Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions contentctl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -241,10 +241,10 @@ apps:
version: 4.0.3
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-vmware-indexes_403.tgz
- uid: 1467
title: Cisco Networks Add-on
appid: TA-cisco_ios
version: 2.7.9
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/add-on-for-cisco-network-data_279.tgz
title: Cisco Enterprise Networking Add-on for Splunk
appid: TA-cisco-enterprise-networking-add-on-for-splunk
version: 4.0.35
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-enterprise-networking-add-on-for-splunk_4035.tgz
- uid: 8024
title: TA-ollama
appid: ta-ollama
Expand Down
12 changes: 6 additions & 6 deletions data_sources/cisco_ios_logs.yml
Original file line number Diff line number Diff line change
@@ -1,17 +1,17 @@
name: Cisco IOS Logs
id: 9e4c8d7b-6f5e-4a3d-b2c1-0a9b8c7d6e5f
version: 2
version: 3
creation_date: '2025-08-21'
modification_date: '2026-05-13'
modification_date: '2026-10-01'
author: Michael Haag, Splunk
description: Data source object for Cisco IOS system logs. Cisco IOS logs provide operational and security telemetry from Cisco network devices (IOS, IOS XE, IOS XR, NX-OS, WLC, and APs). The Cisco Networks Add-on for Splunk (TA-cisco_ios) normalizes these events by setting proper sourcetypes and extracting fields for switches, routers, controllers, and access points; deploy the TA on indexers/HFs and search heads, and the Cisco Networks (cisco_ios) App on search heads. Supported platforms include Catalyst, ASR, ISR, Nexus, CRS, and other IOS-based devices, enabling consistent investigation, alerting, and reporting in Splunk Enterprise and Splunk Cloud. This data is ingested via SYSLOG.
description: Data source object for Cisco IOS system logs.
source: cisco:ios
sourcetype: cisco:ios
separator:
supported_TA:
- name: Cisco Networks Add-on
url: https://splunkbase.splunk.com/app/1467
version: 2.8.2
- name: Cisco Enterprise Networking Add-on for Splunk
url: https://splunkbase.splunk.com/app/7538
version: 4.0.35
fields:
- _time
- aci_message_text
Expand Down
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Circle CI Disable Security Job
id: 4a2fdd41-c578-4cd4-9ef7-980e352517f2
version: 10
version: 11
creation_date: '2021-09-02'
modification_date: '2026-05-13'
modification_date: '2026-10-01'
author: Patrick Bareiss, Splunk
status: production
status: deprecated
type: Anomaly
description: The following analytic detects the disabling of security jobs in CircleCI pipelines. It leverages CircleCI log data, renaming and extracting fields such as job names, workflow IDs, user information, commit messages, URLs, and branches. The detection identifies mandatory jobs for each workflow and checks if they were executed. This activity is significant because disabling security jobs can allow malicious code to bypass security checks, leading to potential data breaches, system downtime, and reputational damage. If confirmed malicious, this could result in unauthorized code execution and compromised pipeline integrity.
data_source:
Expand Down Expand Up @@ -60,3 +60,7 @@ tests:
sourcetype: circleci
source: circleci
test_type: unit
deprecation_info:
reason: Detection deprecated because the Technology Add-on it uses has been archived, and no replacement TA exists.
removed_in_version: 6.12.0
replacement_content: []
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Circle CI Disable Security Step
id: 72cb9de9-e98b-4ac9-80b2-5331bba6ea97
version: 9
version: 10
creation_date: '2021-09-01'
modification_date: '2026-05-13'
modification_date: '2026-10-01'
author: Patrick Bareiss, Splunk
status: experimental
status: deprecated
type: Anomaly
description: The following analytic detects the disablement of security steps in a CircleCI pipeline. It leverages CircleCI logs, using field renaming, joining, and statistical analysis to identify instances where mandatory security steps are not executed. This activity is significant because disabling security steps can introduce vulnerabilities, unauthorized changes, or malicious code into the pipeline. If confirmed malicious, this could lead to potential attacks, data breaches, or compromised infrastructure. Investigate by reviewing job names, commit details, and user information associated with the disablement, and examine any relevant artifacts and concurrent processes.
data_source:
Expand Down Expand Up @@ -58,3 +58,7 @@ tests:
source: circleci
test_type: experimental
description: This test is a legacy experimental test and may not be accurate.
deprecation_info:
reason: Detection deprecated because the Technology Add-on it uses has been archived, and no replacement TA exists.
removed_in_version: 6.12.0
replacement_content: []
File renamed without changes.
2 changes: 2 additions & 0 deletions scripts/check_archived_tas.py
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,8 @@ def discover_used_tas() -> dict[str, dict[str, Any]]:
detection = load_yaml(path)
if not detection:
continue
if str(detection.get("status") or "").strip().casefold() == "deprecated":
continue
references = detection.get("data_source") or []
if isinstance(references, str):
references = [references]
Expand Down
Loading