From bab410ac356affdc9b641e55bfb7b1cb6d00ca00 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Thu, 18 Jun 2026 21:08:29 +0000 Subject: [PATCH 01/32] Update datasource TA versions --- data_sources/cisco_ai_defense_alerts.yml | 6 +++--- data_sources/cisco_asa_logs.yml | 6 +++--- data_sources/cisco_duo_activity.yml | 6 +++--- data_sources/cisco_duo_administrator.yml | 6 +++--- data_sources/cisco_isovalent_process_connect.yml | 6 +++--- data_sources/cisco_isovalent_process_exec.yml | 6 +++--- data_sources/cisco_isovalent_process_kprobe.yml | 6 +++--- ...isco_secure_firewall_threat_defense_connection_event.yml | 6 +++--- .../cisco_secure_firewall_threat_defense_file_event.yml | 6 +++--- ...cisco_secure_firewall_threat_defense_intrusion_event.yml | 6 +++--- data_sources/crowdstrike_falcon_stream_alert.yml | 6 +++--- data_sources/crowdstrike_processrollup2.yml | 6 +++--- data_sources/g_suite_drive.yml | 6 +++--- data_sources/g_suite_gmail.yml | 6 +++--- data_sources/github_enterprise_audit_logs.yml | 6 +++--- data_sources/github_organizations_audit_logs.yml | 6 +++--- data_sources/google_workspace.yml | 6 +++--- data_sources/google_workspace_login_failure.yml | 6 +++--- data_sources/google_workspace_login_success.yml | 6 +++--- 19 files changed, 57 insertions(+), 57 deletions(-) diff --git a/data_sources/cisco_ai_defense_alerts.yml b/data_sources/cisco_ai_defense_alerts.yml index aa3e7c95cb..7dc36fc3f9 100644 --- a/data_sources/cisco_ai_defense_alerts.yml +++ b/data_sources/cisco_ai_defense_alerts.yml @@ -1,8 +1,8 @@ name: Cisco AI Defense Alerts id: cbb06880-9dd9-4542-ac60-bd6e1d3c3e4e -version: 2 +version: 3 creation_date: '2025-02-14' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Bhavin Patel description: Data source object for Cisco AI Defense Alerts source: cisco_ai_defense @@ -11,5 +11,5 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: diff --git a/data_sources/cisco_asa_logs.yml b/data_sources/cisco_asa_logs.yml index 04a92090d7..8633d2eedd 100644 --- a/data_sources/cisco_asa_logs.yml +++ b/data_sources/cisco_asa_logs.yml @@ -1,8 +1,8 @@ name: Cisco ASA Logs id: 3f2a9b6d-1c8e-4f7b-a2d3-8b7f1c2a9d4e -version: 3 +version: 4 creation_date: '2025-09-25' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Bhavin Patel, Splunk description: "Data source object for Cisco ASA system logs. Cisco ASA logs provide firewall operational and security telemetry (connection events, ACL denies, VPN events, NAT translations, and device health). Deploy the Splunk Add-on for Cisco ASA (TA-cisco_asa) on indexers/heavy forwarders and the Cisco ASA App on search heads for best parsing, CIM mapping, and dashboards. This data is ingested via SYSLOG. You must be ingesting Cisco ASA syslog data into your Splunk environment. To ensure all detections work, configure your ASA and FTD devices to generate and forward both debug and informational level syslog messages before they are sent to Splunk. A few analytics are designed to be used with comprehensive logging enabled, as it relies on the presence of specific message IDs. You can find specific instructions on how to set this up here : https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/63884-config-asa-00.html#toc-hId--1451069880. \n" source: not_applicable @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - Cisco_ASA_action - Cisco_ASA_message_id diff --git a/data_sources/cisco_duo_activity.yml b/data_sources/cisco_duo_activity.yml index 3bea5f94aa..90080a9c57 100644 --- a/data_sources/cisco_duo_activity.yml +++ b/data_sources/cisco_duo_activity.yml @@ -1,8 +1,8 @@ name: Cisco Duo Activity id: 83f727f6-8754-41f8-b9f7-8226886a659e -version: 2 +version: 3 creation_date: '2025-07-10' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Activity source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - access_device.browser - access_device.browser_version diff --git a/data_sources/cisco_duo_administrator.yml b/data_sources/cisco_duo_administrator.yml index b3fa5fb6d7..0461bdd9a3 100644 --- a/data_sources/cisco_duo_administrator.yml +++ b/data_sources/cisco_duo_administrator.yml @@ -1,8 +1,8 @@ name: Cisco Duo Administrator id: 38e22de6-8b6b-449c-ae26-a640c88ff7f9 -version: 2 +version: 3 creation_date: '2025-07-10' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Administrator source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - action - actionlabel diff --git a/data_sources/cisco_isovalent_process_connect.yml b/data_sources/cisco_isovalent_process_connect.yml index d0c47aadec..49521f5c93 100644 --- a/data_sources/cisco_isovalent_process_connect.yml +++ b/data_sources/cisco_isovalent_process_connect.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Connect id: bf8c76a1-6066-4759-ab77-d3f0a375519e -version: 2 +version: 3 creation_date: '2026-01-05' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Bhavin Patel, Splunk description: "Captures detailed process connection events—including source and destination process metadata, execution lineage (ancestry), and Kubernetes workload context—generated by Cisco Isovalent instrumentation. Enables technical analysis of inter-process communications, container-level activity, and workload-specific network flows in cloud-native environments." source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processConnect supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - _time - app diff --git a/data_sources/cisco_isovalent_process_exec.yml b/data_sources/cisco_isovalent_process_exec.yml index 5c86c068fd..2b55b3c975 100644 --- a/data_sources/cisco_isovalent_process_exec.yml +++ b/data_sources/cisco_isovalent_process_exec.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Exec id: 87654321-dcba-4321-00fe-0987654321ba -version: 2 +version: 3 creation_date: '2026-01-05' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Bhavin Patel, Splunk description: Logs process execution events within Cisco Isovalent environments, providing visibility into process exec ancestry and Kubernetes workload identity. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processExec supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - _time - cluster_name diff --git a/data_sources/cisco_isovalent_process_kprobe.yml b/data_sources/cisco_isovalent_process_kprobe.yml index 8487727aad..4d06806d7c 100644 --- a/data_sources/cisco_isovalent_process_kprobe.yml +++ b/data_sources/cisco_isovalent_process_kprobe.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Kprobe id: b2620ef2-fac6-467f-bdc8-253d65db1cb9 -version: 2 +version: 3 creation_date: '2026-01-05' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Bhavin Patel, Splunk description: Captures kernel probe (kprobe) telemetry from Cisco Isovalent Runtime Security, including function name, arguments, and process context, enabling visibility into low-level kernel interactions that may indicate container escape attempts or system tampering. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - _time - app diff --git a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml index ed96cbbe2d..f9af12e7c6 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Connection Event id: 18878597-8f8a-4bca-a805-bfbe35e00032 -version: 3 +version: 4 creation_date: '2025-04-03' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Nasreddine Bencherchali, Splunk description: Data source object for raw connection events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - AC_RuleAction - action diff --git a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml index fdfd338ddb..ee09653ac5 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense File Event id: 19878597-8f8a-4bca-a805-bfbe35e00032 -version: 2 +version: 3 creation_date: '2025-04-09' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Nasreddine Bencherchali, Splunk description: Data source object for raw file events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - app - Application diff --git a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml index 309b325466..ba988be306 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Intrusion Event id: d11b67ec-1cb2-4f6f-a2d8-a099c7e15b29 -version: 2 +version: 3 creation_date: '2025-04-16' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Nasreddine Bencherchali, Splunk description: Data source object for raw intrusion events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.5 + version: 3.6.7 fields: - Application - Classification diff --git a/data_sources/crowdstrike_falcon_stream_alert.yml b/data_sources/crowdstrike_falcon_stream_alert.yml index 32b048111d..5c97773012 100644 --- a/data_sources/crowdstrike_falcon_stream_alert.yml +++ b/data_sources/crowdstrike_falcon_stream_alert.yml @@ -1,8 +1,8 @@ name: CrowdStrike Falcon Stream Alert id: 52b38751-b0db-4965-a800-ebaabd1fd7d5 -version: 2 +version: 3 creation_date: '2025-07-01' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Bhavin Patel, Bryan Pluta, Splunk description: Logs of CrowdStrike Falcon Stream Alerts mitre_components: @@ -17,7 +17,7 @@ separator: event.DetectName supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 2.0.5 + version: 3.0.0 fields: - action - description diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml index 05c7e2f476..95579d5dab 100644 --- a/data_sources/crowdstrike_processrollup2.yml +++ b/data_sources/crowdstrike_processrollup2.yml @@ -1,8 +1,8 @@ name: CrowdStrike ProcessRollup2 id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments. mitre_components: @@ -18,7 +18,7 @@ separator_value: ProcessRollup2 supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 2.0.5 + version: 3.0.0 fields: - AuthenticationId - AuthenticationId_meaning diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml index a9b1f66987..d8f395e74b 100644 --- a/data_sources/g_suite_drive.yml +++ b/data_sources/g_suite_drive.yml @@ -1,8 +1,8 @@ name: G Suite Drive id: 5f79120f-a235-4468-bd0d-55203758ac22 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details. mitre_components: @@ -16,7 +16,7 @@ sourcetype: gsuite:drive:json supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 4.0.0 fields: - _time - email diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml index 5e9526e61b..ba14091ca7 100644 --- a/data_sources/g_suite_gmail.yml +++ b/data_sources/g_suite_gmail.yml @@ -1,8 +1,8 @@ name: G Suite Gmail id: 706c3978-41de-406b-b6e0-75bd01e12a5d -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events. mitre_components: @@ -15,7 +15,7 @@ sourcetype: gsuite:gmail:bigquery supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 4.0.0 fields: - _time - action_type diff --git a/data_sources/github_enterprise_audit_logs.yml b/data_sources/github_enterprise_audit_logs.yml index 893b9b4e98..e94866708d 100644 --- a/data_sources/github_enterprise_audit_logs.yml +++ b/data_sources/github_enterprise_audit_logs.yml @@ -1,8 +1,8 @@ name: GitHub Enterprise Audit Logs id: 8a4d656f-8801-4a2c-ae10-553d2696a59f -version: 2 +version: 3 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Data source object for GitHub Enterprise logs using Audit log streaming as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk using a Splunk HTTP Event Collector. source: http:github @@ -10,7 +10,7 @@ sourcetype: httpevent supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.2.0 + version: 3.3.0 fields: - _document_id - action diff --git a/data_sources/github_organizations_audit_logs.yml b/data_sources/github_organizations_audit_logs.yml index e6e106f4a1..e398025625 100644 --- a/data_sources/github_organizations_audit_logs.yml +++ b/data_sources/github_organizations_audit_logs.yml @@ -1,8 +1,8 @@ name: GitHub Organizations Audit Logs id: ce520b1c-79fe-48ef-a0f9-71fbbd4837b0 -version: 2 +version: 3 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Data source object for GitHub Organizations logs using the Splunk Add-on for Github using a Personal Access Token. source: github @@ -10,7 +10,7 @@ sourcetype: github:cloud:audit supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.2.0 + version: 3.3.0 fields: - _document_id - action diff --git a/data_sources/google_workspace.yml b/data_sources/google_workspace.yml index acd5970dd5..9a5e332fbe 100644 --- a/data_sources/google_workspace.yml +++ b/data_sources/google_workspace.yml @@ -1,8 +1,8 @@ name: Google Workspace id: f1a044e3-113a-4e4d-84f2-b153ade83087 -version: 2 +version: 3 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Bhavin Patel, Splunk description: Data source object for Google Workspace source: google_workspace @@ -10,7 +10,7 @@ sourcetype: gws:reports:login supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 4.0.0 fields: - action - actor.callerType diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml index ed05961581..c817af96ff 100644 --- a/data_sources/google_workspace_login_failure.yml +++ b/data_sources/google_workspace_login_failure.yml @@ -1,8 +1,8 @@ name: Google Workspace login_failure id: cabec7cf-4008-4899-b47e-39c34a9a1255 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure. mitre_components: @@ -17,7 +17,7 @@ separator_value: login_failure supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 4.0.0 fields: - _time - actor.email diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml index 4b61dd8b5f..424a893a42 100644 --- a/data_sources/google_workspace_login_success.yml +++ b/data_sources/google_workspace_login_success.yml @@ -1,8 +1,8 @@ name: Google Workspace login_success id: bffe8013-9cdf-4fe6-9c1b-6784391a4951 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: login_success supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 3.1.1 + version: 4.0.0 fields: - _time - actor.email From be154800379512dfec3d4a425cc7f3fe85af7f3b Mon Sep 17 00:00:00 2001 From: Eric McGinnis Date: Thu, 18 Jun 2026 14:15:13 -0700 Subject: [PATCH 02/32] downgrade zeek --- data_sources/zeek_conn.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data_sources/zeek_conn.yml b/data_sources/zeek_conn.yml index 814f426321..e36acc0a9d 100644 --- a/data_sources/zeek_conn.yml +++ b/data_sources/zeek_conn.yml @@ -10,7 +10,7 @@ sourcetype: bro:conn:json supported_TA: - name: TA for Zeek url: https://splunkbase.splunk.com/app/5466 - version: 1.0.11 + version: 1.0.10 fields: - action - bytes From c0563eef56c0989c037fff830a2fd26e65f61af7 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Thu, 18 Jun 2026 21:17:24 +0000 Subject: [PATCH 03/32] Update datasource TA versions --- data_sources/zeek_conn.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/data_sources/zeek_conn.yml b/data_sources/zeek_conn.yml index e36acc0a9d..867105f843 100644 --- a/data_sources/zeek_conn.yml +++ b/data_sources/zeek_conn.yml @@ -1,8 +1,8 @@ name: Zeek Conn id: 01dff429-9c29-4181-87ae-ea19cde20031 -version: 2 +version: 3 creation_date: '2025-03-13' -modification_date: '2026-05-13' +modification_date: '2026-06-18' author: Patrick Bareiss, Splunk description: Data source object for Zeek connection logs source: bro:conn:json @@ -10,7 +10,7 @@ sourcetype: bro:conn:json supported_TA: - name: TA for Zeek url: https://splunkbase.splunk.com/app/5466 - version: 1.0.10 + version: 1.0.11 fields: - action - bytes From b5d2ca63e2c99e51159e164112c36ccd86ca9fb4 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Wed, 24 Jun 2026 06:35:41 +0000 Subject: [PATCH 04/32] Update datasource TA versions --- data_sources/github_enterprise_audit_logs.yml | 6 +++--- data_sources/github_organizations_audit_logs.yml | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/data_sources/github_enterprise_audit_logs.yml b/data_sources/github_enterprise_audit_logs.yml index e94866708d..04b18f4964 100644 --- a/data_sources/github_enterprise_audit_logs.yml +++ b/data_sources/github_enterprise_audit_logs.yml @@ -1,8 +1,8 @@ name: GitHub Enterprise Audit Logs id: 8a4d656f-8801-4a2c-ae10-553d2696a59f -version: 3 +version: 4 creation_date: '2024-07-16' -modification_date: '2026-06-18' +modification_date: '2026-06-24' author: Patrick Bareiss, Splunk description: Data source object for GitHub Enterprise logs using Audit log streaming as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk using a Splunk HTTP Event Collector. source: http:github @@ -10,7 +10,7 @@ sourcetype: httpevent supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.3.0 + version: 3.3.1 fields: - _document_id - action diff --git a/data_sources/github_organizations_audit_logs.yml b/data_sources/github_organizations_audit_logs.yml index e398025625..e27b87cbd8 100644 --- a/data_sources/github_organizations_audit_logs.yml +++ b/data_sources/github_organizations_audit_logs.yml @@ -1,8 +1,8 @@ name: GitHub Organizations Audit Logs id: ce520b1c-79fe-48ef-a0f9-71fbbd4837b0 -version: 3 +version: 4 creation_date: '2024-07-16' -modification_date: '2026-06-18' +modification_date: '2026-06-24' author: Patrick Bareiss, Splunk description: Data source object for GitHub Organizations logs using the Splunk Add-on for Github using a Personal Access Token. source: github @@ -10,7 +10,7 @@ sourcetype: github:cloud:audit supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.3.0 + version: 3.3.1 fields: - _document_id - action From 881d7f2383605ea466d548854e3364dfdde93a2b Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Tue, 30 Jun 2026 10:23:26 +0000 Subject: [PATCH 05/32] Update datasource TA versions --- data_sources/okta.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/data_sources/okta.yml b/data_sources/okta.yml index 01fc34cfdf..712b211cfc 100644 --- a/data_sources/okta.yml +++ b/data_sources/okta.yml @@ -1,8 +1,8 @@ name: Okta id: ec26febe-e760-4981-bbee-72e107c7b9d2 -version: 3 +version: 4 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-06-30' author: Patrick Bareiss, Splunk description: Logs authentication and administrative activities captured by Okta, including user login attempts, session management, and configuration changes. mitre_components: @@ -16,7 +16,7 @@ sourcetype: OktaIM2:log supported_TA: - name: Splunk Add-on for Okta Identity Cloud url: https://splunkbase.splunk.com/app/6553 - version: 5.0.2 + version: 5.0.3 output_fields: - dest - src From 5628702ecb652f122dc073f3e96f2bcbfd0c0122 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Mon, 6 Jul 2026 11:21:40 +0000 Subject: [PATCH 06/32] Update datasource TA versions --- data_sources/sysmon_eventid_1.yml | 6 +++--- data_sources/sysmon_eventid_10.yml | 6 +++--- data_sources/sysmon_eventid_11.yml | 6 +++--- data_sources/sysmon_eventid_12.yml | 6 +++--- data_sources/sysmon_eventid_13.yml | 6 +++--- data_sources/sysmon_eventid_14.yml | 6 +++--- data_sources/sysmon_eventid_15.yml | 6 +++--- data_sources/sysmon_eventid_17.yml | 6 +++--- data_sources/sysmon_eventid_18.yml | 6 +++--- data_sources/sysmon_eventid_20.yml | 6 +++--- data_sources/sysmon_eventid_21.yml | 6 +++--- data_sources/sysmon_eventid_22.yml | 6 +++--- data_sources/sysmon_eventid_23.yml | 6 +++--- data_sources/sysmon_eventid_26.yml | 6 +++--- data_sources/sysmon_eventid_29.yml | 6 +++--- data_sources/sysmon_eventid_3.yml | 6 +++--- data_sources/sysmon_eventid_5.yml | 6 +++--- data_sources/sysmon_eventid_6.yml | 6 +++--- data_sources/sysmon_eventid_7.yml | 6 +++--- data_sources/sysmon_eventid_8.yml | 6 +++--- data_sources/sysmon_eventid_9.yml | 6 +++--- 21 files changed, 63 insertions(+), 63 deletions(-) diff --git a/data_sources/sysmon_eventid_1.yml b/data_sources/sysmon_eventid_1.yml index f0a8effbdf..a52186c2e7 100644 --- a/data_sources/sysmon_eventid_1.yml +++ b/data_sources/sysmon_eventid_1.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 1 id: b375f4d1-d7ca-4bc0-9103-294825c0af17 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new process, including details such as process ID, parent process, command line arguments, and hashes of the executable. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_10.yml b/data_sources/sysmon_eventid_10.yml index d54f84444d..71d0f6af70 100644 --- a/data_sources/sysmon_eventid_10.yml +++ b/data_sources/sysmon_eventid_10.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 10 id: 659cd5a8-148a-4c59-ade1-05f41ac1b096 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs events where one process accesses another process, typically for memory reads or injections, including details about the source and target processes. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - CallTrace diff --git a/data_sources/sysmon_eventid_11.yml b/data_sources/sysmon_eventid_11.yml index 47c82f9ac8..62449e9bac 100644 --- a/data_sources/sysmon_eventid_11.yml +++ b/data_sources/sysmon_eventid_11.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 11 id: f3db9179-f4f5-416d-bc03-39f4d4ff699e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new file, including details about the file path, hash information, and associated process metadata. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_12.yml b/data_sources/sysmon_eventid_12.yml index bfc98a539c..879cd3aba2 100644 --- a/data_sources/sysmon_eventid_12.yml +++ b/data_sources/sysmon_eventid_12.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 12 id: 3ef28798-8eaa-4fd2-b074-6f36d08a1b33 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new registry key, including details about the key name, registry path, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_13.yml b/data_sources/sysmon_eventid_13.yml index 9e4f2384db..7ee9550436 100644 --- a/data_sources/sysmon_eventid_13.yml +++ b/data_sources/sysmon_eventid_13.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 13 id: 19cd00ee-f65f-48ca-bb08-64aac28638ce -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs changes to a registry key, including details about the modified key, value, and associated process. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_14.yml b/data_sources/sysmon_eventid_14.yml index 4a0eea5ee2..2323c7f421 100644 --- a/data_sources/sysmon_eventid_14.yml +++ b/data_sources/sysmon_eventid_14.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 14 id: 77c4b345-0eab-415e-98c6-f4114b021723 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Bhavin Patel, Splunk description: Data source object for Sysmon EventID 14 source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational @@ -12,7 +12,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time example_log: '' diff --git a/data_sources/sysmon_eventid_15.yml b/data_sources/sysmon_eventid_15.yml index bcae8778e0..9c6a15b7be 100644 --- a/data_sources/sysmon_eventid_15.yml +++ b/data_sources/sysmon_eventid_15.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 15 id: 95785e02-93b4-47e2-81f1-be326295348e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new file stream, including details about the file stream's hash, path, and associated process metadata. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_17.yml b/data_sources/sysmon_eventid_17.yml index b149c566ed..08b7da81b0 100644 --- a/data_sources/sysmon_eventid_17.yml +++ b/data_sources/sysmon_eventid_17.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 17 id: 08924246-c8e8-4c95-a9fc-633c43cc82df -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Sysmon EventID 17 logs details about the detection of a named pipe. mitre_components: @@ -15,7 +15,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_18.yml b/data_sources/sysmon_eventid_18.yml index 09741457b3..ba254eaa5a 100644 --- a/data_sources/sysmon_eventid_18.yml +++ b/data_sources/sysmon_eventid_18.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 18 id: 37eb3554-214e-4e66-af10-c3ffc5b8ca82 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the connection to a named pipe, including details about the pipe name, source and destination processes, and communication direction. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_20.yml b/data_sources/sysmon_eventid_20.yml index a92ac49516..867fa77eab 100644 --- a/data_sources/sysmon_eventid_20.yml +++ b/data_sources/sysmon_eventid_20.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 20 id: aeee5374-3203-4286-b744-a8cc4ad1cd7e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs WMI (Windows Management Instrumentation) consumer activity, including details about the WMI event consumer, associated process, and event data. mitre_components: @@ -17,7 +17,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_21.yml b/data_sources/sysmon_eventid_21.yml index c1add4adfd..77c423b0c6 100644 --- a/data_sources/sysmon_eventid_21.yml +++ b/data_sources/sysmon_eventid_21.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 21 id: 304384bc-715e-4958-988b-a8051a91349a -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs activity related to the association of a WMI event consumer with a filter, including details about the consumer, filter, and associated process. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_22.yml b/data_sources/sysmon_eventid_22.yml index e267c09d70..af88015dcf 100644 --- a/data_sources/sysmon_eventid_22.yml +++ b/data_sources/sysmon_eventid_22.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 22 id: 911538b2-eba7-4d3e-85e8-d82d380c37bf -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs DNS query events, including details about the queried domain, source IP, query type, and response data. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_23.yml b/data_sources/sysmon_eventid_23.yml index d9436f249c..e63ceaf147 100644 --- a/data_sources/sysmon_eventid_23.yml +++ b/data_sources/sysmon_eventid_23.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 23 id: 5ea2721d-f60c-4f48-a047-47d514e327c3 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the deletion of a file, including details about the file path, associated process, and the time of deletion. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Archived diff --git a/data_sources/sysmon_eventid_26.yml b/data_sources/sysmon_eventid_26.yml index ee3d6376a2..59a566abfd 100644 --- a/data_sources/sysmon_eventid_26.yml +++ b/data_sources/sysmon_eventid_26.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 26 id: 77f946e0-4afb-4789-8d9e-c29c1658f501 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Bhavin Patel, Splunk description: Data source object for Sysmon EventID 26 source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational @@ -12,7 +12,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time output_fields: diff --git a/data_sources/sysmon_eventid_29.yml b/data_sources/sysmon_eventid_29.yml index 75955a4689..8c6770639c 100644 --- a/data_sources/sysmon_eventid_29.yml +++ b/data_sources/sysmon_eventid_29.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 29 id: 06c61e04-2d07-4e85-bcd5-8110938b1b18 -version: 2 +version: 3 creation_date: '2025-11-21' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Teoderick Contreras, Splunk description: Data source object for Sysmon EventID 29 source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational @@ -12,7 +12,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - action diff --git a/data_sources/sysmon_eventid_3.yml b/data_sources/sysmon_eventid_3.yml index 71d8619875..96e3cd293a 100644 --- a/data_sources/sysmon_eventid_3.yml +++ b/data_sources/sysmon_eventid_3.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 3 id: 01d84dff-4e26-422c-9389-6a579ee6e75b -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs details of network connections initiated by processes, including source and destination IPs, ports, protocols, and the associated process metadata. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_5.yml b/data_sources/sysmon_eventid_5.yml index d62d02fe1b..b7fdfe1b8f 100644 --- a/data_sources/sysmon_eventid_5.yml +++ b/data_sources/sysmon_eventid_5.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 5 id: 556471bf-44fa-44e6-97e2-eb25416aeb6d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process name, process ID, parent process, and associated metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_6.yml b/data_sources/sysmon_eventid_6.yml index 2aa7542d3a..e8205bd002 100644 --- a/data_sources/sysmon_eventid_6.yml +++ b/data_sources/sysmon_eventid_6.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 6 id: eadc297a-c20c-45a1-8fac-74ad54019767 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the loading of a driver into the kernel or user mode, including details about the driver name, file path, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_7.yml b/data_sources/sysmon_eventid_7.yml index 00a6d580c0..63f0e59c3a 100644 --- a/data_sources/sysmon_eventid_7.yml +++ b/data_sources/sysmon_eventid_7.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 7 id: 45512fa5-4d55-4088-9d51-f4dedc16fdff -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the loading of an image (module) into a process, including details about the image name, file path, and hash information. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_8.yml b/data_sources/sysmon_eventid_8.yml index a03b6240b2..0b0fdc2446 100644 --- a/data_sources/sysmon_eventid_8.yml +++ b/data_sources/sysmon_eventid_8.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 8 id: df7a786c-ade0-48f0-8596-26f10d169f7d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the creation of a new thread in a process, including details about the thread ID, start address, and source process. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel diff --git a/data_sources/sysmon_eventid_9.yml b/data_sources/sysmon_eventid_9.yml index 6f6ee986d5..9d88ff92f0 100644 --- a/data_sources/sysmon_eventid_9.yml +++ b/data_sources/sysmon_eventid_9.yml @@ -1,8 +1,8 @@ name: Sysmon EventID 9 id: ae4a6a24-9b8c-4386-a7ac-677d7ad5bf09 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-06' author: Patrick Bareiss, Splunk description: Logs the access of raw disk data by a process, including details about the disk name, process ID, and process metadata. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 - version: 5.0.0 + version: 5.0.1 fields: - _time - Channel From f6d61eeaac6c55c6f4e31ed04b7ca0c2bcdfdbb1 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Wed, 8 Jul 2026 15:07:50 +0000 Subject: [PATCH 07/32] Update datasource TA versions --- data_sources/linux_auditd_add_user.yml | 6 +++--- data_sources/linux_auditd_cwd.yml | 6 +++--- data_sources/linux_auditd_daemon_abort.yml | 6 +++--- data_sources/linux_auditd_daemon_end.yml | 6 +++--- data_sources/linux_auditd_daemon_start.yml | 6 +++--- data_sources/linux_auditd_execve.yml | 6 +++--- data_sources/linux_auditd_path.yml | 6 +++--- data_sources/linux_auditd_proctitle.yml | 6 +++--- data_sources/linux_auditd_service_stop.yml | 6 +++--- data_sources/linux_auditd_syscall.yml | 6 +++--- data_sources/linux_messages_syslog.yml | 6 +++--- data_sources/linux_secure.yml | 6 +++--- data_sources/ntlm_operational_8004.yml | 6 +++--- data_sources/ntlm_operational_8005.yml | 6 +++--- data_sources/ntlm_operational_8006.yml | 6 +++--- data_sources/powershell_script_block_logging_4104.yml | 6 +++--- data_sources/windows_active_directory_admon.yml | 6 +++--- data_sources/windows_event_log_application_15457.yml | 6 +++--- data_sources/windows_event_log_application_17135.yml | 6 +++--- data_sources/windows_event_log_application_2282.yml | 6 +++--- data_sources/windows_event_log_application_3000.yml | 6 +++--- data_sources/windows_event_log_application_8128.yml | 6 +++--- .../windows_event_log_appxdeployment_server_400.yml | 6 +++--- .../windows_event_log_appxdeployment_server_854.yml | 6 +++--- .../windows_event_log_appxdeployment_server_855.yml | 6 +++--- data_sources/windows_event_log_appxpackaging_171.yml | 6 +++--- data_sources/windows_event_log_capi2_70.yml | 6 +++--- data_sources/windows_event_log_capi2_81.yml | 6 +++--- .../windows_event_log_certificateservicesclient_1007.yml | 6 +++--- data_sources/windows_event_log_defender_1121.yml | 6 +++--- data_sources/windows_event_log_defender_1122.yml | 6 +++--- data_sources/windows_event_log_defender_1125.yml | 6 +++--- data_sources/windows_event_log_defender_1126.yml | 6 +++--- data_sources/windows_event_log_defender_1129.yml | 6 +++--- data_sources/windows_event_log_defender_1131.yml | 6 +++--- data_sources/windows_event_log_defender_1132.yml | 6 +++--- data_sources/windows_event_log_defender_1133.yml | 6 +++--- data_sources/windows_event_log_defender_1134.yml | 6 +++--- data_sources/windows_event_log_defender_5007.yml | 6 +++--- data_sources/windows_event_log_printservice_316.yml | 6 +++--- data_sources/windows_event_log_printservice_4909.yml | 6 +++--- data_sources/windows_event_log_printservice_808.yml | 6 +++--- .../windows_event_log_remoteconnectionmanager_1149.yml | 6 +++--- data_sources/windows_event_log_security_1100.yml | 6 +++--- data_sources/windows_event_log_security_1102.yml | 6 +++--- data_sources/windows_event_log_security_4624.yml | 6 +++--- data_sources/windows_event_log_security_4625.yml | 6 +++--- data_sources/windows_event_log_security_4627.yml | 6 +++--- data_sources/windows_event_log_security_4648.yml | 6 +++--- data_sources/windows_event_log_security_4662.yml | 6 +++--- data_sources/windows_event_log_security_4663.yml | 6 +++--- data_sources/windows_event_log_security_4672.yml | 6 +++--- data_sources/windows_event_log_security_4688.yml | 6 +++--- data_sources/windows_event_log_security_4698.yml | 6 +++--- data_sources/windows_event_log_security_4699.yml | 6 +++--- data_sources/windows_event_log_security_4700.yml | 6 +++--- data_sources/windows_event_log_security_4702.yml | 6 +++--- data_sources/windows_event_log_security_4703.yml | 6 +++--- data_sources/windows_event_log_security_4719.yml | 6 +++--- data_sources/windows_event_log_security_4720.yml | 6 +++--- data_sources/windows_event_log_security_4723.yml | 6 +++--- data_sources/windows_event_log_security_4724.yml | 6 +++--- data_sources/windows_event_log_security_4725.yml | 6 +++--- data_sources/windows_event_log_security_4726.yml | 6 +++--- data_sources/windows_event_log_security_4727.yml | 6 +++--- data_sources/windows_event_log_security_4728.yml | 6 +++--- data_sources/windows_event_log_security_4730.yml | 6 +++--- data_sources/windows_event_log_security_4731.yml | 6 +++--- data_sources/windows_event_log_security_4732.yml | 6 +++--- data_sources/windows_event_log_security_4737.yml | 6 +++--- data_sources/windows_event_log_security_4738.yml | 6 +++--- data_sources/windows_event_log_security_4739.yml | 6 +++--- data_sources/windows_event_log_security_4741.yml | 6 +++--- data_sources/windows_event_log_security_4742.yml | 6 +++--- data_sources/windows_event_log_security_4744.yml | 6 +++--- data_sources/windows_event_log_security_4749.yml | 6 +++--- data_sources/windows_event_log_security_4754.yml | 6 +++--- data_sources/windows_event_log_security_4756.yml | 6 +++--- data_sources/windows_event_log_security_4759.yml | 6 +++--- data_sources/windows_event_log_security_4768.yml | 6 +++--- data_sources/windows_event_log_security_4769.yml | 6 +++--- data_sources/windows_event_log_security_4771.yml | 6 +++--- data_sources/windows_event_log_security_4776.yml | 6 +++--- data_sources/windows_event_log_security_4781.yml | 6 +++--- data_sources/windows_event_log_security_4783.yml | 6 +++--- data_sources/windows_event_log_security_4790.yml | 6 +++--- data_sources/windows_event_log_security_4794.yml | 6 +++--- data_sources/windows_event_log_security_4798.yml | 6 +++--- data_sources/windows_event_log_security_4876.yml | 6 +++--- data_sources/windows_event_log_security_4886.yml | 6 +++--- data_sources/windows_event_log_security_4887.yml | 6 +++--- data_sources/windows_event_log_security_4946.yml | 6 +++--- data_sources/windows_event_log_security_4947.yml | 6 +++--- data_sources/windows_event_log_security_4948.yml | 6 +++--- data_sources/windows_event_log_security_5136.yml | 6 +++--- data_sources/windows_event_log_security_5137.yml | 6 +++--- data_sources/windows_event_log_security_5140.yml | 6 +++--- data_sources/windows_event_log_security_5141.yml | 6 +++--- data_sources/windows_event_log_security_5145.yml | 6 +++--- data_sources/windows_event_log_system_104.yml | 6 +++--- data_sources/windows_event_log_system_4720.yml | 6 +++--- data_sources/windows_event_log_system_4726.yml | 6 +++--- data_sources/windows_event_log_system_4728.yml | 6 +++--- data_sources/windows_event_log_system_7036.yml | 6 +++--- data_sources/windows_event_log_system_7040.yml | 6 +++--- data_sources/windows_event_log_system_7045.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_200.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_201.yml | 6 +++--- data_sources/windows_iis.yml | 6 +++--- data_sources/windows_iis_29.yml | 6 +++--- 110 files changed, 330 insertions(+), 330 deletions(-) diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index 164e9aefb7..2a590b14a4 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -1,8 +1,8 @@ name: Linux Auditd Add User id: 30f79353-e1d2-4585-8735-1e0359559f3f -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - msg - type diff --git a/data_sources/linux_auditd_cwd.yml b/data_sources/linux_auditd_cwd.yml index afbe0ec701..ebd48529c9 100644 --- a/data_sources/linux_auditd_cwd.yml +++ b/data_sources/linux_auditd_cwd.yml @@ -1,8 +1,8 @@ name: Linux Auditd Cwd id: a9ef851b-d864-478b-b1b3-76535d7ff7fc -version: 2 +version: 3 creation_date: '2025-12-02' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Nasreddine Bencherchali, Splunk description: This type is used to record the working directory from which the process that invoked the system call specified in the first record was executed. The purpose of this record is to record the current process's location in case a relative path winds up being captured in the associated PATH record. This way the absolute path can be reconstructed. source: auditd @@ -13,7 +13,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - cwd - date_hour diff --git a/data_sources/linux_auditd_daemon_abort.yml b/data_sources/linux_auditd_daemon_abort.yml index 9b83e49dc1..983f143a5b 100644 --- a/data_sources/linux_auditd_daemon_abort.yml +++ b/data_sources/linux_auditd_daemon_abort.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Abort id: cc8b3bb0-0fae-4236-9c61-fe2d7138bd63 -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_end.yml b/data_sources/linux_auditd_daemon_end.yml index f7b4fcf4dd..37c18b161a 100644 --- a/data_sources/linux_auditd_daemon_end.yml +++ b/data_sources/linux_auditd_daemon_end.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon End id: 15135c45-e302-4d5a-a38a-3e8279f2ebd8 -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_start.yml b/data_sources/linux_auditd_daemon_start.yml index 9f96075a6e..5af1eac5bf 100644 --- a/data_sources/linux_auditd_daemon_start.yml +++ b/data_sources/linux_auditd_daemon_start.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Start id: f1b97407-ddf0-41a5-8685-ada05aae3555 -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - type - op diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 1d5c039877..2eebe98500 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -1,8 +1,8 @@ name: Linux Auditd Execve id: 9ef6364d-cc67-480e-8448-3306829a6a24 -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - msg - type diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index 6f0953cec0..0368fa9ebe 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -1,8 +1,8 @@ name: Linux Auditd Path id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - msg - type diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index 44e2a8935b..229dd55572 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -1,8 +1,8 @@ name: Linux Auditd Proctitle id: 5a25984a-2789-400a-858b-d75c923e06b1 -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - proctitle - msg diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index 1db5103e14..104d53d16f 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -1,8 +1,8 @@ name: Linux Auditd Service Stop id: 0643483c-bc62-455c-8d6e-1630e5f0e00d -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - msg - type diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index b5d9647033..4b7294673e 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -1,8 +1,8 @@ name: Linux Auditd Syscall id: 4dff7047-0d43-4096-bb3f-b756c889bbad -version: 3 +version: 4 creation_date: '2024-08-08' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - msg - type diff --git a/data_sources/linux_messages_syslog.yml b/data_sources/linux_messages_syslog.yml index 090a768534..14ae9328e9 100644 --- a/data_sources/linux_messages_syslog.yml +++ b/data_sources/linux_messages_syslog.yml @@ -1,8 +1,8 @@ name: Linux Messages Syslog id: c9e3bbb5-e0a2-4bac-8457-227e71841bda -version: 1 +version: 2 creation_date: '2025-05-06' -modification_date: '2025-05-06' +modification_date: '2026-07-08' author: Ravent Tait, Splunk description: Logs kernel events on a Linux system, including service starts/stops, hardware events, authentication notices, and other OS-level activity. @@ -16,7 +16,7 @@ sourcetype: linux_messages_syslog supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - _time - action diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index b8dd8ae5ba..d184209af7 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -1,8 +1,8 @@ name: Linux Secure id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. mitre_components: @@ -16,7 +16,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.0 fields: - _time - action diff --git a/data_sources/ntlm_operational_8004.yml b/data_sources/ntlm_operational_8004.yml index 141ebdf0de..0b02c924f0 100644 --- a/data_sources/ntlm_operational_8004.yml +++ b/data_sources/ntlm_operational_8004.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8004 id: fd08cb77-c26e-464c-a43e-2867e232127e -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8004 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8005.yml b/data_sources/ntlm_operational_8005.yml index da24c4688c..b96c7b9cc3 100644 --- a/data_sources/ntlm_operational_8005.yml +++ b/data_sources/ntlm_operational_8005.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8005 id: ad15a1cf-4b21-43de-81e4-6307c69172fb -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8005 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8006.yml b/data_sources/ntlm_operational_8006.yml index e4ec349eb5..13c04e7822 100644 --- a/data_sources/ntlm_operational_8006.yml +++ b/data_sources/ntlm_operational_8006.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8006 id: 9f50a672-6f7d-4621-a3bd-69468c6b7a7f -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8006 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 6a20ab8128..6d2a45a0ab 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,8 +1,8 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: @@ -18,7 +18,7 @@ separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index 7e1ec4fde7..21557a53d1 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -1,8 +1,8 @@ name: Windows Active Directory Admon id: 22bbf4e4-d313-43c1-98ee-808b8775519d -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ActiveDirectory supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Guid diff --git a/data_sources/windows_event_log_application_15457.yml b/data_sources/windows_event_log_application_15457.yml index 4ef6ecee00..e7ab6592db 100644 --- a/data_sources/windows_event_log_application_15457.yml +++ b/data_sources/windows_event_log_application_15457.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 15457 id: 4491537e-520c-46f7-9209-f56f852aa237 -version: 2 +version: 3 creation_date: '2025-02-25' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 15457 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_17135.yml b/data_sources/windows_event_log_application_17135.yml index fb960b1d42..7adcc433b1 100644 --- a/data_sources/windows_event_log_application_17135.yml +++ b/data_sources/windows_event_log_application_17135.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 17135 id: 4491537e-520c-46f7-9209-f56f852aa231 -version: 2 +version: 3 creation_date: '2025-02-25' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 17135 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index 9107707eaf..26f50ddeaf 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 2282 id: 4490537e-5e0c-46f7-9209-f56f852aa237 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index a98f34690b..ea4135b413 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: @@ -17,7 +17,7 @@ separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_8128.yml b/data_sources/windows_event_log_application_8128.yml index b45b9b50fa..513162f8aa 100644 --- a/data_sources/windows_event_log_application_8128.yml +++ b/data_sources/windows_event_log_application_8128.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 8128 id: 4491537e-5e0c-46f7-9209-f56f852aa237 -version: 2 +version: 3 creation_date: '2025-02-25' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 8128 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_400.yml b/data_sources/windows_event_log_appxdeployment_server_400.yml index 869197ab81..fa31f868e5 100644 --- a/data_sources/windows_event_log_appxdeployment_server_400.yml +++ b/data_sources/windows_event_log_appxdeployment_server_400.