates to permissions, storage quotas, and configuration settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: Set-Mailbox supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - AppId diff --git a/data_sources/o365_update_application_.yml b/data_sources/o365_update_application_.yml index 949c78147e..a119f868b1 100644 --- a/data_sources/o365_update_application_.yml +++ b/data_sources/o365_update_application_.yml @@ -1,8 +1,8 @@ name: O365 Update application. id: 62159133-911b-4c63-9e30-a6a8c89195ca -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs updates made to applications in Microsoft 365, including changes to configurations, permissions, and role assignments. mitre_components: @@ -17,7 +17,7 @@ separator_value: Update application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_update_authorization_policy_.yml b/data_sources/o365_update_authorization_policy_.yml index 7bae300e3d..e64ef5fcfa 100644 --- a/data_sources/o365_update_authorization_policy_.yml +++ b/data_sources/o365_update_authorization_policy_.yml @@ -1,8 +1,8 @@ name: O365 Update authorization policy. id: d40e6a20-4d64-404c-8351-2caae8228d34 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs changes to authorization policies in Microsoft 365, including updates to access controls, permissions, and security settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: Update authorization policy. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_update_user_.yml b/data_sources/o365_update_user_.yml index 16dce5cfdb..328bb65b22 100644 --- a/data_sources/o365_update_user_.yml +++ b/data_sources/o365_update_user_.yml @@ -1,8 +1,8 @@ name: O365 Update user. id: a05fd01e-34d9-4233-9089-11272416b531 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs updates to user account properties in Microsoft 365, including changes to roles, permissions, and profile information. mitre_components: @@ -17,7 +17,7 @@ separator_value: Update user. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_userloggedin.yml b/data_sources/o365_userloggedin.yml index 8471cc627b..351a2ab594 100644 --- a/data_sources/o365_userloggedin.yml +++ b/data_sources/o365_userloggedin.yml @@ -1,8 +1,8 @@ name: O365 UserLoggedIn id: ed29c8c4-4053-419c-b133-16abf2a1c4c9 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs successful login events by users in Microsoft 365, including details about the user account, IP address, and session metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: UserLoggedIn supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/o365_userloginfailed.yml b/data_sources/o365_userloginfailed.yml index a898d3063e..e31ea32575 100644 --- a/data_sources/o365_userloginfailed.yml +++ b/data_sources/o365_userloginfailed.yml @@ -1,8 +1,8 @@ name: O365 UserLoginFailed id: 6099b33d-d581-43ed-8401-911862590361 -version: 3 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Patrick Bareiss, Splunk description: Logs failed login attempts by users in Microsoft 365, including details about the user account, IP address, and reason for failure. mitre_components: @@ -17,7 +17,7 @@ separator_value: UserLoginFailed supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time - ActorContextId diff --git a/data_sources/office_365_reporting_message_trace.yml b/data_sources/office_365_reporting_message_trace.yml index ef82a079e7..3e22f62f08 100644 --- a/data_sources/office_365_reporting_message_trace.yml +++ b/data_sources/office_365_reporting_message_trace.yml @@ -1,8 +1,8 @@ name: Office 365 Reporting Message Trace id: b637788e-fcf0-44fa-86ea-cab81193f939 -version: 2 +version: 4 creation_date: '2025-02-28' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Steven Dick description: Data source object for Office 365 Reporting Message Trace source: o365 @@ -11,7 +11,7 @@ separator: Organization supported_TA: - name: Splunk Microsoft Office 365 Add-on url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - FromIP - Index diff --git a/data_sources/office_365_universal_audit_log.yml b/data_sources/office_365_universal_audit_log.yml index 0e03e59a90..43505ad598 100644 --- a/data_sources/office_365_universal_audit_log.yml +++ b/data_sources/office_365_universal_audit_log.yml @@ -1,8 +1,8 @@ name: Office 365 Universal Audit Log id: 86369e87-5b0b-46fe-8b96-310473dffe7f -version: 2 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-09-30' author: Bhavin Patel, Splunk description: Data source object for Office 365 Universal Audit Log source: o365 @@ -11,7 +11,7 @@ separator: Operation supported_TA: - name: Splunk Microsoft Office 365 Add-on url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.1 fields: - _time example_log: '' diff --git a/data_sources/okta.yml b/data_sources/okta.yml index 01fc34cfdf..81560d167b 100644 --- a/data_sources/okta.yml +++ b/data_sources/okta.yml @@ -1,8 +1,8 @@ name: Okta id: ec26febe-e760-4981-bbee-72e107c7b9d2 -version: 3 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs authentication and administrative activities captured by Okta, including user login attempts, session management, and configuration changes. mitre_components: @@ -16,7 +16,7 @@ sourcetype: OktaIM2:log supported_TA: - name: Splunk Add-on for Okta Identity Cloud url: https://splunkbase.splunk.com/app/6553 - version: 5.0.2 + version: 5.1.0 output_fields: - dest - src diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml index b83bd67d0b..5eaa7bf10b 100644 --- a/data_sources/palo_alto_network_threat.yml +++ b/data_sources/palo_alto_network_threat.