Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions Solutions/Flare/Analytic Rules/FlareCloudBucket.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ status: Available
requiredDataConnectors:
- connectorId: Flare
dataTypes:
- Firework_CL
- FireworkV2_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
Expand All @@ -17,7 +17,7 @@ tactics:
relevantTechniques:
- T1593
query: |
Firework_CL
FireworkV2_CL
| where source_s contains "Grayhat_warfare" and (risk_score_d == "3" or risk_score_d == "4" or risk_score_d == "5")
version: 1.0.1
kind: Scheduled
version: 2.0.0
kind: Scheduled
8 changes: 4 additions & 4 deletions Solutions/Flare/Analytic Rules/FlareCredentialLeaks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ status: Available
requiredDataConnectors:
- connectorId: Flare
dataTypes:
- Firework_CL
- FireworkV2_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
Expand All @@ -17,7 +17,7 @@ tactics:
relevantTechniques:
- T1110
query: |
Firework_CL
FireworkV2_CL
| where notempty(data_new_leaks_s) and source_s != 'stealer_logs_samples'
version: 1.0.2
kind: Scheduled
version: 2.0.0
kind: Scheduled
23 changes: 0 additions & 23 deletions Solutions/Flare/Analytic Rules/FlareDarkweb.yaml

This file was deleted.

8 changes: 4 additions & 4 deletions Solutions/Flare/Analytic Rules/FlareDork.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ status: Available
requiredDataConnectors:
- connectorId: Flare
dataTypes:
- Firework_CL
- FireworkV2_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
Expand All @@ -17,7 +17,7 @@ tactics:
relevantTechniques:
- T1593
query: |
Firework_CL
FireworkV2_CL
| where source_s contains "google_search" and (risk_score_d == "3" or risk_score_d == "4" or risk_score_d == "5")
version: 1.0.1
kind: Scheduled
version: 2.0.0
kind: Scheduled
8 changes: 4 additions & 4 deletions Solutions/Flare/Analytic Rules/FlareHost.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ status: Available
requiredDataConnectors:
- connectorId: Flare
dataTypes:
- Firework_CL
- FireworkV2_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
Expand All @@ -17,7 +17,7 @@ tactics:
relevantTechniques:
- T1596
query: |
Firework_CL
FireworkV2_CL
| where source_s contains "driller_shodan" and (risk_score_d == "3" or risk_score_d == "4" or risk_score_d == "5")
version: 1.0.1
kind: Scheduled
version: 2.0.0
kind: Scheduled
8 changes: 4 additions & 4 deletions Solutions/Flare/Analytic Rules/FlareInfectedDevice.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ status: Available
requiredDataConnectors:
- connectorId: Flare
dataTypes:
- Firework_CL
- FireworkV2_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
Expand All @@ -17,7 +17,7 @@ tactics:
relevantTechniques:
- T1555
query: |
Firework_CL
FireworkV2_CL
| where category_name_s contains "Infected Device" or source_s=="genesis_market" and (risk_score_d == "3" or risk_score_d == "4" or risk_score_d == "5")
version: 1.0.1
kind: Scheduled
version: 2.0.0
kind: Scheduled
8 changes: 4 additions & 4 deletions Solutions/Flare/Analytic Rules/FlarePaste.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ status: Available
requiredDataConnectors:
- connectorId: Flare
dataTypes:
- Firework_CL
- FireworkV2_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
Expand All @@ -17,7 +17,7 @@ tactics:
relevantTechniques:
- T1593
query: |
Firework_CL
FireworkV2_CL
| where source_s in ("gist_github","Pastebin","driller_stackexchange") and (risk_score_d == "3" or risk_score_d == "4" or risk_score_d == "5")
version: 1.0.1
kind: Scheduled
version: 2.0.0
kind: Scheduled
8 changes: 4 additions & 4 deletions Solutions/Flare/Analytic Rules/FlareSSLcert.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ status: Available
requiredDataConnectors:
- connectorId: Flare
dataTypes:
- Firework_CL
- FireworkV2_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
Expand All @@ -17,7 +17,7 @@ tactics:
relevantTechniques:
- T1583
query: |
Firework_CL
FireworkV2_CL
| where source_s contains "certstream" and (risk_score_d == "3" or risk_score_d == "4" or risk_score_d == "5")
version: 1.0.1
kind: Scheduled
version: 2.0.0
kind: Scheduled
8 changes: 4 additions & 4 deletions Solutions/Flare/Analytic Rules/FlareSourceCode.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ status: Available
requiredDataConnectors:
- connectorId: Flare
dataTypes:
- Firework_CL
- FireworkV2_CL
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
Expand All @@ -17,7 +17,7 @@ tactics:
relevantTechniques:
- T1593
query: |
Firework_CL
FireworkV2_CL
| where source_s contains "driller_github" and (risk_score_d == "3" or risk_score_d == "4" or risk_score_d == "5")
version: 1.0.1
kind: Scheduled
version: 2.0.0
kind: Scheduled

This file was deleted.

Loading
Loading