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 400 id: 3e5f9d2a-b8c7-4d1e-a6f3-7b9c8d5e4f2a -version: 2 +version: 3 creation_date: '2025-08-18' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 400. These events are generated when a package deployment operation begins, providing details about the package being deployed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_854.yml b/data_sources/windows_event_log_appxdeployment_server_854.yml index 792a15ebbc..0e14eec2a5 100644 --- a/data_sources/windows_event_log_appxdeployment_server_854.yml +++ b/data_sources/windows_event_log_appxdeployment_server_854.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 854 id: 4d2e6f8a-c9b7-5a3e-8d1f-2e9c7b5a4f3d -version: 2 +version: 3 creation_date: '2025-08-18' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 854. These events are generated when an MSIX/AppX package has been successfully installed on a system. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_855.yml b/data_sources/windows_event_log_appxdeployment_server_855.yml index 22e3b71725..3004c04f8a 100644 --- a/data_sources/windows_event_log_appxdeployment_server_855.yml +++ b/data_sources/windows_event_log_appxdeployment_server_855.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 855 id: 4491537c-521c-46f7-9209-f56f852aa231 -version: 2 +version: 3 creation_date: '2025-08-18' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 855. These events are generated when a package deployment operation completes successfully, providing details about the packages that were installed or updated. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxpackaging_171.yml b/data_sources/windows_event_log_appxpackaging_171.yml index 00920b4b37..a6148b83b9 100644 --- a/data_sources/windows_event_log_appxpackaging_171.yml +++ b/data_sources/windows_event_log_appxpackaging_171.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXPackaging 171 id: 2d0f8e3c-a2d7-4b9e-8f1c-6a5d7e3e9f2b -version: 2 +version: 3 creation_date: '2025-08-18' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXPackaging/Operational channel, specifically focusing on EventCode 171. These events are generated when a user clicks on or attempts to interact with an MSIX package, even if the package is not fully installed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 2701795166..5389b8c010 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: @@ -18,7 +18,7 @@ separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index f4e7771023..5a6e0d2df7 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 81 id: 463ff898-8135-4c0e-811e-f8629dfc5027 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index 14d92e22a7..d195462611 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -1,8 +1,8 @@ name: Windows Event Log CertificateServicesClient 1007 id: c51444e3-479d-4c4a-b111-e8276a3acf39 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index 011347afb2..b38cfc8cc3 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1121 id: 84a254c5-7900-4b52-a324-a176adb7c11d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index 9c97a01efe..45d66ac3a1 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1122 id: 4a2d0499-f489-4557-82f4-f357025cf3e7 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1125.yml b/data_sources/windows_event_log_defender_1125.yml index 77928d8273..43724aba19 100644 --- a/data_sources/windows_event_log_defender_1125.yml +++ b/data_sources/windows_event_log_defender_1125.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1125 id: 0cddda76-6fd8-4fb6-9026-f23a2761c95d -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1125 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time example_log: 112204000x80000000000000003701Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender Antivirus4.18.23100.2009E6DB77E5-3DF2-4CF1-B95A-636979351E5B2023-11-26T23:43:08.709Z(unknown user)C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1.401.1247.01.1.23100.2009ENT\ConsRC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x00000000 diff --git a/data_sources/windows_event_log_defender_1126.yml b/data_sources/windows_event_log_defender_1126.yml index b0b5c2cef0..5e81cab693 100644 --- a/data_sources/windows_event_log_defender_1126.yml +++ b/data_sources/windows_event_log_defender_1126.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1126 id: c1c6284b-b663-4001-bdf2-c0cacee22a2a -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1126 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index 8d9767ba9c..c744c85074 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1129 id: 0572e119-a48a-4c70-bc58-90e453edacd2 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_defender_1131.yml b/data_sources/windows_event_log_defender_1131.yml index 7b59c9cd6b..1babca257c 100644 --- a/data_sources/windows_event_log_defender_1131.yml +++ b/data_sources/windows_event_log_defender_1131.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1131 id: 638f884e-439a-4328-923c-ec5a2679f450 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1131 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1132.yml b/data_sources/windows_event_log_defender_1132.yml index 1a813f46f9..88f817f8a3 100644 --- a/data_sources/windows_event_log_defender_1132.yml +++ b/data_sources/windows_event_log_defender_1132.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1132 id: 18f93f60-4eca-46e8-a29d-147e6451a34c -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1132 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1133.yml b/data_sources/windows_event_log_defender_1133.yml index 88cb4531d3..38bc7270c8 100644 --- a/data_sources/windows_event_log_defender_1133.yml +++ b/data_sources/windows_event_log_defender_1133.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1133 id: 63c97a9a-cc7f-46c5-b219-8be388666637 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1133 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1134.yml b/data_sources/windows_event_log_defender_1134.yml index 3b54c95906..5e142c4260 100644 --- a/data_sources/windows_event_log_defender_1134.yml +++ b/data_sources/windows_event_log_defender_1134.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1134 id: 26abac7d-d026-44e9-b1a3-13e3e11b232d -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1134 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index 882e7a7bd0..56a6bb41ad 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 5007 id: 27f18792-8d95-4871-8853-874b7faf023f -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when Windows Defender antimalware settings are modified. mitre_components: @@ -14,7 +14,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index 257bd4a5d4..ed8ae20a38 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_printservice_4909.yml b/data_sources/windows_event_log_printservice_4909.yml index 529620eb60..34e63e6a7d 100644 --- a/data_sources/windows_event_log_printservice_4909.yml +++ b/data_sources/windows_event_log_printservice_4909.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 4909 id: 4c00e353-18b8-4de6-896d-83bc5817dbaa -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Printservice 4909 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time example_log: '' diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index d952de1f7e..f86ef8b178 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: @@ -16,7 +16,7 @@ separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 6bd7d957fc..4f93b44453 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,8 +1,8 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index 3dbf23664f..ef7f00a7a2 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: @@ -15,7 +15,7 @@ separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index 8586c6984d..b021cec12d 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 3971f62bfc..e71b124be8 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 28e5d9fead..8efc3b6754 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4625 id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when an account fails to log on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index e8c1fb0efb..70a2f53280 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4627 id: e35c7b9a-b451-4084-95a5-43b7f8965cac -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index 6b8fa7d829..317381d704 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4648 id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account mitre_components: @@ -15,7 +15,7 @@ separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index c0dc0121e4..18d1a7a37d 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4662 id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it mitre_components: @@ -15,7 +15,7 @@ separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index f74d26c94a..0d0b74287d 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4663 id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer mitre_components: @@ -15,7 +15,7 @@ separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 280d7f8262..68e138ecbe 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index 642687b596..d1942d1deb 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4688 id: d195eb26-a81c-45ed-aeb3-25792e8a985a -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the creation of a new process mitre_components: @@ -16,7 +16,7 @@ configuration: Enabling Windows event log process command line logging via group supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - Caller_Domain - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index 3b4b6a9c06..9d6e6080b1 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4698 id: 32c06703-02d3-47ec-8856-b0dc3045866c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a new scheduled task is created mitre_components: @@ -15,7 +15,7 @@ separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index a80ed23a9b..20da4bd80d 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4699 id: 4727dead-d063-4333-9ddd-59823a416aff -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a scheduled task is deleted from the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4700.yml b/data_sources/windows_event_log_security_4700.yml index 4dc60cd9bd..1eeeb7130a 100644 --- a/data_sources/windows_event_log_security_4700.yml +++ b/data_sources/windows_event_log_security_4700.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4700 id: 89895c7b-2aba-41ca-ad12-8b6d290b5dde -version: 3 +version: 4 creation_date: '2025-03-11' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Steven Dick description: Data source object for Windows Event Log Security 4700 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - EventID example_log: 4700 0 0 12804 0 0x8020000000000000 344861 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin LeastPrivilege CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4702.yml b/data_sources/windows_event_log_security_4702.yml index 7184ff77e3..a5d4ddd7f0 100644 --- a/data_sources/windows_event_log_security_4702.yml +++ b/data_sources/windows_event_log_security_4702.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 -version: 3 +version: 4 creation_date: '2025-03-11' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 5c1d729155..75ef7bf90e 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4703 id: e256673b-16e8-4b74-b7aa-9eed6ce67072 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a token right is adjusted on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index 06b3adb988..f5617cab2a 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4719 id: 954033e6-dd05-4775-a1f2-1f19632f4420 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a system audit policy is modified on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index 31484a3587..8292197532 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4720 id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a new user account is created on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4723.yml b/data_sources/windows_event_log_security_4723.yml index 5105961915..16cc1763f9 100644 --- a/data_sources/windows_event_log_security_4723.yml +++ b/data_sources/windows_event_log_security_4723.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4723 id: df19b271-57c8-4f31-817a-6c5566985484 -version: 1 +version: 2 creation_date: '2026-06-15' -modification_date: '2026-06-15' +modification_date: '2026-07-08' author: Raven Tait, Splunk description: Logs an event when an attempt is made to change an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4723' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index 0b06b7823a..9df2d88826 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4724 id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when an attempt is made to reset an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index ca05c7b840..181863a0a6 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4725 id: 31fd887d-0d14-44cc-bb64-80063a9f2968 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a user account has been disabled in Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index 6ddc2aba57..e9f4ce1145 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4726 id: 0b56dcd7-0f72-4a05-9226-d6059781737b -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a user account is deleted from Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4727.yml b/data_sources/windows_event_log_security_4727.yml index 0aa2c2f0b7..911a1f0a75 100644 --- a/data_sources/windows_event_log_security_4727.yml +++ b/data_sources/windows_event_log_security_4727.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4727 id: 4d2078ab-36f5-447e-b7e4-474890b8040b -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4727 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4728.yml b/data_sources/windows_event_log_security_4728.yml index bcba79a79d..b722c93399 100644 --- a/data_sources/windows_event_log_security_4728.yml +++ b/data_sources/windows_event_log_security_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4728 id: c0cb4907-d715-41f2-a98a-4f4e75f248c1 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4728 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4730.yml b/data_sources/windows_event_log_security_4730.yml index 9487a6ac52..52214b0ea8 100644 --- a/data_sources/windows_event_log_security_4730.yml +++ b/data_sources/windows_event_log_security_4730.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4730 id: 126966ba-a17d-4194-882b-57d303aaf46d -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4730 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4731.yml b/data_sources/windows_event_log_security_4731.yml index 30f8bc23e8..fbbf85a995 100644 --- a/data_sources/windows_event_log_security_4731.yml +++ b/data_sources/windows_event_log_security_4731.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4731 id: 1bbc004e-a75e-4d94-a619-c5aaf5d11ed5 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4731 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index d95f852eb8..5c0f7c6095 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4732 id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a member is added to a security-enabled local group on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4737.yml b/data_sources/windows_event_log_security_4737.yml index f128bbfcc4..1bce97a8ad 100644 --- a/data_sources/windows_event_log_security_4737.yml +++ b/data_sources/windows_event_log_security_4737.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4737 id: 132fc609-17f0-4efd-8f7e-db12139c6690 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4737 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index fb6f1f3ca8..eccfa80690 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4738 id: cb85709b-101e-41a9-bb60-d2108f79dfbd -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index b0f6314703..baa3c88cd3 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4739 id: c1e0442a-8a97-405d-baf2-057c5d68cd9a -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index 7b643fb3d0..12d479d6f5 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4741 id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index eb26156fe9..6cba4f482e 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4742 id: ea830adf-5450-489a-bcdc-fb8d2cbe674c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4744.yml b/data_sources/windows_event_log_security_4744.yml index 216eb54d2c..7474a85350 100644 --- a/data_sources/windows_event_log_security_4744.yml +++ b/data_sources/windows_event_log_security_4744.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4744 id: 244e0bd4-00b0-4091-b8b4-9d435aca6ad8 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4744 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4749.yml b/data_sources/windows_event_log_security_4749.yml index 8b61381ede..2c6a0678e8 100644 --- a/data_sources/windows_event_log_security_4749.yml +++ b/data_sources/windows_event_log_security_4749.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4749 id: eb322056-01a3-4cd5-bc09-01140d33194a -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4749 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4754.yml b/data_sources/windows_event_log_security_4754.yml index 4dbe460a36..b2c903055b 100644 --- a/data_sources/windows_event_log_security_4754.yml +++ b/data_sources/windows_event_log_security_4754.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4754 id: 501a507e-3275-4c4b-9c44-53eecfeae487 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4754 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4756.yml b/data_sources/windows_event_log_security_4756.yml index c53348491f..c6dc944bbf 100644 --- a/data_sources/windows_event_log_security_4756.yml +++ b/data_sources/windows_event_log_security_4756.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4756 id: b0093058-0cb6-4c73-a95b-fb0f3541e88c -version: 2 +version: 3 creation_date: '2026-03-30' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Nasreddine Bencherchali, Splunk description: Data source object for Windows Event Log Security 4756 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4759.yml b/data_sources/windows_event_log_security_4759.yml index 9db0814db3..303431a86e 100644 --- a/data_sources/windows_event_log_security_4759.yml +++ b/data_sources/windows_event_log_security_4759.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4759 id: 431e3520-505b-4ace-aced-cb51e3f7311e -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4759 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index 0d954d3b5c..3460a3e401 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4768 id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index 2b1506eda9..4f3de666c6 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index 16751ea4ef..8ec36bc5a3 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4771 id: 418debbb-adf3-48ec-9efd-59d45f8861e5 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index 408aaa466b..a827c2661f 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4776 id: 1da9092a-c795-4a26-ace8-d43855524e96 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index ed8f3691a8..c0f950cc3b 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4783.yml b/data_sources/windows_event_log_security_4783.yml index 4b239b5056..b2f3d40071 100644 --- a/data_sources/windows_event_log_security_4783.yml +++ b/data_sources/windows_event_log_security_4783.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4783 id: 6b945150-785c-49a1-b705-56b42215630b -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4783 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4790.yml b/data_sources/windows_event_log_security_4790.yml index 8a945e0fe8..f23eea5a08 100644 --- a/data_sources/windows_event_log_security_4790.yml +++ b/data_sources/windows_event_log_security_4790.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4790 id: 1cc6ecbb-af04-432b-a224-02c65243ac88 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4790 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index 70bae43f05..b686f9b1b1 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4794 id: ec7da74f-274a-4bde-aa0e-15c68aca0426 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index 8eebe0e5a9..7844bd7c3c 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4798 id: 29e97f72-eb2e-400e-b0c9-81277547e43b -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index bdd7735a81..16d99f96c1 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4876 id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index 9379641c7d..dbb3c03ec4 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index 2016e280f6..25ff5dab88 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4887 id: 994c7b19-a623-4231-9818-f00e453b9a75 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4946.yml b/data_sources/windows_event_log_security_4946.yml index 2d9e806305..33d09cc53d 100644 --- a/data_sources/windows_event_log_security_4946.yml +++ b/data_sources/windows_event_log_security_4946.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4946 id: d7dafd01-a22d-4b05-b793-7571ef1fa789 -version: 3 +version: 4 creation_date: '2025-03-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4946 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4946' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4947.yml b/data_sources/windows_event_log_security_4947.yml index b10ef8870b..5f1d9b8048 100644 --- a/data_sources/windows_event_log_security_4947.yml +++ b/data_sources/windows_event_log_security_4947.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4947 id: 63d4a2fa-a7dc-46d2-b702-54794e1f4d3c -version: 3 +version: 4 creation_date: '2025-03-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4947 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4947' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4948.yml b/data_sources/windows_event_log_security_4948.yml index 961be864ee..bbf504d371 100644 --- a/data_sources/windows_event_log_security_4948.yml +++ b/data_sources/windows_event_log_security_4948.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4948 id: 910032df-4e49-42fe-a611-d4c29557d83a -version: 3 +version: 4 creation_date: '2025-03-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4948 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4948' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index b2035008e4..93ae642867 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5136 id: 7ba3737e-231e-455d-824e-cd077749f835 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index 253ce10397..b36bae7bff 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AppCorrelationID diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index f5f3cf1116..4f998e5ec2 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index 393098f288..e413b3d87a 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5141 id: eafb35fa-f034-4be3-8508-d9173a73c0a1 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 1647d2e832..e8cda60333 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_system_104.yml b/data_sources/windows_event_log_system_104.yml index faea29ccad..64e29fb193 100644 --- a/data_sources/windows_event_log_system_104.yml +++ b/data_sources/windows_event_log_system_104.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 104 id: 577b9b41-6b37-44c4-9016-3d890b909050 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log System 104 source: XmlWinEventLog:System @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index 49df88f658..d6e84e8786 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4720 id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 642359a985..014245216e 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4726 id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index dd3e3849ea..2b5a3626da 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index 0cf395b1d2..499335100a 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7036 id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). mitre_components: @@ -17,7 +17,7 @@ separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 518d67eacf..bd23a43f73 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index a1fda46fe8..298c49eacb 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - AccountName diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index e7fe0ff722..33d4d43917 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ActionName diff --git a/data_sources/windows_event_log_taskscheduler_201.yml b/data_sources/windows_event_log_taskscheduler_201.yml index 01ff84004b..714a132def 100644 --- a/data_sources/windows_event_log_taskscheduler_201.yml +++ b/data_sources/windows_event_log_taskscheduler_201.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 201 id: 4c09ae64-01cd-4b65-8221-20f803b0d86e -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log TaskScheduler 201 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time output_fields: diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index a3412a3b42..c979d0b125 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -1,8 +1,8 @@ name: Windows IIS id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. mitre_components: @@ -16,4 +16,4 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index 8c6977fd3a..c48ee8e61d 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -1,8 +1,8 @@ name: Windows IIS 29 id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-08' author: Patrick Bareiss, Splunk description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. mitre_components: @@ -17,7 +17,7 @@ separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 10.1.0 fields: - _time - ComputerName From 8ed8feab85ea1d4feaa60504334118c8e0d3855f Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Thu, 9 Jul 2026 11:54:14 +0000 Subject: [PATCH 08/32] Update datasource TA versions --- data_sources/linux_auditd_add_user.yml | 6 +++--- data_sources/linux_auditd_cwd.yml | 6 +++--- data_sources/linux_auditd_daemon_abort.yml | 6 +++--- data_sources/linux_auditd_daemon_end.yml | 6 +++--- data_sources/linux_auditd_daemon_start.yml | 6 +++--- data_sources/linux_auditd_execve.yml | 6 +++--- data_sources/linux_auditd_path.yml | 6 +++--- data_sources/linux_auditd_proctitle.yml | 6 +++--- data_sources/linux_auditd_service_stop.yml | 6 +++--- data_sources/linux_auditd_syscall.yml | 6 +++--- data_sources/linux_messages_syslog.yml | 6 +++--- data_sources/linux_secure.yml | 6 +++--- data_sources/ntlm_operational_8004.yml | 6 +++--- data_sources/ntlm_operational_8005.yml | 6 +++--- data_sources/ntlm_operational_8006.yml | 6 +++--- data_sources/powershell_script_block_logging_4104.yml | 6 +++--- data_sources/windows_active_directory_admon.yml | 6 +++--- data_sources/windows_event_log_application_15457.yml | 6 +++--- data_sources/windows_event_log_application_17135.yml | 6 +++--- data_sources/windows_event_log_application_2282.yml | 6 +++--- data_sources/windows_event_log_application_3000.yml | 6 +++--- data_sources/windows_event_log_application_8128.yml | 6 +++--- .../windows_event_log_appxdeployment_server_400.yml | 6 +++--- .../windows_event_log_appxdeployment_server_854.yml | 6 +++--- .../windows_event_log_appxdeployment_server_855.yml | 6 +++--- data_sources/windows_event_log_appxpackaging_171.yml | 6 +++--- data_sources/windows_event_log_capi2_70.yml | 6 +++--- data_sources/windows_event_log_capi2_81.yml | 6 +++--- .../windows_event_log_certificateservicesclient_1007.yml | 6 +++--- data_sources/windows_event_log_defender_1121.yml | 6 +++--- data_sources/windows_event_log_defender_1122.yml | 6 +++--- data_sources/windows_event_log_defender_1125.yml | 6 +++--- data_sources/windows_event_log_defender_1126.yml | 6 +++--- data_sources/windows_event_log_defender_1129.yml | 6 +++--- data_sources/windows_event_log_defender_1131.yml | 6 +++--- data_sources/windows_event_log_defender_1132.yml | 6 +++--- data_sources/windows_event_log_defender_1133.yml | 6 +++--- data_sources/windows_event_log_defender_1134.yml | 6 +++--- data_sources/windows_event_log_defender_5007.yml | 6 +++--- data_sources/windows_event_log_printservice_316.yml | 6 +++--- data_sources/windows_event_log_printservice_4909.yml | 6 +++--- data_sources/windows_event_log_printservice_808.yml | 6 +++--- .../windows_event_log_remoteconnectionmanager_1149.yml | 6 +++--- data_sources/windows_event_log_security_1100.yml | 6 +++--- data_sources/windows_event_log_security_1102.yml | 6 +++--- data_sources/windows_event_log_security_4624.yml | 6 +++--- data_sources/windows_event_log_security_4625.yml | 6 +++--- data_sources/windows_event_log_security_4627.yml | 6 +++--- data_sources/windows_event_log_security_4648.yml | 6 +++--- data_sources/windows_event_log_security_4662.yml | 6 +++--- data_sources/windows_event_log_security_4663.yml | 6 +++--- data_sources/windows_event_log_security_4672.yml | 6 +++--- data_sources/windows_event_log_security_4688.yml | 6 +++--- data_sources/windows_event_log_security_4698.yml | 6 +++--- data_sources/windows_event_log_security_4699.yml | 6 +++--- data_sources/windows_event_log_security_4700.yml | 6 +++--- data_sources/windows_event_log_security_4702.yml | 6 +++--- data_sources/windows_event_log_security_4703.yml | 6 +++--- data_sources/windows_event_log_security_4719.yml | 6 +++--- data_sources/windows_event_log_security_4720.yml | 6 +++--- data_sources/windows_event_log_security_4723.yml | 6 +++--- data_sources/windows_event_log_security_4724.yml | 6 +++--- data_sources/windows_event_log_security_4725.yml | 6 +++--- data_sources/windows_event_log_security_4726.yml | 6 +++--- data_sources/windows_event_log_security_4727.yml | 6 +++--- data_sources/windows_event_log_security_4728.yml | 6 +++--- data_sources/windows_event_log_security_4730.yml | 6 +++--- data_sources/windows_event_log_security_4731.yml | 6 +++--- data_sources/windows_event_log_security_4732.yml | 6 +++--- data_sources/windows_event_log_security_4737.yml | 6 +++--- data_sources/windows_event_log_security_4738.yml | 6 +++--- data_sources/windows_event_log_security_4739.yml | 6 +++--- data_sources/windows_event_log_security_4741.yml | 6 +++--- data_sources/windows_event_log_security_4742.yml | 6 +++--- data_sources/windows_event_log_security_4744.yml | 6 +++--- data_sources/windows_event_log_security_4749.yml | 6 +++--- data_sources/windows_event_log_security_4754.yml | 6 +++--- data_sources/windows_event_log_security_4756.yml | 6 +++--- data_sources/windows_event_log_security_4759.yml | 6 +++--- data_sources/windows_event_log_security_4768.yml | 6 +++--- data_sources/windows_event_log_security_4769.yml | 6 +++--- data_sources/windows_event_log_security_4771.yml | 6 +++--- data_sources/windows_event_log_security_4776.yml | 6 +++--- data_sources/windows_event_log_security_4781.yml | 6 +++--- data_sources/windows_event_log_security_4783.yml | 6 +++--- data_sources/windows_event_log_security_4790.yml | 6 +++--- data_sources/windows_event_log_security_4794.yml | 6 +++--- data_sources/windows_event_log_security_4798.yml | 6 +++--- data_sources/windows_event_log_security_4876.yml | 6 +++--- data_sources/windows_event_log_security_4886.yml | 6 +++--- data_sources/windows_event_log_security_4887.yml | 6 +++--- data_sources/windows_event_log_security_4946.yml | 6 +++--- data_sources/windows_event_log_security_4947.yml | 6 +++--- data_sources/windows_event_log_security_4948.yml | 6 +++--- data_sources/windows_event_log_security_5136.yml | 6 +++--- data_sources/windows_event_log_security_5137.yml | 6 +++--- data_sources/windows_event_log_security_5140.yml | 6 +++--- data_sources/windows_event_log_security_5141.yml | 6 +++--- data_sources/windows_event_log_security_5145.yml | 6 +++--- data_sources/windows_event_log_system_104.yml | 6 +++--- data_sources/windows_event_log_system_4720.yml | 6 +++--- data_sources/windows_event_log_system_4726.yml | 6 +++--- data_sources/windows_event_log_system_4728.yml | 6 +++--- data_sources/windows_event_log_system_7036.yml | 6 +++--- data_sources/windows_event_log_system_7040.yml | 6 +++--- data_sources/windows_event_log_system_7045.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_200.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_201.yml | 6 +++--- data_sources/windows_iis.yml | 6 +++--- data_sources/windows_iis_29.yml | 6 +++--- 110 files changed, 330 insertions(+), 330 deletions(-) diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index 2a590b14a4..0ab54a3a49 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -1,8 +1,8 @@ name: Linux Auditd Add User id: 30f79353-e1d2-4585-8735-1e0359559f3f -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - msg - type diff --git a/data_sources/linux_auditd_cwd.yml b/data_sources/linux_auditd_cwd.yml index ebd48529c9..43f6ced21f 100644 --- a/data_sources/linux_auditd_cwd.yml +++ b/data_sources/linux_auditd_cwd.yml @@ -1,8 +1,8 @@ name: Linux Auditd Cwd id: a9ef851b-d864-478b-b1b3-76535d7ff7fc -version: 3 +version: 4 creation_date: '2025-12-02' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Nasreddine Bencherchali, Splunk description: This type is used to record the working directory from which the process that invoked the system call specified in the first record was executed. The purpose of this record is to record the current process's location in case a relative path winds up being captured in the associated PATH record. This way the absolute path can be reconstructed. source: auditd @@ -13,7 +13,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - cwd - date_hour diff --git a/data_sources/linux_auditd_daemon_abort.yml b/data_sources/linux_auditd_daemon_abort.yml index 983f143a5b..6e4f417599 100644 --- a/data_sources/linux_auditd_daemon_abort.yml +++ b/data_sources/linux_auditd_daemon_abort.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Abort id: cc8b3bb0-0fae-4236-9c61-fe2d7138bd63 -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_end.yml b/data_sources/linux_auditd_daemon_end.yml index 37c18b161a..bc8354e256 100644 --- a/data_sources/linux_auditd_daemon_end.yml +++ b/data_sources/linux_auditd_daemon_end.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon End id: 15135c45-e302-4d5a-a38a-3e8279f2ebd8 -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_start.yml b/data_sources/linux_auditd_daemon_start.yml index 5af1eac5bf..686fb15ba9 100644 --- a/data_sources/linux_auditd_daemon_start.yml +++ b/data_sources/linux_auditd_daemon_start.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Start id: f1b97407-ddf0-41a5-8685-ada05aae3555 -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - type - op diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 2eebe98500..022387f57e 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -1,8 +1,8 @@ name: Linux Auditd Execve id: 9ef6364d-cc67-480e-8448-3306829a6a24 -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - msg - type diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index 0368fa9ebe..83185d152c 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -1,8 +1,8 @@ name: Linux Auditd Path id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - msg - type diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index 229dd55572..00ce2b4f65 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -1,8 +1,8 @@ name: Linux Auditd Proctitle id: 5a25984a-2789-400a-858b-d75c923e06b1 -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - proctitle - msg diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index 104d53d16f..4be8b93396 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -1,8 +1,8 @@ name: Linux Auditd Service Stop id: 0643483c-bc62-455c-8d6e-1630e5f0e00d -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - msg - type diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index 4b7294673e..e6ac3135d3 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -1,8 +1,8 @@ name: Linux Auditd Syscall id: 4dff7047-0d43-4096-bb3f-b756c889bbad -version: 4 +version: 5 creation_date: '2024-08-08' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - msg - type diff --git a/data_sources/linux_messages_syslog.yml b/data_sources/linux_messages_syslog.yml index 14ae9328e9..52b3bc98d2 100644 --- a/data_sources/linux_messages_syslog.yml +++ b/data_sources/linux_messages_syslog.yml @@ -1,8 +1,8 @@ name: Linux Messages Syslog id: c9e3bbb5-e0a2-4bac-8457-227e71841bda -version: 2 +version: 3 creation_date: '2025-05-06' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Ravent Tait, Splunk description: Logs kernel events on a Linux system, including service starts/stops, hardware events, authentication notices, and other OS-level activity. @@ -16,7 +16,7 @@ sourcetype: linux_messages_syslog supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - _time - action diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index d184209af7..85811d0cfe 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -1,8 +1,8 @@ name: Linux Secure id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. mitre_components: @@ -16,7 +16,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.0 + version: 10.3.1 fields: - _time - action diff --git a/data_sources/ntlm_operational_8004.yml b/data_sources/ntlm_operational_8004.yml index 0b02c924f0..dbccc351f2 100644 --- a/data_sources/ntlm_operational_8004.yml +++ b/data_sources/ntlm_operational_8004.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8004 id: fd08cb77-c26e-464c-a43e-2867e232127e -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8004 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8005.yml b/data_sources/ntlm_operational_8005.yml index b96c7b9cc3..1117117dce 100644 --- a/data_sources/ntlm_operational_8005.yml +++ b/data_sources/ntlm_operational_8005.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8005 id: ad15a1cf-4b21-43de-81e4-6307c69172fb -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8005 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8006.yml b/data_sources/ntlm_operational_8006.yml index 13c04e7822..5c8d1b96f7 100644 --- a/data_sources/ntlm_operational_8006.yml +++ b/data_sources/ntlm_operational_8006.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8006 id: 9f50a672-6f7d-4621-a3bd-69468c6b7a7f -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8006 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 6d2a45a0ab..70d01b44d8 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,8 +1,8 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: @@ -18,7 +18,7 @@ separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index 21557a53d1..ed5ec2455f 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -1,8 +1,8 @@ name: Windows Active Directory Admon id: 22bbf4e4-d313-43c1-98ee-808b8775519d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ActiveDirectory supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Guid diff --git a/data_sources/windows_event_log_application_15457.yml b/data_sources/windows_event_log_application_15457.yml index e7ab6592db..2a411551b1 100644 --- a/data_sources/windows_event_log_application_15457.yml +++ b/data_sources/windows_event_log_application_15457.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 15457 id: 4491537e-520c-46f7-9209-f56f852aa237 -version: 3 +version: 4 creation_date: '2025-02-25' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 15457 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_17135.yml b/data_sources/windows_event_log_application_17135.yml index 7adcc433b1..b0ee4676ff 100644 --- a/data_sources/windows_event_log_application_17135.yml +++ b/data_sources/windows_event_log_application_17135.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 17135 id: 4491537e-520c-46f7-9209-f56f852aa231 -version: 3 +version: 4 creation_date: '2025-02-25' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 17135 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index 26f50ddeaf..97975c40c2 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 2282 id: 4490537e-5e0c-46f7-9209-f56f852aa237 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index ea4135b413..76d8b09e7e 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: @@ -17,7 +17,7 @@ separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_8128.yml b/data_sources/windows_event_log_application_8128.yml index 513162f8aa..178140c103 100644 --- a/data_sources/windows_event_log_application_8128.yml +++ b/data_sources/windows_event_log_application_8128.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 8128 id: 4491537e-5e0c-46f7-9209-f56f852aa237 -version: 3 +version: 4 creation_date: '2025-02-25' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 8128 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_400.yml b/data_sources/windows_event_log_appxdeployment_server_400.yml index fa31f868e5..cbd5df74e6 100644 --- a/data_sources/windows_event_log_appxdeployment_server_400.yml +++ b/data_sources/windows_event_log_appxdeployment_server_400.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 400 id: 3e5f9d2a-b8c7-4d1e-a6f3-7b9c8d5e4f2a -version: 3 +version: 4 creation_date: '2025-08-18' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 400. These events are generated when a package deployment operation begins, providing details about the package being deployed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_854.yml b/data_sources/windows_event_log_appxdeployment_server_854.yml index 0e14eec2a5..04859a7601 100644 --- a/data_sources/windows_event_log_appxdeployment_server_854.yml +++ b/data_sources/windows_event_log_appxdeployment_server_854.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 854 id: 4d2e6f8a-c9b7-5a3e-8d1f-2e9c7b5a4f3d -version: 3 +version: 4 creation_date: '2025-08-18' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 854. These events are generated when an MSIX/AppX package has been successfully installed on a system. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_855.yml b/data_sources/windows_event_log_appxdeployment_server_855.yml index 3004c04f8a..d5856f19a1 100644 --- a/data_sources/windows_event_log_appxdeployment_server_855.yml +++ b/data_sources/windows_event_log_appxdeployment_server_855.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 855 id: 4491537c-521c-46f7-9209-f56f852aa231 -version: 3 +version: 4 creation_date: '2025-08-18' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 855. These events are generated when a package deployment operation completes successfully, providing details about the packages that were installed or updated. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxpackaging_171.yml b/data_sources/windows_event_log_appxpackaging_171.yml index a6148b83b9..ad3bb1c1b8 100644 --- a/data_sources/windows_event_log_appxpackaging_171.yml +++ b/data_sources/windows_event_log_appxpackaging_171.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXPackaging 171 id: 2d0f8e3c-a2d7-4b9e-8f1c-6a5d7e3e9f2b -version: 3 +version: 4 creation_date: '2025-08-18' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXPackaging/Operational channel, specifically focusing on EventCode 171. These events are generated when a user clicks on or attempts to interact with an MSIX package, even if the package is not fully installed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 5389b8c010..7c0fb1cec9 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: @@ -18,7 +18,7 @@ separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index 5a6e0d2df7..dafe5f47e3 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 81 id: 463ff898-8135-4c0e-811e-f8629dfc5027 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index d195462611..185d48ba7e 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -1,8 +1,8 @@ name: Windows Event Log CertificateServicesClient 1007 id: c51444e3-479d-4c4a-b111-e8276a3acf39 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index b38cfc8cc3..942f72411f 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1121 id: 84a254c5-7900-4b52-a324-a176adb7c11d -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index 45d66ac3a1..aa0d7d40ef 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1122 id: 4a2d0499-f489-4557-82f4-f357025cf3e7 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1125.yml b/data_sources/windows_event_log_defender_1125.yml index 43724aba19..dfcdc11be7 100644 --- a/data_sources/windows_event_log_defender_1125.yml +++ b/data_sources/windows_event_log_defender_1125.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1125 id: 0cddda76-6fd8-4fb6-9026-f23a2761c95d -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1125 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time example_log: 112204000x80000000000000003701Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender Antivirus4.18.23100.2009E6DB77E5-3DF2-4CF1-B95A-636979351E5B2023-11-26T23:43:08.709Z(unknown user)C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1.401.1247.01.1.23100.2009ENT\ConsRC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x00000000 diff --git a/data_sources/windows_event_log_defender_1126.yml b/data_sources/windows_event_log_defender_1126.yml index 5e81cab693..5cc303b04f 100644 --- a/data_sources/windows_event_log_defender_1126.yml +++ b/data_sources/windows_event_log_defender_1126.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1126 id: c1c6284b-b663-4001-bdf2-c0cacee22a2a -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1126 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index c744c85074..4fc5a5289d 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1129 id: 0572e119-a48a-4c70-bc58-90e453edacd2 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_defender_1131.yml b/data_sources/windows_event_log_defender_1131.yml index 1babca257c..cc4d6bf89b 100644 --- a/data_sources/windows_event_log_defender_1131.yml +++ b/data_sources/windows_event_log_defender_1131.