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Threat id: 375c2b0e-d216-41ad-9406-200464595209 -version: 5 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-14' author: Patrick Bareiss, Splunk description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:threat supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.1.0 + version: 4.0.0 fields: - _time - date_hour diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml index 00e9798ece..1ed6b26abb 100644 --- a/data_sources/palo_alto_network_traffic.yml +++ b/data_sources/palo_alto_network_traffic.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Traffic id: 182a83bc-c31a-4817-8c7a-263744cec52a -version: 5 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-14' author: Patrick Bareiss, Splunk description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:traffic supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.1.0 + version: 4.0.0 fields: - _time - date_hour diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 6a20ab8128..9e87565f12 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,8 +1,8 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: @@ -18,7 +18,7 @@ separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/splunk_common_information_model_(cim).yml b/data_sources/splunk_common_information_model_(cim).yml index f9056852f2..dfb2a1285a 100644 --- a/data_sources/splunk_common_information_model_(cim).yml +++ b/data_sources/splunk_common_information_model_(cim).yml @@ -1,8 +1,8 @@ name: Splunk Common Information Model (CIM) id: d3dd8270-7e1c-4bcd-8f3a-e5ec4a0e740a -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-09-02' author: Bhavin Patel, Splunk description: Data source object for Splunk CIM source: not_applicable @@ -10,4 +10,4 @@ sourcetype: not_applicable supported_TA: - name: Splunk Common Information Model (CIM) url: https://splunkbase.splunk.com/app/1621 - version: 8.5.0 + version: 8.7.0 diff --git a/data_sources/sysmon_eventid_1.yml b/data_sources/sysmon_eventid_1.yml index f0a8effbdf..a52186c2e7 100644 --- a/data_sources/sysmon_eventid_1.yml +++ b/data_sources/sysmon_eventid_1.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 1 id: b375f4d1-d7ca-4bc0-9103-294825c0af17 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new process, including details such as process ID, parent process, command line arguments, and hashes of the executable. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml index d54f84444d..71d0f6af70 100644 --- a/data_sources/sysmon_eventid_10.yml +++ b/data_sources/sysmon_eventid_10.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 10 id: 659cd5a8-148a-4c59-ade1-05f41ac1b096 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs events where one process accesses another process, typically for memory reads or injections, including details about the source and target processes. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - CallTrace diff --git a/data_sources/sysmon_eventid_11.yml b/data_sources/sysmon_eventid_11.yml index 47c82f9ac8..62449e9bac 100644 --- a/data_sources/sysmon_eventid_11.yml +++ b/data_sources/sysmon_eventid_11.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 11 id: f3db9179-f4f5-416d-bc03-39f4d4ff699e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new file, including details about the file path, hash information, and associated process metadata. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml index bfc98a539c..879cd3aba2 100644 --- a/data_sources/sysmon_eventid_12.yml +++ b/data_sources/sysmon_eventid_12.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 12 id: 3ef28798-8eaa-4fd2-b074-6f36d08a1b33 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new registry key, including details about the key name, registry path, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml index 9e4f2384db..7ee9550436 100644 --- a/data_sources/sysmon_eventid_13.yml +++ b/data_sources/sysmon_eventid_13.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 13 id: 19cd00ee-f65f-48ca-bb08-64aac28638ce -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs changes to a registry key, including details about the modified key, value, and associated process. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_14.yml b/data_sources/sysmon_eventid_14.yml index 4a0eea5ee2..2323c7f421 100644 --- a/data_sources/sysmon_eventid_14.yml +++ b/data_sources/sysmon_eventid_14.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 14 id: 77c4b345-0eab-415e-98c6-f4114b021723 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Bhavin Patel, Splunk description: Data source object for Sysmon EventID 14 source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational @@ -12,7 +12,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time example_log: '' diff --git a/data_sources/sysmon_eventid_15.yml b/data_sources/sysmon_eventid_15.yml index bcae8778e0..9c6a15b7be 100644 --- a/data_sources/sysmon_eventid_15.yml +++ b/data_sources/sysmon_eventid_15.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 15 id: 95785e02-93b4-47e2-81f1-be326295348e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new file stream, including details about the file stream's hash, path, and associated process metadata. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml index b149c566ed..08b7da81b0 100644 --- a/data_sources/sysmon_eventid_17.yml +++ b/data_sources/sysmon_eventid_17.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 17 id: 08924246-c8e8-4c95-a9fc-633c43cc82df -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Sysmon EventID 17 logs details about the detection of a named pipe. mitre_components: @@ -15,7 +15,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_18.yml b/data_sources/sysmon_eventid_18.yml index 09741457b3..ba254eaa5a 100644 --- a/data_sources/sysmon_eventid_18.yml +++ b/data_sources/sysmon_eventid_18.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 18 id: 37eb3554-214e-4e66-af10-c3ffc5b8ca82 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the connection to a named pipe, including details about the pipe name, source and destination processes, and communication direction. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_20.yml b/data_sources/sysmon_eventid_20.yml index a92ac49516..867fa77eab 100644 --- a/data_sources/sysmon_eventid_20.yml +++ b/data_sources/sysmon_eventid_20.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 20 id: aeee5374-3203-4286-b744-a8cc4ad1cd7e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs WMI (Windows Management Instrumentation) consumer activity, including details about the WMI event consumer, associated process, and event data. mitre_components: @@ -17,7 +17,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_21.yml b/data_sources/sysmon_eventid_21.yml index c1add4adfd..77c423b0c6 100644 --- a/data_sources/sysmon_eventid_21.yml +++ b/data_sources/sysmon_eventid_21.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 21 id: 304384bc-715e-4958-988b-a8051a91349a -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs activity related to the association of a WMI event consumer with a filter, including details about the consumer, filter, and associated process. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml index e267c09d70..af88015dcf 100644 --- a/data_sources/sysmon_eventid_22.yml +++ b/data_sources/sysmon_eventid_22.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 22 id: 911538b2-eba7-4d3e-85e8-d82d380c37bf -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs DNS query events, including details about the queried domain, source IP, query type, and response data. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_23.yml b/data_sources/sysmon_eventid_23.yml index d9436f249c..e63ceaf147 100644 --- a/data_sources/sysmon_eventid_23.yml +++ b/data_sources/sysmon_eventid_23.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 23 id: 5ea2721d-f60c-4f48-a047-47d514e327c3 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the deletion of a file, including details about the file path, associated process, and the time of deletion. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Archived diff --git a/data_sources/sysmon_eventid_26.yml b/data_sources/sysmon_eventid_26.yml index ee3d6376a2..59a566abfd 100644 --- a/data_sources/sysmon_eventid_26.yml +++ b/data_sources/sysmon_eventid_26.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 26 id: 77f946e0-4afb-4789-8d9e-c29c1658f501 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Bhavin Patel, Splunk description: Data source object for Sysmon EventID 26 source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational @@ -12,7 +12,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time output_fields: diff --git a/data_sources/sysmon_eventid_29.yml b/data_sources/sysmon_eventid_29.yml index 75955a4689..8c6770639c 100644 --- a/data_sources/sysmon_eventid_29.yml +++ b/data_sources/sysmon_eventid_29.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 29 id: 06c61e04-2d07-4e85-bcd5-8110938b1b18 -version: 2 +version: 3 creation_date: '2025-11-21' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Teoderick Contreras, Splunk description: Data source object for Sysmon EventID 29 source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational @@ -12,7 +12,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - action diff --git a/data_sources/sysmon_eventid_3.yml b/data_sources/sysmon_eventid_3.yml index 71d8619875..96e3cd293a 100644 --- a/data_sources/sysmon_eventid_3.yml +++ b/data_sources/sysmon_eventid_3.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 3 id: 01d84dff-4e26-422c-9389-6a579ee6e75b -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs details of network connections initiated by processes, including source and destination IPs, ports, protocols, and the associated process metadata. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_5.yml b/data_sources/sysmon_eventid_5.yml index d62d02fe1b..b7fdfe1b8f 100644 --- a/data_sources/sysmon_eventid_5.yml +++ b/data_sources/sysmon_eventid_5.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 5 id: 556471bf-44fa-44e6-97e2-eb25416aeb6d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process name, process ID, parent process, and associated metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml index 2aa7542d3a..e8205bd002 100644 --- a/data_sources/sysmon_eventid_6.yml +++ b/data_sources/sysmon_eventid_6.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 6 id: eadc297a-c20c-45a1-8fac-74ad54019767 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the loading of a driver into the kernel or user mode, including details about the driver name, file path, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml index 00a6d580c0..63f0e59c3a 100644 --- a/data_sources/sysmon_eventid_7.yml +++ b/data_sources/sysmon_eventid_7.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 7 id: 45512fa5-4d55-4088-9d51-f4dedc16fdff -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the loading of an image (module) into a process, including details about the image name, file path, and hash information. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml index a03b6240b2..0b0fdc2446 100644 --- a/data_sources/sysmon_eventid_8.yml +++ b/data_sources/sysmon_eventid_8.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 8 id: df7a786c-ade0-48f0-8596-26f10d169f7d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new thread in a process, including details about the thread ID, start address, and source process. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_9.yml b/data_sources/sysmon_eventid_9.yml index 6f6ee986d5..9d88ff92f0 100644 --- a/data_sources/sysmon_eventid_9.yml +++ b/data_sources/sysmon_eventid_9.