From 491135d877951111e5c2b60b25cf5db604a30054 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Thu, 1 Oct 2026 18:11:29 +0200 Subject: [PATCH 1/5] update data source object --- contentctl.yml | 8 ++++---- data_sources/cisco_ios_logs.yml | 12 ++++++------ 2 files changed, 10 insertions(+), 10 deletions(-) diff --git a/contentctl.yml b/contentctl.yml index 1ffa66afde..e9761e70bc 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -241,10 +241,10 @@ apps: version: 4.0.3 hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-vmware-indexes_403.tgz - uid: 1467 - title: Cisco Networks Add-on - appid: TA-cisco_ios - version: 2.7.9 - hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/add-on-for-cisco-network-data_279.tgz + title: Cisco Enterprise Networking Add-on for Splunk + appid: TA-cisco-enterprise-networking-add-on-for-splunk + version: 4.0.35 + hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-enterprise-networking-add-on-for-splunk_4035.tgz - uid: 8024 title: TA-ollama appid: ta-ollama diff --git a/data_sources/cisco_ios_logs.yml b/data_sources/cisco_ios_logs.yml index bf6b6c5e82..d8d10d3b7e 100644 --- a/data_sources/cisco_ios_logs.yml +++ b/data_sources/cisco_ios_logs.yml @@ -1,17 +1,17 @@ name: Cisco IOS Logs id: 9e4c8d7b-6f5e-4a3d-b2c1-0a9b8c7d6e5f -version: 2 +version: 3 creation_date: '2025-08-21' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Michael Haag, Splunk -description: Data source object for Cisco IOS system logs. Cisco IOS logs provide operational and security telemetry from Cisco network devices (IOS, IOS XE, IOS XR, NX-OS, WLC, and APs). The Cisco Networks Add-on for Splunk (TA-cisco_ios) normalizes these events by setting proper sourcetypes and extracting fields for switches, routers, controllers, and access points; deploy the TA on indexers/HFs and search heads, and the Cisco Networks (cisco_ios) App on search heads. Supported platforms include Catalyst, ASR, ISR, Nexus, CRS, and other IOS-based devices, enabling consistent investigation, alerting, and reporting in Splunk Enterprise and Splunk Cloud. This data is ingested via SYSLOG. +description: Data source object for Cisco IOS system logs. source: cisco:ios sourcetype: cisco:ios separator: supported_TA: - - name: Cisco Networks Add-on - url: https://splunkbase.splunk.com/app/1467 - version: 2.8.2 + - name: Cisco Enterprise Networking Add-on for Splunk + url: https://splunkbase.splunk.com/app/7538 + version: 4.0.35 fields: - _time - aci_message_text From 4820794eed649a900c257f2cc9adca82eb00db99 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Thu, 1 Oct 2026 23:06:00 +0200 Subject: [PATCH 2/5] deprecate circle CI content --- .../circle_ci_disable_security_job.yml | 8 ++++++-- .../circle_ci_disable_security_step.yml | 8 ++++++-- macros/{ => deprecated}/circleci.yml | 0 3 files changed, 12 insertions(+), 4 deletions(-) rename detections/{cloud => deprecated}/circle_ci_disable_security_job.yml (92%) rename detections/{cloud => deprecated}/circle_ci_disable_security_step.yml (91%) rename macros/{ => deprecated}/circleci.yml (100%) diff --git a/detections/cloud/circle_ci_disable_security_job.yml b/detections/deprecated/circle_ci_disable_security_job.yml similarity index 92% rename from detections/cloud/circle_ci_disable_security_job.yml rename to detections/deprecated/circle_ci_disable_security_job.yml index 86c52cf751..8fd2d2c87a 100644 --- a/detections/cloud/circle_ci_disable_security_job.yml +++ b/detections/deprecated/circle_ci_disable_security_job.yml @@ -2,9 +2,9 @@ name: Circle CI Disable Security Job id: 4a2fdd41-c578-4cd4-9ef7-980e352517f2 version: 10 creation_date: '2021-09-02' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk -status: production +status: deprecated type: Anomaly description: The following analytic detects the disabling of security jobs in CircleCI pipelines. It leverages CircleCI log data, renaming and extracting fields such as job names, workflow IDs, user information, commit messages, URLs, and branches. The detection identifies mandatory jobs for each workflow and checks if they were executed. This activity is significant because disabling security jobs can allow malicious code to bypass security checks, leading to potential data breaches, system downtime, and reputational damage. If confirmed malicious, this could result in unauthorized code execution and compromised pipeline integrity. data_source: @@ -60,3 +60,7 @@ tests: sourcetype: circleci source: circleci test_type: unit +deprecation_info: + reason: Detection deprecated because the Technology Add-on it uses has been archived, and no replacement TA exists. + removed_in_version: 6.10.0 + replacement_content: [] diff --git a/detections/cloud/circle_ci_disable_security_step.yml b/detections/deprecated/circle_ci_disable_security_step.yml similarity index 91% rename from detections/cloud/circle_ci_disable_security_step.yml rename to detections/deprecated/circle_ci_disable_security_step.yml index 9f5d5ce02e..cda9411de9 100644 --- a/detections/cloud/circle_ci_disable_security_step.yml +++ b/detections/deprecated/circle_ci_disable_security_step.yml @@ -2,9 +2,9 @@ name: Circle CI Disable Security Step id: 72cb9de9-e98b-4ac9-80b2-5331bba6ea97 version: 9 creation_date: '2021-09-01' -modification_date: '2026-05-13' +modification_date: '2026-10-01' author: Patrick Bareiss, Splunk -status: experimental +status: deprecated type: Anomaly description: The following analytic detects the disablement of security steps in a CircleCI pipeline. It leverages CircleCI logs, using field renaming, joining, and statistical analysis to identify instances where mandatory security steps are not executed. This activity is significant because disabling security steps can introduce vulnerabilities, unauthorized changes, or malicious code into the pipeline. If confirmed malicious, this could lead to potential attacks, data breaches, or compromised infrastructure. Investigate by reviewing job names, commit details, and user information associated with the disablement, and examine any relevant artifacts and concurrent processes. data_source: @@ -58,3 +58,7 @@ tests: source: circleci test_type: experimental description: This test is a legacy experimental test and may not be accurate. +deprecation_info: + reason: Detection deprecated because the Technology Add-on it uses has been archived, and no replacement TA exists. + removed_in_version: 6.10.0 + replacement_content: [] diff --git a/macros/circleci.yml b/macros/deprecated/circleci.yml similarity index 100% rename from macros/circleci.yml rename to macros/deprecated/circleci.yml From 6fa25a8abeacca1cf16e7cf4f388138d3c2ef8b4 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Thu, 1 Oct 2026 23:11:01 +0200 Subject: [PATCH 3/5] bump version --- detections/deprecated/circle_ci_disable_security_job.yml | 2 +- detections/deprecated/circle_ci_disable_security_step.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/detections/deprecated/circle_ci_disable_security_job.yml b/detections/deprecated/circle_ci_disable_security_job.yml index 8fd2d2c87a..98e1defa25 100644 --- a/detections/deprecated/circle_ci_disable_security_job.yml +++ b/detections/deprecated/circle_ci_disable_security_job.yml @@ -1,6 +1,6 @@ name: Circle CI Disable Security Job id: 4a2fdd41-c578-4cd4-9ef7-980e352517f2 -version: 10 +version: 11 creation_date: '2021-09-02' modification_date: '2026-10-01' author: Patrick Bareiss, Splunk diff --git a/detections/deprecated/circle_ci_disable_security_step.yml b/detections/deprecated/circle_ci_disable_security_step.yml index cda9411de9..bb7f5b6c16 100644 --- a/detections/deprecated/circle_ci_disable_security_step.yml +++ b/detections/deprecated/circle_ci_disable_security_step.yml @@ -1,6 +1,6 @@ name: Circle CI Disable Security Step id: 72cb9de9-e98b-4ac9-80b2-5331bba6ea97 -version: 9 +version: 10 creation_date: '2021-09-01' modification_date: '2026-10-01' author: Patrick Bareiss, Splunk From a5afc9816efd6c147510b59d1826d540c21620a2 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Fri, 2 Oct 2026 00:51:16 +0200 Subject: [PATCH 4/5] Update check_archived_tas.py --- scripts/check_archived_tas.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/scripts/check_archived_tas.py b/scripts/check_archived_tas.py index 020fa3f2d7..23b05144ed 100644 --- a/scripts/check_archived_tas.py +++ b/scripts/check_archived_tas.py @@ -59,6 +59,8 @@ def discover_used_tas() -> dict[str, dict[str, Any]]: detection = load_yaml(path) if not detection: continue + if str(detection.get("status") or "").strip().casefold() == "deprecated": + continue references = detection.get("data_source") or [] if isinstance(references, str): references = [references] From a3edb5c250f267db8b4a75dcd64d27f1bdc3b275 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Fri, 2 Oct 2026 00:52:54 +0200 Subject: [PATCH 5/5] bump removed in version --- detections/deprecated/circle_ci_disable_security_job.yml | 2 +- detections/deprecated/circle_ci_disable_security_step.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/detections/deprecated/circle_ci_disable_security_job.yml b/detections/deprecated/circle_ci_disable_security_job.yml index 98e1defa25..d7ac9e3393 100644 --- a/detections/deprecated/circle_ci_disable_security_job.yml +++ b/detections/deprecated/circle_ci_disable_security_job.yml @@ -62,5 +62,5 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated because the Technology Add-on it uses has been archived, and no replacement TA exists. - removed_in_version: 6.10.0 + removed_in_version: 6.12.0 replacement_content: [] diff --git a/detections/deprecated/circle_ci_disable_security_step.yml b/detections/deprecated/circle_ci_disable_security_step.yml index bb7f5b6c16..5b234e57c1 100644 --- a/detections/deprecated/circle_ci_disable_security_step.yml +++ b/detections/deprecated/circle_ci_disable_security_step.yml @@ -60,5 +60,5 @@ tests: description: This test is a legacy experimental test and may not be accurate. deprecation_info: reason: Detection deprecated because the Technology Add-on it uses has been archived, and no replacement TA exists. - removed_in_version: 6.10.0 + removed_in_version: 6.12.0 replacement_content: []