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1131 id: 638f884e-439a-4328-923c-ec5a2679f450 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1131 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1132.yml b/data_sources/windows_event_log_defender_1132.yml index 88f817f8a3..fd0c92f136 100644 --- a/data_sources/windows_event_log_defender_1132.yml +++ b/data_sources/windows_event_log_defender_1132.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1132 id: 18f93f60-4eca-46e8-a29d-147e6451a34c -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1132 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1133.yml b/data_sources/windows_event_log_defender_1133.yml index 38bc7270c8..42785c454a 100644 --- a/data_sources/windows_event_log_defender_1133.yml +++ b/data_sources/windows_event_log_defender_1133.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1133 id: 63c97a9a-cc7f-46c5-b219-8be388666637 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1133 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1134.yml b/data_sources/windows_event_log_defender_1134.yml index 5e142c4260..347e09bb73 100644 --- a/data_sources/windows_event_log_defender_1134.yml +++ b/data_sources/windows_event_log_defender_1134.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1134 id: 26abac7d-d026-44e9-b1a3-13e3e11b232d -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1134 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index 56a6bb41ad..2e2da74db8 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 5007 id: 27f18792-8d95-4871-8853-874b7faf023f -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when Windows Defender antimalware settings are modified. mitre_components: @@ -14,7 +14,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index ed8ae20a38..e75bfd0869 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_printservice_4909.yml b/data_sources/windows_event_log_printservice_4909.yml index 34e63e6a7d..9181e429c7 100644 --- a/data_sources/windows_event_log_printservice_4909.yml +++ b/data_sources/windows_event_log_printservice_4909.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 4909 id: 4c00e353-18b8-4de6-896d-83bc5817dbaa -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Printservice 4909 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time example_log: '' diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index f86ef8b178..b3e0f9eb4d 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: @@ -16,7 +16,7 @@ separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 4f93b44453..f25fbf6088 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,8 +1,8 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index ef7f00a7a2..0b92196127 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: @@ -15,7 +15,7 @@ separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index b021cec12d..28049f6bb5 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index e71b124be8..02a568dc82 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 8efc3b6754..0f8e828830 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4625 id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when an account fails to log on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index 70a2f53280..eb3105c2fe 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4627 id: e35c7b9a-b451-4084-95a5-43b7f8965cac -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index 317381d704..ffe53ac16d 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4648 id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account mitre_components: @@ -15,7 +15,7 @@ separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index 18d1a7a37d..ff6f24e77e 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4662 id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it mitre_components: @@ -15,7 +15,7 @@ separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index 0d0b74287d..cc7343e6be 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4663 id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer mitre_components: @@ -15,7 +15,7 @@ separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 68e138ecbe..690f6574d2 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index d1942d1deb..5cd7ca5404 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4688 id: d195eb26-a81c-45ed-aeb3-25792e8a985a -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the creation of a new process mitre_components: @@ -16,7 +16,7 @@ configuration: Enabling Windows event log process command line logging via group supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - Caller_Domain - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index 9d6e6080b1..711f75a4fe 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4698 id: 32c06703-02d3-47ec-8856-b0dc3045866c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a new scheduled task is created mitre_components: @@ -15,7 +15,7 @@ separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index 20da4bd80d..7b8bf5a9c8 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4699 id: 4727dead-d063-4333-9ddd-59823a416aff -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a scheduled task is deleted from the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4700.yml b/data_sources/windows_event_log_security_4700.yml index 1eeeb7130a..c481ce6fea 100644 --- a/data_sources/windows_event_log_security_4700.yml +++ b/data_sources/windows_event_log_security_4700.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4700 id: 89895c7b-2aba-41ca-ad12-8b6d290b5dde -version: 4 +version: 5 creation_date: '2025-03-11' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Steven Dick description: Data source object for Windows Event Log Security 4700 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - EventID example_log: 4700 0 0 12804 0 0x8020000000000000 344861 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin LeastPrivilege CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4702.yml b/data_sources/windows_event_log_security_4702.yml index a5d4ddd7f0..8330ac843e 100644 --- a/data_sources/windows_event_log_security_4702.yml +++ b/data_sources/windows_event_log_security_4702.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 -version: 4 +version: 5 creation_date: '2025-03-11' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 75ef7bf90e..7c4c8aa4e6 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4703 id: e256673b-16e8-4b74-b7aa-9eed6ce67072 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a token right is adjusted on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index f5617cab2a..40ed628e22 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4719 id: 954033e6-dd05-4775-a1f2-1f19632f4420 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a system audit policy is modified on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index 8292197532..806ea95994 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4720 id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a new user account is created on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4723.yml b/data_sources/windows_event_log_security_4723.yml index 16cc1763f9..f0bee2be18 100644 --- a/data_sources/windows_event_log_security_4723.yml +++ b/data_sources/windows_event_log_security_4723.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4723 id: df19b271-57c8-4f31-817a-6c5566985484 -version: 2 +version: 3 creation_date: '2026-06-15' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Raven Tait, Splunk description: Logs an event when an attempt is made to change an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4723' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index 9df2d88826..ca731a9a4d 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4724 id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when an attempt is made to reset an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index 181863a0a6..44493db4b1 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4725 id: 31fd887d-0d14-44cc-bb64-80063a9f2968 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a user account has been disabled in Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index e9f4ce1145..63e2a2e051 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4726 id: 0b56dcd7-0f72-4a05-9226-d6059781737b -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a user account is deleted from Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4727.yml b/data_sources/windows_event_log_security_4727.yml index 911a1f0a75..79157829b0 100644 --- a/data_sources/windows_event_log_security_4727.yml +++ b/data_sources/windows_event_log_security_4727.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4727 id: 4d2078ab-36f5-447e-b7e4-474890b8040b -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4727 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4728.yml b/data_sources/windows_event_log_security_4728.yml index b722c93399..fee1e2ba28 100644 --- a/data_sources/windows_event_log_security_4728.yml +++ b/data_sources/windows_event_log_security_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4728 id: c0cb4907-d715-41f2-a98a-4f4e75f248c1 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4728 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4730.yml b/data_sources/windows_event_log_security_4730.yml index 52214b0ea8..04b66ccda5 100644 --- a/data_sources/windows_event_log_security_4730.yml +++ b/data_sources/windows_event_log_security_4730.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4730 id: 126966ba-a17d-4194-882b-57d303aaf46d -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4730 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4731.yml b/data_sources/windows_event_log_security_4731.yml index fbbf85a995..bb71e8ad83 100644 --- a/data_sources/windows_event_log_security_4731.yml +++ b/data_sources/windows_event_log_security_4731.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4731 id: 1bbc004e-a75e-4d94-a619-c5aaf5d11ed5 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4731 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index 5c0f7c6095..c7c04625da 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4732 id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a member is added to a security-enabled local group on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4737.yml b/data_sources/windows_event_log_security_4737.yml index 1bce97a8ad..b1f5a09487 100644 --- a/data_sources/windows_event_log_security_4737.yml +++ b/data_sources/windows_event_log_security_4737.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4737 id: 132fc609-17f0-4efd-8f7e-db12139c6690 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4737 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index eccfa80690..4352ec2687 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4738 id: cb85709b-101e-41a9-bb60-d2108f79dfbd -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index baa3c88cd3..93021d1a3b 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4739 id: c1e0442a-8a97-405d-baf2-057c5d68cd9a -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index 12d479d6f5..fdb0965278 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4741 id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index 6cba4f482e..583f432381 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4742 id: ea830adf-5450-489a-bcdc-fb8d2cbe674c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4744.yml b/data_sources/windows_event_log_security_4744.yml index 7474a85350..c2b8df0f9b 100644 --- a/data_sources/windows_event_log_security_4744.yml +++ b/data_sources/windows_event_log_security_4744.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4744 id: 244e0bd4-00b0-4091-b8b4-9d435aca6ad8 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4744 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4749.yml b/data_sources/windows_event_log_security_4749.yml index 2c6a0678e8..3c11cc4ebd 100644 --- a/data_sources/windows_event_log_security_4749.yml +++ b/data_sources/windows_event_log_security_4749.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4749 id: eb322056-01a3-4cd5-bc09-01140d33194a -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4749 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4754.yml b/data_sources/windows_event_log_security_4754.yml index b2c903055b..b06e47374a 100644 --- a/data_sources/windows_event_log_security_4754.yml +++ b/data_sources/windows_event_log_security_4754.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4754 id: 501a507e-3275-4c4b-9c44-53eecfeae487 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4754 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4756.yml b/data_sources/windows_event_log_security_4756.yml index c6dc944bbf..1f9df9e69e 100644 --- a/data_sources/windows_event_log_security_4756.yml +++ b/data_sources/windows_event_log_security_4756.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4756 id: b0093058-0cb6-4c73-a95b-fb0f3541e88c -version: 3 +version: 4 creation_date: '2026-03-30' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Nasreddine Bencherchali, Splunk description: Data source object for Windows Event Log Security 4756 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4759.yml b/data_sources/windows_event_log_security_4759.yml index 303431a86e..c46f1dfe69 100644 --- a/data_sources/windows_event_log_security_4759.yml +++ b/data_sources/windows_event_log_security_4759.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4759 id: 431e3520-505b-4ace-aced-cb51e3f7311e -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4759 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index 3460a3e401..59ffa510c1 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4768 id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index 4f3de666c6..4cca5368c3 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index 8ec36bc5a3..5bf91c3397 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4771 id: 418debbb-adf3-48ec-9efd-59d45f8861e5 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index a827c2661f..92f613562b 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4776 id: 1da9092a-c795-4a26-ace8-d43855524e96 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index c0f950cc3b..862d436a12 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4783.yml b/data_sources/windows_event_log_security_4783.yml index b2f3d40071..fed9070c8d 100644 --- a/data_sources/windows_event_log_security_4783.yml +++ b/data_sources/windows_event_log_security_4783.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4783 id: 6b945150-785c-49a1-b705-56b42215630b -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4783 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4790.yml b/data_sources/windows_event_log_security_4790.yml index f23eea5a08..d91ba1001a 100644 --- a/data_sources/windows_event_log_security_4790.yml +++ b/data_sources/windows_event_log_security_4790.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4790 id: 1cc6ecbb-af04-432b-a224-02c65243ac88 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4790 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index b686f9b1b1..01478f91d6 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4794 id: ec7da74f-274a-4bde-aa0e-15c68aca0426 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index 7844bd7c3c..9cdbe23c7e 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4798 id: 29e97f72-eb2e-400e-b0c9-81277547e43b -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index 16d99f96c1..632f4d751e 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4876 id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index dbb3c03ec4..2d41b87255 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index 25ff5dab88..e199abbcff 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4887 id: 994c7b19-a623-4231-9818-f00e453b9a75 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4946.yml b/data_sources/windows_event_log_security_4946.yml index 33d09cc53d..29a8ee27b8 100644 --- a/data_sources/windows_event_log_security_4946.yml +++ b/data_sources/windows_event_log_security_4946.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4946 id: d7dafd01-a22d-4b05-b793-7571ef1fa789 -version: 4 +version: 5 creation_date: '2025-03-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4946 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4946' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4947.yml b/data_sources/windows_event_log_security_4947.yml index 5f1d9b8048..1592a39217 100644 --- a/data_sources/windows_event_log_security_4947.yml +++ b/data_sources/windows_event_log_security_4947.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4947 id: 63d4a2fa-a7dc-46d2-b702-54794e1f4d3c -version: 4 +version: 5 creation_date: '2025-03-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4947 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4947' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4948.yml b/data_sources/windows_event_log_security_4948.yml index bbf504d371..9454a0bf7e 100644 --- a/data_sources/windows_event_log_security_4948.yml +++ b/data_sources/windows_event_log_security_4948.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4948 id: 910032df-4e49-42fe-a611-d4c29557d83a -version: 4 +version: 5 creation_date: '2025-03-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4948 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4948' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index 93ae642867..e10584b1cc 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5136 id: 7ba3737e-231e-455d-824e-cd077749f835 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index b36bae7bff..76e411d753 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AppCorrelationID diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index 4f998e5ec2..b78d356eb5 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index e413b3d87a..ac75647a7b 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5141 id: eafb35fa-f034-4be3-8508-d9173a73c0a1 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index e8cda60333..049e447d03 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_system_104.yml b/data_sources/windows_event_log_system_104.yml index 64e29fb193..d91ccc3cf8 100644 --- a/data_sources/windows_event_log_system_104.yml +++ b/data_sources/windows_event_log_system_104.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 104 id: 577b9b41-6b37-44c4-9016-3d890b909050 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log System 104 source: XmlWinEventLog:System @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index d6e84e8786..f359df765e 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4720 id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 014245216e..9886c8cf59 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4726 id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index 2b5a3626da..d3d5267324 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index 499335100a..30b3edad3b 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7036 id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). mitre_components: @@ -17,7 +17,7 @@ separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index bd23a43f73..44f76d3651 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index 298c49eacb..e150941521 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - AccountName diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index 33d4d43917..acbffe0aa1 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ActionName diff --git a/data_sources/windows_event_log_taskscheduler_201.yml b/data_sources/windows_event_log_taskscheduler_201.yml index 714a132def..2413c89d90 100644 --- a/data_sources/windows_event_log_taskscheduler_201.yml +++ b/data_sources/windows_event_log_taskscheduler_201.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 201 id: 4c09ae64-01cd-4b65-8221-20f803b0d86e -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log TaskScheduler 201 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time output_fields: diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index c979d0b125..43befd9349 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -1,8 +1,8 @@ name: Windows IIS id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. mitre_components: @@ -16,4 +16,4 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index c48ee8e61d..d60e527479 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -1,8 +1,8 @@ name: Windows IIS 29 id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-08' +modification_date: '2026-07-09' author: Patrick Bareiss, Splunk description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. mitre_components: @@ -17,7 +17,7 @@ separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.0 + version: 10.1.1 fields: - _time - ComputerName From 6f69a8acfd9b798ee69879000770078b04158c8c Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Mon, 13 Jul 2026 18:26:12 +0000 Subject: [PATCH 09/32] Update datasource TA versions --- data_sources/cisco_secure_access_dns.yml | 6 +++--- data_sources/cisco_secure_access_firewall.yml | 6 +++--- data_sources/cisco_secure_access_proxy.yml | 6 +++--- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/data_sources/cisco_secure_access_dns.yml b/data_sources/cisco_secure_access_dns.yml index bdf4c50c56..127286df5e 100644 --- a/data_sources/cisco_secure_access_dns.yml +++ b/data_sources/cisco_secure_access_dns.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access DNS id: 5673dba3-cae9-449e-8991-03832d79f729 -version: 1 +version: 2 creation_date: '2026-05-06' -modification_date: '2026-05-06' +modification_date: '2026-07-13' author: Bhavin Patel, Splunk description: | Captures DNS security events from Cisco Secure Access (including Umbrella-style DNS policy and roaming client telemetry) with client identity, query and response metadata, resolved domain, and URL/content categorization. @@ -12,7 +12,7 @@ sourcetype: cisco:cloud_security:dns supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.50 + version: 1.0.52 fields: - RecordType - ReplyCode diff --git a/data_sources/cisco_secure_access_firewall.yml b/data_sources/cisco_secure_access_firewall.yml index 5b1c49627c..78f544c792 100644 --- a/data_sources/cisco_secure_access_firewall.yml +++ b/data_sources/cisco_secure_access_firewall.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access Firewall id: 5dc07487-f834-4850-b6a7-4cc09e56549b -version: 2 +version: 3 creation_date: '2026-04-29' -modification_date: '2026-05-13' +modification_date: '2026-07-13' author: Bhavin Patel, Splunk description: Captures firewall connection events from Cisco Secure Access including user identity, source and destination metadata, protocol details, and session statistics. Enables analysis of network traffic patterns, access policy enforcement, brute force attempts, and anomalous connection behavior across cloud-managed network access infrastructure. source: cisco_secure_access:firewall @@ -10,7 +10,7 @@ sourcetype: cisco:cloud_security:firewall supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.50 + version: 1.0.52 fields: - _time - action diff --git a/data_sources/cisco_secure_access_proxy.yml b/data_sources/cisco_secure_access_proxy.yml index 3b981bad63..622012e3bd 100644 --- a/data_sources/cisco_secure_access_proxy.yml +++ b/data_sources/cisco_secure_access_proxy.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access Proxy id: 2dc95ec2-8964-4ddb-8714-8d7dfe264922 -version: 1 +version: 2 creation_date: '2026-05-08' -modification_date: '2026-05-08' +modification_date: '2026-07-13' author: Bhavin Patel, Splunk description: | Captures HTTP/HTTPS proxy access events from Cisco Secure Access, including requesting source, user identity, URL, HTTP method, response status, and user-agent metadata. @@ -12,7 +12,7 @@ sourcetype: cisco:cloud_security:proxy supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.50 + version: 1.0.52 fields: - _time - action From 13d26cf6158258bcaeb003cc9fb63abc5eec6917 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Wed, 15 Jul 2026 15:17:25 +0000 Subject: [PATCH 10/32] Update datasource TA versions --- data_sources/crowdstrike_falcon_stream_alert.yml | 6 +++--- data_sources/crowdstrike_processrollup2.yml | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/data_sources/crowdstrike_falcon_stream_alert.yml b/data_sources/crowdstrike_falcon_stream_alert.yml index 5c97773012..3f19ad789d 100644 --- a/data_sources/crowdstrike_falcon_stream_alert.yml +++ b/data_sources/crowdstrike_falcon_stream_alert.yml @@ -1,8 +1,8 @@ name: CrowdStrike Falcon Stream Alert id: 52b38751-b0db-4965-a800-ebaabd1fd7d5 -version: 3 +version: 4 creation_date: '2025-07-01' -modification_date: '2026-06-18' +modification_date: '2026-07-15' author: Bhavin Patel, Bryan Pluta, Splunk description: Logs of CrowdStrike Falcon Stream Alerts mitre_components: @@ -17,7 +17,7 @@ separator: event.DetectName supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 3.0.0 + version: 3.1.1 fields: - action - description diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml index 95579d5dab..f5b4fc8ac7 100644 --- a/data_sources/crowdstrike_processrollup2.yml +++ b/data_sources/crowdstrike_processrollup2.yml @@ -1,8 +1,8 @@ name: CrowdStrike ProcessRollup2 id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-06-18' +modification_date: '2026-07-15' author: Patrick Bareiss, Splunk description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments. mitre_components: @@ -18,7 +18,7 @@ separator_value: ProcessRollup2 supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 3.0.0 + version: 3.1.1 fields: - AuthenticationId - AuthenticationId_meaning From dd9fefd6999f6c26720afc41bdbca50cb84ff987 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Thu, 16 Jul 2026 11:26:21 +0000 Subject: [PATCH 11/32] Update datasource TA versions --- data_sources/palo_alto_network_threat.yml | 6 +++--- data_sources/palo_alto_network_traffic.yml | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml index b83bd67d0b..531150f3b3 100644 --- a/data_sources/palo_alto_network_threat.yml +++ b/data_sources/palo_alto_network_threat.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Threat id: 375c2b0e-d216-41ad-9406-200464595209 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:threat supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.1.0 + version: 3.2.1 fields: - _time - date_hour diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml index 00e9798ece..a4b39748cf 100644 --- a/data_sources/palo_alto_network_traffic.yml +++ b/data_sources/palo_alto_network_traffic.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Traffic id: 182a83bc-c31a-4817-8c7a-263744cec52a -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:traffic supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.1.0 + version: 3.2.1 fields: - _time - date_hour From 1113b4ca2b438645807d381340b2c436eaac77f2 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Thu, 16 Jul 2026 13:15:32 +0000 Subject: [PATCH 12/32] Update datasource TA versions --- data_sources/ntlm_operational_8004.yml | 6 +++--- data_sources/ntlm_operational_8005.yml | 6 +++--- data_sources/ntlm_operational_8006.yml | 6 +++--- data_sources/powershell_script_block_logging_4104.yml | 6 +++--- data_sources/windows_active_directory_admon.yml | 6 +++--- data_sources/windows_event_log_application_15457.yml | 6 +++--- data_sources/windows_event_log_application_17135.yml | 6 +++--- data_sources/windows_event_log_application_2282.yml | 6 +++--- data_sources/windows_event_log_application_3000.yml | 6 +++--- data_sources/windows_event_log_application_8128.yml | 6 +++--- .../windows_event_log_appxdeployment_server_400.yml | 6 +++--- .../windows_event_log_appxdeployment_server_854.yml | 6 +++--- .../windows_event_log_appxdeployment_server_855.yml | 6 +++--- data_sources/windows_event_log_appxpackaging_171.yml | 6 +++--- data_sources/windows_event_log_capi2_70.yml | 6 +++--- data_sources/windows_event_log_capi2_81.yml | 6 +++--- .../windows_event_log_certificateservicesclient_1007.yml | 6 +++--- data_sources/windows_event_log_defender_1121.yml | 6 +++--- data_sources/windows_event_log_defender_1122.yml | 6 +++--- data_sources/windows_event_log_defender_1125.yml | 6 +++--- data_sources/windows_event_log_defender_1126.yml | 6 +++--- data_sources/windows_event_log_defender_1129.yml | 6 +++--- data_sources/windows_event_log_defender_1131.yml | 6 +++--- data_sources/windows_event_log_defender_1132.yml | 6 +++--- data_sources/windows_event_log_defender_1133.yml | 6 +++--- data_sources/windows_event_log_defender_1134.yml | 6 +++--- data_sources/windows_event_log_defender_5007.yml | 6 +++--- data_sources/windows_event_log_printservice_316.yml | 6 +++--- data_sources/windows_event_log_printservice_4909.yml | 6 +++--- data_sources/windows_event_log_printservice_808.yml | 6 +++--- .../windows_event_log_remoteconnectionmanager_1149.yml | 6 +++--- data_sources/windows_event_log_security_1100.yml | 6 +++--- data_sources/windows_event_log_security_1102.yml | 6 +++--- data_sources/windows_event_log_security_4624.yml | 6 +++--- data_sources/windows_event_log_security_4625.yml | 6 +++--- data_sources/windows_event_log_security_4627.yml | 6 +++--- data_sources/windows_event_log_security_4648.yml | 6 +++--- data_sources/windows_event_log_security_4662.yml | 6 +++--- data_sources/windows_event_log_security_4663.yml | 6 +++--- data_sources/windows_event_log_security_4672.yml | 6 +++--- data_sources/windows_event_log_security_4688.yml | 6 +++--- data_sources/windows_event_log_security_4698.yml | 6 +++--- data_sources/windows_event_log_security_4699.yml | 6 +++--- data_sources/windows_event_log_security_4700.yml | 6 +++--- data_sources/windows_event_log_security_4702.yml | 6 +++--- data_sources/windows_event_log_security_4703.yml | 6 +++--- data_sources/windows_event_log_security_4719.yml | 6 +++--- data_sources/windows_event_log_security_4720.yml | 6 +++--- data_sources/windows_event_log_security_4723.yml | 6 +++--- data_sources/windows_event_log_security_4724.yml | 6 +++--- data_sources/windows_event_log_security_4725.yml | 6 +++--- data_sources/windows_event_log_security_4726.yml | 6 +++--- data_sources/windows_event_log_security_4727.yml | 6 +++--- data_sources/windows_event_log_security_4728.yml | 6 +++--- data_sources/windows_event_log_security_4730.yml | 6 +++--- data_sources/windows_event_log_security_4731.yml | 6 +++--- data_sources/windows_event_log_security_4732.yml | 6 +++--- data_sources/windows_event_log_security_4737.yml | 6 +++--- data_sources/windows_event_log_security_4738.yml | 6 +++--- data_sources/windows_event_log_security_4739.yml | 6 +++--- data_sources/windows_event_log_security_4741.yml | 6 +++--- data_sources/windows_event_log_security_4742.yml | 6 +++--- data_sources/windows_event_log_security_4744.yml | 6 +++--- data_sources/windows_event_log_security_4749.yml | 6 +++--- data_sources/windows_event_log_security_4754.yml | 6 +++--- data_sources/windows_event_log_security_4756.yml | 6 +++--- data_sources/windows_event_log_security_4759.yml | 6 +++--- data_sources/windows_event_log_security_4768.yml | 6 +++--- data_sources/windows_event_log_security_4769.yml | 6 +++--- data_sources/windows_event_log_security_4771.yml | 6 +++--- data_sources/windows_event_log_security_4776.yml | 6 +++--- data_sources/windows_event_log_security_4781.yml | 6 +++--- data_sources/windows_event_log_security_4783.yml | 6 +++--- data_sources/windows_event_log_security_4790.yml | 6 +++--- data_sources/windows_event_log_security_4794.yml | 6 +++--- data_sources/windows_event_log_security_4798.yml | 6 +++--- data_sources/windows_event_log_security_4876.yml | 6 +++--- data_sources/windows_event_log_security_4886.yml | 6 +++--- data_sources/windows_event_log_security_4887.yml | 6 +++--- data_sources/windows_event_log_security_4946.yml | 6 +++--- data_sources/windows_event_log_security_4947.yml | 6 +++--- data_sources/windows_event_log_security_4948.yml | 6 +++--- data_sources/windows_event_log_security_5136.yml | 6 +++--- data_sources/windows_event_log_security_5137.yml | 6 +++--- data_sources/windows_event_log_security_5140.yml | 6 +++--- data_sources/windows_event_log_security_5141.yml | 6 +++--- data_sources/windows_event_log_security_5145.yml | 6 +++--- data_sources/windows_event_log_system_104.yml | 6 +++--- data_sources/windows_event_log_system_4720.yml | 6 +++--- data_sources/windows_event_log_system_4726.yml | 6 +++--- data_sources/windows_event_log_system_4728.yml | 6 +++--- data_sources/windows_event_log_system_7036.yml | 6 +++--- data_sources/windows_event_log_system_7040.yml | 6 +++--- data_sources/windows_event_log_system_7045.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_200.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_201.yml | 6 +++--- data_sources/windows_iis.yml | 6 +++--- data_sources/windows_iis_29.yml | 6 +++--- 98 files changed, 294 insertions(+), 294 deletions(-) diff --git a/data_sources/ntlm_operational_8004.yml b/data_sources/ntlm_operational_8004.yml index dbccc351f2..f1c94194e9 100644 --- a/data_sources/ntlm_operational_8004.yml +++ b/data_sources/ntlm_operational_8004.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8004 id: fd08cb77-c26e-464c-a43e-2867e232127e -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8004 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8005.yml b/data_sources/ntlm_operational_8005.yml index 1117117dce..d88b79d79a 100644 --- a/data_sources/ntlm_operational_8005.yml +++ b/data_sources/ntlm_operational_8005.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8005 id: ad15a1cf-4b21-43de-81e4-6307c69172fb -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8005 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8006.yml b/data_sources/ntlm_operational_8006.yml index 5c8d1b96f7..6ed526560b 100644 --- a/data_sources/ntlm_operational_8006.yml +++ b/data_sources/ntlm_operational_8006.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8006 id: 9f50a672-6f7d-4621-a3bd-69468c6b7a7f -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8006 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 70d01b44d8..46c093b3c6 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,8 +1,8 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: @@ -18,7 +18,7 @@ separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index ed5ec2455f..2a474e96ff 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -1,8 +1,8 @@ name: Windows Active Directory Admon id: 22bbf4e4-d313-43c1-98ee-808b8775519d -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ActiveDirectory supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Guid diff --git a/data_sources/windows_event_log_application_15457.yml b/data_sources/windows_event_log_application_15457.yml index 2a411551b1..ca078905ef 100644 --- a/data_sources/windows_event_log_application_15457.yml +++ b/data_sources/windows_event_log_application_15457.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 15457 id: 4491537e-520c-46f7-9209-f56f852aa237 -version: 4 +version: 5 creation_date: '2025-02-25' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 15457 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_17135.yml b/data_sources/windows_event_log_application_17135.yml index b0ee4676ff..b4ccd50596 100644 --- a/data_sources/windows_event_log_application_17135.yml +++ b/data_sources/windows_event_log_application_17135.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 17135 id: 4491537e-520c-46f7-9209-f56f852aa231 -version: 4 +version: 5 creation_date: '2025-02-25' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 17135 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index 97975c40c2..ab2ed67b3d 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 2282 id: 4490537e-5e0c-46f7-9209-f56f852aa237 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index 76d8b09e7e..4ef4af2e8d 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: @@ -17,7 +17,7 @@ separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_8128.yml b/data_sources/windows_event_log_application_8128.yml index 178140c103..2f9e5e6b86 100644 --- a/data_sources/windows_event_log_application_8128.yml +++ b/data_sources/windows_event_log_application_8128.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 8128 id: 4491537e-5e0c-46f7-9209-f56f852aa237 -version: 4 +version: 5 creation_date: '2025-02-25' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 8128 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_400.yml b/data_sources/windows_event_log_appxdeployment_server_400.yml index cbd5df74e6..b1d534b02c 100644 --- a/data_sources/windows_event_log_appxdeployment_server_400.yml +++ b/data_sources/windows_event_log_appxdeployment_server_400.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 400 id: 3e5f9d2a-b8c7-4d1e-a6f3-7b9c8d5e4f2a -version: 4 +version: 5 creation_date: '2025-08-18' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 400. These events are generated when a package deployment operation begins, providing details about the package being deployed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_854.yml b/data_sources/windows_event_log_appxdeployment_server_854.yml index 04859a7601..88bbdbfcb4 100644 --- a/data_sources/windows_event_log_appxdeployment_server_854.yml +++ b/data_sources/windows_event_log_appxdeployment_server_854.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 854 id: 4d2e6f8a-c9b7-5a3e-8d1f-2e9c7b5a4f3d -version: 4 +version: 5 creation_date: '2025-08-18' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 854. These events are generated when an MSIX/AppX package has been successfully installed on a system. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_855.yml b/data_sources/windows_event_log_appxdeployment_server_855.yml index d5856f19a1..a50f231d1c 100644 --- a/data_sources/windows_event_log_appxdeployment_server_855.yml +++ b/data_sources/windows_event_log_appxdeployment_server_855.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 855 id: 4491537c-521c-46f7-9209-f56f852aa231 -version: 4 +version: 5 creation_date: '2025-08-18' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 855. These events are generated when a package deployment operation completes successfully, providing details about the packages that were installed or updated. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxpackaging_171.yml b/data_sources/windows_event_log_appxpackaging_171.yml index ad3bb1c1b8..d8d6d8cd19 100644 --- a/data_sources/windows_event_log_appxpackaging_171.yml +++ b/data_sources/windows_event_log_appxpackaging_171.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXPackaging 171 id: 2d0f8e3c-a2d7-4b9e-8f1c-6a5d7e3e9f2b -version: 4 +version: 5 creation_date: '2025-08-18' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXPackaging/Operational channel, specifically focusing on EventCode 171. These events are generated when a user clicks on or attempts to interact with an MSIX package, even if the package is not fully installed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 7c0fb1cec9..cb13bb776c 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: @@ -18,7 +18,7 @@ separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index dafe5f47e3..9e0e5f0fd8 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 81 id: 463ff898-8135-4c0e-811e-f8629dfc5027 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index 185d48ba7e..c288476d02 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -1,8 +1,8 @@ name: Windows Event Log CertificateServicesClient 1007 id: c51444e3-479d-4c4a-b111-e8276a3acf39 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index 942f72411f..1d74267d5b 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1121 id: 84a254c5-7900-4b52-a324-a176adb7c11d -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index aa0d7d40ef..57a6696eb2 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1122 id: 4a2d0499-f489-4557-82f4-f357025cf3e7 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1125.yml b/data_sources/windows_event_log_defender_1125.yml index dfcdc11be7..598a9553bd 100644 --- a/data_sources/windows_event_log_defender_1125.yml +++ b/data_sources/windows_event_log_defender_1125.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1125 id: 0cddda76-6fd8-4fb6-9026-f23a2761c95d -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1125 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time example_log: 112204000x80000000000000003701Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender Antivirus4.18.23100.2009E6DB77E5-3DF2-4CF1-B95A-636979351E5B2023-11-26T23:43:08.709Z(unknown user)C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1.401.1247.01.1.23100.2009ENT\ConsRC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x00000000 diff --git a/data_sources/windows_event_log_defender_1126.yml b/data_sources/windows_event_log_defender_1126.yml index 5cc303b04f..644997da2f 100644 --- a/data_sources/windows_event_log_defender_1126.yml +++ b/data_sources/windows_event_log_defender_1126.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1126 id: c1c6284b-b663-4001-bdf2-c0cacee22a2a -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1126 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index 4fc5a5289d..df6df911d4 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1129 id: 0572e119-a48a-4c70-bc58-90e453edacd2 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_defender_1131.yml b/data_sources/windows_event_log_defender_1131.yml index cc4d6bf89b..c1f9c9f521 100644 --- a/data_sources/windows_event_log_defender_1131.yml +++ b/data_sources/windows_event_log_defender_1131.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1131 id: 638f884e-439a-4328-923c-ec5a2679f450 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1131 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1132.yml b/data_sources/windows_event_log_defender_1132.yml index fd0c92f136..cd431d99c0 100644 --- a/data_sources/windows_event_log_defender_1132.yml +++ b/data_sources/windows_event_log_defender_1132.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1132 id: 18f93f60-4eca-46e8-a29d-147e6451a34c -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1132 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1133.yml b/data_sources/windows_event_log_defender_1133.yml index 42785c454a..1de8ae7655 100644 --- a/data_sources/windows_event_log_defender_1133.yml +++ b/data_sources/windows_event_log_defender_1133.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1133 id: 63c97a9a-cc7f-46c5-b219-8be388666637 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1133 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1134.yml b/data_sources/windows_event_log_defender_1134.yml index 347e09bb73..1f7bcb4443 100644 --- a/data_sources/windows_event_log_defender_1134.yml +++ b/data_sources/windows_event_log_defender_1134.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1134 id: 26abac7d-d026-44e9-b1a3-13e3e11b232d -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1134 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index 2e2da74db8..eb4ba43796 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 5007 id: 27f18792-8d95-4871-8853-874b7faf023f -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when Windows Defender antimalware settings are modified. mitre_components: @@ -14,7 +14,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index e75bfd0869..e5f95f897b 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_printservice_4909.yml b/data_sources/windows_event_log_printservice_4909.yml index 9181e429c7..ac15d79b6a 100644 --- a/data_sources/windows_event_log_printservice_4909.yml +++ b/data_sources/windows_event_log_printservice_4909.