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 9 id: ae4a6a24-9b8c-4386-a7ac-677d7ad5bf09 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the access of raw disk data by a process, including details about the disk name, process ID, and process metadata. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index 7e1ec4fde7..992f1f4849 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -1,8 +1,8 @@ name: Windows Active Directory Admon id: 22bbf4e4-d313-43c1-98ee-808b8775519d -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ActiveDirectory supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Guid diff --git a/data_sources/windows_event_log_application_15457.yml b/data_sources/windows_event_log_application_15457.yml index 4ef6ecee00..3633d3212d 100644 --- a/data_sources/windows_event_log_application_15457.yml +++ b/data_sources/windows_event_log_application_15457.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 15457 id: 4491537e-520c-46f7-9209-f56f852aa237 -version: 2 +version: 11 creation_date: '2025-02-25' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 15457 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_17135.yml b/data_sources/windows_event_log_application_17135.yml index fb960b1d42..3cab7c37e5 100644 --- a/data_sources/windows_event_log_application_17135.yml +++ b/data_sources/windows_event_log_application_17135.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 17135 id: 4491537e-520c-46f7-9209-f56f852aa231 -version: 2 +version: 11 creation_date: '2025-02-25' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 17135 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index 9107707eaf..cebf67e4eb 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 2282 id: 4490537e-5e0c-46f7-9209-f56f852aa237 -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index a98f34690b..ec285e0cdc 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: @@ -17,7 +17,7 @@ separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_8128.yml b/data_sources/windows_event_log_application_8128.yml index b45b9b50fa..0fc96a5ab2 100644 --- a/data_sources/windows_event_log_application_8128.yml +++ b/data_sources/windows_event_log_application_8128.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 8128 id: 4491537e-5e0c-46f7-9209-f56f852aa237 -version: 2 +version: 11 creation_date: '2025-02-25' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 8128 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_400.yml b/data_sources/windows_event_log_appxdeployment_server_400.yml index 869197ab81..53443173e8 100644 --- a/data_sources/windows_event_log_appxdeployment_server_400.yml +++ b/data_sources/windows_event_log_appxdeployment_server_400.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 400 id: 3e5f9d2a-b8c7-4d1e-a6f3-7b9c8d5e4f2a -version: 2 +version: 11 creation_date: '2025-08-18' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 400. These events are generated when a package deployment operation begins, providing details about the package being deployed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_854.yml b/data_sources/windows_event_log_appxdeployment_server_854.yml index 792a15ebbc..0690f3d482 100644 --- a/data_sources/windows_event_log_appxdeployment_server_854.yml +++ b/data_sources/windows_event_log_appxdeployment_server_854.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 854 id: 4d2e6f8a-c9b7-5a3e-8d1f-2e9c7b5a4f3d -version: 2 +version: 11 creation_date: '2025-08-18' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 854. These events are generated when an MSIX/AppX package has been successfully installed on a system. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_855.yml b/data_sources/windows_event_log_appxdeployment_server_855.yml index 22e3b71725..13efbd0361 100644 --- a/data_sources/windows_event_log_appxdeployment_server_855.yml +++ b/data_sources/windows_event_log_appxdeployment_server_855.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 855 id: 4491537c-521c-46f7-9209-f56f852aa231 -version: 2 +version: 11 creation_date: '2025-08-18' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 855. These events are generated when a package deployment operation completes successfully, providing details about the packages that were installed or updated. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxpackaging_171.yml b/data_sources/windows_event_log_appxpackaging_171.yml index 00920b4b37..18b5cdef1a 100644 --- a/data_sources/windows_event_log_appxpackaging_171.yml +++ b/data_sources/windows_event_log_appxpackaging_171.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXPackaging 171 id: 2d0f8e3c-a2d7-4b9e-8f1c-6a5d7e3e9f2b -version: 2 +version: 11 creation_date: '2025-08-18' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXPackaging/Operational channel, specifically focusing on EventCode 171. These events are generated when a user clicks on or attempts to interact with an MSIX package, even if the package is not fully installed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 2701795166..ea9cb37808 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: @@ -18,7 +18,7 @@ separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index f4e7771023..15ab7bccb1 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 81 id: 463ff898-8135-4c0e-811e-f8629dfc5027 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index 14d92e22a7..8ebed38bce 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -1,8 +1,8 @@ name: Windows Event Log CertificateServicesClient 1007 id: c51444e3-479d-4c4a-b111-e8276a3acf39 -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index 011347afb2..c23b00e18a 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1121 id: 84a254c5-7900-4b52-a324-a176adb7c11d -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index 9c97a01efe..8ac4abdd01 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1122 id: 4a2d0499-f489-4557-82f4-f357025cf3e7 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1125.yml b/data_sources/windows_event_log_defender_1125.yml index 77928d8273..33bd7db9ea 100644 --- a/data_sources/windows_event_log_defender_1125.yml +++ b/data_sources/windows_event_log_defender_1125.