diff --git a/contentctl.yml b/contentctl.yml index 1ffa66afdee..e9761e70bcf 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -241,10 +241,10 @@ apps: version: 4.0.3 hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-vmware-indexes_403.tgz - uid: 1467 - title: Cisco Networks Add-on - appid: TA-cisco_ios - version: 2.7.9 - hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/add-on-for-cisco-network-data_279.tgz + title: Cisco Enterprise Networking Add-on for Splunk + appid: TA-cisco-enterprise-networking-add-on-for-splunk + version: 4.0.35 + hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-enterprise-networking-add-on-for-splunk_4035.tgz - uid: 8024 title: TA-ollama appid: ta-ollama diff --git a/data_sources/cisco_ios_logs.yml b/data_sources/cisco_ios_logs.yml index bf6b6c5e82a..d8d10d3b7ec 100644 --- a/data_sources/cisco_ios_logs.yml +++ b/data_sources/cisco_ios_logs.yml @@ -1,17 +1,17 @@ name: Cisco IOS Logs id: 9e4c8d7b-6f5e-4a3d-b2c1-0a9b8c7d6e5f -version: 2 +version: 3 creation_date: '2025-08-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk -description: Data source object for Cisco IOS system logs. Cisco IOS logs provide operational and security telemetry from Cisco network devices (IOS, IOS XE, IOS XR, NX-OS, WLC, and APs). The Cisco Networks Add-on for Splunk (TA-cisco_ios) normalizes these events by setting proper sourcetypes and extracting fields for switches, routers, controllers, and access points; deploy the TA on indexers/HFs and search heads, and the Cisco Networks (cisco_ios) App on search heads. Supported platforms include Catalyst, ASR, ISR, Nexus, CRS, and other IOS-based devices, enabling consistent investigation, alerting, and reporting in Splunk Enterprise and Splunk Cloud. This data is ingested via SYSLOG. +description: Data source object for Cisco IOS system logs. source: cisco:ios sourcetype: cisco:ios separator: supported_TA: - - name: Cisco Networks Add-on - url: https://splunkbase.splunk.com/app/1467 - version: 2.8.2 + - name: Cisco Enterprise Networking Add-on for Splunk + url: https://splunkbase.splunk.com/app/7538 + version: 4.0.35 fields: - _time - aci_message_text diff --git a/detections/cloud/circle_ci_disable_security_job.yml b/detections/deprecated/circle_ci_disable_security_job.yml similarity index 92% rename from detections/cloud/circle_ci_disable_security_job.yml rename to detections/deprecated/circle_ci_disable_security_job.yml index 86c52cf751c..d7ac9e33930 100644 --- a/detections/cloud/circle_ci_disable_security_job.yml +++ b/detections/deprecated/circle_ci_disable_security_job.yml @@ -1,10 +1,10 @@ name: Circle CI Disable Security Job id: 4a2fdd41-c578-4cd4-9ef7-980e352517f2 -version: 10 +version: 11 creation_date: '2021-09-02' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk -status: production +status: deprecated type: Anomaly description: The following analytic detects the disabling of security jobs in CircleCI pipelines. It leverages CircleCI log data, renaming and extracting fields such as job names, workflow IDs, user information, commit messages, URLs, and branches. The detection identifies mandatory jobs for each workflow and checks if they were executed. This activity is significant because disabling security jobs can allow malicious code to bypass security checks, leading to potential data breaches, system downtime, and reputational damage. If confirmed malicious, this could result in unauthorized code execution and compromised pipeline integrity. data_source: @@ -60,3 +60,7 @@ tests: sourcetype: circleci source: circleci test_type: unit +deprecation_info: + reason: Detection deprecated because the Technology Add-on it uses has been archived, and no replacement TA exists. + removed_in_version: 6.12.0 + replacement_content: [] diff --git a/detections/cloud/circle_ci_disable_security_step.yml b/detections/deprecated/circle_ci_disable_security_step.yml similarity index 91% rename from detections/cloud/circle_ci_disable_security_step.yml rename to detections/deprecated/circle_ci_disable_security_step.yml index 9f5d5ce02e0..5b234e57c1c 100644 --- a/detections/cloud/circle_ci_disable_security_step.yml +++ b/detections/deprecated/circle_ci_disable_security_step.yml @@ -1,10 +1,10 @@ name: Circle CI Disable Security Step id: 72cb9de9-e98b-4ac9-80b2-5331bba6ea97 -version: 9 +version: 10 creation_date: '2021-09-01' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk -status: experimental +status: deprecated type: Anomaly description: The following analytic detects the disablement of security steps in a CircleCI pipeline. It leverages CircleCI logs, using field renaming, joining, and statistical analysis to identify instances where mandatory security steps are not executed. This activity is significant because disabling security steps can introduce vulnerabilities, unauthorized changes, or malicious code into the pipeline. If confirmed malicious, this could lead to potential attacks, data breaches, or compromised infrastructure. Investigate by reviewing job names, commit details, and user information associated with the disablement, and examine any relevant artifacts and concurrent processes. data_source: @@ -58,3 +58,7 @@ tests: source: circleci test_type: experimental description: This test is a legacy experimental test and may not be accurate. +deprecation_info: + reason: Detection deprecated because the Technology Add-on it uses has been archived, and no replacement TA exists. + removed_in_version: 6.12.0 + replacement_content: [] diff --git a/macros/circleci.yml b/macros/deprecated/circleci.yml similarity index 100% rename from macros/circleci.yml rename to macros/deprecated/circleci.yml diff --git a/scripts/check_archived_tas.py b/scripts/check_archived_tas.py index 020fa3f2d71..23b05144ed2 100644 --- a/scripts/check_archived_tas.py +++ b/scripts/check_archived_tas.py @@ -59,6 +59,8 @@ def discover_used_tas() -> dict[str, dict[str, Any]]: detection = load_yaml(path) if not detection: continue + if str(detection.get("status") or "").strip().casefold() == "deprecated": + continue references = detection.get("data_source") or [] if isinstance(references, str): references = [references]