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 4909 id: 4c00e353-18b8-4de6-896d-83bc5817dbaa -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Printservice 4909 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time example_log: '' diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index b3e0f9eb4d..bc7ec739f6 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: @@ -16,7 +16,7 @@ separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index f25fbf6088..9cc952673f 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,8 +1,8 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index 0b92196127..b862efa32c 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: @@ -15,7 +15,7 @@ separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index 28049f6bb5..f5d9aaead3 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 02a568dc82..09cd63fa76 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 0f8e828830..535890c599 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4625 id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when an account fails to log on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index eb3105c2fe..6fc8ff84f8 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4627 id: e35c7b9a-b451-4084-95a5-43b7f8965cac -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index ffe53ac16d..94706a706f 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4648 id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account mitre_components: @@ -15,7 +15,7 @@ separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index ff6f24e77e..6c9eb7856b 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4662 id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it mitre_components: @@ -15,7 +15,7 @@ separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index cc7343e6be..9ec70f1e71 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4663 id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer mitre_components: @@ -15,7 +15,7 @@ separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 690f6574d2..c4d5339550 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index 5cd7ca5404..cf95648d73 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4688 id: d195eb26-a81c-45ed-aeb3-25792e8a985a -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the creation of a new process mitre_components: @@ -16,7 +16,7 @@ configuration: Enabling Windows event log process command line logging via group supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - Caller_Domain - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index 711f75a4fe..d2aa8c68d5 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4698 id: 32c06703-02d3-47ec-8856-b0dc3045866c -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a new scheduled task is created mitre_components: @@ -15,7 +15,7 @@ separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index 7b8bf5a9c8..eca0c1bf7a 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4699 id: 4727dead-d063-4333-9ddd-59823a416aff -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a scheduled task is deleted from the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4700.yml b/data_sources/windows_event_log_security_4700.yml index c481ce6fea..df26da4bbf 100644 --- a/data_sources/windows_event_log_security_4700.yml +++ b/data_sources/windows_event_log_security_4700.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4700 id: 89895c7b-2aba-41ca-ad12-8b6d290b5dde -version: 5 +version: 6 creation_date: '2025-03-11' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Steven Dick description: Data source object for Windows Event Log Security 4700 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - EventID example_log: 4700 0 0 12804 0 0x8020000000000000 344861 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin LeastPrivilege CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4702.yml b/data_sources/windows_event_log_security_4702.yml index 8330ac843e..e11e8bd49e 100644 --- a/data_sources/windows_event_log_security_4702.yml +++ b/data_sources/windows_event_log_security_4702.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 -version: 5 +version: 6 creation_date: '2025-03-11' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 7c4c8aa4e6..7e61a50e7f 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4703 id: e256673b-16e8-4b74-b7aa-9eed6ce67072 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a token right is adjusted on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index 40ed628e22..513ee6b035 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4719 id: 954033e6-dd05-4775-a1f2-1f19632f4420 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a system audit policy is modified on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index 806ea95994..bc28680dd6 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4720 id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a new user account is created on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4723.yml b/data_sources/windows_event_log_security_4723.yml index f0bee2be18..42d07cb837 100644 --- a/data_sources/windows_event_log_security_4723.yml +++ b/data_sources/windows_event_log_security_4723.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4723 id: df19b271-57c8-4f31-817a-6c5566985484 -version: 3 +version: 4 creation_date: '2026-06-15' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Raven Tait, Splunk description: Logs an event when an attempt is made to change an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4723' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index ca731a9a4d..dc80781f29 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4724 id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when an attempt is made to reset an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index 44493db4b1..0814e35384 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4725 id: 31fd887d-0d14-44cc-bb64-80063a9f2968 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a user account has been disabled in Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index 63e2a2e051..4eaf70de01 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4726 id: 0b56dcd7-0f72-4a05-9226-d6059781737b -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a user account is deleted from Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4727.yml b/data_sources/windows_event_log_security_4727.yml index 79157829b0..e6c33c3f97 100644 --- a/data_sources/windows_event_log_security_4727.yml +++ b/data_sources/windows_event_log_security_4727.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4727 id: 4d2078ab-36f5-447e-b7e4-474890b8040b -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4727 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4728.yml b/data_sources/windows_event_log_security_4728.yml index fee1e2ba28..73d3af406d 100644 --- a/data_sources/windows_event_log_security_4728.yml +++ b/data_sources/windows_event_log_security_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4728 id: c0cb4907-d715-41f2-a98a-4f4e75f248c1 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4728 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4730.yml b/data_sources/windows_event_log_security_4730.yml index 04b66ccda5..d357c16f0d 100644 --- a/data_sources/windows_event_log_security_4730.yml +++ b/data_sources/windows_event_log_security_4730.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4730 id: 126966ba-a17d-4194-882b-57d303aaf46d -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4730 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4731.yml b/data_sources/windows_event_log_security_4731.yml index bb71e8ad83..f3e5fcba88 100644 --- a/data_sources/windows_event_log_security_4731.yml +++ b/data_sources/windows_event_log_security_4731.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4731 id: 1bbc004e-a75e-4d94-a619-c5aaf5d11ed5 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4731 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index c7c04625da..dc12ba9438 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4732 id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a member is added to a security-enabled local group on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4737.yml b/data_sources/windows_event_log_security_4737.yml index b1f5a09487..ccb10c1908 100644 --- a/data_sources/windows_event_log_security_4737.yml +++ b/data_sources/windows_event_log_security_4737.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4737 id: 132fc609-17f0-4efd-8f7e-db12139c6690 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4737 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index 4352ec2687..404f43f14f 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4738 id: cb85709b-101e-41a9-bb60-d2108f79dfbd -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index 93021d1a3b..5dcd4a2f3f 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4739 id: c1e0442a-8a97-405d-baf2-057c5d68cd9a -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index fdb0965278..9b444f4daa 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4741 id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index 583f432381..d5a66f9fe9 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4742 id: ea830adf-5450-489a-bcdc-fb8d2cbe674c -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4744.yml b/data_sources/windows_event_log_security_4744.yml index c2b8df0f9b..45699ac492 100644 --- a/data_sources/windows_event_log_security_4744.yml +++ b/data_sources/windows_event_log_security_4744.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4744 id: 244e0bd4-00b0-4091-b8b4-9d435aca6ad8 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4744 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4749.yml b/data_sources/windows_event_log_security_4749.yml index 3c11cc4ebd..553c59f1c5 100644 --- a/data_sources/windows_event_log_security_4749.yml +++ b/data_sources/windows_event_log_security_4749.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4749 id: eb322056-01a3-4cd5-bc09-01140d33194a -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4749 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4754.yml b/data_sources/windows_event_log_security_4754.yml index b06e47374a..feda34317e 100644 --- a/data_sources/windows_event_log_security_4754.yml +++ b/data_sources/windows_event_log_security_4754.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4754 id: 501a507e-3275-4c4b-9c44-53eecfeae487 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4754 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4756.yml b/data_sources/windows_event_log_security_4756.yml index 1f9df9e69e..2e81cbe353 100644 --- a/data_sources/windows_event_log_security_4756.yml +++ b/data_sources/windows_event_log_security_4756.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4756 id: b0093058-0cb6-4c73-a95b-fb0f3541e88c -version: 4 +version: 5 creation_date: '2026-03-30' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Nasreddine Bencherchali, Splunk description: Data source object for Windows Event Log Security 4756 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4759.yml b/data_sources/windows_event_log_security_4759.yml index c46f1dfe69..5b0113c63d 100644 --- a/data_sources/windows_event_log_security_4759.yml +++ b/data_sources/windows_event_log_security_4759.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4759 id: 431e3520-505b-4ace-aced-cb51e3f7311e -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4759 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index 59ffa510c1..26446f9d2e 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4768 id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index 4cca5368c3..fa497d59d3 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index 5bf91c3397..e6714cabc0 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4771 id: 418debbb-adf3-48ec-9efd-59d45f8861e5 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index 92f613562b..84bfe3ea6f 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4776 id: 1da9092a-c795-4a26-ace8-d43855524e96 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index 862d436a12..3bc0d6b7fc 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4783.yml b/data_sources/windows_event_log_security_4783.yml index fed9070c8d..916445209f 100644 --- a/data_sources/windows_event_log_security_4783.yml +++ b/data_sources/windows_event_log_security_4783.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4783 id: 6b945150-785c-49a1-b705-56b42215630b -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4783 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4790.yml b/data_sources/windows_event_log_security_4790.yml index d91ba1001a..f889cb6940 100644 --- a/data_sources/windows_event_log_security_4790.yml +++ b/data_sources/windows_event_log_security_4790.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4790 id: 1cc6ecbb-af04-432b-a224-02c65243ac88 -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4790 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index 01478f91d6..0b2362f822 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4794 id: ec7da74f-274a-4bde-aa0e-15c68aca0426 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index 9cdbe23c7e..139b23f846 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4798 id: 29e97f72-eb2e-400e-b0c9-81277547e43b -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index 632f4d751e..b1d9624b51 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4876 id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index 2d41b87255..0d80804438 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index e199abbcff..4becf1a1b3 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4887 id: 994c7b19-a623-4231-9818-f00e453b9a75 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4946.yml b/data_sources/windows_event_log_security_4946.yml index 29a8ee27b8..8078c39c4d 100644 --- a/data_sources/windows_event_log_security_4946.yml +++ b/data_sources/windows_event_log_security_4946.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4946 id: d7dafd01-a22d-4b05-b793-7571ef1fa789 -version: 5 +version: 6 creation_date: '2025-03-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4946 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4946' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4947.yml b/data_sources/windows_event_log_security_4947.yml index 1592a39217..a3e2e2b357 100644 --- a/data_sources/windows_event_log_security_4947.yml +++ b/data_sources/windows_event_log_security_4947.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4947 id: 63d4a2fa-a7dc-46d2-b702-54794e1f4d3c -version: 5 +version: 6 creation_date: '2025-03-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4947 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4947' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4948.yml b/data_sources/windows_event_log_security_4948.yml index 9454a0bf7e..33e9f91450 100644 --- a/data_sources/windows_event_log_security_4948.yml +++ b/data_sources/windows_event_log_security_4948.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4948 id: 910032df-4e49-42fe-a611-d4c29557d83a -version: 5 +version: 6 creation_date: '2025-03-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4948 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4948' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index e10584b1cc..c37d4847a1 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5136 id: 7ba3737e-231e-455d-824e-cd077749f835 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index 76e411d753..40cc759239 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AppCorrelationID diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index b78d356eb5..90a806c017 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index ac75647a7b..c2e3a95a15 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5141 id: eafb35fa-f034-4be3-8508-d9173a73c0a1 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 049e447d03..81503a152e 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_system_104.yml b/data_sources/windows_event_log_system_104.yml index d91ccc3cf8..658c7b0df8 100644 --- a/data_sources/windows_event_log_system_104.yml +++ b/data_sources/windows_event_log_system_104.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 104 id: 577b9b41-6b37-44c4-9016-3d890b909050 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log System 104 source: XmlWinEventLog:System @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index f359df765e..2eba810b8a 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4720 id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 9886c8cf59..dc7e79721e 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4726 id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index d3d5267324..59d634d9b2 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index 30b3edad3b..c213f15ae8 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7036 id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). mitre_components: @@ -17,7 +17,7 @@ separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 44f76d3651..e84d7cbcc8 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index e150941521..73dd1d9343 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - AccountName diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index acbffe0aa1..6e43e5e1fd 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ActionName diff --git a/data_sources/windows_event_log_taskscheduler_201.yml b/data_sources/windows_event_log_taskscheduler_201.yml index 2413c89d90..7bfc93b7d1 100644 --- a/data_sources/windows_event_log_taskscheduler_201.yml +++ b/data_sources/windows_event_log_taskscheduler_201.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 201 id: 4c09ae64-01cd-4b65-8221-20f803b0d86e -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log TaskScheduler 201 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time output_fields: diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index 43befd9349..9874913f17 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -1,8 +1,8 @@ name: Windows IIS id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. mitre_components: @@ -16,4 +16,4 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index d60e527479..90286b7acb 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -1,8 +1,8 @@ name: Windows IIS 29 id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-16' author: Patrick Bareiss, Splunk description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. mitre_components: @@ -17,7 +17,7 @@ separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.1 + version: 10.1.2 fields: - _time - ComputerName From e8713d1a6fc85b615c4928ae4f0d47ba1f22d433 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Fri, 17 Jul 2026 09:44:56 +0000 Subject: [PATCH 13/32] Update datasource TA versions --- data_sources/azure_active_directory.yml | 6 +++--- ...rectory_add_app_role_assignment_to_service_principal.yml | 6 +++--- data_sources/azure_active_directory_add_member_to_role.yml | 6 +++--- .../azure_active_directory_add_owner_to_application.yml | 6 +++--- .../azure_active_directory_add_service_principal.yml | 6 +++--- .../azure_active_directory_add_unverified_domain.yml | 6 +++--- .../azure_active_directory_consent_to_application.yml | 6 +++--- ...azure_active_directory_disable_strong_authentication.yml | 6 +++--- data_sources/azure_active_directory_enable_account.yml | 6 +++--- .../azure_active_directory_invite_external_user.yml | 6 +++--- .../azure_active_directory_microsoftgraphactivitylogs.yml | 6 +++--- .../azure_active_directory_noninteractiveusersigninlogs.yml | 6 +++--- .../azure_active_directory_reset_password_(by_admin).yml | 6 +++--- .../azure_active_directory_set_domain_authentication.yml | 6 +++--- data_sources/azure_active_directory_sign_in_activity.yml | 6 +++--- data_sources/azure_active_directory_update_application.yml | 6 +++--- .../azure_active_directory_update_authorization_policy.yml | 6 +++--- data_sources/azure_active_directory_update_user.yml | 6 +++--- ...azure_active_directory_user_registered_security_info.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_account.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_runbook.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_webhook.yml | 6 +++--- data_sources/azure_monitor_activity.yml | 6 +++--- 23 files changed, 69 insertions(+), 69 deletions(-) diff --git a/data_sources/azure_active_directory.yml b/data_sources/azure_active_directory.yml index 4b353862ea..0f61908be9 100644 --- a/data_sources/azure_active_directory.yml +++ b/data_sources/azure_active_directory.yml @@ -1,8 +1,8 @@ name: Azure Active Directory id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c -version: 2 +version: 3 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: All Azure Active Directory events source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 output_fields: - dest - user diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml index 182d512dca..20be2d2d46 100644 --- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml +++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add app role assignment to service principal id: 8b2e84cd-6db0-47e9-badc-75c17df1995f -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs the addition of an application role assignment to a service principal in Azure Active Directory, including details about the role, service principal, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add app role assignment to service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml index 5031b5cd33..c8c0a3fe86 100644 --- a/data_sources/azure_active_directory_add_member_to_role.yml +++ b/data_sources/azure_active_directory_add_member_to_role.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add member to role id: 1660d196-127f-4678-81b2-472d51711b07 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add member to role supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml index f0c01197f6..6feb542ceb 100644 --- a/data_sources/azure_active_directory_add_owner_to_application.yml +++ b/data_sources/azure_active_directory_add_owner_to_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add owner to application id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add owner to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml index c5e2c3a4e5..3fa25b765f 100644 --- a/data_sources/azure_active_directory_add_service_principal.yml +++ b/data_sources/azure_active_directory_add_service_principal.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add service principal id: fd89d337-e4c0-4162-ad13-bca36f096fe6 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml index 7b4411afbd..30ec67befc 100644 --- a/data_sources/azure_active_directory_add_unverified_domain.yml +++ b/data_sources/azure_active_directory_add_unverified_domain.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add unverified domain id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add unverified domain supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml index 1461a8eaa6..d056dcb7ca 100644 --- a/data_sources/azure_active_directory_consent_to_application.yml +++ b/data_sources/azure_active_directory_consent_to_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Consent to application id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the consenting user or process. mitre_components: @@ -17,7 +17,7 @@ separator_value: Consent to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml index 177b30e212..4c84bea712 100644 --- a/data_sources/azure_active_directory_disable_strong_authentication.yml +++ b/data_sources/azure_active_directory_disable_strong_authentication.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Disable Strong Authentication id: 8f31966d-c496-496d-8837-f7fd11f31255 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when strong authentication methods are disabled in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Disable Strong Authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml index b7fd87116e..4996fb4530 100644 --- a/data_sources/azure_active_directory_enable_account.yml +++ b/data_sources/azure_active_directory_enable_account.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Enable account id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Active Directory account is enabled. mitre_components: @@ -16,7 +16,7 @@ separator_value: Enable account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml index 22983a3d9f..7142e0a001 100644 --- a/data_sources/azure_active_directory_invite_external_user.yml +++ b/data_sources/azure_active_directory_invite_external_user.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Invite external user id: d3818bd5-f283-4518-8b67-df19240c3e40 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when an external user is invited to join an Azure Active Directory tenant. mitre_components: @@ -16,7 +16,7 @@ separator_value: Invite external user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml b/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml index 65cb093d4f..3338304ff9 100644 --- a/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml +++ b/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml @@ -1,8 +1,8 @@ name: Azure Active Directory MicrosoftGraphActivityLogs id: 63ff93ba-2bbb-4542-8773-239bf5266367 -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Bhavin Patel, Splunk description: Data source object for Azure Active Directory MicrosoftGraphActivityLogs source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time example_log: '{"time": "2024-04-30T01:22:46.4948958Z", "resourceId": "/TENANTS/225E05A1-5914-4688-A404-7030E60F3143/PROVIDERS/MICROSOFT.AADIAM", "operationName": "Microsoft Graph Activity", "operationVersion": "beta", "category": "MicrosoftGraphActivityLogs", "resultSignature": "200", "durationMs": "948894", "callerIpAddress": "45.83.145.6", "correlationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "level": "Informational", "location": "East US 2", "properties": {"__UDI_RequiredFields_TenantId": "225e05a1-5914-4688-a404-7030e60f3143", "__UDI_RequiredFields_UniqueId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "__UDI_RequiredFields_EventTime": 638500369660000000, "__UDI_RequiredFields_RegionScope": "NA", "timeGenerated": "2024-04-30T01:22:46.4948958Z", "location": "East US 2", "requestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "operationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "clientRequestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "apiVersion": "beta", "requestMethod": "GET", "responseStatusCode": 200, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143", "durationMs": 948894, "responseSizeBytes": 91, "signInActivityId": "KRsphQ_4s0-oHv_Br8qSAQ", "roles": "", "appId": "1950a258-227b-4e31-a9cf-717495945fc2", "UserPrincipalObjectID": "7b934539-7366-494e-a8ac-3517694d32db", "scopes": "AuditLog.Read.All Directory.AccessAsUser.All email openid profile", "identityProvider": "", "clientAuthMethod": "0", "wids": "b79fbf4d-3ef9-4689-8143-76b194e85509", "C_Idtyp": "user", "C_Iat": "1714439850", "ipAddress": "45.83.145.6", "userAgent": "azurehound/v2.1.8", "requestUri": "https://graph.microsoft.com/beta/servicePrincipals/ffe3e001-d8cf-43a4-89ab-bfce35fd7786/owners?%24top=999", "userId": "7b934539-7366-494e-a8ac-3517694d32db", "tokenIssuedAt": "2024-04-30T01:17:30.0000000Z"}, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143"}' diff --git a/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml b/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml index 8c5adbf8ae..41469630c5 100644 --- a/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml +++ b/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml @@ -1,8 +1,8 @@ name: Azure Active Directory NonInteractiveUserSignInLogs id: 11fe8a43-164d-47e4-b542-afc2f242068b -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Bhavin Patel, Splunk description: Data source object for Azure Active Directory NonInteractiveUserSignInLogs source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - action - additional_details diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml index da60f90a28..24e05a01bc 100644 --- a/data_sources/azure_active_directory_reset_password_(by_admin).yml +++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml @@ -1,8 +1,8 @@ name: Azure Active Directory Reset password (by admin) id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when an admin resets a user's password in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Reset password (by admin) supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml index 9a0c666f20..1979b9e01c 100644 --- a/data_sources/azure_active_directory_set_domain_authentication.yml +++ b/data_sources/azure_active_directory_set_domain_authentication.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Set domain authentication id: e7bcdab9-908c-40ab-ba38-5db54fa87750 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified. mitre_components: @@ -16,7 +16,7 @@ separator_value: Set domain authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml index d6888c0dee..5422691296 100644 --- a/data_sources/azure_active_directory_sign_in_activity.yml +++ b/data_sources/azure_active_directory_sign_in_activity.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Sign-in activity id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes. mitre_components: @@ -16,7 +16,7 @@ separator_value: Sign-in activity supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml index b0ae6b37c9..06068873ac 100644 --- a/data_sources/azure_active_directory_update_application.yml +++ b/data_sources/azure_active_directory_update_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update application id: 2c08188a-ba25-496e-87c7-803cf28b6c90 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions. mitre_components: @@ -16,7 +16,7 @@ separator_value: Update application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml index 7a086791e4..d65fb762c1 100644 --- a/data_sources/azure_active_directory_update_authorization_policy.yml +++ b/data_sources/azure_active_directory_update_authorization_policy.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update authorization policy id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when an authorization policy is updated in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Update authorization policy supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml index f0ca04a229..0aec2427cf 100644 --- a/data_sources/azure_active_directory_update_user.yml +++ b/data_sources/azure_active_directory_update_user.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update user id: 5495c90a-047c-4b8e-b2fe-1db6282d3872 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when a user account is updated in Azure Active Directory. mitre_components: @@ -15,7 +15,7 @@ separator_value: Update user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml index ce39762a76..f80440e810 100644 --- a/data_sources/azure_active_directory_user_registered_security_info.yml +++ b/data_sources/azure_active_directory_user_registered_security_info.yml @@ -1,8 +1,8 @@ name: Azure Active Directory User registered security info id: b63240de-8a01-4ba8-8987-89d18d4b375d -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when a user registers or updates their security information in Azure Active Directory. mitre_components: @@ -15,7 +15,7 @@ separator_value: User registered security info supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - Level diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml index fb083554f3..92b9a8bc1a 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation account id: 2ab182e7-feda-4249-9418-32710b55a885 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Automation account is created or updated. mitre_components: @@ -16,7 +16,7 @@ separator_value: Create or Update an Azure Automation account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - authorization.action diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml index 1c61b96dac..0f1f853a67 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation Runbook id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: Create or Update an Azure Automation Runbook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - authorization.action diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml index c1d309bda9..6c35ac44d4 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation webhook id: 575faeb2-09d0-4849-b1f6-eae241f26ff2 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Patrick Bareiss, Splunk description: Logs an event when a webhook is created or updated in Azure Automation. mitre_components: @@ -16,7 +16,7 @@ separator_value: Create or Update an Azure Automation webhook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - _time - authorization.action diff --git a/data_sources/azure_monitor_activity.yml b/data_sources/azure_monitor_activity.yml index 5b89633bdb..bc882f6d6b 100644 --- a/data_sources/azure_monitor_activity.yml +++ b/data_sources/azure_monitor_activity.yml @@ -1,8 +1,8 @@ name: Azure Monitor Activity id: 1997a515-a61a-4f78-ada9-54af34c764f2 -version: 2 +version: 3 creation_date: '2025-01-13' -modification_date: '2026-05-13' +modification_date: '2026-07-17' author: Bhavin Patel, Splunk description: Data source object for Azure Monitor Activity. The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub. source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.0 fields: - column - action From 553392f286dd539b049042aa84da861bfc17cba6 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Mon, 20 Jul 2026 11:34:32 +0000 Subject: [PATCH 14/32] Update datasource TA versions --- data_sources/asl_aws_cloudtrail.yml | 6 +++--- data_sources/aws_cloudfront.yml | 6 +++--- data_sources/aws_cloudtrail.yml | 6 +++--- data_sources/aws_cloudtrail_assumerolewithsaml.yml | 6 +++--- data_sources/aws_cloudtrail_consolelogin.yml | 6 +++--- data_sources/aws_cloudtrail_copyobject.yml | 6 +++--- data_sources/aws_cloudtrail_createaccesskey.yml | 6 +++--- data_sources/aws_cloudtrail_createkey.yml | 6 +++--- data_sources/aws_cloudtrail_createloginprofile.yml | 6 +++--- data_sources/aws_cloudtrail_createnetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_createpolicyversion.yml | 6 +++--- data_sources/aws_cloudtrail_createsnapshot.yml | 6 +++--- data_sources/aws_cloudtrail_createtask.yml | 6 +++--- data_sources/aws_cloudtrail_createvirtualmfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deactivatemfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_deletealarms.yml | 6 +++--- data_sources/aws_cloudtrail_deletedetector.yml | 6 +++--- data_sources/aws_cloudtrail_deletegroup.yml | 6 +++--- data_sources/aws_cloudtrail_deleteguardrail.yml | 6 +++--- data_sources/aws_cloudtrail_deleteipset.yml | 6 +++--- data_sources/aws_cloudtrail_deleteknowledgebase.yml | 6 +++--- data_sources/aws_cloudtrail_deleteloggingconfiguration.yml | 6 +++--- data_sources/aws_cloudtrail_deleteloggroup.yml | 6 +++--- data_sources/aws_cloudtrail_deletelogstream.yml | 6 +++--- ...cloudtrail_deletemodelinvocationloggingconfiguration.yml | 6 +++--- data_sources/aws_cloudtrail_deletenetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_deletepolicy.yml | 6 +++--- data_sources/aws_cloudtrail_deleterule.yml | 6 +++--- data_sources/aws_cloudtrail_deleterulegroup.yml | 6 +++--- data_sources/aws_cloudtrail_deletesnapshot.yml | 6 +++--- data_sources/aws_cloudtrail_deletetrail.yml | 6 +++--- data_sources/aws_cloudtrail_deletevirtualmfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deletewebacl.yml | 6 +++--- data_sources/aws_cloudtrail_describeeventaggregates.yml | 6 +++--- data_sources/aws_cloudtrail_describeimagescanfindings.yml | 6 +++--- data_sources/aws_cloudtrail_describesnapshotattribute.yml | 6 +++--- data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_getobject.yml | 6 +++--- data_sources/aws_cloudtrail_getpassworddata.yml | 6 +++--- data_sources/aws_cloudtrail_invokemodel.yml | 6 +++--- data_sources/aws_cloudtrail_jobcreated.yml | 6 +++--- data_sources/aws_cloudtrail_listfoundationmodels.yml | 6 +++--- data_sources/aws_cloudtrail_modifydbinstance.yml | 6 +++--- data_sources/aws_cloudtrail_modifyimageattribute.yml | 6 +++--- data_sources/aws_cloudtrail_modifysnapshotattribute.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketacl.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketlifecycle.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketreplication.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketversioning.yml | 6 +++--- data_sources/aws_cloudtrail_putimage.yml | 6 +++--- data_sources/aws_cloudtrail_putkeypolicy.yml | 6 +++--- data_sources/aws_cloudtrail_replacenetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_setdefaultpolicyversion.yml | 6 +++--- data_sources/aws_cloudtrail_stoplogging.yml | 6 +++--- data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_updateloginprofile.yml | 6 +++--- data_sources/aws_cloudtrail_updatesamlprovider.yml | 6 +++--- data_sources/aws_cloudtrail_updatetrail.yml | 6 +++--- data_sources/aws_cloudwatchlogs_vpcflow.yml | 6 +++--- data_sources/aws_security_hub.yml | 6 +++--- 61 files changed, 183 insertions(+), 183 deletions(-) diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index c40126191c..ff5ef21df4 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -1,8 +1,8 @@ name: ASL AWS CloudTrail id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898 -version: 3 +version: 4 creation_date: '2025-01-14' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Represents AWS API dataset data collection from Amazon Security Lake. mitre_components: @@ -24,7 +24,7 @@ separator: api.operation supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 output_fields: - dest - user diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml index dbe9bbafd8..654d75b8b2 100644 --- a/data_sources/aws_cloudfront.yml +++ b/data_sources/aws_cloudfront.yml @@ -1,8 +1,8 @@ name: AWS Cloudfront id: 780086dc-2384-45b6-ade7-56cb00105464 -version: 3 +version: 4 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics. mitre_components: @@ -17,7 +17,7 @@ sourcetype: aws:cloudfront:accesslogs supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail.yml b/data_sources/aws_cloudtrail.yml index d80e70b155..1db2a95a38 100644 --- a/data_sources/aws_cloudtrail.yml +++ b/data_sources/aws_cloudtrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail id: e8ace6db-1dbd-4c72-a1fb-334684619a38 -version: 2 +version: 3 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: All AWS CloudTrail events source: aws_cloudtrail @@ -11,4 +11,4 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml index efe8b33ddb..7c1ec90971 100644 --- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml +++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail AssumeRoleWithSAML id: 1e28f2a6-2db9-405f-b298-18734a293f77 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs attempts to assume roles via SAML authentication in AWS, including details of identity provider and role mapping. mitre_components: @@ -18,7 +18,7 @@ separator_value: AssumeRoleWithSAML supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml index 47f47f1900..eb1a5291bd 100644 --- a/data_sources/aws_cloudtrail_consolelogin.yml +++ b/data_sources/aws_cloudtrail_consolelogin.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ConsoleLogin id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events. mitre_components: @@ -18,7 +18,7 @@ separator_value: ConsoleLogin supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index afce3a4582..293e495c02 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CopyObject id: 965083f4-64a8-403f-99cc-252e1a6bd3b6 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination. mitre_components: @@ -17,7 +17,7 @@ separator_value: CopyObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml index 55fa3c5e41..b0be0502e9 100644 --- a/data_sources/aws_cloudtrail_createaccesskey.yml +++ b/data_sources/aws_cloudtrail_createaccesskey.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateAccessKey id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the creation of new AWS access keys, including details of the associated user and permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateAccessKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml index a421c79763..3f5d9a90ea 100644 --- a/data_sources/aws_cloudtrail_createkey.yml +++ b/data_sources/aws_cloudtrail_createkey.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateKey id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml index 3f8eab8b67..b1aaa7c6cc 100644 --- a/data_sources/aws_cloudtrail_createloginprofile.yml +++ b/data_sources/aws_cloudtrail_createloginprofile.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateLoginProfile id: 0024fdb1-0d62-4449-970a-746952cf80b6 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml index 1ad5447148..5c60071db3 100644 --- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateNetworkAclEntry id: 45934028-10ec-4ab5-a7b1-a6349b833e67 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml index dfd4ba9321..5d3f954868 100644 --- a/data_sources/aws_cloudtrail_createpolicyversion.yml +++ b/data_sources/aws_cloudtrail_createpolicyversion.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreatePolicyVersion id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreatePolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml index e2a3e40ce3..a23a4a2888 100644 --- a/data_sources/aws_cloudtrail_createsnapshot.yml +++ b/data_sources/aws_cloudtrail_createsnapshot.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateSnapshot id: 514135a2-f4b2-4d32-8f31-d87824887f9f -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index 1a462fcf5d..d6e9e6301f 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateTask id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateTask supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml index 1dd734b3c2..69df8ce713 100644 --- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateVirtualMFADevice id: 13e6e952-0dad-4190-865c-fb5911725f7a -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml index bf04e2a317..63c6c76b56 100644 --- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml +++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeactivateMFADevice id: 7397a10b-1150-4de9-8062-a96454ae53b2 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeactivateMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml index e08314d029..f0d6815a9c 100644 --- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteAccountPasswordPolicy id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml index 44405c5e8b..29a241bd43 100644 --- a/data_sources/aws_cloudtrail_deletealarms.yml +++ b/data_sources/aws_cloudtrail_deletealarms.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteAlarms id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f -version: 3 +version: 4 creation_date: '2024-08-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteAlarms supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml index 3d53d8c6c7..fb03e28da9 100644 --- a/data_sources/aws_cloudtrail_deletedetector.yml +++ b/data_sources/aws_cloudtrail_deletedetector.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteDetector id: 5d8bd475-c8bc-4447-b27f-efa508728b90 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteDetector supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml index 67d95cdb65..db0dca7ae1 100644 --- a/data_sources/aws_cloudtrail_deletegroup.yml +++ b/data_sources/aws_cloudtrail_deletegroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteGroup id: c95308a4-a943-42ca-b112-f90a05c21bd3 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteguardrail.yml b/data_sources/aws_cloudtrail_deleteguardrail.yml index c4f6cc2598..eb00338eda 100644 --- a/data_sources/aws_cloudtrail_deleteguardrail.yml +++ b/data_sources/aws_cloudtrail_deleteguardrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteGuardrail id: 2f6e9d7a-1c53-48b1-be57-33a91e0f8c42 -version: 2 +version: 3 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Logs an event when a guardrail is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteGuardrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml index 010c2162c1..84ef4da7ab 100644 --- a/data_sources/aws_cloudtrail_deleteipset.yml +++ b/data_sources/aws_cloudtrail_deleteipset.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteIPSet id: ebdeeb63-77a0-4808-a6fe-549956731377 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations. mitre_components: @@ -16,7 +16,7 @@ separator_value: DeleteIPSet supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deleteknowledgebase.yml b/data_sources/aws_cloudtrail_deleteknowledgebase.yml index 8b13e8bdc2..be2b969bef 100644 --- a/data_sources/aws_cloudtrail_deleteknowledgebase.yml +++ b/data_sources/aws_cloudtrail_deleteknowledgebase.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteKnowledgeBase id: a8c47f25-5693-4d1a-9f8b-6e94d15ac2d9 -version: 2 +version: 3 creation_date: '2025-04-17' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Logs an event when a knowledge base is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteKnowledgeBase supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml b/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml index 55c95ea4ad..ba8df958a5 100644 --- a/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml +++ b/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLoggingConfiguration id: 24a28726-28f3-4537-a953-71bfbbc3b831 -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DeleteLoggingConfiguration source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time example_log: '' diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml index 3809b00a30..1f0112a459 100644 --- a/data_sources/aws_cloudtrail_deleteloggroup.yml +++ b/data_sources/aws_cloudtrail_deleteloggroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLogGroup id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteLogGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml index 7270838ad1..d21638a834 100644 --- a/data_sources/aws_cloudtrail_deletelogstream.yml +++ b/data_sources/aws_cloudtrail_deletelogstream.