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1125 id: 0cddda76-6fd8-4fb6-9026-f23a2761c95d -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1125 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time example_log: 112204000x80000000000000003701Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender Antivirus4.18.23100.2009E6DB77E5-3DF2-4CF1-B95A-636979351E5B2023-11-26T23:43:08.709Z(unknown user)C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1.401.1247.01.1.23100.2009ENT\ConsRC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x00000000 diff --git a/data_sources/windows_event_log_defender_1126.yml b/data_sources/windows_event_log_defender_1126.yml index b0b5c2cef0..f735310b4d 100644 --- a/data_sources/windows_event_log_defender_1126.yml +++ b/data_sources/windows_event_log_defender_1126.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1126 id: c1c6284b-b663-4001-bdf2-c0cacee22a2a -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1126 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index 8d9767ba9c..5a6bffc752 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1129 id: 0572e119-a48a-4c70-bc58-90e453edacd2 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_defender_1131.yml b/data_sources/windows_event_log_defender_1131.yml index 7b59c9cd6b..db9b6eb123 100644 --- a/data_sources/windows_event_log_defender_1131.yml +++ b/data_sources/windows_event_log_defender_1131.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1131 id: 638f884e-439a-4328-923c-ec5a2679f450 -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1131 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1132.yml b/data_sources/windows_event_log_defender_1132.yml index 1a813f46f9..549d77eade 100644 --- a/data_sources/windows_event_log_defender_1132.yml +++ b/data_sources/windows_event_log_defender_1132.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1132 id: 18f93f60-4eca-46e8-a29d-147e6451a34c -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1132 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1133.yml b/data_sources/windows_event_log_defender_1133.yml index 88cb4531d3..8fd7885fb6 100644 --- a/data_sources/windows_event_log_defender_1133.yml +++ b/data_sources/windows_event_log_defender_1133.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1133 id: 63c97a9a-cc7f-46c5-b219-8be388666637 -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1133 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1134.yml b/data_sources/windows_event_log_defender_1134.yml index 3b54c95906..cdad778127 100644 --- a/data_sources/windows_event_log_defender_1134.yml +++ b/data_sources/windows_event_log_defender_1134.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1134 id: 26abac7d-d026-44e9-b1a3-13e3e11b232d -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1134 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index 882e7a7bd0..21516b6849 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 5007 id: 27f18792-8d95-4871-8853-874b7faf023f -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when Windows Defender antimalware settings are modified. mitre_components: @@ -14,7 +14,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index 257bd4a5d4..2d7e996683 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_printservice_4909.yml b/data_sources/windows_event_log_printservice_4909.yml index 529620eb60..a5c10dcf16 100644 --- a/data_sources/windows_event_log_printservice_4909.yml +++ b/data_sources/windows_event_log_printservice_4909.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 4909 id: 4c00e353-18b8-4de6-896d-83bc5817dbaa -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Printservice 4909 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time example_log: '' diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index d952de1f7e..b908b29683 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: @@ -16,7 +16,7 @@ separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 6bd7d957fc..5cbed6decf 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,8 +1,8 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index 3dbf23664f..a1342a5cdd 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: @@ -15,7 +15,7 @@ separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index 8586c6984d..304a91f2ae 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 5 +version: 14 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 3971f62bfc..516ccc8de8 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 28e5d9fead..fd2f13012b 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4625 id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when an account fails to log on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index e8c1fb0efb..c85c5b545a 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4627 id: e35c7b9a-b451-4084-95a5-43b7f8965cac -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index 6b8fa7d829..42ca9a81a7 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4648 id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account mitre_components: @@ -15,7 +15,7 @@ separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index c0dc0121e4..abc2a0f4cf 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4662 id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it mitre_components: @@ -15,7 +15,7 @@ separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index f74d26c94a..9ca6b12d8a 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4663 id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer mitre_components: @@ -15,7 +15,7 @@ separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 280d7f8262..b54d49d354 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index 642687b596..56329c6f13 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4688 id: d195eb26-a81c-45ed-aeb3-25792e8a985a -version: 5 +version: 14 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of a new process mitre_components: @@ -16,7 +16,7 @@ configuration: Enabling Windows event log process command line logging via group supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - Caller_Domain - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index 3b4b6a9c06..11ae08ee76 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4698 id: 32c06703-02d3-47ec-8856-b0dc3045866c -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a new scheduled task is created mitre_components: @@ -15,7 +15,7 @@ separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index a80ed23a9b..2f4b485888 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4699 id: 4727dead-d063-4333-9ddd-59823a416aff -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a scheduled task is deleted from the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4700.yml b/data_sources/windows_event_log_security_4700.yml index 4dc60cd9bd..6f37033f8a 100644 --- a/data_sources/windows_event_log_security_4700.yml +++ b/data_sources/windows_event_log_security_4700.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4700 id: 89895c7b-2aba-41ca-ad12-8b6d290b5dde -version: 3 +version: 12 creation_date: '2025-03-11' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Steven Dick description: Data source object for Windows Event Log Security 4700 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - EventID example_log: 4700 0 0 12804 0 0x8020000000000000 344861 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin LeastPrivilege CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4702.yml b/data_sources/windows_event_log_security_4702.yml index 7184ff77e3..70558e2dee 100644 --- a/data_sources/windows_event_log_security_4702.yml +++ b/data_sources/windows_event_log_security_4702.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 -version: 3 +version: 12 creation_date: '2025-03-11' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 5c1d729155..beaea55d60 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4703 id: e256673b-16e8-4b74-b7aa-9eed6ce67072 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a token right is adjusted on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index 06b3adb988..7255be60c2 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4719 id: 954033e6-dd05-4775-a1f2-1f19632f4420 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a system audit policy is modified on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index 31484a3587..54c3daa230 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4720 id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a new user account is created on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4723.yml b/data_sources/windows_event_log_security_4723.yml index 5105961915..87f7ecfe34 100644 --- a/data_sources/windows_event_log_security_4723.yml +++ b/data_sources/windows_event_log_security_4723.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4723 id: df19b271-57c8-4f31-817a-6c5566985484 -version: 1 +version: 10 creation_date: '2026-06-15' -modification_date: '2026-06-15' +modification_date: '2026-10-01' author: Raven Tait, Splunk description: Logs an event when an attempt is made to change an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4723' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index 0b06b7823a..e1aee39656 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4724 id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when an attempt is made to reset an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index ca05c7b840..d052e1be7b 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4725 id: 31fd887d-0d14-44cc-bb64-80063a9f2968 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a user account has been disabled in Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index 6ddc2aba57..6c712e5f86 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4726 id: 0b56dcd7-0f72-4a05-9226-d6059781737b -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a user account is deleted from Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4727.yml b/data_sources/windows_event_log_security_4727.yml index 0aa2c2f0b7..914cc2f0c0 100644 --- a/data_sources/windows_event_log_security_4727.yml +++ b/data_sources/windows_event_log_security_4727.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4727 id: 4d2078ab-36f5-447e-b7e4-474890b8040b -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4727 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4728.yml b/data_sources/windows_event_log_security_4728.yml index bcba79a79d..087b05f463 100644 --- a/data_sources/windows_event_log_security_4728.yml +++ b/data_sources/windows_event_log_security_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4728 id: c0cb4907-d715-41f2-a98a-4f4e75f248c1 -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4728 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4730.yml b/data_sources/windows_event_log_security_4730.yml index 9487a6ac52..975613ba23 100644 --- a/data_sources/windows_event_log_security_4730.yml +++ b/data_sources/windows_event_log_security_4730.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4730 id: 126966ba-a17d-4194-882b-57d303aaf46d -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4730 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4731.yml b/data_sources/windows_event_log_security_4731.yml index 30f8bc23e8..99a7c8846e 100644 --- a/data_sources/windows_event_log_security_4731.yml +++ b/data_sources/windows_event_log_security_4731.