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLogStream id: 6f8bb808-89f8-465e-a34d-229df2f46402 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteLogStream supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml b/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml index 614f3fd068..ba446896df 100644 --- a/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml +++ b/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteModelInvocationLoggingConfiguration id: fe2b3a52-1c8d-4e17-9f74-76c531a87e21 -version: 2 +version: 3 creation_date: '2025-04-17' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Logs an event when a model invocation logging configuration is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteModelInvocationLoggingConfiguration supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml index 6562a321da..a93bae517c 100644 --- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteNetworkAclEntry id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL. mitre_components: @@ -16,7 +16,7 @@ separator_value: DeleteNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml index 84c522f2f4..62213eb38e 100644 --- a/data_sources/aws_cloudtrail_deletepolicy.yml +++ b/data_sources/aws_cloudtrail_deletepolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeletePolicy id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeletePolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml index 4929e2e883..30caaccb51 100644 --- a/data_sources/aws_cloudtrail_deleterule.yml +++ b/data_sources/aws_cloudtrail_deleterule.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteRule id: b5760623-f3ca-492d-a372-d5c2b3567dfc -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteRule supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deleterulegroup.yml b/data_sources/aws_cloudtrail_deleterulegroup.yml index b8105c4862..f4214f0c9e 100644 --- a/data_sources/aws_cloudtrail_deleterulegroup.yml +++ b/data_sources/aws_cloudtrail_deleterulegroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteRuleGroup id: 21c9b538-fa11-4bdf-9138-0dfe06b4d730 -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DeleteRuleGroup source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time example_log: '' diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml index c234e022e6..3bea186387 100644 --- a/data_sources/aws_cloudtrail_deletesnapshot.yml +++ b/data_sources/aws_cloudtrail_deletesnapshot.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteSnapshot id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f -version: 3 +version: 4 creation_date: '2024-08-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml index e52c960d46..d79a2536a8 100644 --- a/data_sources/aws_cloudtrail_deletetrail.yml +++ b/data_sources/aws_cloudtrail_deletetrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteTrail id: a5af09ff-07b6-4df6-92a0-2146bfe402c8 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml index abcf17e438..3f43296acb 100644 --- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteVirtualMFADevice id: 84a08d6b-3d59-4260-8cab-84278ada262f -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml index c88017ac48..b65017b448 100644 --- a/data_sources/aws_cloudtrail_deletewebacl.yml +++ b/data_sources/aws_cloudtrail_deletewebacl.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteWebACL id: 90da5f08-7961-4c29-8de8-01364982aadf -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteWebACL supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml index ee363cb8cd..3d41adcfd2 100644 --- a/data_sources/aws_cloudtrail_describeeventaggregates.yml +++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeEventAggregates id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when aggregate details about AWS events are queried, often for analysis. mitre_components: @@ -15,7 +15,7 @@ separator_value: DescribeEventAggregates supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml index d19da791f6..302b2b8f02 100644 --- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml +++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeImageScanFindings id: 688ea789-9ba2-4970-90a2-17e541e273c9 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail. mitre_components: @@ -16,7 +16,7 @@ separator_value: DescribeImageScanFindings supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_describesnapshotattribute.yml b/data_sources/aws_cloudtrail_describesnapshotattribute.yml index 2346b22494..1bfb2496ea 100644 --- a/data_sources/aws_cloudtrail_describesnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_describesnapshotattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeSnapshotAttribute id: f054c99b-63b8-4236-8a62-b52fbbabacba -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DescribeSnapshotAttribute source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - action - app diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml index 38d1565418..460ad7ba51 100644 --- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetAccountPasswordPolicy id: 439bdc53-6e4b-4cd7-b326-86c7317fd396 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to get the account password policy in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: GetAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml index c39f7ca141..9a75bca557 100644 --- a/data_sources/aws_cloudtrail_getobject.yml +++ b/data_sources/aws_cloudtrail_getobject.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetObject id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to access an object stored in an AWS S3 bucket. mitre_components: @@ -16,7 +16,7 @@ separator_value: GetObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml index 060a86c2dc..ec62d994c9 100644 --- a/data_sources/aws_cloudtrail_getpassworddata.yml +++ b/data_sources/aws_cloudtrail_getpassworddata.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetPasswordData id: 6ff2ce99-85b1-4c17-888a-56dbc3570671 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance. mitre_components: @@ -15,7 +15,7 @@ separator_value: GetPasswordData supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_invokemodel.yml b/data_sources/aws_cloudtrail_invokemodel.yml index 924c2c1367..99f7cf7853 100644 --- a/data_sources/aws_cloudtrail_invokemodel.yml +++ b/data_sources/aws_cloudtrail_invokemodel.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail InvokeModel id: 5d92a1b6-3e78-4ff2-be83-7a4c01f9df6c -version: 2 +version: 3 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Logs an event when a model is invoked within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: InvokeModel supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml index 83b42f8449..baa1d2b80a 100644 --- a/data_sources/aws_cloudtrail_jobcreated.yml +++ b/data_sources/aws_cloudtrail_jobcreated.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail JobCreated id: 6473289b-d097-4c86-a837-3cc5ae408155 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a new job is created in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: JobCreated supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_listfoundationmodels.yml b/data_sources/aws_cloudtrail_listfoundationmodels.yml index 06a7cd7584..1a4a083886 100644 --- a/data_sources/aws_cloudtrail_listfoundationmodels.yml +++ b/data_sources/aws_cloudtrail_listfoundationmodels.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ListFoundationModels id: e7f31c68-84b9-4d21-a8c5-ec9d2fb3a457 -version: 2 +version: 3 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Logs an event when a list of foundation models is requested within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: ListFoundationModels supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml index a6b0eeca89..c24648e2ef 100644 --- a/data_sources/aws_cloudtrail_modifydbinstance.yml +++ b/data_sources/aws_cloudtrail_modifydbinstance.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifyDBInstance id: bfa2912d-1a33-4b05-be46-543874d68241 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations. mitre_components: @@ -16,7 +16,7 @@ separator_value: ModifyDBInstance supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml index 272e734d13..92e743de36 100644 --- a/data_sources/aws_cloudtrail_modifyimageattribute.yml +++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifyImageAttribute id: 667c2115-8082-419e-b541-8150066bda4d -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified. mitre_components: @@ -15,7 +15,7 @@ separator_value: ModifyImageAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml index afebb51c8f..1f1d1f8dbf 100644 --- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifySnapshotAttribute id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: ModifySnapshotAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml index 172b11719d..c8e339e26a 100644 --- a/data_sources/aws_cloudtrail_putbucketacl.yml +++ b/data_sources/aws_cloudtrail_putbucketacl.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketAcl id: 28fffbfd-d98d-4a42-990b-b04ab47422eb -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutBucketAcl supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml index c24c6c2417..fe9b0743e7 100644 --- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml +++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketLifecycle id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutBucketLifecycle supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml index ac76f2f355..c9678d8ac0 100644 --- a/data_sources/aws_cloudtrail_putbucketreplication.yml +++ b/data_sources/aws_cloudtrail_putbucketreplication.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketReplication id: 0e1362eb-e592-419f-8fa5-556d3a122417 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when replication configurations are added or modified for an S3 bucket. mitre_components: @@ -14,7 +14,7 @@ separator_value: PutBucketReplication supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml index 9f834c10ce..7fba284a5d 100644 --- a/data_sources/aws_cloudtrail_putbucketversioning.yml +++ b/data_sources/aws_cloudtrail_putbucketversioning.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketVersioning id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket. mitre_components: @@ -14,7 +14,7 @@ separator_value: PutBucketVersioning supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml index 22e5498275..4ab09f0341 100644 --- a/data_sources/aws_cloudtrail_putimage.yml +++ b/data_sources/aws_cloudtrail_putimage.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutImage id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutImage supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml index 37d43a3286..91c0f63c35 100644 --- a/data_sources/aws_cloudtrail_putkeypolicy.yml +++ b/data_sources/aws_cloudtrail_putkeypolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutKeyPolicy id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs changes made to AWS Key Management Service (KMS) key policies, including updates and permission assignments. mitre_components: @@ -13,7 +13,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml index 34e190129c..07c6f17851 100644 --- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ReplaceNetworkAclEntry id: db0c240e-3754-40e4-86ef-cde018ee9f65 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: ReplaceNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml index c3264444c1..e8e0e1267c 100644 --- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml +++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail SetDefaultPolicyVersion id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when the default version of a resource policy in AWS is set or changed. mitre_components: @@ -15,7 +15,7 @@ separator_value: SetDefaultPolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml index 7858189b11..539e18aa7a 100644 --- a/data_sources/aws_cloudtrail_stoplogging.yml +++ b/data_sources/aws_cloudtrail_stoplogging.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail StopLogging id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped. mitre_components: @@ -14,7 +14,7 @@ separator_value: StopLogging supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml index 9790a74d67..776d4d77ac 100644 --- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateAccountPasswordPolicy id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when an AWS account's password policy is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml index 2e58b10a33..df17c74e71 100644 --- a/data_sources/aws_cloudtrail_updateloginprofile.yml +++ b/data_sources/aws_cloudtrail_updateloginprofile.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateLoginProfile id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when an IAM user's login profile is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml index 755e03f508..dcacdeddf9 100644 --- a/data_sources/aws_cloudtrail_updatesamlprovider.yml +++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateSAMLProvider id: e5eb628d-711e-499c-87d9-8fa5dee419ec -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when a SAML provider is updated in AWS. mitre_components: @@ -16,7 +16,7 @@ separator_value: UpdateSAMLProvider supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml index cd980da894..5dfc178caf 100644 --- a/data_sources/aws_cloudtrail_updatetrail.yml +++ b/data_sources/aws_cloudtrail_updatetrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateTrail id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - app diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml index eb0cdc7ecf..7e468d8d82 100644 --- a/data_sources/aws_cloudwatchlogs_vpcflow.yml +++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml @@ -1,8 +1,8 @@ name: AWS CloudWatchLogs VPCflow id: 38a34fc4-e128-4478-a8f4-7835d51d5135 -version: 3 +version: 4 creation_date: '2024-07-31' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Logs an event when network traffic flow information such as source and destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS. mitre_components: @@ -12,7 +12,7 @@ source: aws_cloudwatchlogs_vpcflow sourcetype: aws:cloudwatchlogs:vpcflow supported_TA: - name: Splunk Add-on for AWS - version: 8.1.2 + version: 8.2.0 url: https://splunkbase.splunk.com/app/1876 fields: - _raw diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml index b2bda6430e..4c8d0d7874 100644 --- a/data_sources/aws_security_hub.yml +++ b/data_sources/aws_security_hub.yml @@ -1,8 +1,8 @@ name: AWS Security Hub id: b02bfbf3-294f-478e-99a1-e24b8c692d7e -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-07-20' author: Patrick Bareiss, Splunk description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts. mitre_components: @@ -15,7 +15,7 @@ sourcetype: aws:securityhub:finding supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.1.2 + version: 8.2.0 fields: - _time - AwsAccountId From 6e02f07f4be353a298712d158a401564529cef6f Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Mon, 20 Jul 2026 19:22:45 +0000 Subject: [PATCH 15/32] Update datasource TA versions --- data_sources/cisco_secure_access_dns.yml | 6 +++--- data_sources/cisco_secure_access_firewall.yml | 6 +++--- data_sources/cisco_secure_access_proxy.yml | 6 +++--- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/data_sources/cisco_secure_access_dns.yml b/data_sources/cisco_secure_access_dns.yml index 127286df5e..bdbb24f7eb 100644 --- a/data_sources/cisco_secure_access_dns.yml +++ b/data_sources/cisco_secure_access_dns.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access DNS id: 5673dba3-cae9-449e-8991-03832d79f729 -version: 2 +version: 3 creation_date: '2026-05-06' -modification_date: '2026-07-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: | Captures DNS security events from Cisco Secure Access (including Umbrella-style DNS policy and roaming client telemetry) with client identity, query and response metadata, resolved domain, and URL/content categorization. @@ -12,7 +12,7 @@ sourcetype: cisco:cloud_security:dns supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.52 + version: 1.0.53 fields: - RecordType - ReplyCode diff --git a/data_sources/cisco_secure_access_firewall.yml b/data_sources/cisco_secure_access_firewall.yml index 78f544c792..82102814c2 100644 --- a/data_sources/cisco_secure_access_firewall.yml +++ b/data_sources/cisco_secure_access_firewall.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access Firewall id: 5dc07487-f834-4850-b6a7-4cc09e56549b -version: 3 +version: 4 creation_date: '2026-04-29' -modification_date: '2026-07-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: Captures firewall connection events from Cisco Secure Access including user identity, source and destination metadata, protocol details, and session statistics. Enables analysis of network traffic patterns, access policy enforcement, brute force attempts, and anomalous connection behavior across cloud-managed network access infrastructure. source: cisco_secure_access:firewall @@ -10,7 +10,7 @@ sourcetype: cisco:cloud_security:firewall supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.52 + version: 1.0.53 fields: - _time - action diff --git a/data_sources/cisco_secure_access_proxy.yml b/data_sources/cisco_secure_access_proxy.yml index 622012e3bd..cdd959f3ad 100644 --- a/data_sources/cisco_secure_access_proxy.yml +++ b/data_sources/cisco_secure_access_proxy.yml @@ -1,8 +1,8 @@ name: Cisco Secure Access Proxy id: 2dc95ec2-8964-4ddb-8714-8d7dfe264922 -version: 2 +version: 3 creation_date: '2026-05-08' -modification_date: '2026-07-13' +modification_date: '2026-07-20' author: Bhavin Patel, Splunk description: | Captures HTTP/HTTPS proxy access events from Cisco Secure Access, including requesting source, user identity, URL, HTTP method, response status, and user-agent metadata. @@ -12,7 +12,7 @@ sourcetype: cisco:cloud_security:proxy supported_TA: - name: Cisco Secure Access Add-on for Splunk url: https://splunkbase.splunk.com/app/7569 - version: 1.0.52 + version: 1.0.53 fields: - _time - action From 8c63c1b6ab303f7166e9513d44044afe888aae5f Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Tue, 21 Jul 2026 10:13:14 +0000 Subject: [PATCH 16/32] Update datasource TA versions --- data_sources/ms365_defender_incident_alerts.yml | 6 +++--- data_sources/ms_defender_atp_alerts.yml | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/data_sources/ms365_defender_incident_alerts.yml b/data_sources/ms365_defender_incident_alerts.yml index 7d33235198..5e2f25797f 100644 --- a/data_sources/ms365_defender_incident_alerts.yml +++ b/data_sources/ms365_defender_incident_alerts.yml @@ -1,8 +1,8 @@ name: MS365 Defender Incident Alerts id: 12345678-90ab-cdef-1234-567890abcdef -version: 3 +version: 4 creation_date: '2024-10-29' -modification_date: '2026-05-13' +modification_date: '2026-07-21' author: Bhavin Patel, Splunk description: Logs security incidents and correlated alerts in Microsoft 365 Defender, including details about affected assets, threat types, and remediation steps. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ms365:defender:incident:alerts supported_TA: - name: Splunk Add-on for Microsoft Security url: https://splunkbase.splunk.com/app/6207 - version: 3.0.0 + version: 4.0.0 fields: - actorName - alertId diff --git a/data_sources/ms_defender_atp_alerts.yml b/data_sources/ms_defender_atp_alerts.yml index a38abee6a2..3263b1edaa 100644 --- a/data_sources/ms_defender_atp_alerts.yml +++ b/data_sources/ms_defender_atp_alerts.yml @@ -1,8 +1,8 @@ name: MS Defender ATP Alerts id: 38f034ed-1598-46c8-95e8-14edf01fdf5d -version: 3 +version: 4 creation_date: '2024-11-07' -modification_date: '2026-05-13' +modification_date: '2026-07-21' author: Bryan Pluta, Bhavin Patel, Splunk description: Logs security alerts generated by Microsoft Defender for Endpoint, including information about detected threats, impacted devices, and recommended actions. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ms:defender:atp:alerts supported_TA: - name: Splunk Add-on for Microsoft Security url: https://splunkbase.splunk.com/app/6207 - version: 3.0.0 + version: 4.0.0 fields: - column - accountName From 5781ffd0f21a9d9fd7ad2fd5e60a4b082d453eef Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Fri, 24 Jul 2026 21:54:13 +0000 Subject: [PATCH 17/32] Update datasource TA versions --- data_sources/asl_aws_cloudtrail.yml | 6 +++--- data_sources/aws_cloudfront.yml | 6 +++--- data_sources/aws_cloudtrail.yml | 6 +++--- data_sources/aws_cloudtrail_assumerolewithsaml.yml | 6 +++--- data_sources/aws_cloudtrail_consolelogin.yml | 6 +++--- data_sources/aws_cloudtrail_copyobject.yml | 6 +++--- data_sources/aws_cloudtrail_createaccesskey.yml | 6 +++--- data_sources/aws_cloudtrail_createkey.yml | 6 +++--- data_sources/aws_cloudtrail_createloginprofile.yml | 6 +++--- data_sources/aws_cloudtrail_createnetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_createpolicyversion.yml | 6 +++--- data_sources/aws_cloudtrail_createsnapshot.yml | 6 +++--- data_sources/aws_cloudtrail_createtask.yml | 6 +++--- data_sources/aws_cloudtrail_createvirtualmfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deactivatemfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_deletealarms.yml | 6 +++--- data_sources/aws_cloudtrail_deletedetector.yml | 6 +++--- data_sources/aws_cloudtrail_deletegroup.yml | 6 +++--- data_sources/aws_cloudtrail_deleteguardrail.yml | 6 +++--- data_sources/aws_cloudtrail_deleteipset.yml | 6 +++--- data_sources/aws_cloudtrail_deleteknowledgebase.yml | 6 +++--- data_sources/aws_cloudtrail_deleteloggingconfiguration.yml | 6 +++--- data_sources/aws_cloudtrail_deleteloggroup.yml | 6 +++--- data_sources/aws_cloudtrail_deletelogstream.yml | 6 +++--- ...cloudtrail_deletemodelinvocationloggingconfiguration.yml | 6 +++--- data_sources/aws_cloudtrail_deletenetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_deletepolicy.yml | 6 +++--- data_sources/aws_cloudtrail_deleterule.yml | 6 +++--- data_sources/aws_cloudtrail_deleterulegroup.yml | 6 +++--- data_sources/aws_cloudtrail_deletesnapshot.yml | 6 +++--- data_sources/aws_cloudtrail_deletetrail.yml | 6 +++--- data_sources/aws_cloudtrail_deletevirtualmfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deletewebacl.yml | 6 +++--- data_sources/aws_cloudtrail_describeeventaggregates.yml | 6 +++--- data_sources/aws_cloudtrail_describeimagescanfindings.yml | 6 +++--- data_sources/aws_cloudtrail_describesnapshotattribute.yml | 6 +++--- data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_getobject.yml | 6 +++--- data_sources/aws_cloudtrail_getpassworddata.yml | 6 +++--- data_sources/aws_cloudtrail_invokemodel.yml | 6 +++--- data_sources/aws_cloudtrail_jobcreated.yml | 6 +++--- data_sources/aws_cloudtrail_listfoundationmodels.yml | 6 +++--- data_sources/aws_cloudtrail_modifydbinstance.yml | 6 +++--- data_sources/aws_cloudtrail_modifyimageattribute.yml | 6 +++--- data_sources/aws_cloudtrail_modifysnapshotattribute.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketacl.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketlifecycle.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketreplication.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketversioning.yml | 6 +++--- data_sources/aws_cloudtrail_putimage.yml | 6 +++--- data_sources/aws_cloudtrail_putkeypolicy.yml | 6 +++--- data_sources/aws_cloudtrail_replacenetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_setdefaultpolicyversion.yml | 6 +++--- data_sources/aws_cloudtrail_stoplogging.yml | 6 +++--- data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_updateloginprofile.yml | 6 +++--- data_sources/aws_cloudtrail_updatesamlprovider.yml | 6 +++--- data_sources/aws_cloudtrail_updatetrail.yml | 6 +++--- data_sources/aws_cloudwatchlogs_vpcflow.yml | 6 +++--- data_sources/aws_security_hub.yml | 6 +++--- data_sources/azure_active_directory.yml | 6 +++--- ...rectory_add_app_role_assignment_to_service_principal.yml | 6 +++--- data_sources/azure_active_directory_add_member_to_role.yml | 6 +++--- .../azure_active_directory_add_owner_to_application.yml | 6 +++--- .../azure_active_directory_add_service_principal.yml | 6 +++--- .../azure_active_directory_add_unverified_domain.yml | 6 +++--- .../azure_active_directory_consent_to_application.yml | 6 +++--- ...azure_active_directory_disable_strong_authentication.yml | 6 +++--- data_sources/azure_active_directory_enable_account.yml | 6 +++--- .../azure_active_directory_invite_external_user.yml | 6 +++--- .../azure_active_directory_microsoftgraphactivitylogs.yml | 6 +++--- .../azure_active_directory_noninteractiveusersigninlogs.yml | 6 +++--- .../azure_active_directory_reset_password_(by_admin).yml | 6 +++--- .../azure_active_directory_set_domain_authentication.yml | 6 +++--- data_sources/azure_active_directory_sign_in_activity.yml | 6 +++--- data_sources/azure_active_directory_update_application.yml | 6 +++--- .../azure_active_directory_update_authorization_policy.yml | 6 +++--- data_sources/azure_active_directory_update_user.yml | 6 +++--- ...azure_active_directory_user_registered_security_info.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_account.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_runbook.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_webhook.yml | 6 +++--- data_sources/azure_monitor_activity.yml | 6 +++--- data_sources/linux_auditd_add_user.yml | 6 +++--- data_sources/linux_auditd_cwd.yml | 6 +++--- data_sources/linux_auditd_daemon_abort.yml | 6 +++--- data_sources/linux_auditd_daemon_end.yml | 6 +++--- data_sources/linux_auditd_daemon_start.yml | 6 +++--- data_sources/linux_auditd_execve.yml | 6 +++--- data_sources/linux_auditd_path.yml | 6 +++--- data_sources/linux_auditd_proctitle.yml | 6 +++--- data_sources/linux_auditd_service_stop.yml | 6 +++--- data_sources/linux_auditd_syscall.yml | 6 +++--- data_sources/linux_messages_syslog.yml | 6 +++--- data_sources/linux_secure.yml | 6 +++--- data_sources/ntlm_operational_8004.yml | 6 +++--- data_sources/ntlm_operational_8005.yml | 6 +++--- data_sources/ntlm_operational_8006.yml | 6 +++--- data_sources/powershell_script_block_logging_4104.yml | 6 +++--- data_sources/windows_active_directory_admon.yml | 6 +++--- data_sources/windows_event_log_application_15457.yml | 6 +++--- data_sources/windows_event_log_application_17135.yml | 6 +++--- data_sources/windows_event_log_application_2282.yml | 6 +++--- data_sources/windows_event_log_application_3000.yml | 6 +++--- data_sources/windows_event_log_application_8128.yml | 6 +++--- .../windows_event_log_appxdeployment_server_400.yml | 6 +++--- .../windows_event_log_appxdeployment_server_854.yml | 6 +++--- .../windows_event_log_appxdeployment_server_855.yml | 6 +++--- data_sources/windows_event_log_appxpackaging_171.yml | 6 +++--- data_sources/windows_event_log_capi2_70.yml | 6 +++--- data_sources/windows_event_log_capi2_81.yml | 6 +++--- .../windows_event_log_certificateservicesclient_1007.yml | 6 +++--- data_sources/windows_event_log_defender_1121.yml | 6 +++--- data_sources/windows_event_log_defender_1122.yml | 6 +++--- data_sources/windows_event_log_defender_1125.yml | 6 +++--- data_sources/windows_event_log_defender_1126.yml | 6 +++--- data_sources/windows_event_log_defender_1129.yml | 6 +++--- data_sources/windows_event_log_defender_1131.yml | 6 +++--- data_sources/windows_event_log_defender_1132.yml | 6 +++--- data_sources/windows_event_log_defender_1133.yml | 6 +++--- data_sources/windows_event_log_defender_1134.yml | 6 +++--- data_sources/windows_event_log_defender_5007.yml | 6 +++--- data_sources/windows_event_log_printservice_316.yml | 6 +++--- data_sources/windows_event_log_printservice_4909.yml | 6 +++--- data_sources/windows_event_log_printservice_808.yml | 6 +++--- .../windows_event_log_remoteconnectionmanager_1149.yml | 6 +++--- data_sources/windows_event_log_security_1100.yml | 6 +++--- data_sources/windows_event_log_security_1102.yml | 6 +++--- data_sources/windows_event_log_security_4624.yml | 6 +++--- data_sources/windows_event_log_security_4625.yml | 6 +++--- data_sources/windows_event_log_security_4627.yml | 6 +++--- data_sources/windows_event_log_security_4648.yml | 6 +++--- data_sources/windows_event_log_security_4662.yml | 6 +++--- data_sources/windows_event_log_security_4663.yml | 6 +++--- data_sources/windows_event_log_security_4672.yml | 6 +++--- data_sources/windows_event_log_security_4688.yml | 6 +++--- data_sources/windows_event_log_security_4698.yml | 6 +++--- data_sources/windows_event_log_security_4699.yml | 6 +++--- data_sources/windows_event_log_security_4700.yml | 6 +++--- data_sources/windows_event_log_security_4702.yml | 6 +++--- data_sources/windows_event_log_security_4703.yml | 6 +++--- data_sources/windows_event_log_security_4719.yml | 6 +++--- data_sources/windows_event_log_security_4720.yml | 6 +++--- data_sources/windows_event_log_security_4723.yml | 6 +++--- data_sources/windows_event_log_security_4724.yml | 6 +++--- data_sources/windows_event_log_security_4725.yml | 6 +++--- data_sources/windows_event_log_security_4726.yml | 6 +++--- data_sources/windows_event_log_security_4727.yml | 6 +++--- data_sources/windows_event_log_security_4728.yml | 6 +++--- data_sources/windows_event_log_security_4730.yml | 6 +++--- data_sources/windows_event_log_security_4731.yml | 6 +++--- data_sources/windows_event_log_security_4732.yml | 6 +++--- data_sources/windows_event_log_security_4737.yml | 6 +++--- data_sources/windows_event_log_security_4738.yml | 6 +++--- data_sources/windows_event_log_security_4739.yml | 6 +++--- data_sources/windows_event_log_security_4741.yml | 6 +++--- data_sources/windows_event_log_security_4742.yml | 6 +++--- data_sources/windows_event_log_security_4744.yml | 6 +++--- data_sources/windows_event_log_security_4749.yml | 6 +++--- data_sources/windows_event_log_security_4754.yml | 6 +++--- data_sources/windows_event_log_security_4756.yml | 6 +++--- data_sources/windows_event_log_security_4759.yml | 6 +++--- data_sources/windows_event_log_security_4768.yml | 6 +++--- data_sources/windows_event_log_security_4769.yml | 6 +++--- data_sources/windows_event_log_security_4771.yml | 6 +++--- data_sources/windows_event_log_security_4776.yml | 6 +++--- data_sources/windows_event_log_security_4781.yml | 6 +++--- data_sources/windows_event_log_security_4783.yml | 6 +++--- data_sources/windows_event_log_security_4790.yml | 6 +++--- data_sources/windows_event_log_security_4794.yml | 6 +++--- data_sources/windows_event_log_security_4798.yml | 6 +++--- data_sources/windows_event_log_security_4876.yml | 6 +++--- data_sources/windows_event_log_security_4886.yml | 6 +++--- data_sources/windows_event_log_security_4887.yml | 6 +++--- data_sources/windows_event_log_security_4946.yml | 6 +++--- data_sources/windows_event_log_security_4947.yml | 6 +++--- data_sources/windows_event_log_security_4948.yml | 6 +++--- data_sources/windows_event_log_security_5136.yml | 6 +++--- data_sources/windows_event_log_security_5137.yml | 6 +++--- data_sources/windows_event_log_security_5140.yml | 6 +++--- data_sources/windows_event_log_security_5141.yml | 6 +++--- data_sources/windows_event_log_security_5145.yml | 6 +++--- data_sources/windows_event_log_system_104.yml | 6 +++--- data_sources/windows_event_log_system_4720.yml | 6 +++--- data_sources/windows_event_log_system_4726.yml | 6 +++--- data_sources/windows_event_log_system_4728.yml | 6 +++--- data_sources/windows_event_log_system_7036.yml | 6 +++--- data_sources/windows_event_log_system_7040.yml | 6 +++--- data_sources/windows_event_log_system_7045.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_200.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_201.yml | 6 +++--- data_sources/windows_iis.yml | 6 +++--- data_sources/windows_iis_29.yml | 6 +++--- 194 files changed, 582 insertions(+), 582 deletions(-) diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index ff5ef21df4..8e24476198 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -1,8 +1,8 @@ name: ASL AWS CloudTrail id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898 -version: 4 +version: 5 creation_date: '2025-01-14' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Represents AWS API dataset data collection from Amazon Security Lake. mitre_components: @@ -24,7 +24,7 @@ separator: api.operation supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 output_fields: - dest - user diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml index 654d75b8b2..f8aca128aa 100644 --- a/data_sources/aws_cloudfront.yml +++ b/data_sources/aws_cloudfront.yml @@ -1,8 +1,8 @@ name: AWS Cloudfront id: 780086dc-2384-45b6-ade7-56cb00105464 -version: 4 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics. mitre_components: @@ -17,7 +17,7 @@ sourcetype: aws:cloudfront:accesslogs supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail.yml b/data_sources/aws_cloudtrail.yml index 1db2a95a38..9156c59691 100644 --- a/data_sources/aws_cloudtrail.yml +++ b/data_sources/aws_cloudtrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail id: e8ace6db-1dbd-4c72-a1fb-334684619a38 -version: 3 +version: 4 creation_date: '2024-07-16' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: All AWS CloudTrail events source: aws_cloudtrail @@ -11,4 +11,4 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml index 7c1ec90971..e7cb56eb33 100644 --- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml +++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail AssumeRoleWithSAML id: 1e28f2a6-2db9-405f-b298-18734a293f77 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs attempts to assume roles via SAML authentication in AWS, including details of identity provider and role mapping. mitre_components: @@ -18,7 +18,7 @@ separator_value: AssumeRoleWithSAML supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml index eb1a5291bd..752b3e824a 100644 --- a/data_sources/aws_cloudtrail_consolelogin.yml +++ b/data_sources/aws_cloudtrail_consolelogin.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ConsoleLogin id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events. mitre_components: @@ -18,7 +18,7 @@ separator_value: ConsoleLogin supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index 293e495c02..a07a045627 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CopyObject id: 965083f4-64a8-403f-99cc-252e1a6bd3b6 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination. mitre_components: @@ -17,7 +17,7 @@ separator_value: CopyObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml index b0be0502e9..e072a9d07b 100644 --- a/data_sources/aws_cloudtrail_createaccesskey.yml +++ b/data_sources/aws_cloudtrail_createaccesskey.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateAccessKey id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of new AWS access keys, including details of the associated user and permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateAccessKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml index 3f5d9a90ea..3654474298 100644 --- a/data_sources/aws_cloudtrail_createkey.yml +++ b/data_sources/aws_cloudtrail_createkey.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateKey id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml index b1aaa7c6cc..f4edbb63d0 100644 --- a/data_sources/aws_cloudtrail_createloginprofile.yml +++ b/data_sources/aws_cloudtrail_createloginprofile.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateLoginProfile id: 0024fdb1-0d62-4449-970a-746952cf80b6 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml index 5c60071db3..350a4ee218 100644 --- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateNetworkAclEntry id: 45934028-10ec-4ab5-a7b1-a6349b833e67 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml index 5d3f954868..a2279627a8 100644 --- a/data_sources/aws_cloudtrail_createpolicyversion.yml +++ b/data_sources/aws_cloudtrail_createpolicyversion.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreatePolicyVersion id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreatePolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml index a23a4a2888..25b3a3027c 100644 --- a/data_sources/aws_cloudtrail_createsnapshot.yml +++ b/data_sources/aws_cloudtrail_createsnapshot.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateSnapshot id: 514135a2-f4b2-4d32-8f31-d87824887f9f -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index d6e9e6301f..e018044ab5 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateTask id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateTask supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml index 69df8ce713..976a3d7b64 100644 --- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateVirtualMFADevice id: 13e6e952-0dad-4190-865c-fb5911725f7a -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml index 63c6c76b56..dd4133ce9e 100644 --- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml +++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeactivateMFADevice id: 7397a10b-1150-4de9-8062-a96454ae53b2 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeactivateMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml index f0d6815a9c..cb19785312 100644 --- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteAccountPasswordPolicy id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml index 29a241bd43..4d1182b396 100644 --- a/data_sources/aws_cloudtrail_deletealarms.yml +++ b/data_sources/aws_cloudtrail_deletealarms.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteAlarms id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f -version: 4 +version: 5 creation_date: '2024-08-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteAlarms supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml index fb03e28da9..81e4601ba6 100644 --- a/data_sources/aws_cloudtrail_deletedetector.yml +++ b/data_sources/aws_cloudtrail_deletedetector.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteDetector id: 5d8bd475-c8bc-4447-b27f-efa508728b90 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteDetector supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml index db0dca7ae1..7b3cece2f0 100644 --- a/data_sources/aws_cloudtrail_deletegroup.yml +++ b/data_sources/aws_cloudtrail_deletegroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteGroup id: c95308a4-a943-42ca-b112-f90a05c21bd3 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteguardrail.yml b/data_sources/aws_cloudtrail_deleteguardrail.yml index eb00338eda..65abb9cd58 100644 --- a/data_sources/aws_cloudtrail_deleteguardrail.yml +++ b/data_sources/aws_cloudtrail_deleteguardrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteGuardrail id: 2f6e9d7a-1c53-48b1-be57-33a91e0f8c42 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Logs an event when a guardrail is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteGuardrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml index 84ef4da7ab..24712253a8 100644 --- a/data_sources/aws_cloudtrail_deleteipset.yml +++ b/data_sources/aws_cloudtrail_deleteipset.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteIPSet id: ebdeeb63-77a0-4808-a6fe-549956731377 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations. mitre_components: @@ -16,7 +16,7 @@ separator_value: DeleteIPSet supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deleteknowledgebase.yml b/data_sources/aws_cloudtrail_deleteknowledgebase.yml index be2b969bef..30a883423a 100644 --- a/data_sources/aws_cloudtrail_deleteknowledgebase.yml +++ b/data_sources/aws_cloudtrail_deleteknowledgebase.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteKnowledgeBase id: a8c47f25-5693-4d1a-9f8b-6e94d15ac2d9 -version: 3 +version: 4 creation_date: '2025-04-17' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Logs an event when a knowledge base is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteKnowledgeBase supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml b/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml index ba8df958a5..dca67db6e3 100644 --- a/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml +++ b/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLoggingConfiguration id: 24a28726-28f3-4537-a953-71bfbbc3b831 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DeleteLoggingConfiguration source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time example_log: '' diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml index 1f0112a459..53a5f9f232 100644 --- a/data_sources/aws_cloudtrail_deleteloggroup.yml +++ b/data_sources/aws_cloudtrail_deleteloggroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLogGroup id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteLogGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml index d21638a834..600e2e6a6d 100644 --- a/data_sources/aws_cloudtrail_deletelogstream.yml +++ b/data_sources/aws_cloudtrail_deletelogstream.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLogStream id: 6f8bb808-89f8-465e-a34d-229df2f46402 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteLogStream supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml b/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml index ba446896df..ec8d87792c 100644 --- a/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml +++ b/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteModelInvocationLoggingConfiguration id: fe2b3a52-1c8d-4e17-9f74-76c531a87e21 -version: 3 +version: 4 creation_date: '2025-04-17' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Logs an event when a model invocation logging configuration is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteModelInvocationLoggingConfiguration supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml index a93bae517c..f32c7624f0 100644 --- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteNetworkAclEntry id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL. mitre_components: @@ -16,7 +16,7 @@ separator_value: DeleteNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml index 62213eb38e..4d16441766 100644 --- a/data_sources/aws_cloudtrail_deletepolicy.yml +++ b/data_sources/aws_cloudtrail_deletepolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeletePolicy id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeletePolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml index 30caaccb51..bd985d6379 100644 --- a/data_sources/aws_cloudtrail_deleterule.yml +++ b/data_sources/aws_cloudtrail_deleterule.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteRule id: b5760623-f3ca-492d-a372-d5c2b3567dfc -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteRule supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deleterulegroup.yml b/data_sources/aws_cloudtrail_deleterulegroup.yml index f4214f0c9e..e466952e7c 100644 --- a/data_sources/aws_cloudtrail_deleterulegroup.yml +++ b/data_sources/aws_cloudtrail_deleterulegroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteRuleGroup id: 21c9b538-fa11-4bdf-9138-0dfe06b4d730 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DeleteRuleGroup source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time example_log: '' diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml index 3bea186387..2a72058f2c 100644 --- a/data_sources/aws_cloudtrail_deletesnapshot.yml +++ b/data_sources/aws_cloudtrail_deletesnapshot.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteSnapshot id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f -version: 4 +version: 5 creation_date: '2024-08-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml index d79a2536a8..7298f7642f 100644 --- a/data_sources/aws_cloudtrail_deletetrail.yml +++ b/data_sources/aws_cloudtrail_deletetrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteTrail id: a5af09ff-07b6-4df6-92a0-2146bfe402c8 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml index 3f43296acb..7d370b6117 100644 --- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteVirtualMFADevice id: 84a08d6b-3d59-4260-8cab-84278ada262f -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml index b65017b448..ca9f5e3f8b 100644 --- a/data_sources/aws_cloudtrail_deletewebacl.yml +++ b/data_sources/aws_cloudtrail_deletewebacl.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteWebACL id: 90da5f08-7961-4c29-8de8-01364982aadf -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteWebACL supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml index 3d41adcfd2..d79cca07a9 100644 --- a/data_sources/aws_cloudtrail_describeeventaggregates.yml +++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeEventAggregates id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when aggregate details about AWS events are queried, often for analysis. mitre_components: @@ -15,7 +15,7 @@ separator_value: DescribeEventAggregates supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml index 302b2b8f02..88b6786e76 100644 --- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml +++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeImageScanFindings id: 688ea789-9ba2-4970-90a2-17e541e273c9 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail. mitre_components: @@ -16,7 +16,7 @@ separator_value: DescribeImageScanFindings supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_describesnapshotattribute.yml b/data_sources/aws_cloudtrail_describesnapshotattribute.yml index 1bfb2496ea..6ec540f2d8 100644 --- a/data_sources/aws_cloudtrail_describesnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_describesnapshotattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeSnapshotAttribute id: f054c99b-63b8-4236-8a62-b52fbbabacba -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DescribeSnapshotAttribute source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - action - app diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml index 460ad7ba51..6c5e4465a6 100644 --- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetAccountPasswordPolicy id: 439bdc53-6e4b-4cd7-b326-86c7317fd396 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to get the account password policy in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: GetAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml index 9a75bca557..c066fa3405 100644 --- a/data_sources/aws_cloudtrail_getobject.yml +++ b/data_sources/aws_cloudtrail_getobject.