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4731 id: 1bbc004e-a75e-4d94-a619-c5aaf5d11ed5 -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4731 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index d95f852eb8..57aa270334 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4732 id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a member is added to a security-enabled local group on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4737.yml b/data_sources/windows_event_log_security_4737.yml index f128bbfcc4..2cc266914c 100644 --- a/data_sources/windows_event_log_security_4737.yml +++ b/data_sources/windows_event_log_security_4737.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4737 id: 132fc609-17f0-4efd-8f7e-db12139c6690 -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4737 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index fb6f1f3ca8..3a6533901d 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4738 id: cb85709b-101e-41a9-bb60-d2108f79dfbd -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index b0f6314703..4a8a8e3745 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4739 id: c1e0442a-8a97-405d-baf2-057c5d68cd9a -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index 7b643fb3d0..9e55a00455 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4741 id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index eb26156fe9..437861d351 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4742 id: ea830adf-5450-489a-bcdc-fb8d2cbe674c -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4744.yml b/data_sources/windows_event_log_security_4744.yml index 216eb54d2c..fa0a9713d8 100644 --- a/data_sources/windows_event_log_security_4744.yml +++ b/data_sources/windows_event_log_security_4744.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4744 id: 244e0bd4-00b0-4091-b8b4-9d435aca6ad8 -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4744 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4749.yml b/data_sources/windows_event_log_security_4749.yml index 8b61381ede..ae9eb073d4 100644 --- a/data_sources/windows_event_log_security_4749.yml +++ b/data_sources/windows_event_log_security_4749.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4749 id: eb322056-01a3-4cd5-bc09-01140d33194a -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4749 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4754.yml b/data_sources/windows_event_log_security_4754.yml index 4dbe460a36..06ee81513f 100644 --- a/data_sources/windows_event_log_security_4754.yml +++ b/data_sources/windows_event_log_security_4754.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4754 id: 501a507e-3275-4c4b-9c44-53eecfeae487 -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4754 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4756.yml b/data_sources/windows_event_log_security_4756.yml index c53348491f..e2a5ff2c6e 100644 --- a/data_sources/windows_event_log_security_4756.yml +++ b/data_sources/windows_event_log_security_4756.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4756 id: b0093058-0cb6-4c73-a95b-fb0f3541e88c -version: 2 +version: 11 creation_date: '2026-03-30' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Nasreddine Bencherchali, Splunk description: Data source object for Windows Event Log Security 4756 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4759.yml b/data_sources/windows_event_log_security_4759.yml index 9db0814db3..3253f9b344 100644 --- a/data_sources/windows_event_log_security_4759.yml +++ b/data_sources/windows_event_log_security_4759.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4759 id: 431e3520-505b-4ace-aced-cb51e3f7311e -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4759 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index 0d954d3b5c..00672114c5 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4768 id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index 2b1506eda9..11fa4d17f9 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index 16751ea4ef..3d5fee977c 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4771 id: 418debbb-adf3-48ec-9efd-59d45f8861e5 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index 408aaa466b..a236778730 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4776 id: 1da9092a-c795-4a26-ace8-d43855524e96 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index ed8f3691a8..763316f491 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4783.yml b/data_sources/windows_event_log_security_4783.yml index 4b239b5056..a9f0644f48 100644 --- a/data_sources/windows_event_log_security_4783.yml +++ b/data_sources/windows_event_log_security_4783.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4783 id: 6b945150-785c-49a1-b705-56b42215630b -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4783 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4790.yml b/data_sources/windows_event_log_security_4790.yml index 8a945e0fe8..efd75093fa 100644 --- a/data_sources/windows_event_log_security_4790.yml +++ b/data_sources/windows_event_log_security_4790.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4790 id: 1cc6ecbb-af04-432b-a224-02c65243ac88 -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4790 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index 70bae43f05..7882dcbb56 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4794 id: ec7da74f-274a-4bde-aa0e-15c68aca0426 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index 8eebe0e5a9..d03717e008 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4798 id: 29e97f72-eb2e-400e-b0c9-81277547e43b -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index bdd7735a81..7969c9e3f4 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4876 id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index 9379641c7d..a7701df9a2 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index 2016e280f6..579a87dfab 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4887 id: 994c7b19-a623-4231-9818-f00e453b9a75 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4946.yml b/data_sources/windows_event_log_security_4946.yml index 2d9e806305..8ea6fcc2e3 100644 --- a/data_sources/windows_event_log_security_4946.yml +++ b/data_sources/windows_event_log_security_4946.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4946 id: d7dafd01-a22d-4b05-b793-7571ef1fa789 -version: 3 +version: 12 creation_date: '2025-03-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4946 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4946' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4947.yml b/data_sources/windows_event_log_security_4947.yml index b10ef8870b..15c3c226df 100644 --- a/data_sources/windows_event_log_security_4947.yml +++ b/data_sources/windows_event_log_security_4947.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4947 id: 63d4a2fa-a7dc-46d2-b702-54794e1f4d3c -version: 3 +version: 12 creation_date: '2025-03-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4947 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4947' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4948.yml b/data_sources/windows_event_log_security_4948.yml index 961be864ee..5967b829f0 100644 --- a/data_sources/windows_event_log_security_4948.yml +++ b/data_sources/windows_event_log_security_4948.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4948 id: 910032df-4e49-42fe-a611-d4c29557d83a -version: 3 +version: 12 creation_date: '2025-03-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4948 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4948' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index b2035008e4..eb57e1980a 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5136 id: 7ba3737e-231e-455d-824e-cd077749f835 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index 253ce10397..f7a86e5df7 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AppCorrelationID diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index f5f3cf1116..2fd830afbf 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index 393098f288..e58dc9e304 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5141 id: eafb35fa-f034-4be3-8508-d9173a73c0a1 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 1647d2e832..c8e5c4714e 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 5 +version: 14 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_system_104.yml b/data_sources/windows_event_log_system_104.yml index faea29ccad..85cde3230c 100644 --- a/data_sources/windows_event_log_system_104.yml +++ b/data_sources/windows_event_log_system_104.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 104 id: 577b9b41-6b37-44c4-9016-3d890b909050 -version: 4 +version: 13 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log System 104 source: XmlWinEventLog:System @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index 49df88f658..5f9f6f8c34 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4720 id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 642359a985..df618bd394 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4726 id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index dd3e3849ea..44191702b1 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index 0cf395b1d2..ed5840b2cb 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7036 id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). mitre_components: @@ -17,7 +17,7 @@ separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 518d67eacf..9494a07ba9 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index a1fda46fe8..15335bfeba 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 4 +version: 13 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - AccountName diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index e7fe0ff722..94e221fd48 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ActionName diff --git a/data_sources/windows_event_log_taskscheduler_201.yml b/data_sources/windows_event_log_taskscheduler_201.yml index 01ff84004b..37dd4c686d 100644 --- a/data_sources/windows_event_log_taskscheduler_201.yml +++ b/data_sources/windows_event_log_taskscheduler_201.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 201 id: 4c09ae64-01cd-4b65-8221-20f803b0d86e -version: 3 +version: 12 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log TaskScheduler 201 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time output_fields: diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index a3412a3b42..04df098056 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -1,8 +1,8 @@ name: Windows IIS id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. mitre_components: @@ -16,4 +16,4 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index 8c6977fd3a..b8676b6493 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -1,8 +1,8 @@ name: Windows IIS 29 id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 -version: 3 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. mitre_components: @@ -17,7 +17,7 @@ separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.3 fields: - _time - ComputerName diff --git a/data_sources/zeek_conn.yml b/data_sources/zeek_conn.yml index 814f426321..867105f843 100644 --- a/data_sources/zeek_conn.yml +++ b/data_sources/zeek_conn.yml @@ -1,8 +1,8 @@ name: Zeek Conn id: 01dff429-9c29-4181-87ae-ea19cde20031 -version: 2 +version: 3 creation_date: '2025-03-13' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Data source object for Zeek connection logs source: bro:conn:json