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetObject id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to access an object stored in an AWS S3 bucket. mitre_components: @@ -16,7 +16,7 @@ separator_value: GetObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml index ec62d994c9..059a989f6c 100644 --- a/data_sources/aws_cloudtrail_getpassworddata.yml +++ b/data_sources/aws_cloudtrail_getpassworddata.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetPasswordData id: 6ff2ce99-85b1-4c17-888a-56dbc3570671 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance. mitre_components: @@ -15,7 +15,7 @@ separator_value: GetPasswordData supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_invokemodel.yml b/data_sources/aws_cloudtrail_invokemodel.yml index 99f7cf7853..27e8747f84 100644 --- a/data_sources/aws_cloudtrail_invokemodel.yml +++ b/data_sources/aws_cloudtrail_invokemodel.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail InvokeModel id: 5d92a1b6-3e78-4ff2-be83-7a4c01f9df6c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Logs an event when a model is invoked within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: InvokeModel supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml index baa1d2b80a..f09d3ddff8 100644 --- a/data_sources/aws_cloudtrail_jobcreated.yml +++ b/data_sources/aws_cloudtrail_jobcreated.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail JobCreated id: 6473289b-d097-4c86-a837-3cc5ae408155 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a new job is created in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: JobCreated supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_listfoundationmodels.yml b/data_sources/aws_cloudtrail_listfoundationmodels.yml index 1a4a083886..2023ce93ce 100644 --- a/data_sources/aws_cloudtrail_listfoundationmodels.yml +++ b/data_sources/aws_cloudtrail_listfoundationmodels.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ListFoundationModels id: e7f31c68-84b9-4d21-a8c5-ec9d2fb3a457 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Logs an event when a list of foundation models is requested within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: ListFoundationModels supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml index c24648e2ef..9b04d54402 100644 --- a/data_sources/aws_cloudtrail_modifydbinstance.yml +++ b/data_sources/aws_cloudtrail_modifydbinstance.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifyDBInstance id: bfa2912d-1a33-4b05-be46-543874d68241 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations. mitre_components: @@ -16,7 +16,7 @@ separator_value: ModifyDBInstance supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml index 92e743de36..0c0cd054cf 100644 --- a/data_sources/aws_cloudtrail_modifyimageattribute.yml +++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifyImageAttribute id: 667c2115-8082-419e-b541-8150066bda4d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified. mitre_components: @@ -15,7 +15,7 @@ separator_value: ModifyImageAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml index 1f1d1f8dbf..8c604340d0 100644 --- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifySnapshotAttribute id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: ModifySnapshotAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml index c8e339e26a..9863e14e23 100644 --- a/data_sources/aws_cloudtrail_putbucketacl.yml +++ b/data_sources/aws_cloudtrail_putbucketacl.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketAcl id: 28fffbfd-d98d-4a42-990b-b04ab47422eb -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutBucketAcl supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml index fe9b0743e7..a882cd6f08 100644 --- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml +++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketLifecycle id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutBucketLifecycle supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml index c9678d8ac0..196635d159 100644 --- a/data_sources/aws_cloudtrail_putbucketreplication.yml +++ b/data_sources/aws_cloudtrail_putbucketreplication.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketReplication id: 0e1362eb-e592-419f-8fa5-556d3a122417 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when replication configurations are added or modified for an S3 bucket. mitre_components: @@ -14,7 +14,7 @@ separator_value: PutBucketReplication supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml index 7fba284a5d..8c57a29bc2 100644 --- a/data_sources/aws_cloudtrail_putbucketversioning.yml +++ b/data_sources/aws_cloudtrail_putbucketversioning.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketVersioning id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket. mitre_components: @@ -14,7 +14,7 @@ separator_value: PutBucketVersioning supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml index 4ab09f0341..9a1eb819d5 100644 --- a/data_sources/aws_cloudtrail_putimage.yml +++ b/data_sources/aws_cloudtrail_putimage.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutImage id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutImage supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml index 91c0f63c35..f1a9dba2cf 100644 --- a/data_sources/aws_cloudtrail_putkeypolicy.yml +++ b/data_sources/aws_cloudtrail_putkeypolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutKeyPolicy id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs changes made to AWS Key Management Service (KMS) key policies, including updates and permission assignments. mitre_components: @@ -13,7 +13,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml index 07c6f17851..abde7734c5 100644 --- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ReplaceNetworkAclEntry id: db0c240e-3754-40e4-86ef-cde018ee9f65 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: ReplaceNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml index e8e0e1267c..7b1f87e774 100644 --- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml +++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail SetDefaultPolicyVersion id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when the default version of a resource policy in AWS is set or changed. mitre_components: @@ -15,7 +15,7 @@ separator_value: SetDefaultPolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml index 539e18aa7a..65b985f568 100644 --- a/data_sources/aws_cloudtrail_stoplogging.yml +++ b/data_sources/aws_cloudtrail_stoplogging.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail StopLogging id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped. mitre_components: @@ -14,7 +14,7 @@ separator_value: StopLogging supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml index 776d4d77ac..333ec17d6e 100644 --- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateAccountPasswordPolicy id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an AWS account's password policy is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml index df17c74e71..4ef2c0a61d 100644 --- a/data_sources/aws_cloudtrail_updateloginprofile.yml +++ b/data_sources/aws_cloudtrail_updateloginprofile.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateLoginProfile id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an IAM user's login profile is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml index dcacdeddf9..d2225c8e5e 100644 --- a/data_sources/aws_cloudtrail_updatesamlprovider.yml +++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateSAMLProvider id: e5eb628d-711e-499c-87d9-8fa5dee419ec -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a SAML provider is updated in AWS. mitre_components: @@ -16,7 +16,7 @@ separator_value: UpdateSAMLProvider supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml index 5dfc178caf..2125d54906 100644 --- a/data_sources/aws_cloudtrail_updatetrail.yml +++ b/data_sources/aws_cloudtrail_updatetrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateTrail id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - app diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml index 7e468d8d82..bf85b19bc0 100644 --- a/data_sources/aws_cloudwatchlogs_vpcflow.yml +++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml @@ -1,8 +1,8 @@ name: AWS CloudWatchLogs VPCflow id: 38a34fc4-e128-4478-a8f4-7835d51d5135 -version: 4 +version: 5 creation_date: '2024-07-31' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Logs an event when network traffic flow information such as source and destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS. mitre_components: @@ -12,7 +12,7 @@ source: aws_cloudwatchlogs_vpcflow sourcetype: aws:cloudwatchlogs:vpcflow supported_TA: - name: Splunk Add-on for AWS - version: 8.2.0 + version: 8.0.0 url: https://splunkbase.splunk.com/app/1876 fields: - _raw diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml index 4c8d0d7874..1eeac0e085 100644 --- a/data_sources/aws_security_hub.yml +++ b/data_sources/aws_security_hub.yml @@ -1,8 +1,8 @@ name: AWS Security Hub id: b02bfbf3-294f-478e-99a1-e24b8c692d7e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-20' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts. mitre_components: @@ -15,7 +15,7 @@ sourcetype: aws:securityhub:finding supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.2.0 + version: 8.0.0 fields: - _time - AwsAccountId diff --git a/data_sources/azure_active_directory.yml b/data_sources/azure_active_directory.yml index 0f61908be9..383248079a 100644 --- a/data_sources/azure_active_directory.yml +++ b/data_sources/azure_active_directory.yml @@ -1,8 +1,8 @@ name: Azure Active Directory id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: All Azure Active Directory events source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 output_fields: - dest - user diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml index 20be2d2d46..ece15c61ab 100644 --- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml +++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add app role assignment to service principal id: 8b2e84cd-6db0-47e9-badc-75c17df1995f -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the addition of an application role assignment to a service principal in Azure Active Directory, including details about the role, service principal, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add app role assignment to service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml index c8c0a3fe86..9d862a4feb 100644 --- a/data_sources/azure_active_directory_add_member_to_role.yml +++ b/data_sources/azure_active_directory_add_member_to_role.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add member to role id: 1660d196-127f-4678-81b2-472d51711b07 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add member to role supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml index 6feb542ceb..d5676313fa 100644 --- a/data_sources/azure_active_directory_add_owner_to_application.yml +++ b/data_sources/azure_active_directory_add_owner_to_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add owner to application id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add owner to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml index 3fa25b765f..faf84b2b66 100644 --- a/data_sources/azure_active_directory_add_service_principal.yml +++ b/data_sources/azure_active_directory_add_service_principal.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add service principal id: fd89d337-e4c0-4162-ad13-bca36f096fe6 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml index 30ec67befc..5688a9aca8 100644 --- a/data_sources/azure_active_directory_add_unverified_domain.yml +++ b/data_sources/azure_active_directory_add_unverified_domain.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add unverified domain id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add unverified domain supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml index d056dcb7ca..101219780c 100644 --- a/data_sources/azure_active_directory_consent_to_application.yml +++ b/data_sources/azure_active_directory_consent_to_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Consent to application id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the consenting user or process. mitre_components: @@ -17,7 +17,7 @@ separator_value: Consent to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml index 4c84bea712..b9ba531cba 100644 --- a/data_sources/azure_active_directory_disable_strong_authentication.yml +++ b/data_sources/azure_active_directory_disable_strong_authentication.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Disable Strong Authentication id: 8f31966d-c496-496d-8837-f7fd11f31255 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when strong authentication methods are disabled in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Disable Strong Authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml index 4996fb4530..b4dc489b01 100644 --- a/data_sources/azure_active_directory_enable_account.yml +++ b/data_sources/azure_active_directory_enable_account.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Enable account id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Active Directory account is enabled. mitre_components: @@ -16,7 +16,7 @@ separator_value: Enable account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml index 7142e0a001..8df50ab23a 100644 --- a/data_sources/azure_active_directory_invite_external_user.yml +++ b/data_sources/azure_active_directory_invite_external_user.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Invite external user id: d3818bd5-f283-4518-8b67-df19240c3e40 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an external user is invited to join an Azure Active Directory tenant. mitre_components: @@ -16,7 +16,7 @@ separator_value: Invite external user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml b/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml index 3338304ff9..d7afe84f09 100644 --- a/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml +++ b/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml @@ -1,8 +1,8 @@ name: Azure Active Directory MicrosoftGraphActivityLogs id: 63ff93ba-2bbb-4542-8773-239bf5266367 -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Azure Active Directory MicrosoftGraphActivityLogs source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time example_log: '{"time": "2024-04-30T01:22:46.4948958Z", "resourceId": "/TENANTS/225E05A1-5914-4688-A404-7030E60F3143/PROVIDERS/MICROSOFT.AADIAM", "operationName": "Microsoft Graph Activity", "operationVersion": "beta", "category": "MicrosoftGraphActivityLogs", "resultSignature": "200", "durationMs": "948894", "callerIpAddress": "45.83.145.6", "correlationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "level": "Informational", "location": "East US 2", "properties": {"__UDI_RequiredFields_TenantId": "225e05a1-5914-4688-a404-7030e60f3143", "__UDI_RequiredFields_UniqueId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "__UDI_RequiredFields_EventTime": 638500369660000000, "__UDI_RequiredFields_RegionScope": "NA", "timeGenerated": "2024-04-30T01:22:46.4948958Z", "location": "East US 2", "requestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "operationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "clientRequestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "apiVersion": "beta", "requestMethod": "GET", "responseStatusCode": 200, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143", "durationMs": 948894, "responseSizeBytes": 91, "signInActivityId": "KRsphQ_4s0-oHv_Br8qSAQ", "roles": "", "appId": "1950a258-227b-4e31-a9cf-717495945fc2", "UserPrincipalObjectID": "7b934539-7366-494e-a8ac-3517694d32db", "scopes": "AuditLog.Read.All Directory.AccessAsUser.All email openid profile", "identityProvider": "", "clientAuthMethod": "0", "wids": "b79fbf4d-3ef9-4689-8143-76b194e85509", "C_Idtyp": "user", "C_Iat": "1714439850", "ipAddress": "45.83.145.6", "userAgent": "azurehound/v2.1.8", "requestUri": "https://graph.microsoft.com/beta/servicePrincipals/ffe3e001-d8cf-43a4-89ab-bfce35fd7786/owners?%24top=999", "userId": "7b934539-7366-494e-a8ac-3517694d32db", "tokenIssuedAt": "2024-04-30T01:17:30.0000000Z"}, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143"}' diff --git a/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml b/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml index 41469630c5..e43241ff0c 100644 --- a/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml +++ b/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml @@ -1,8 +1,8 @@ name: Azure Active Directory NonInteractiveUserSignInLogs id: 11fe8a43-164d-47e4-b542-afc2f242068b -version: 3 +version: 4 creation_date: '2025-02-21' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Azure Active Directory NonInteractiveUserSignInLogs source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - action - additional_details diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml index 24e05a01bc..299932977e 100644 --- a/data_sources/azure_active_directory_reset_password_(by_admin).yml +++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml @@ -1,8 +1,8 @@ name: Azure Active Directory Reset password (by admin) id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an admin resets a user's password in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Reset password (by admin) supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml index 1979b9e01c..f4a366a02b 100644 --- a/data_sources/azure_active_directory_set_domain_authentication.yml +++ b/data_sources/azure_active_directory_set_domain_authentication.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Set domain authentication id: e7bcdab9-908c-40ab-ba38-5db54fa87750 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified. mitre_components: @@ -16,7 +16,7 @@ separator_value: Set domain authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml index 5422691296..e5b21a3ba8 100644 --- a/data_sources/azure_active_directory_sign_in_activity.yml +++ b/data_sources/azure_active_directory_sign_in_activity.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Sign-in activity id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes. mitre_components: @@ -16,7 +16,7 @@ separator_value: Sign-in activity supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml index 06068873ac..e51d0727b6 100644 --- a/data_sources/azure_active_directory_update_application.yml +++ b/data_sources/azure_active_directory_update_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update application id: 2c08188a-ba25-496e-87c7-803cf28b6c90 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions. mitre_components: @@ -16,7 +16,7 @@ separator_value: Update application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml index d65fb762c1..381b94dff1 100644 --- a/data_sources/azure_active_directory_update_authorization_policy.yml +++ b/data_sources/azure_active_directory_update_authorization_policy.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update authorization policy id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an authorization policy is updated in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Update authorization policy supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml index 0aec2427cf..c67db742f0 100644 --- a/data_sources/azure_active_directory_update_user.yml +++ b/data_sources/azure_active_directory_update_user.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update user id: 5495c90a-047c-4b8e-b2fe-1db6282d3872 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user account is updated in Azure Active Directory. mitre_components: @@ -15,7 +15,7 @@ separator_value: Update user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml index f80440e810..77af9e9d8a 100644 --- a/data_sources/azure_active_directory_user_registered_security_info.yml +++ b/data_sources/azure_active_directory_user_registered_security_info.yml @@ -1,8 +1,8 @@ name: Azure Active Directory User registered security info id: b63240de-8a01-4ba8-8987-89d18d4b375d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user registers or updates their security information in Azure Active Directory. mitre_components: @@ -15,7 +15,7 @@ separator_value: User registered security info supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - Level diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml index 92b9a8bc1a..d7259cc19f 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation account id: 2ab182e7-feda-4249-9418-32710b55a885 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Automation account is created or updated. mitre_components: @@ -16,7 +16,7 @@ separator_value: Create or Update an Azure Automation account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - authorization.action diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml index 0f1f853a67..a676995a3e 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation Runbook id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: Create or Update an Azure Automation Runbook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - authorization.action diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml index 6c35ac44d4..7e49be1be5 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation webhook id: 575faeb2-09d0-4849-b1f6-eae241f26ff2 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a webhook is created or updated in Azure Automation. mitre_components: @@ -16,7 +16,7 @@ separator_value: Create or Update an Azure Automation webhook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - _time - authorization.action diff --git a/data_sources/azure_monitor_activity.yml b/data_sources/azure_monitor_activity.yml index bc882f6d6b..b856400073 100644 --- a/data_sources/azure_monitor_activity.yml +++ b/data_sources/azure_monitor_activity.yml @@ -1,8 +1,8 @@ name: Azure Monitor Activity id: 1997a515-a61a-4f78-ada9-54af34c764f2 -version: 3 +version: 4 creation_date: '2025-01-13' -modification_date: '2026-07-17' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Azure Monitor Activity. The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub. source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.3.0 + version: 6.1.3 fields: - column - action diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index 0ab54a3a49..4252849930 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -1,8 +1,8 @@ name: Linux Auditd Add User id: 30f79353-e1d2-4585-8735-1e0359559f3f -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - msg - type diff --git a/data_sources/linux_auditd_cwd.yml b/data_sources/linux_auditd_cwd.yml index 43f6ced21f..a8414e00c7 100644 --- a/data_sources/linux_auditd_cwd.yml +++ b/data_sources/linux_auditd_cwd.yml @@ -1,8 +1,8 @@ name: Linux Auditd Cwd id: a9ef851b-d864-478b-b1b3-76535d7ff7fc -version: 4 +version: 5 creation_date: '2025-12-02' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Nasreddine Bencherchali, Splunk description: This type is used to record the working directory from which the process that invoked the system call specified in the first record was executed. The purpose of this record is to record the current process's location in case a relative path winds up being captured in the associated PATH record. This way the absolute path can be reconstructed. source: auditd @@ -13,7 +13,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - cwd - date_hour diff --git a/data_sources/linux_auditd_daemon_abort.yml b/data_sources/linux_auditd_daemon_abort.yml index 6e4f417599..f671e65f03 100644 --- a/data_sources/linux_auditd_daemon_abort.yml +++ b/data_sources/linux_auditd_daemon_abort.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Abort id: cc8b3bb0-0fae-4236-9c61-fe2d7138bd63 -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_end.yml b/data_sources/linux_auditd_daemon_end.yml index bc8354e256..a4f8a05408 100644 --- a/data_sources/linux_auditd_daemon_end.yml +++ b/data_sources/linux_auditd_daemon_end.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon End id: 15135c45-e302-4d5a-a38a-3e8279f2ebd8 -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_start.yml b/data_sources/linux_auditd_daemon_start.yml index 686fb15ba9..08df6c79e2 100644 --- a/data_sources/linux_auditd_daemon_start.yml +++ b/data_sources/linux_auditd_daemon_start.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Start id: f1b97407-ddf0-41a5-8685-ada05aae3555 -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - type - op diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 022387f57e..550c15c753 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -1,8 +1,8 @@ name: Linux Auditd Execve id: 9ef6364d-cc67-480e-8448-3306829a6a24 -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - msg - type diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index 83185d152c..bb9eda21f2 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -1,8 +1,8 @@ name: Linux Auditd Path id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - msg - type diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index 00ce2b4f65..f3f1d85365 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -1,8 +1,8 @@ name: Linux Auditd Proctitle id: 5a25984a-2789-400a-858b-d75c923e06b1 -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - proctitle - msg diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index 4be8b93396..adbcff9a61 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -1,8 +1,8 @@ name: Linux Auditd Service Stop id: 0643483c-bc62-455c-8d6e-1630e5f0e00d -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - msg - type diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index e6ac3135d3..01141c44d0 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -1,8 +1,8 @@ name: Linux Auditd Syscall id: 4dff7047-0d43-4096-bb3f-b756c889bbad -version: 5 +version: 6 creation_date: '2024-08-08' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - msg - type diff --git a/data_sources/linux_messages_syslog.yml b/data_sources/linux_messages_syslog.yml index 52b3bc98d2..16dd97f143 100644 --- a/data_sources/linux_messages_syslog.yml +++ b/data_sources/linux_messages_syslog.yml @@ -1,8 +1,8 @@ name: Linux Messages Syslog id: c9e3bbb5-e0a2-4bac-8457-227e71841bda -version: 3 +version: 4 creation_date: '2025-05-06' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Ravent Tait, Splunk description: Logs kernel events on a Linux system, including service starts/stops, hardware events, authentication notices, and other OS-level activity. @@ -16,7 +16,7 @@ sourcetype: linux_messages_syslog supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - _time - action diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index 85811d0cfe..a6285162b7 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -1,8 +1,8 @@ name: Linux Secure id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-09' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. mitre_components: @@ -16,7 +16,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.1 + version: 10.2.0 fields: - _time - action diff --git a/data_sources/ntlm_operational_8004.yml b/data_sources/ntlm_operational_8004.yml index f1c94194e9..f021a32a67 100644 --- a/data_sources/ntlm_operational_8004.yml +++ b/data_sources/ntlm_operational_8004.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8004 id: fd08cb77-c26e-464c-a43e-2867e232127e -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8004 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8005.yml b/data_sources/ntlm_operational_8005.yml index d88b79d79a..cea1358b38 100644 --- a/data_sources/ntlm_operational_8005.yml +++ b/data_sources/ntlm_operational_8005.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8005 id: ad15a1cf-4b21-43de-81e4-6307c69172fb -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8005 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8006.yml b/data_sources/ntlm_operational_8006.yml index 6ed526560b..357150d23c 100644 --- a/data_sources/ntlm_operational_8006.yml +++ b/data_sources/ntlm_operational_8006.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8006 id: 9f50a672-6f7d-4621-a3bd-69468c6b7a7f -version: 5 +version: 6 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8006 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 46c093b3c6..d66d449cf0 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,8 +1,8 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: @@ -18,7 +18,7 @@ separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index 2a474e96ff..0e5ebff6bd 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -1,8 +1,8 @@ name: Windows Active Directory Admon id: 22bbf4e4-d313-43c1-98ee-808b8775519d -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ActiveDirectory supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Guid diff --git a/data_sources/windows_event_log_application_15457.yml b/data_sources/windows_event_log_application_15457.yml index ca078905ef..8fe42e1e7f 100644 --- a/data_sources/windows_event_log_application_15457.yml +++ b/data_sources/windows_event_log_application_15457.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 15457 id: 4491537e-520c-46f7-9209-f56f852aa237 -version: 5 +version: 6 creation_date: '2025-02-25' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 15457 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_17135.yml b/data_sources/windows_event_log_application_17135.yml index b4ccd50596..852fd9286b 100644 --- a/data_sources/windows_event_log_application_17135.yml +++ b/data_sources/windows_event_log_application_17135.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 17135 id: 4491537e-520c-46f7-9209-f56f852aa231 -version: 5 +version: 6 creation_date: '2025-02-25' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 17135 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index ab2ed67b3d..ffab0ffddc 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 2282 id: 4490537e-5e0c-46f7-9209-f56f852aa237 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index 4ef4af2e8d..00915b2464 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: @@ -17,7 +17,7 @@ separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_8128.yml b/data_sources/windows_event_log_application_8128.yml index 2f9e5e6b86..8fa1f13e70 100644 --- a/data_sources/windows_event_log_application_8128.yml +++ b/data_sources/windows_event_log_application_8128.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 8128 id: 4491537e-5e0c-46f7-9209-f56f852aa237 -version: 5 +version: 6 creation_date: '2025-02-25' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 8128 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_400.yml b/data_sources/windows_event_log_appxdeployment_server_400.yml index b1d534b02c..f6431ed5f5 100644 --- a/data_sources/windows_event_log_appxdeployment_server_400.yml +++ b/data_sources/windows_event_log_appxdeployment_server_400.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 400 id: 3e5f9d2a-b8c7-4d1e-a6f3-7b9c8d5e4f2a -version: 5 +version: 6 creation_date: '2025-08-18' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 400. These events are generated when a package deployment operation begins, providing details about the package being deployed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_854.yml b/data_sources/windows_event_log_appxdeployment_server_854.yml index 88bbdbfcb4..14bcf95530 100644 --- a/data_sources/windows_event_log_appxdeployment_server_854.yml +++ b/data_sources/windows_event_log_appxdeployment_server_854.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 854 id: 4d2e6f8a-c9b7-5a3e-8d1f-2e9c7b5a4f3d -version: 5 +version: 6 creation_date: '2025-08-18' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 854. These events are generated when an MSIX/AppX package has been successfully installed on a system. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_855.yml b/data_sources/windows_event_log_appxdeployment_server_855.yml index a50f231d1c..e495831796 100644 --- a/data_sources/windows_event_log_appxdeployment_server_855.yml +++ b/data_sources/windows_event_log_appxdeployment_server_855.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 855 id: 4491537c-521c-46f7-9209-f56f852aa231 -version: 5 +version: 6 creation_date: '2025-08-18' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 855. These events are generated when a package deployment operation completes successfully, providing details about the packages that were installed or updated. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxpackaging_171.yml b/data_sources/windows_event_log_appxpackaging_171.yml index d8d6d8cd19..206067ecf9 100644 --- a/data_sources/windows_event_log_appxpackaging_171.yml +++ b/data_sources/windows_event_log_appxpackaging_171.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXPackaging 171 id: 2d0f8e3c-a2d7-4b9e-8f1c-6a5d7e3e9f2b -version: 5 +version: 6 creation_date: '2025-08-18' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXPackaging/Operational channel, specifically focusing on EventCode 171. These events are generated when a user clicks on or attempts to interact with an MSIX package, even if the package is not fully installed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index cb13bb776c..719e16841e 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: @@ -18,7 +18,7 @@ separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index 9e0e5f0fd8..6dd58c7dd8 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 81 id: 463ff898-8135-4c0e-811e-f8629dfc5027 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index c288476d02..3bffd0b680 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -1,8 +1,8 @@ name: Windows Event Log CertificateServicesClient 1007 id: c51444e3-479d-4c4a-b111-e8276a3acf39 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index 1d74267d5b..7d1dd00abb 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1121 id: 84a254c5-7900-4b52-a324-a176adb7c11d -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index 57a6696eb2..ce5abc85a4 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1122 id: 4a2d0499-f489-4557-82f4-f357025cf3e7 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1125.yml b/data_sources/windows_event_log_defender_1125.yml index 598a9553bd..6f83c49759 100644 --- a/data_sources/windows_event_log_defender_1125.yml +++ b/data_sources/windows_event_log_defender_1125.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1125 id: 0cddda76-6fd8-4fb6-9026-f23a2761c95d -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1125 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time example_log: 112204000x80000000000000003701Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender Antivirus4.18.23100.2009E6DB77E5-3DF2-4CF1-B95A-636979351E5B2023-11-26T23:43:08.709Z(unknown user)C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1.401.1247.01.1.23100.2009ENT\ConsRC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x00000000 diff --git a/data_sources/windows_event_log_defender_1126.yml b/data_sources/windows_event_log_defender_1126.yml index 644997da2f..dac1bf224f 100644 --- a/data_sources/windows_event_log_defender_1126.yml +++ b/data_sources/windows_event_log_defender_1126.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1126 id: c1c6284b-b663-4001-bdf2-c0cacee22a2a -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1126 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index df6df911d4..c26b7bf0c0 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1129 id: 0572e119-a48a-4c70-bc58-90e453edacd2 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_defender_1131.yml b/data_sources/windows_event_log_defender_1131.yml index c1f9c9f521..811685381d 100644 --- a/data_sources/windows_event_log_defender_1131.yml +++ b/data_sources/windows_event_log_defender_1131.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1131 id: 638f884e-439a-4328-923c-ec5a2679f450 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1131 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1132.yml b/data_sources/windows_event_log_defender_1132.yml index cd431d99c0..4cd6e2a32e 100644 --- a/data_sources/windows_event_log_defender_1132.yml +++ b/data_sources/windows_event_log_defender_1132.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1132 id: 18f93f60-4eca-46e8-a29d-147e6451a34c -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1132 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1133.yml b/data_sources/windows_event_log_defender_1133.yml index 1de8ae7655..e8a711475e 100644 --- a/data_sources/windows_event_log_defender_1133.yml +++ b/data_sources/windows_event_log_defender_1133.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1133 id: 63c97a9a-cc7f-46c5-b219-8be388666637 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1133 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1134.yml b/data_sources/windows_event_log_defender_1134.yml index 1f7bcb4443..4f24129663 100644 --- a/data_sources/windows_event_log_defender_1134.yml +++ b/data_sources/windows_event_log_defender_1134.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1134 id: 26abac7d-d026-44e9-b1a3-13e3e11b232d -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1134 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index eb4ba43796..63bd60a44a 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 5007 id: 27f18792-8d95-4871-8853-874b7faf023f -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when Windows Defender antimalware settings are modified. mitre_components: @@ -14,7 +14,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index e5f95f897b..137e086222 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_printservice_4909.yml b/data_sources/windows_event_log_printservice_4909.yml index ac15d79b6a..c77a2c8ede 100644 --- a/data_sources/windows_event_log_printservice_4909.yml +++ b/data_sources/windows_event_log_printservice_4909.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 4909 id: 4c00e353-18b8-4de6-896d-83bc5817dbaa -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Printservice 4909 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time example_log: '' diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index bc7ec739f6..9567d3c63a 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: @@ -16,7 +16,7 @@ separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 9cc952673f..f02c5bb7ca 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,8 +1,8 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index b862efa32c..cc56da8360 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: @@ -15,7 +15,7 @@ separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index f5d9aaead3..bb8b0045fe 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 09cd63fa76..315f526e9c 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 535890c599..aa781065d5 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4625 id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an account fails to log on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index 6fc8ff84f8..33bb61a791 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4627 id: e35c7b9a-b451-4084-95a5-43b7f8965cac -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index 94706a706f..4923f2fc2e 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4648 id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account mitre_components: @@ -15,7 +15,7 @@ separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index 6c9eb7856b..345208a98d 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4662 id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it mitre_components: @@ -15,7 +15,7 @@ separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index 9ec70f1e71..f899833505 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4663 id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer mitre_components: @@ -15,7 +15,7 @@ separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index c4d5339550..76f06e225c 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index cf95648d73..77461e0635 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4688 id: d195eb26-a81c-45ed-aeb3-25792e8a985a -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of a new process mitre_components: @@ -16,7 +16,7 @@ configuration: Enabling Windows event log process command line logging via group supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - Caller_Domain - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index d2aa8c68d5..07c820e013 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4698 id: 32c06703-02d3-47ec-8856-b0dc3045866c -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a new scheduled task is created mitre_components: @@ -15,7 +15,7 @@ separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index eca0c1bf7a..89cd725f48 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4699 id: 4727dead-d063-4333-9ddd-59823a416aff -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a scheduled task is deleted from the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4700.yml b/data_sources/windows_event_log_security_4700.yml index df26da4bbf..1e855d66a3 100644 --- a/data_sources/windows_event_log_security_4700.yml +++ b/data_sources/windows_event_log_security_4700.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4700 id: 89895c7b-2aba-41ca-ad12-8b6d290b5dde -version: 6 +version: 7 creation_date: '2025-03-11' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Steven Dick description: Data source object for Windows Event Log Security 4700 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - EventID example_log: 4700 0 0 12804 0 0x8020000000000000 344861 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin LeastPrivilege CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4702.yml b/data_sources/windows_event_log_security_4702.yml index e11e8bd49e..bd331b7e49 100644 --- a/data_sources/windows_event_log_security_4702.yml +++ b/data_sources/windows_event_log_security_4702.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 -version: 6 +version: 7 creation_date: '2025-03-11' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 7e61a50e7f..8da3e9d9f0 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4703 id: e256673b-16e8-4b74-b7aa-9eed6ce67072 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a token right is adjusted on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index 513ee6b035..54cb74defe 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4719 id: 954033e6-dd05-4775-a1f2-1f19632f4420 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a system audit policy is modified on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index bc28680dd6..54d88e8b70 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4720 id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a new user account is created on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4723.yml b/data_sources/windows_event_log_security_4723.yml index 42d07cb837..4f41302167 100644 --- a/data_sources/windows_event_log_security_4723.yml +++ b/data_sources/windows_event_log_security_4723.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4723 id: df19b271-57c8-4f31-817a-6c5566985484 -version: 4 +version: 5 creation_date: '2026-06-15' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Raven Tait, Splunk description: Logs an event when an attempt is made to change an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4723' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index dc80781f29..fc3f1d494e 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4724 id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when an attempt is made to reset an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index 0814e35384..204a6c56e0 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4725 id: 31fd887d-0d14-44cc-bb64-80063a9f2968 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user account has been disabled in Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index 4eaf70de01..66c53d1906 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4726 id: 0b56dcd7-0f72-4a05-9226-d6059781737b -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user account is deleted from Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4727.yml b/data_sources/windows_event_log_security_4727.yml index e6c33c3f97..1cc19bd45f 100644 --- a/data_sources/windows_event_log_security_4727.yml +++ b/data_sources/windows_event_log_security_4727.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4727 id: 4d2078ab-36f5-447e-b7e4-474890b8040b -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4727 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4728.yml b/data_sources/windows_event_log_security_4728.yml index 73d3af406d..291b930bcf 100644 --- a/data_sources/windows_event_log_security_4728.yml +++ b/data_sources/windows_event_log_security_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4728 id: c0cb4907-d715-41f2-a98a-4f4e75f248c1 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4728 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4730.yml b/data_sources/windows_event_log_security_4730.yml index d357c16f0d..76628f6320 100644 --- a/data_sources/windows_event_log_security_4730.yml +++ b/data_sources/windows_event_log_security_4730.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4730 id: 126966ba-a17d-4194-882b-57d303aaf46d -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4730 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4731.yml b/data_sources/windows_event_log_security_4731.yml index f3e5fcba88..8ef95376d2 100644 --- a/data_sources/windows_event_log_security_4731.yml +++ b/data_sources/windows_event_log_security_4731.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4731 id: 1bbc004e-a75e-4d94-a619-c5aaf5d11ed5 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4731 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index dc12ba9438..7d337cd245 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4732 id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a member is added to a security-enabled local group on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4737.yml b/data_sources/windows_event_log_security_4737.yml index ccb10c1908..5eb8b5d315 100644 --- a/data_sources/windows_event_log_security_4737.yml +++ b/data_sources/windows_event_log_security_4737.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4737 id: 132fc609-17f0-4efd-8f7e-db12139c6690 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4737 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index 404f43f14f..5727e4d47d 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4738 id: cb85709b-101e-41a9-bb60-d2108f79dfbd -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index 5dcd4a2f3f..cb67eff56d 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4739 id: c1e0442a-8a97-405d-baf2-057c5d68cd9a -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index 9b444f4daa..93bdaaa343 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4741 id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index d5a66f9fe9..b9f02855bc 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4742 id: ea830adf-5450-489a-bcdc-fb8d2cbe674c -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4744.yml b/data_sources/windows_event_log_security_4744.yml index 45699ac492..88c5a61c84 100644 --- a/data_sources/windows_event_log_security_4744.yml +++ b/data_sources/windows_event_log_security_4744.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4744 id: 244e0bd4-00b0-4091-b8b4-9d435aca6ad8 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4744 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4749.yml b/data_sources/windows_event_log_security_4749.yml index 553c59f1c5..0890cc241c 100644 --- a/data_sources/windows_event_log_security_4749.yml +++ b/data_sources/windows_event_log_security_4749.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4749 id: eb322056-01a3-4cd5-bc09-01140d33194a -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4749 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4754.yml b/data_sources/windows_event_log_security_4754.yml index feda34317e..8712919afe 100644 --- a/data_sources/windows_event_log_security_4754.yml +++ b/data_sources/windows_event_log_security_4754.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4754 id: 501a507e-3275-4c4b-9c44-53eecfeae487 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4754 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4756.yml b/data_sources/windows_event_log_security_4756.yml index 2e81cbe353..c68931342d 100644 --- a/data_sources/windows_event_log_security_4756.yml +++ b/data_sources/windows_event_log_security_4756.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4756 id: b0093058-0cb6-4c73-a95b-fb0f3541e88c -version: 5 +version: 6 creation_date: '2026-03-30' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Nasreddine Bencherchali, Splunk description: Data source object for Windows Event Log Security 4756 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4759.yml b/data_sources/windows_event_log_security_4759.yml index 5b0113c63d..65cf71ef83 100644 --- a/data_sources/windows_event_log_security_4759.yml +++ b/data_sources/windows_event_log_security_4759.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4759 id: 431e3520-505b-4ace-aced-cb51e3f7311e -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4759 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index 26446f9d2e..192d1a5467 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4768 id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index fa497d59d3..597e751aa4 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index e6714cabc0..caed5336e0 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4771 id: 418debbb-adf3-48ec-9efd-59d45f8861e5 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index 84bfe3ea6f..797c8619ff 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4776 id: 1da9092a-c795-4a26-ace8-d43855524e96 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index 3bc0d6b7fc..5f3f6117d0 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4783.yml b/data_sources/windows_event_log_security_4783.yml index 916445209f..809fd32066 100644 --- a/data_sources/windows_event_log_security_4783.yml +++ b/data_sources/windows_event_log_security_4783.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4783 id: 6b945150-785c-49a1-b705-56b42215630b -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4783 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4790.yml b/data_sources/windows_event_log_security_4790.yml index f889cb6940..9f279e858e 100644 --- a/data_sources/windows_event_log_security_4790.yml +++ b/data_sources/windows_event_log_security_4790.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4790 id: 1cc6ecbb-af04-432b-a224-02c65243ac88 -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4790 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index 0b2362f822..1a37f12377 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4794 id: ec7da74f-274a-4bde-aa0e-15c68aca0426 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index 139b23f846..bbe93844aa 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4798 id: 29e97f72-eb2e-400e-b0c9-81277547e43b -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index b1d9624b51..0c55023bb4 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4876 id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index 0d80804438..22c6449735 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index 4becf1a1b3..0d24f76626 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4887 id: 994c7b19-a623-4231-9818-f00e453b9a75 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4946.yml b/data_sources/windows_event_log_security_4946.yml index 8078c39c4d..ff6cf07f68 100644 --- a/data_sources/windows_event_log_security_4946.yml +++ b/data_sources/windows_event_log_security_4946.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4946 id: d7dafd01-a22d-4b05-b793-7571ef1fa789 -version: 6 +version: 7 creation_date: '2025-03-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4946 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4946' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4947.yml b/data_sources/windows_event_log_security_4947.yml index a3e2e2b357..43ba1a7db0 100644 --- a/data_sources/windows_event_log_security_4947.yml +++ b/data_sources/windows_event_log_security_4947.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4947 id: 63d4a2fa-a7dc-46d2-b702-54794e1f4d3c -version: 6 +version: 7 creation_date: '2025-03-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4947 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4947' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4948.yml b/data_sources/windows_event_log_security_4948.yml index 33e9f91450..e19cd033ff 100644 --- a/data_sources/windows_event_log_security_4948.yml +++ b/data_sources/windows_event_log_security_4948.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4948 id: 910032df-4e49-42fe-a611-d4c29557d83a -version: 6 +version: 7 creation_date: '2025-03-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4948 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4948' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index c37d4847a1..abe97668fc 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5136 id: 7ba3737e-231e-455d-824e-cd077749f835 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index 40cc759239..0c328521c5 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AppCorrelationID diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index 90a806c017..acf0811514 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index c2e3a95a15..e7514167c5 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5141 id: eafb35fa-f034-4be3-8508-d9173a73c0a1 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 81503a152e..157b9712c9 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_system_104.yml b/data_sources/windows_event_log_system_104.yml index 658c7b0df8..bac593b36a 100644 --- a/data_sources/windows_event_log_system_104.yml +++ b/data_sources/windows_event_log_system_104.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 104 id: 577b9b41-6b37-44c4-9016-3d890b909050 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log System 104 source: XmlWinEventLog:System @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index 2eba810b8a..988e936a7d 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4720 id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index dc7e79721e..96f54036eb 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4726 id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index 59d634d9b2..c99f13b74a 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index c213f15ae8..5e8d01067e 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7036 id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). mitre_components: @@ -17,7 +17,7 @@ separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index e84d7cbcc8..25161cbf0a 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index 73dd1d9343..0482cfa5b9 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - AccountName diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index 6e43e5e1fd..a381f769e9 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ActionName diff --git a/data_sources/windows_event_log_taskscheduler_201.yml b/data_sources/windows_event_log_taskscheduler_201.yml index 7bfc93b7d1..b257f738b5 100644 --- a/data_sources/windows_event_log_taskscheduler_201.yml +++ b/data_sources/windows_event_log_taskscheduler_201.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 201 id: 4c09ae64-01cd-4b65-8221-20f803b0d86e -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log TaskScheduler 201 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index 9874913f17..07d2bc2697 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -1,8 +1,8 @@ name: Windows IIS id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. mitre_components: @@ -16,4 +16,4 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index 90286b7acb..cdc858c568 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -1,8 +1,8 @@ name: Windows IIS 29 id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-24' author: Patrick Bareiss, Splunk description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. mitre_components: @@ -17,7 +17,7 @@ separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.1.2 + version: 10.0.1 fields: - _time - ComputerName From e2d208077b25aa5ee4e62280a380db6f09f94650 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Sat, 25 Jul 2026 07:09:16 +0000 Subject: [PATCH 18/32] Update datasource TA versions --- data_sources/crowdstrike_falcon_stream_alert.yml | 6 +++--- data_sources/crowdstrike_processrollup2.yml | 6 +++--- data_sources/palo_alto_network_threat.yml | 6 +++--- data_sources/palo_alto_network_traffic.yml | 6 +++--- 4 files changed, 12 insertions(+), 12 deletions(-) diff --git a/data_sources/crowdstrike_falcon_stream_alert.yml b/data_sources/crowdstrike_falcon_stream_alert.yml index 3f19ad789d..02449e7dbc 100644 --- a/data_sources/crowdstrike_falcon_stream_alert.yml +++ b/data_sources/crowdstrike_falcon_stream_alert.yml @@ -1,8 +1,8 @@ name: CrowdStrike Falcon Stream Alert id: 52b38751-b0db-4965-a800-ebaabd1fd7d5 -version: 4 +version: 5 creation_date: '2025-07-01' -modification_date: '2026-07-15' +modification_date: '2026-07-25' author: Bhavin Patel, Bryan Pluta, Splunk description: Logs of CrowdStrike Falcon Stream Alerts mitre_components: @@ -17,7 +17,7 @@ separator: event.DetectName supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 3.1.1 + version: 3.0.0 fields: - action - description diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml index f5b4fc8ac7..97feb0702b 100644 --- a/data_sources/crowdstrike_processrollup2.yml +++ b/data_sources/crowdstrike_processrollup2.yml @@ -1,8 +1,8 @@ name: CrowdStrike ProcessRollup2 id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-15' +modification_date: '2026-07-25' author: Patrick Bareiss, Splunk description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments. mitre_components: @@ -18,7 +18,7 @@ separator_value: ProcessRollup2 supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 3.1.1 + version: 3.0.0 fields: - AuthenticationId - AuthenticationId_meaning diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml index 531150f3b3..b4135fec26 100644 --- a/data_sources/palo_alto_network_threat.yml +++ b/data_sources/palo_alto_network_threat.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Threat id: 375c2b0e-d216-41ad-9406-200464595209 -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-25' author: Patrick Bareiss, Splunk description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:threat supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.2.1 + version: 3.1.0 fields: - _time - date_hour diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml index a4b39748cf..b4a7d6e3da 100644 --- a/data_sources/palo_alto_network_traffic.yml +++ b/data_sources/palo_alto_network_traffic.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Traffic id: 182a83bc-c31a-4817-8c7a-263744cec52a -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-16' +modification_date: '2026-07-25' author: Patrick Bareiss, Splunk description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:traffic supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.2.1 + version: 3.1.0 fields: - _time - date_hour From da2f6ed032e8fb3337dc6a4c8a2765ae1e12c077 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Tue, 28 Jul 2026 15:10:55 +0000 Subject: [PATCH 19/32] Update datasource TA versions --- data_sources/cisco_ai_defense_alerts.yml | 6 +++--- data_sources/cisco_asa_logs.yml | 6 +++--- data_sources/cisco_duo_activity.yml | 6 +++--- data_sources/cisco_duo_administrator.yml | 6 +++--- data_sources/cisco_isovalent_process_connect.yml | 6 +++--- data_sources/cisco_isovalent_process_exec.yml | 6 +++--- data_sources/cisco_isovalent_process_kprobe.yml | 6 +++--- ...isco_secure_firewall_threat_defense_connection_event.yml | 6 +++--- .../cisco_secure_firewall_threat_defense_file_event.yml | 6 +++--- ...cisco_secure_firewall_threat_defense_intrusion_event.yml | 6 +++--- 10 files changed, 30 insertions(+), 30 deletions(-) diff --git a/data_sources/cisco_ai_defense_alerts.yml b/data_sources/cisco_ai_defense_alerts.yml index 7dc36fc3f9..1a4274a4e6 100644 --- a/data_sources/cisco_ai_defense_alerts.yml +++ b/data_sources/cisco_ai_defense_alerts.yml @@ -1,8 +1,8 @@ name: Cisco AI Defense Alerts id: cbb06880-9dd9-4542-ac60-bd6e1d3c3e4e -version: 3 +version: 4 creation_date: '2025-02-14' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Bhavin Patel description: Data source object for Cisco AI Defense Alerts source: cisco_ai_defense @@ -11,5 +11,5 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: diff --git a/data_sources/cisco_asa_logs.yml b/data_sources/cisco_asa_logs.yml index 8633d2eedd..857035ae40 100644 --- a/data_sources/cisco_asa_logs.yml +++ b/data_sources/cisco_asa_logs.yml @@ -1,8 +1,8 @@ name: Cisco ASA Logs id: 3f2a9b6d-1c8e-4f7b-a2d3-8b7f1c2a9d4e -version: 4 +version: 5 creation_date: '2025-09-25' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Bhavin Patel, Splunk description: "Data source object for Cisco ASA system logs. Cisco ASA logs provide firewall operational and security telemetry (connection events, ACL denies, VPN events, NAT translations, and device health). Deploy the Splunk Add-on for Cisco ASA (TA-cisco_asa) on indexers/heavy forwarders and the Cisco ASA App on search heads for best parsing, CIM mapping, and dashboards. This data is ingested via SYSLOG. You must be ingesting Cisco ASA syslog data into your Splunk environment. To ensure all detections work, configure your ASA and FTD devices to generate and forward both debug and informational level syslog messages before they are sent to Splunk. A few analytics are designed to be used with comprehensive logging enabled, as it relies on the presence of specific message IDs. You can find specific instructions on how to set this up here : https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/63884-config-asa-00.html#toc-hId--1451069880. \n" source: not_applicable @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - Cisco_ASA_action - Cisco_ASA_message_id diff --git a/data_sources/cisco_duo_activity.yml b/data_sources/cisco_duo_activity.yml index 90080a9c57..80cd08546d 100644 --- a/data_sources/cisco_duo_activity.yml +++ b/data_sources/cisco_duo_activity.yml @@ -1,8 +1,8 @@ name: Cisco Duo Activity id: 83f727f6-8754-41f8-b9f7-8226886a659e -version: 3 +version: 4 creation_date: '2025-07-10' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Activity source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - access_device.browser - access_device.browser_version diff --git a/data_sources/cisco_duo_administrator.yml b/data_sources/cisco_duo_administrator.yml index 0461bdd9a3..115560695e 100644 --- a/data_sources/cisco_duo_administrator.yml +++ b/data_sources/cisco_duo_administrator.yml @@ -1,8 +1,8 @@ name: Cisco Duo Administrator id: 38e22de6-8b6b-449c-ae26-a640c88ff7f9 -version: 3 +version: 4 creation_date: '2025-07-10' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Administrator source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - action - actionlabel diff --git a/data_sources/cisco_isovalent_process_connect.yml b/data_sources/cisco_isovalent_process_connect.yml index 49521f5c93..98ab25136f 100644 --- a/data_sources/cisco_isovalent_process_connect.yml +++ b/data_sources/cisco_isovalent_process_connect.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Connect id: bf8c76a1-6066-4759-ab77-d3f0a375519e -version: 3 +version: 4 creation_date: '2026-01-05' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Bhavin Patel, Splunk description: "Captures detailed process connection events—including source and destination process metadata, execution lineage (ancestry), and Kubernetes workload context—generated by Cisco Isovalent instrumentation. Enables technical analysis of inter-process communications, container-level activity, and workload-specific network flows in cloud-native environments." source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processConnect supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - _time - app diff --git a/data_sources/cisco_isovalent_process_exec.yml b/data_sources/cisco_isovalent_process_exec.yml index 2b55b3c975..1c1238299b 100644 --- a/data_sources/cisco_isovalent_process_exec.yml +++ b/data_sources/cisco_isovalent_process_exec.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Exec id: 87654321-dcba-4321-00fe-0987654321ba -version: 3 +version: 4 creation_date: '2026-01-05' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Bhavin Patel, Splunk description: Logs process execution events within Cisco Isovalent environments, providing visibility into process exec ancestry and Kubernetes workload identity. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processExec supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - _time - cluster_name diff --git a/data_sources/cisco_isovalent_process_kprobe.yml b/data_sources/cisco_isovalent_process_kprobe.yml index 4d06806d7c..f6fb1902a7 100644 --- a/data_sources/cisco_isovalent_process_kprobe.yml +++ b/data_sources/cisco_isovalent_process_kprobe.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Kprobe id: b2620ef2-fac6-467f-bdc8-253d65db1cb9 -version: 3 +version: 4 creation_date: '2026-01-05' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Bhavin Patel, Splunk description: Captures kernel probe (kprobe) telemetry from Cisco Isovalent Runtime Security, including function name, arguments, and process context, enabling visibility into low-level kernel interactions that may indicate container escape attempts or system tampering. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - _time - app diff --git a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml index f9af12e7c6..f0a581fdee 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Connection Event id: 18878597-8f8a-4bca-a805-bfbe35e00032 -version: 4 +version: 5 creation_date: '2025-04-03' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Nasreddine Bencherchali, Splunk description: Data source object for raw connection events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - AC_RuleAction - action diff --git a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml index ee09653ac5..d4f5494230 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense File Event id: 19878597-8f8a-4bca-a805-bfbe35e00032 -version: 3 +version: 4 creation_date: '2025-04-09' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Nasreddine Bencherchali, Splunk description: Data source object for raw file events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - app - Application diff --git a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml index ba988be306..b545cd0ed5 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Intrusion Event id: d11b67ec-1cb2-4f6f-a2d8-a099c7e15b29 -version: 3 +version: 4 creation_date: '2025-04-16' -modification_date: '2026-06-18' +modification_date: '2026-07-28' author: Nasreddine Bencherchali, Splunk description: Data source object for raw intrusion events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.7 + version: 3.6.8 fields: - Application - Classification From fdac755828991df33b017dcbcf0b6850330783ab Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Thu, 30 Jul 2026 15:02:56 +0000 Subject: [PATCH 20/32] Update datasource TA versions --- data_sources/asl_aws_cloudtrail.yml | 6 +++--- data_sources/aws_cloudfront.yml | 6 +++--- data_sources/aws_cloudtrail.yml | 6 +++--- data_sources/aws_cloudtrail_assumerolewithsaml.yml | 6 +++--- data_sources/aws_cloudtrail_consolelogin.yml | 6 +++--- data_sources/aws_cloudtrail_copyobject.yml | 6 +++--- data_sources/aws_cloudtrail_createaccesskey.yml | 6 +++--- data_sources/aws_cloudtrail_createkey.yml | 6 +++--- data_sources/aws_cloudtrail_createloginprofile.yml | 6 +++--- data_sources/aws_cloudtrail_createnetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_createpolicyversion.yml | 6 +++--- data_sources/aws_cloudtrail_createsnapshot.yml | 6 +++--- data_sources/aws_cloudtrail_createtask.yml | 6 +++--- data_sources/aws_cloudtrail_createvirtualmfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deactivatemfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_deletealarms.yml | 6 +++--- data_sources/aws_cloudtrail_deletedetector.yml | 6 +++--- data_sources/aws_cloudtrail_deletegroup.yml | 6 +++--- data_sources/aws_cloudtrail_deleteguardrail.yml | 6 +++--- data_sources/aws_cloudtrail_deleteipset.yml | 6 +++--- data_sources/aws_cloudtrail_deleteknowledgebase.yml | 6 +++--- data_sources/aws_cloudtrail_deleteloggingconfiguration.yml | 6 +++--- data_sources/aws_cloudtrail_deleteloggroup.yml | 6 +++--- data_sources/aws_cloudtrail_deletelogstream.yml | 6 +++--- ...cloudtrail_deletemodelinvocationloggingconfiguration.yml | 6 +++--- data_sources/aws_cloudtrail_deletenetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_deletepolicy.yml | 6 +++--- data_sources/aws_cloudtrail_deleterule.yml | 6 +++--- data_sources/aws_cloudtrail_deleterulegroup.yml | 6 +++--- data_sources/aws_cloudtrail_deletesnapshot.yml | 6 +++--- data_sources/aws_cloudtrail_deletetrail.yml | 6 +++--- data_sources/aws_cloudtrail_deletevirtualmfadevice.yml | 6 +++--- data_sources/aws_cloudtrail_deletewebacl.yml | 6 +++--- data_sources/aws_cloudtrail_describeeventaggregates.yml | 6 +++--- data_sources/aws_cloudtrail_describeimagescanfindings.yml | 6 +++--- data_sources/aws_cloudtrail_describesnapshotattribute.yml | 6 +++--- data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_getobject.yml | 6 +++--- data_sources/aws_cloudtrail_getpassworddata.yml | 6 +++--- data_sources/aws_cloudtrail_invokemodel.yml | 6 +++--- data_sources/aws_cloudtrail_jobcreated.yml | 6 +++--- data_sources/aws_cloudtrail_listfoundationmodels.yml | 6 +++--- data_sources/aws_cloudtrail_modifydbinstance.yml | 6 +++--- data_sources/aws_cloudtrail_modifyimageattribute.yml | 6 +++--- data_sources/aws_cloudtrail_modifysnapshotattribute.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketacl.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketlifecycle.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketreplication.yml | 6 +++--- data_sources/aws_cloudtrail_putbucketversioning.yml | 6 +++--- data_sources/aws_cloudtrail_putimage.yml | 6 +++--- data_sources/aws_cloudtrail_putkeypolicy.yml | 6 +++--- data_sources/aws_cloudtrail_replacenetworkaclentry.yml | 6 +++--- data_sources/aws_cloudtrail_setdefaultpolicyversion.yml | 6 +++--- data_sources/aws_cloudtrail_stoplogging.yml | 6 +++--- data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml | 6 +++--- data_sources/aws_cloudtrail_updateloginprofile.yml | 6 +++--- data_sources/aws_cloudtrail_updatesamlprovider.yml | 6 +++--- data_sources/aws_cloudtrail_updatetrail.yml | 6 +++--- data_sources/aws_cloudwatchlogs_vpcflow.yml | 6 +++--- data_sources/aws_security_hub.yml | 6 +++--- data_sources/azure_active_directory.yml | 6 +++--- ...rectory_add_app_role_assignment_to_service_principal.yml | 6 +++--- data_sources/azure_active_directory_add_member_to_role.yml | 6 +++--- .../azure_active_directory_add_owner_to_application.yml | 6 +++--- .../azure_active_directory_add_service_principal.yml | 6 +++--- .../azure_active_directory_add_unverified_domain.yml | 6 +++--- .../azure_active_directory_consent_to_application.yml | 6 +++--- ...azure_active_directory_disable_strong_authentication.yml | 6 +++--- data_sources/azure_active_directory_enable_account.yml | 6 +++--- .../azure_active_directory_invite_external_user.yml | 6 +++--- .../azure_active_directory_microsoftgraphactivitylogs.yml | 6 +++--- .../azure_active_directory_noninteractiveusersigninlogs.yml | 6 +++--- .../azure_active_directory_reset_password_(by_admin).yml | 6 +++--- .../azure_active_directory_set_domain_authentication.yml | 6 +++--- data_sources/azure_active_directory_sign_in_activity.yml | 6 +++--- data_sources/azure_active_directory_update_application.yml | 6 +++--- .../azure_active_directory_update_authorization_policy.yml | 6 +++--- data_sources/azure_active_directory_update_user.yml | 6 +++--- ...azure_active_directory_user_registered_security_info.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_account.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_runbook.yml | 6 +++--- ...e_audit_create_or_update_an_azure_automation_webhook.yml | 6 +++--- data_sources/azure_monitor_activity.yml | 6 +++--- data_sources/crowdstrike_falcon_stream_alert.yml | 6 +++--- data_sources/crowdstrike_processrollup2.yml | 6 +++--- data_sources/okta.yml | 6 +++--- data_sources/palo_alto_network_threat.yml | 6 +++--- data_sources/palo_alto_network_traffic.yml | 6 +++--- 89 files changed, 267 insertions(+), 267 deletions(-) diff --git a/data_sources/asl_aws_cloudtrail.yml b/data_sources/asl_aws_cloudtrail.yml index 8e24476198..d43e9d9614 100644 --- a/data_sources/asl_aws_cloudtrail.yml +++ b/data_sources/asl_aws_cloudtrail.yml @@ -1,8 +1,8 @@ name: ASL AWS CloudTrail id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898 -version: 5 +version: 6 creation_date: '2025-01-14' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Represents AWS API dataset data collection from Amazon Security Lake. mitre_components: @@ -24,7 +24,7 @@ separator: api.operation supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 output_fields: - dest - user diff --git a/data_sources/aws_cloudfront.yml b/data_sources/aws_cloudfront.yml index f8aca128aa..a0a4edabe6 100644 --- a/data_sources/aws_cloudfront.yml +++ b/data_sources/aws_cloudfront.yml @@ -1,8 +1,8 @@ name: AWS Cloudfront id: 780086dc-2384-45b6-ade7-56cb00105464 -version: 5 +version: 6 creation_date: '2024-07-16' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs requests made to AWS CloudFront distributions, including details on client access, response data, and performance metrics. mitre_components: @@ -17,7 +17,7 @@ sourcetype: aws:cloudfront:accesslogs supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail.yml b/data_sources/aws_cloudtrail.yml index 9156c59691..60a432945d 100644 --- a/data_sources/aws_cloudtrail.yml +++ b/data_sources/aws_cloudtrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail id: e8ace6db-1dbd-4c72-a1fb-334684619a38 -version: 4 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: All AWS CloudTrail events source: aws_cloudtrail @@ -11,4 +11,4 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 diff --git a/data_sources/aws_cloudtrail_assumerolewithsaml.yml b/data_sources/aws_cloudtrail_assumerolewithsaml.yml index e7cb56eb33..2fce8ead54 100644 --- a/data_sources/aws_cloudtrail_assumerolewithsaml.yml +++ b/data_sources/aws_cloudtrail_assumerolewithsaml.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail AssumeRoleWithSAML id: 1e28f2a6-2db9-405f-b298-18734a293f77 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs attempts to assume roles via SAML authentication in AWS, including details of identity provider and role mapping. mitre_components: @@ -18,7 +18,7 @@ separator_value: AssumeRoleWithSAML supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_consolelogin.yml b/data_sources/aws_cloudtrail_consolelogin.yml index 752b3e824a..fb48315648 100644 --- a/data_sources/aws_cloudtrail_consolelogin.yml +++ b/data_sources/aws_cloudtrail_consolelogin.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ConsoleLogin id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs attempts to sign in to the AWS Management Console, including successful and failed login events. mitre_components: @@ -18,7 +18,7 @@ separator_value: ConsoleLogin supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_copyobject.yml b/data_sources/aws_cloudtrail_copyobject.yml index a07a045627..3294dde03c 100644 --- a/data_sources/aws_cloudtrail_copyobject.yml +++ b/data_sources/aws_cloudtrail_copyobject.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CopyObject id: 965083f4-64a8-403f-99cc-252e1a6bd3b6 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs operations that copy objects within or between AWS S3 buckets, including details of source and destination. mitre_components: @@ -17,7 +17,7 @@ separator_value: CopyObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_createaccesskey.yml b/data_sources/aws_cloudtrail_createaccesskey.yml index e072a9d07b..616d459571 100644 --- a/data_sources/aws_cloudtrail_createaccesskey.yml +++ b/data_sources/aws_cloudtrail_createaccesskey.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateAccessKey id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of new AWS access keys, including details of the associated user and permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateAccessKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createkey.yml b/data_sources/aws_cloudtrail_createkey.yml index 3654474298..6acd2a5acf 100644 --- a/data_sources/aws_cloudtrail_createkey.yml +++ b/data_sources/aws_cloudtrail_createkey.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateKey id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of new AWS KMS keys, including details of key properties and associated metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateKey supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createloginprofile.yml b/data_sources/aws_cloudtrail_createloginprofile.yml index f4edbb63d0..7c1649de00 100644 --- a/data_sources/aws_cloudtrail_createloginprofile.yml +++ b/data_sources/aws_cloudtrail_createloginprofile.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateLoginProfile id: 0024fdb1-0d62-4449-970a-746952cf80b6 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of login profiles for IAM users, including associated metadata and authentication settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createnetworkaclentry.yml b/data_sources/aws_cloudtrail_createnetworkaclentry.yml index 350a4ee218..61ac974092 100644 --- a/data_sources/aws_cloudtrail_createnetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_createnetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateNetworkAclEntry id: 45934028-10ec-4ab5-a7b1-a6349b833e67 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of new entries in a network ACL, including rules to allow or deny specific network traffic. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createpolicyversion.yml b/data_sources/aws_cloudtrail_createpolicyversion.yml index a2279627a8..e1ab333ad9 100644 --- a/data_sources/aws_cloudtrail_createpolicyversion.yml +++ b/data_sources/aws_cloudtrail_createpolicyversion.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreatePolicyVersion id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of new versions of IAM policies, including changes to permissions and attached roles or resources. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreatePolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_createsnapshot.yml b/data_sources/aws_cloudtrail_createsnapshot.yml index 25b3a3027c..960add82fd 100644 --- a/data_sources/aws_cloudtrail_createsnapshot.yml +++ b/data_sources/aws_cloudtrail_createsnapshot.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateSnapshot id: 514135a2-f4b2-4d32-8f31-d87824887f9f -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon EBS volume, including details about the snapshot ID and resource type. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createtask.yml b/data_sources/aws_cloudtrail_createtask.yml index e018044ab5..2d5dd3a516 100644 --- a/data_sources/aws_cloudtrail_createtask.yml +++ b/data_sources/aws_cloudtrail_createtask.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateTask id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of a new task in AWS services, such as ECS, including details about the task definition and resource allocation. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateTask supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml index 976a3d7b64..d2990632e5 100644 --- a/data_sources/aws_cloudtrail_createvirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_createvirtualmfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail CreateVirtualMFADevice id: 13e6e952-0dad-4190-865c-fb5911725f7a -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of a new virtual multi-factor authentication (MFA) device, including details about the associated user and configuration. mitre_components: @@ -17,7 +17,7 @@ separator_value: CreateVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deactivatemfadevice.yml b/data_sources/aws_cloudtrail_deactivatemfadevice.yml index dd4133ce9e..92ae3afdf3 100644 --- a/data_sources/aws_cloudtrail_deactivatemfadevice.yml +++ b/data_sources/aws_cloudtrail_deactivatemfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeactivateMFADevice id: 7397a10b-1150-4de9-8062-a96454ae53b2 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deactivation of a multi-factor authentication (MFA) device, including details about the associated user and the device. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeactivateMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml index cb19785312..0ead41cbd6 100644 --- a/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_deleteaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteAccountPasswordPolicy id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of an account-level password policy in AWS, including details about the account and policy being removed. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletealarms.yml b/data_sources/aws_cloudtrail_deletealarms.yml index 4d1182b396..aec6355c97 100644 --- a/data_sources/aws_cloudtrail_deletealarms.yml +++ b/data_sources/aws_cloudtrail_deletealarms.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteAlarms id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f -version: 5 +version: 6 creation_date: '2024-08-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Logs the deletion of CloudWatch alarms, including details about the alarm names and associated monitoring configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteAlarms supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletedetector.yml b/data_sources/aws_cloudtrail_deletedetector.yml index 81e4601ba6..b3b3974744 100644 --- a/data_sources/aws_cloudtrail_deletedetector.yml +++ b/data_sources/aws_cloudtrail_deletedetector.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteDetector id: 5d8bd475-c8bc-4447-b27f-efa508728b90 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of an Amazon GuardDuty detector, including details about the detector ID and associated configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteDetector supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deletegroup.yml b/data_sources/aws_cloudtrail_deletegroup.yml index 7b3cece2f0..3dbeb2dad1 100644 --- a/data_sources/aws_cloudtrail_deletegroup.yml +++ b/data_sources/aws_cloudtrail_deletegroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteGroup id: c95308a4-a943-42ca-b112-f90a05c21bd3 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM group in AWS, including details about the group name and its associated policies or members. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteguardrail.yml b/data_sources/aws_cloudtrail_deleteguardrail.yml index 65abb9cd58..8b0bbbc0ed 100644 --- a/data_sources/aws_cloudtrail_deleteguardrail.yml +++ b/data_sources/aws_cloudtrail_deleteguardrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteGuardrail id: 2f6e9d7a-1c53-48b1-be57-33a91e0f8c42 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Logs an event when a guardrail is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteGuardrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteipset.yml b/data_sources/aws_cloudtrail_deleteipset.yml index 24712253a8..95c0758160 100644 --- a/data_sources/aws_cloudtrail_deleteipset.yml +++ b/data_sources/aws_cloudtrail_deleteipset.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteIPSet id: ebdeeb63-77a0-4808-a6fe-549956731377 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details about the IP set ID and its associated configurations. mitre_components: @@ -16,7 +16,7 @@ separator_value: DeleteIPSet supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deleteknowledgebase.yml b/data_sources/aws_cloudtrail_deleteknowledgebase.yml index 30a883423a..f113eed3fa 100644 --- a/data_sources/aws_cloudtrail_deleteknowledgebase.yml +++ b/data_sources/aws_cloudtrail_deleteknowledgebase.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteKnowledgeBase id: a8c47f25-5693-4d1a-9f8b-6e94d15ac2d9 -version: 4 +version: 5 creation_date: '2025-04-17' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Logs an event when a knowledge base is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteKnowledgeBase supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml b/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml index dca67db6e3..c192a67667 100644 --- a/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml +++ b/data_sources/aws_cloudtrail_deleteloggingconfiguration.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLoggingConfiguration id: 24a28726-28f3-4537-a953-71bfbbc3b831 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DeleteLoggingConfiguration source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time example_log: '' diff --git a/data_sources/aws_cloudtrail_deleteloggroup.yml b/data_sources/aws_cloudtrail_deleteloggroup.yml index 53a5f9f232..c0ee7868fd 100644 --- a/data_sources/aws_cloudtrail_deleteloggroup.yml +++ b/data_sources/aws_cloudtrail_deleteloggroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLogGroup id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of a CloudWatch log group, including details about the log group name and associated resources. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteLogGroup supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deletelogstream.yml b/data_sources/aws_cloudtrail_deletelogstream.yml index 600e2e6a6d..c06e8dde69 100644 --- a/data_sources/aws_cloudtrail_deletelogstream.yml +++ b/data_sources/aws_cloudtrail_deletelogstream.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteLogStream id: 6f8bb808-89f8-465e-a34d-229df2f46402 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of a log stream within a CloudWatch log group, including details about the stream name and associated log group. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteLogStream supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml b/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml index ec8d87792c..e469187ba1 100644 --- a/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml +++ b/data_sources/aws_cloudtrail_deletemodelinvocationloggingconfiguration.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteModelInvocationLoggingConfiguration id: fe2b3a52-1c8d-4e17-9f74-76c531a87e21 -version: 4 +version: 5 creation_date: '2025-04-17' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Logs an event when a model invocation logging configuration is deleted within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: DeleteModelInvocationLoggingConfiguration supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml index f32c7624f0..e98f71d772 100644 --- a/data_sources/aws_cloudtrail_deletenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_deletenetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteNetworkAclEntry id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of a network ACL entry in AWS, including details about the rule number and associated network ACL. mitre_components: @@ -16,7 +16,7 @@ separator_value: DeleteNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletepolicy.yml b/data_sources/aws_cloudtrail_deletepolicy.yml index 4d16441766..4215398f9b 100644 --- a/data_sources/aws_cloudtrail_deletepolicy.yml +++ b/data_sources/aws_cloudtrail_deletepolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeletePolicy id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of an IAM policy in AWS, including details about the policy name and its associated roles or users. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeletePolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deleterule.yml b/data_sources/aws_cloudtrail_deleterule.yml index bd985d6379..e4ba44eb1c 100644 --- a/data_sources/aws_cloudtrail_deleterule.yml +++ b/data_sources/aws_cloudtrail_deleterule.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteRule id: b5760623-f3ca-492d-a372-d5c2b3567dfc -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of an event rule in AWS EventBridge, including details about the rule name and its associated targets or schedules. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteRule supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_deleterulegroup.yml b/data_sources/aws_cloudtrail_deleterulegroup.yml index e466952e7c..af2bf4c936 100644 --- a/data_sources/aws_cloudtrail_deleterulegroup.yml +++ b/data_sources/aws_cloudtrail_deleterulegroup.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteRuleGroup id: 21c9b538-fa11-4bdf-9138-0dfe06b4d730 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DeleteRuleGroup source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time example_log: '' diff --git a/data_sources/aws_cloudtrail_deletesnapshot.yml b/data_sources/aws_cloudtrail_deletesnapshot.yml index 2a72058f2c..2cb3c86243 100644 --- a/data_sources/aws_cloudtrail_deletesnapshot.yml +++ b/data_sources/aws_cloudtrail_deletesnapshot.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteSnapshot id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f -version: 5 +version: 6 creation_date: '2024-08-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS snapshot, including details about the snapshot ID and associated resource. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteSnapshot supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletetrail.yml b/data_sources/aws_cloudtrail_deletetrail.yml index 7298f7642f..1900634ab2 100644 --- a/data_sources/aws_cloudtrail_deletetrail.yml +++ b/data_sources/aws_cloudtrail_deletetrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteTrail id: a5af09ff-07b6-4df6-92a0-2146bfe402c8 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the deletion of an AWS CloudTrail trail, including details about the trail name and its associated logging configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: DeleteTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml index 7d370b6117..4740ee9bab 100644 --- a/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml +++ b/data_sources/aws_cloudtrail_deletevirtualmfadevice.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteVirtualMFADevice id: 84a08d6b-3d59-4260-8cab-84278ada262f -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a virtual Multi-Factor Authentication (MFA) device is deleted in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteVirtualMFADevice supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_deletewebacl.yml b/data_sources/aws_cloudtrail_deletewebacl.yml index ca9f5e3f8b..0baa76c9ca 100644 --- a/data_sources/aws_cloudtrail_deletewebacl.yml +++ b/data_sources/aws_cloudtrail_deletewebacl.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DeleteWebACL id: 90da5f08-7961-4c29-8de8-01364982aadf -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: DeleteWebACL supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - apiVersion diff --git a/data_sources/aws_cloudtrail_describeeventaggregates.yml b/data_sources/aws_cloudtrail_describeeventaggregates.yml index d79cca07a9..96c4610274 100644 --- a/data_sources/aws_cloudtrail_describeeventaggregates.yml +++ b/data_sources/aws_cloudtrail_describeeventaggregates.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeEventAggregates id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when aggregate details about AWS events are queried, often for analysis. mitre_components: @@ -15,7 +15,7 @@ separator_value: DescribeEventAggregates supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_describeimagescanfindings.yml b/data_sources/aws_cloudtrail_describeimagescanfindings.yml index 88b6786e76..9f1b8389ce 100644 --- a/data_sources/aws_cloudtrail_describeimagescanfindings.yml +++ b/data_sources/aws_cloudtrail_describeimagescanfindings.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeImageScanFindings id: 688ea789-9ba2-4970-90a2-17e541e273c9 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when findings from an image vulnerability scan are described using the DescribeImageScanFindings operation in AWS CloudTrail. mitre_components: @@ -16,7 +16,7 @@ separator_value: DescribeImageScanFindings supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_describesnapshotattribute.yml b/data_sources/aws_cloudtrail_describesnapshotattribute.yml index 6ec540f2d8..2e0a01a485 100644 --- a/data_sources/aws_cloudtrail_describesnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_describesnapshotattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail DescribeSnapshotAttribute id: f054c99b-63b8-4236-8a62-b52fbbabacba -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Data source object for AWS CloudTrail DescribeSnapshotAttribute source: aws_cloudtrail @@ -11,7 +11,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - action - app diff --git a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml index 6c5e4465a6..13d2c3abe8 100644 --- a/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_getaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetAccountPasswordPolicy id: 439bdc53-6e4b-4cd7-b326-86c7317fd396 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to get the account password policy in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: GetAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_getobject.yml b/data_sources/aws_cloudtrail_getobject.yml index c066fa3405..b5e681cc88 100644 --- a/data_sources/aws_cloudtrail_getobject.yml +++ b/data_sources/aws_cloudtrail_getobject.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetObject id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to access an object stored in an AWS S3 bucket. mitre_components: @@ -16,7 +16,7 @@ separator_value: GetObject supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_getpassworddata.yml b/data_sources/aws_cloudtrail_getpassworddata.yml index 059a989f6c..b1d3674901 100644 --- a/data_sources/aws_cloudtrail_getpassworddata.yml +++ b/data_sources/aws_cloudtrail_getpassworddata.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail GetPasswordData id: 6ff2ce99-85b1-4c17-888a-56dbc3570671 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a request is made to retrieve the administrator password of an EC2 instance. mitre_components: @@ -15,7 +15,7 @@ separator_value: GetPasswordData supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_invokemodel.yml b/data_sources/aws_cloudtrail_invokemodel.yml index 27e8747f84..08f44c37b1 100644 --- a/data_sources/aws_cloudtrail_invokemodel.yml +++ b/data_sources/aws_cloudtrail_invokemodel.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail InvokeModel id: 5d92a1b6-3e78-4ff2-be83-7a4c01f9df6c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Logs an event when a model is invoked within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: InvokeModel supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_jobcreated.yml b/data_sources/aws_cloudtrail_jobcreated.yml index f09d3ddff8..f549d9e255 100644 --- a/data_sources/aws_cloudtrail_jobcreated.yml +++ b/data_sources/aws_cloudtrail_jobcreated.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail JobCreated id: 6473289b-d097-4c86-a837-3cc5ae408155 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a new job is created in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: JobCreated supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_listfoundationmodels.yml b/data_sources/aws_cloudtrail_listfoundationmodels.yml index 2023ce93ce..2c5587b6e8 100644 --- a/data_sources/aws_cloudtrail_listfoundationmodels.yml +++ b/data_sources/aws_cloudtrail_listfoundationmodels.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ListFoundationModels id: e7f31c68-84b9-4d21-a8c5-ec9d2fb3a457 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Logs an event when a list of foundation models is requested within the AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: ListFoundationModels supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_modifydbinstance.yml b/data_sources/aws_cloudtrail_modifydbinstance.yml index 9b04d54402..41c0c7e6a2 100644 --- a/data_sources/aws_cloudtrail_modifydbinstance.yml +++ b/data_sources/aws_cloudtrail_modifydbinstance.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifyDBInstance id: bfa2912d-1a33-4b05-be46-543874d68241 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a modification is made to an AWS database instance, such as parameters or configurations. mitre_components: @@ -16,7 +16,7 @@ separator_value: ModifyDBInstance supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_modifyimageattribute.yml b/data_sources/aws_cloudtrail_modifyimageattribute.yml index 0c0cd054cf..5277660d71 100644 --- a/data_sources/aws_cloudtrail_modifyimageattribute.yml +++ b/data_sources/aws_cloudtrail_modifyimageattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifyImageAttribute id: 667c2115-8082-419e-b541-8150066bda4d -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when the attributes of an Amazon Machine Image (AMI) are modified. mitre_components: @@ -15,7 +15,7 @@ separator_value: ModifyImageAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml index 8c604340d0..e7f3975ca2 100644 --- a/data_sources/aws_cloudtrail_modifysnapshotattribute.yml +++ b/data_sources/aws_cloudtrail_modifysnapshotattribute.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ModifySnapshotAttribute id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when modifications are made to the attributes of a snapshot in AWS CloudTrail. mitre_components: @@ -14,7 +14,7 @@ separator_value: ModifySnapshotAttribute supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_putbucketacl.yml b/data_sources/aws_cloudtrail_putbucketacl.yml index 9863e14e23..8609bd8c24 100644 --- a/data_sources/aws_cloudtrail_putbucketacl.yml +++ b/data_sources/aws_cloudtrail_putbucketacl.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketAcl id: 28fffbfd-d98d-4a42-990b-b04ab47422eb -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an ACL is set or modified for an S3 bucket in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutBucketAcl supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_putbucketlifecycle.yml b/data_sources/aws_cloudtrail_putbucketlifecycle.yml index a882cd6f08..56f982a5e9 100644 --- a/data_sources/aws_cloudtrail_putbucketlifecycle.yml +++ b/data_sources/aws_cloudtrail_putbucketlifecycle.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketLifecycle id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a lifecycle configuration is added to an S3 bucket in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutBucketLifecycle supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putbucketreplication.yml b/data_sources/aws_cloudtrail_putbucketreplication.yml index 196635d159..a8e0fb0e8a 100644 --- a/data_sources/aws_cloudtrail_putbucketreplication.yml +++ b/data_sources/aws_cloudtrail_putbucketreplication.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketReplication id: 0e1362eb-e592-419f-8fa5-556d3a122417 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when replication configurations are added or modified for an S3 bucket. mitre_components: @@ -14,7 +14,7 @@ separator_value: PutBucketReplication supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putbucketversioning.yml b/data_sources/aws_cloudtrail_putbucketversioning.yml index 8c57a29bc2..cf329674e2 100644 --- a/data_sources/aws_cloudtrail_putbucketversioning.yml +++ b/data_sources/aws_cloudtrail_putbucketversioning.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutBucketVersioning id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when the bucket versioning state is modified in an AWS S3 bucket. mitre_components: @@ -14,7 +14,7 @@ separator_value: PutBucketVersioning supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - additionalEventData.AuthenticationMethod diff --git a/data_sources/aws_cloudtrail_putimage.yml b/data_sources/aws_cloudtrail_putimage.yml index 9a1eb819d5..d6102c22ca 100644 --- a/data_sources/aws_cloudtrail_putimage.yml +++ b/data_sources/aws_cloudtrail_putimage.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutImage id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a container image is uploaded to a repository in AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: PutImage supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_putkeypolicy.yml b/data_sources/aws_cloudtrail_putkeypolicy.yml index f1a9dba2cf..7e649ab8bd 100644 --- a/data_sources/aws_cloudtrail_putkeypolicy.yml +++ b/data_sources/aws_cloudtrail_putkeypolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail PutKeyPolicy id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs changes made to AWS Key Management Service (KMS) key policies, including updates and permission assignments. mitre_components: @@ -13,7 +13,7 @@ separator: eventName supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml index abde7734c5..4d2af17e3e 100644 --- a/data_sources/aws_cloudtrail_replacenetworkaclentry.yml +++ b/data_sources/aws_cloudtrail_replacenetworkaclentry.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail ReplaceNetworkAclEntry id: db0c240e-3754-40e4-86ef-cde018ee9f65 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail. mitre_components: @@ -15,7 +15,7 @@ separator_value: ReplaceNetworkAclEntry supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml index 7b1f87e774..f6d58efb9b 100644 --- a/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml +++ b/data_sources/aws_cloudtrail_setdefaultpolicyversion.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail SetDefaultPolicyVersion id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when the default version of a resource policy in AWS is set or changed. mitre_components: @@ -15,7 +15,7 @@ separator_value: SetDefaultPolicyVersion supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_stoplogging.yml b/data_sources/aws_cloudtrail_stoplogging.yml index 65b985f568..b4b50e452a 100644 --- a/data_sources/aws_cloudtrail_stoplogging.yml +++ b/data_sources/aws_cloudtrail_stoplogging.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail StopLogging id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated or stopped. mitre_components: @@ -14,7 +14,7 @@ separator_value: StopLogging supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml index 333ec17d6e..1329c80f4e 100644 --- a/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml +++ b/data_sources/aws_cloudtrail_updateaccountpasswordpolicy.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateAccountPasswordPolicy id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an AWS account's password policy is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateAccountPasswordPolicy supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updateloginprofile.yml b/data_sources/aws_cloudtrail_updateloginprofile.yml index 4ef2c0a61d..9700af9e09 100644 --- a/data_sources/aws_cloudtrail_updateloginprofile.yml +++ b/data_sources/aws_cloudtrail_updateloginprofile.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateLoginProfile id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an IAM user's login profile is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateLoginProfile supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updatesamlprovider.yml b/data_sources/aws_cloudtrail_updatesamlprovider.yml index d2225c8e5e..c0480ac185 100644 --- a/data_sources/aws_cloudtrail_updatesamlprovider.yml +++ b/data_sources/aws_cloudtrail_updatesamlprovider.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateSAMLProvider id: e5eb628d-711e-499c-87d9-8fa5dee419ec -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a SAML provider is updated in AWS. mitre_components: @@ -16,7 +16,7 @@ separator_value: UpdateSAMLProvider supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - action diff --git a/data_sources/aws_cloudtrail_updatetrail.yml b/data_sources/aws_cloudtrail_updatetrail.yml index 2125d54906..50d678ea8c 100644 --- a/data_sources/aws_cloudtrail_updatetrail.yml +++ b/data_sources/aws_cloudtrail_updatetrail.yml @@ -1,8 +1,8 @@ name: AWS CloudTrail UpdateTrail id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an AWS CloudTrail trail is updated, typically involving changes to settings or configuration. mitre_components: @@ -15,7 +15,7 @@ separator_value: UpdateTrail supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - app diff --git a/data_sources/aws_cloudwatchlogs_vpcflow.yml b/data_sources/aws_cloudwatchlogs_vpcflow.yml index bf85b19bc0..1a82d849fd 100644 --- a/data_sources/aws_cloudwatchlogs_vpcflow.yml +++ b/data_sources/aws_cloudwatchlogs_vpcflow.yml @@ -1,8 +1,8 @@ name: AWS CloudWatchLogs VPCflow id: 38a34fc4-e128-4478-a8f4-7835d51d5135 -version: 5 +version: 6 creation_date: '2024-07-31' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Logs an event when network traffic flow information such as source and destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in AWS. mitre_components: @@ -12,7 +12,7 @@ source: aws_cloudwatchlogs_vpcflow sourcetype: aws:cloudwatchlogs:vpcflow supported_TA: - name: Splunk Add-on for AWS - version: 8.0.0 + version: 8.2.1 url: https://splunkbase.splunk.com/app/1876 fields: - _raw diff --git a/data_sources/aws_security_hub.yml b/data_sources/aws_security_hub.yml index 1eeac0e085..ab16148a55 100644 --- a/data_sources/aws_security_hub.yml +++ b/data_sources/aws_security_hub.yml @@ -1,8 +1,8 @@ name: AWS Security Hub id: b02bfbf3-294f-478e-99a1-e24b8c692d7e -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when AWS Security Hub identifies potential security risks or deviations from configured best practices across AWS accounts. mitre_components: @@ -15,7 +15,7 @@ sourcetype: aws:securityhub:finding supported_TA: - name: Splunk Add-on for AWS url: https://splunkbase.splunk.com/app/1876 - version: 8.0.0 + version: 8.2.1 fields: - _time - AwsAccountId diff --git a/data_sources/azure_active_directory.yml b/data_sources/azure_active_directory.yml index 383248079a..807f4f2691 100644 --- a/data_sources/azure_active_directory.yml +++ b/data_sources/azure_active_directory.yml @@ -1,8 +1,8 @@ name: Azure Active Directory id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: All Azure Active Directory events source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 output_fields: - dest - user diff --git a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml index ece15c61ab..f55fb06ff7 100644 --- a/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml +++ b/data_sources/azure_active_directory_add_app_role_assignment_to_service_principal.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add app role assignment to service principal id: 8b2e84cd-6db0-47e9-badc-75c17df1995f -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the addition of an application role assignment to a service principal in Azure Active Directory, including details about the role, service principal, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add app role assignment to service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_member_to_role.yml b/data_sources/azure_active_directory_add_member_to_role.yml index 9d862a4feb..eacdc0680f 100644 --- a/data_sources/azure_active_directory_add_member_to_role.yml +++ b/data_sources/azure_active_directory_add_member_to_role.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add member to role id: 1660d196-127f-4678-81b2-472d51711b07 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the addition of a member to a directory role in Azure Active Directory, including details about the role, the member added, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add member to role supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_owner_to_application.yml b/data_sources/azure_active_directory_add_owner_to_application.yml index d5676313fa..07e48a62a5 100644 --- a/data_sources/azure_active_directory_add_owner_to_application.yml +++ b/data_sources/azure_active_directory_add_owner_to_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add owner to application id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the addition of an owner to an application in Azure Active Directory, including details about the application, the owner added, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add owner to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_service_principal.yml b/data_sources/azure_active_directory_add_service_principal.yml index faf84b2b66..c40240fb8f 100644 --- a/data_sources/azure_active_directory_add_service_principal.yml +++ b/data_sources/azure_active_directory_add_service_principal.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add service principal id: fd89d337-e4c0-4162-ad13-bca36f096fe6 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the creation of a new service principal in Azure Active Directory, including details about the service principal, associated application, and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add service principal supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_add_unverified_domain.yml b/data_sources/azure_active_directory_add_unverified_domain.yml index 5688a9aca8..a3b3dd1e0b 100644 --- a/data_sources/azure_active_directory_add_unverified_domain.yml +++ b/data_sources/azure_active_directory_add_unverified_domain.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Add unverified domain id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs the addition of an unverified domain to Azure Active Directory, including details about the domain name and the user or process performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add unverified domain supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_consent_to_application.yml b/data_sources/azure_active_directory_consent_to_application.yml index 101219780c..7cb9f76b96 100644 --- a/data_sources/azure_active_directory_consent_to_application.yml +++ b/data_sources/azure_active_directory_consent_to_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Consent to application id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs user or admin consent to an application's permissions in Azure Active Directory, including details about the application, granted permissions, and the consenting user or process. mitre_components: @@ -17,7 +17,7 @@ separator_value: Consent to application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_disable_strong_authentication.yml b/data_sources/azure_active_directory_disable_strong_authentication.yml index b9ba531cba..249e3558cb 100644 --- a/data_sources/azure_active_directory_disable_strong_authentication.yml +++ b/data_sources/azure_active_directory_disable_strong_authentication.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Disable Strong Authentication id: 8f31966d-c496-496d-8837-f7fd11f31255 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when strong authentication methods are disabled in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Disable Strong Authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_enable_account.yml b/data_sources/azure_active_directory_enable_account.yml index b4dc489b01..17bb6b68b6 100644 --- a/data_sources/azure_active_directory_enable_account.yml +++ b/data_sources/azure_active_directory_enable_account.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Enable account id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Active Directory account is enabled. mitre_components: @@ -16,7 +16,7 @@ separator_value: Enable account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_invite_external_user.yml b/data_sources/azure_active_directory_invite_external_user.yml index 8df50ab23a..30772fb2ed 100644 --- a/data_sources/azure_active_directory_invite_external_user.yml +++ b/data_sources/azure_active_directory_invite_external_user.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Invite external user id: d3818bd5-f283-4518-8b67-df19240c3e40 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an external user is invited to join an Azure Active Directory tenant. mitre_components: @@ -16,7 +16,7 @@ separator_value: Invite external user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml b/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml index d7afe84f09..03580f461a 100644 --- a/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml +++ b/data_sources/azure_active_directory_microsoftgraphactivitylogs.yml @@ -1,8 +1,8 @@ name: Azure Active Directory MicrosoftGraphActivityLogs id: 63ff93ba-2bbb-4542-8773-239bf5266367 -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Data source object for Azure Active Directory MicrosoftGraphActivityLogs source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time example_log: '{"time": "2024-04-30T01:22:46.4948958Z", "resourceId": "/TENANTS/225E05A1-5914-4688-A404-7030E60F3143/PROVIDERS/MICROSOFT.AADIAM", "operationName": "Microsoft Graph Activity", "operationVersion": "beta", "category": "MicrosoftGraphActivityLogs", "resultSignature": "200", "durationMs": "948894", "callerIpAddress": "45.83.145.6", "correlationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "level": "Informational", "location": "East US 2", "properties": {"__UDI_RequiredFields_TenantId": "225e05a1-5914-4688-a404-7030e60f3143", "__UDI_RequiredFields_UniqueId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "__UDI_RequiredFields_EventTime": 638500369660000000, "__UDI_RequiredFields_RegionScope": "NA", "timeGenerated": "2024-04-30T01:22:46.4948958Z", "location": "East US 2", "requestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "operationId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "clientRequestId": "8fb849dd-2abe-4c3e-b202-d71af8d1555b", "apiVersion": "beta", "requestMethod": "GET", "responseStatusCode": 200, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143", "durationMs": 948894, "responseSizeBytes": 91, "signInActivityId": "KRsphQ_4s0-oHv_Br8qSAQ", "roles": "", "appId": "1950a258-227b-4e31-a9cf-717495945fc2", "UserPrincipalObjectID": "7b934539-7366-494e-a8ac-3517694d32db", "scopes": "AuditLog.Read.All Directory.AccessAsUser.All email openid profile", "identityProvider": "", "clientAuthMethod": "0", "wids": "b79fbf4d-3ef9-4689-8143-76b194e85509", "C_Idtyp": "user", "C_Iat": "1714439850", "ipAddress": "45.83.145.6", "userAgent": "azurehound/v2.1.8", "requestUri": "https://graph.microsoft.com/beta/servicePrincipals/ffe3e001-d8cf-43a4-89ab-bfce35fd7786/owners?%24top=999", "userId": "7b934539-7366-494e-a8ac-3517694d32db", "tokenIssuedAt": "2024-04-30T01:17:30.0000000Z"}, "tenantId": "225e05a1-5914-4688-a404-7030e60f3143"}' diff --git a/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml b/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml index e43241ff0c..222a54d23f 100644 --- a/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml +++ b/data_sources/azure_active_directory_noninteractiveusersigninlogs.yml @@ -1,8 +1,8 @@ name: Azure Active Directory NonInteractiveUserSignInLogs id: 11fe8a43-164d-47e4-b542-afc2f242068b -version: 4 +version: 5 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Data source object for Azure Active Directory NonInteractiveUserSignInLogs source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - action - additional_details diff --git a/data_sources/azure_active_directory_reset_password_(by_admin).yml b/data_sources/azure_active_directory_reset_password_(by_admin).yml index 299932977e..74477d07e2 100644 --- a/data_sources/azure_active_directory_reset_password_(by_admin).yml +++ b/data_sources/azure_active_directory_reset_password_(by_admin).yml @@ -1,8 +1,8 @@ name: Azure Active Directory Reset password (by admin) id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an admin resets a user's password in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Reset password (by admin) supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_set_domain_authentication.yml b/data_sources/azure_active_directory_set_domain_authentication.yml index f4a366a02b..5272f9819a 100644 --- a/data_sources/azure_active_directory_set_domain_authentication.yml +++ b/data_sources/azure_active_directory_set_domain_authentication.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Set domain authentication id: e7bcdab9-908c-40ab-ba38-5db54fa87750 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when the authentication method for a domain in Azure Active Directory is set or modified. mitre_components: @@ -16,7 +16,7 @@ separator_value: Set domain authentication supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_sign_in_activity.yml b/data_sources/azure_active_directory_sign_in_activity.yml index e5b21a3ba8..c5f01e2bea 100644 --- a/data_sources/azure_active_directory_sign_in_activity.yml +++ b/data_sources/azure_active_directory_sign_in_activity.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Sign-in activity id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a user attempts to sign into Azure Active Directory, capturing authentication details and outcomes. mitre_components: @@ -16,7 +16,7 @@ separator_value: Sign-in activity supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_application.yml b/data_sources/azure_active_directory_update_application.yml index e51d0727b6..bb5240b324 100644 --- a/data_sources/azure_active_directory_update_application.yml +++ b/data_sources/azure_active_directory_update_application.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update application id: 2c08188a-ba25-496e-87c7-803cf28b6c90 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an application in Azure Active Directory is updated, such as changes to its settings or permissions. mitre_components: @@ -16,7 +16,7 @@ separator_value: Update application supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_authorization_policy.yml b/data_sources/azure_active_directory_update_authorization_policy.yml index 381b94dff1..b14cf38014 100644 --- a/data_sources/azure_active_directory_update_authorization_policy.yml +++ b/data_sources/azure_active_directory_update_authorization_policy.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update authorization policy id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an authorization policy is updated in Azure Active Directory. mitre_components: @@ -16,7 +16,7 @@ separator_value: Update authorization policy supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_update_user.yml b/data_sources/azure_active_directory_update_user.yml index c67db742f0..95fc6c570b 100644 --- a/data_sources/azure_active_directory_update_user.yml +++ b/data_sources/azure_active_directory_update_user.yml @@ -1,8 +1,8 @@ name: Azure Active Directory Update user id: 5495c90a-047c-4b8e-b2fe-1db6282d3872 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a user account is updated in Azure Active Directory. mitre_components: @@ -15,7 +15,7 @@ separator_value: Update user supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_active_directory_user_registered_security_info.yml b/data_sources/azure_active_directory_user_registered_security_info.yml index 77af9e9d8a..4bae588435 100644 --- a/data_sources/azure_active_directory_user_registered_security_info.yml +++ b/data_sources/azure_active_directory_user_registered_security_info.yml @@ -1,8 +1,8 @@ name: Azure Active Directory User registered security info id: b63240de-8a01-4ba8-8987-89d18d4b375d -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a user registers or updates their security information in Azure Active Directory. mitre_components: @@ -15,7 +15,7 @@ separator_value: User registered security info supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - Level diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml index d7259cc19f..610f1ddca5 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_account.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation account id: 2ab182e7-feda-4249-9418-32710b55a885 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when an Azure Automation account is created or updated. mitre_components: @@ -16,7 +16,7 @@ separator_value: Create or Update an Azure Automation account supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - authorization.action diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml index a676995a3e..cbbc60fffa 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_runbook.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation Runbook id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a new Azure Automation Runbook is created or an existing one is updated. mitre_components: @@ -15,7 +15,7 @@ separator_value: Create or Update an Azure Automation Runbook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - authorization.action diff --git a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml index 7e49be1be5..679f1a2647 100644 --- a/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml +++ b/data_sources/azure_audit_create_or_update_an_azure_automation_webhook.yml @@ -1,8 +1,8 @@ name: Azure Audit Create or Update an Azure Automation webhook id: 575faeb2-09d0-4849-b1f6-eae241f26ff2 -version: 5 +version: 6 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs an event when a webhook is created or updated in Azure Automation. mitre_components: @@ -16,7 +16,7 @@ separator_value: Create or Update an Azure Automation webhook supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - _time - authorization.action diff --git a/data_sources/azure_monitor_activity.yml b/data_sources/azure_monitor_activity.yml index b856400073..a1e3d8dfab 100644 --- a/data_sources/azure_monitor_activity.yml +++ b/data_sources/azure_monitor_activity.yml @@ -1,8 +1,8 @@ name: Azure Monitor Activity id: 1997a515-a61a-4f78-ada9-54af34c764f2 -version: 4 +version: 5 creation_date: '2025-01-13' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Bhavin Patel, Splunk description: Data source object for Azure Monitor Activity. The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest In-Tune audit logs via Azure EventHub. To configure this logging, visit Intune > Tenant administration > Diagnostic settings > Add diagnostic settings & send events to the activity audit event hub. source: Azure AD @@ -11,7 +11,7 @@ separator: operationName supported_TA: - name: Splunk Add-on for Microsoft Cloud Services url: https://splunkbase.splunk.com/app/3110 - version: 6.1.3 + version: 6.3.1 fields: - column - action diff --git a/data_sources/crowdstrike_falcon_stream_alert.yml b/data_sources/crowdstrike_falcon_stream_alert.yml index 02449e7dbc..03970e7e41 100644 --- a/data_sources/crowdstrike_falcon_stream_alert.yml +++ b/data_sources/crowdstrike_falcon_stream_alert.yml @@ -1,8 +1,8 @@ name: CrowdStrike Falcon Stream Alert id: 52b38751-b0db-4965-a800-ebaabd1fd7d5 -version: 5 +version: 6 creation_date: '2025-07-01' -modification_date: '2026-07-25' +modification_date: '2026-07-30' author: Bhavin Patel, Bryan Pluta, Splunk description: Logs of CrowdStrike Falcon Stream Alerts mitre_components: @@ -17,7 +17,7 @@ separator: event.DetectName supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 3.0.0 + version: 3.1.2 fields: - action - description diff --git a/data_sources/crowdstrike_processrollup2.yml b/data_sources/crowdstrike_processrollup2.yml index 97feb0702b..c7b167e374 100644 --- a/data_sources/crowdstrike_processrollup2.yml +++ b/data_sources/crowdstrike_processrollup2.yml @@ -1,8 +1,8 @@ name: CrowdStrike ProcessRollup2 id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-25' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments. mitre_components: @@ -18,7 +18,7 @@ separator_value: ProcessRollup2 supported_TA: - name: Splunk Add-on for CrowdStrike FDR url: https://splunkbase.splunk.com/app/5579 - version: 3.0.0 + version: 3.1.2 fields: - AuthenticationId - AuthenticationId_meaning diff --git a/data_sources/okta.yml b/data_sources/okta.yml index 712b211cfc..81560d167b 100644 --- a/data_sources/okta.yml +++ b/data_sources/okta.yml @@ -1,8 +1,8 @@ name: Okta id: ec26febe-e760-4981-bbee-72e107c7b9d2 -version: 4 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-06-30' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs authentication and administrative activities captured by Okta, including user login attempts, session management, and configuration changes. mitre_components: @@ -16,7 +16,7 @@ sourcetype: OktaIM2:log supported_TA: - name: Splunk Add-on for Okta Identity Cloud url: https://splunkbase.splunk.com/app/6553 - version: 5.0.3 + version: 5.1.0 output_fields: - dest - src diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml index b4135fec26..f9f8d7f034 100644 --- a/data_sources/palo_alto_network_threat.yml +++ b/data_sources/palo_alto_network_threat.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Threat id: 375c2b0e-d216-41ad-9406-200464595209 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-25' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:threat supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.1.0 + version: 3.2.2 fields: - _time - date_hour diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml index b4a7d6e3da..445f0198ed 100644 --- a/data_sources/palo_alto_network_traffic.yml +++ b/data_sources/palo_alto_network_traffic.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Traffic id: 182a83bc-c31a-4817-8c7a-263744cec52a -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-25' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:traffic supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.1.0 + version: 3.2.2 fields: - _time - date_hour From 049fd715363dd2ba8378fb75a08999fe1dc7b7ab Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Thu, 30 Jul 2026 16:27:47 +0000 Subject: [PATCH 21/32] Update datasource TA versions --- data_sources/linux_auditd_add_user.yml | 6 +++--- data_sources/linux_auditd_cwd.yml | 6 +++--- data_sources/linux_auditd_daemon_abort.yml | 6 +++--- data_sources/linux_auditd_daemon_end.yml | 6 +++--- data_sources/linux_auditd_daemon_start.yml | 6 +++--- data_sources/linux_auditd_execve.yml | 6 +++--- data_sources/linux_auditd_path.yml | 6 +++--- data_sources/linux_auditd_proctitle.yml | 6 +++--- data_sources/linux_auditd_service_stop.yml | 6 +++--- data_sources/linux_auditd_syscall.yml | 6 +++--- data_sources/linux_messages_syslog.yml | 6 +++--- data_sources/linux_secure.yml | 6 +++--- 12 files changed, 36 insertions(+), 36 deletions(-) diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index 4252849930..16d0e52b16 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -1,8 +1,8 @@ name: Linux Auditd Add User id: 30f79353-e1d2-4585-8735-1e0359559f3f -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - msg - type diff --git a/data_sources/linux_auditd_cwd.yml b/data_sources/linux_auditd_cwd.yml index a8414e00c7..74f486cf02 100644 --- a/data_sources/linux_auditd_cwd.yml +++ b/data_sources/linux_auditd_cwd.yml @@ -1,8 +1,8 @@ name: Linux Auditd Cwd id: a9ef851b-d864-478b-b1b3-76535d7ff7fc -version: 5 +version: 6 creation_date: '2025-12-02' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Nasreddine Bencherchali, Splunk description: This type is used to record the working directory from which the process that invoked the system call specified in the first record was executed. The purpose of this record is to record the current process's location in case a relative path winds up being captured in the associated PATH record. This way the absolute path can be reconstructed. source: auditd @@ -13,7 +13,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - cwd - date_hour diff --git a/data_sources/linux_auditd_daemon_abort.yml b/data_sources/linux_auditd_daemon_abort.yml index f671e65f03..8f72d94172 100644 --- a/data_sources/linux_auditd_daemon_abort.yml +++ b/data_sources/linux_auditd_daemon_abort.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Abort id: cc8b3bb0-0fae-4236-9c61-fe2d7138bd63 -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_end.yml b/data_sources/linux_auditd_daemon_end.yml index a4f8a05408..15f3bc7203 100644 --- a/data_sources/linux_auditd_daemon_end.yml +++ b/data_sources/linux_auditd_daemon_end.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon End id: 15135c45-e302-4d5a-a38a-3e8279f2ebd8 -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_start.yml b/data_sources/linux_auditd_daemon_start.yml index 08df6c79e2..5ec90785a6 100644 --- a/data_sources/linux_auditd_daemon_start.yml +++ b/data_sources/linux_auditd_daemon_start.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Start id: f1b97407-ddf0-41a5-8685-ada05aae3555 -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - type - op diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 550c15c753..9bcded1c7b 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -1,8 +1,8 @@ name: Linux Auditd Execve id: 9ef6364d-cc67-480e-8448-3306829a6a24 -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - msg - type diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index bb9eda21f2..b878fc9daa 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -1,8 +1,8 @@ name: Linux Auditd Path id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - msg - type diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index f3f1d85365..1c835ca384 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -1,8 +1,8 @@ name: Linux Auditd Proctitle id: 5a25984a-2789-400a-858b-d75c923e06b1 -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - proctitle - msg diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index adbcff9a61..b4078394b9 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -1,8 +1,8 @@ name: Linux Auditd Service Stop id: 0643483c-bc62-455c-8d6e-1630e5f0e00d -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - msg - type diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index 01141c44d0..3cd1db7d09 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -1,8 +1,8 @@ name: Linux Auditd Syscall id: 4dff7047-0d43-4096-bb3f-b756c889bbad -version: 6 +version: 7 creation_date: '2024-08-08' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Teoderick Contreras, Splunk description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - msg - type diff --git a/data_sources/linux_messages_syslog.yml b/data_sources/linux_messages_syslog.yml index 16dd97f143..ecf265e4ca 100644 --- a/data_sources/linux_messages_syslog.yml +++ b/data_sources/linux_messages_syslog.yml @@ -1,8 +1,8 @@ name: Linux Messages Syslog id: c9e3bbb5-e0a2-4bac-8457-227e71841bda -version: 4 +version: 5 creation_date: '2025-05-06' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Ravent Tait, Splunk description: Logs kernel events on a Linux system, including service starts/stops, hardware events, authentication notices, and other OS-level activity. @@ -16,7 +16,7 @@ sourcetype: linux_messages_syslog supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - _time - action diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index a6285162b7..c5a8884d70 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -1,8 +1,8 @@ name: Linux Secure id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb -version: 6 +version: 7 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-30' author: Patrick Bareiss, Splunk description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. mitre_components: @@ -16,7 +16,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.2.0 + version: 10.3.2 fields: - _time - action From 77a024eab07c2216ba1e234b7851a1fb8a809d68 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Fri, 31 Jul 2026 13:27:32 +0000 Subject: [PATCH 22/32] Update datasource TA versions --- data_sources/ntlm_operational_8004.yml | 6 +++--- data_sources/ntlm_operational_8005.yml | 6 +++--- data_sources/ntlm_operational_8006.yml | 6 +++--- data_sources/powershell_script_block_logging_4104.yml | 6 +++--- data_sources/windows_active_directory_admon.yml | 6 +++--- data_sources/windows_event_log_application_15457.yml | 6 +++--- data_sources/windows_event_log_application_17135.yml | 6 +++--- data_sources/windows_event_log_application_2282.yml | 6 +++--- data_sources/windows_event_log_application_3000.yml | 6 +++--- data_sources/windows_event_log_application_8128.yml | 6 +++--- .../windows_event_log_appxdeployment_server_400.yml | 6 +++--- .../windows_event_log_appxdeployment_server_854.yml | 6 +++--- .../windows_event_log_appxdeployment_server_855.yml | 6 +++--- data_sources/windows_event_log_appxpackaging_171.yml | 6 +++--- data_sources/windows_event_log_capi2_70.yml | 6 +++--- data_sources/windows_event_log_capi2_81.yml | 6 +++--- .../windows_event_log_certificateservicesclient_1007.yml | 6 +++--- data_sources/windows_event_log_defender_1121.yml | 6 +++--- data_sources/windows_event_log_defender_1122.yml | 6 +++--- data_sources/windows_event_log_defender_1125.yml | 6 +++--- data_sources/windows_event_log_defender_1126.yml | 6 +++--- data_sources/windows_event_log_defender_1129.yml | 6 +++--- data_sources/windows_event_log_defender_1131.yml | 6 +++--- data_sources/windows_event_log_defender_1132.yml | 6 +++--- data_sources/windows_event_log_defender_1133.yml | 6 +++--- data_sources/windows_event_log_defender_1134.yml | 6 +++--- data_sources/windows_event_log_defender_5007.yml | 6 +++--- data_sources/windows_event_log_printservice_316.yml | 6 +++--- data_sources/windows_event_log_printservice_4909.yml | 6 +++--- data_sources/windows_event_log_printservice_808.yml | 6 +++--- .../windows_event_log_remoteconnectionmanager_1149.yml | 6 +++--- data_sources/windows_event_log_security_1100.yml | 6 +++--- data_sources/windows_event_log_security_1102.yml | 6 +++--- data_sources/windows_event_log_security_4624.yml | 6 +++--- data_sources/windows_event_log_security_4625.yml | 6 +++--- data_sources/windows_event_log_security_4627.yml | 6 +++--- data_sources/windows_event_log_security_4648.yml | 6 +++--- data_sources/windows_event_log_security_4662.yml | 6 +++--- data_sources/windows_event_log_security_4663.yml | 6 +++--- data_sources/windows_event_log_security_4672.yml | 6 +++--- data_sources/windows_event_log_security_4688.yml | 6 +++--- data_sources/windows_event_log_security_4698.yml | 6 +++--- data_sources/windows_event_log_security_4699.yml | 6 +++--- data_sources/windows_event_log_security_4700.yml | 6 +++--- data_sources/windows_event_log_security_4702.yml | 6 +++--- data_sources/windows_event_log_security_4703.yml | 6 +++--- data_sources/windows_event_log_security_4719.yml | 6 +++--- data_sources/windows_event_log_security_4720.yml | 6 +++--- data_sources/windows_event_log_security_4723.yml | 6 +++--- data_sources/windows_event_log_security_4724.yml | 6 +++--- data_sources/windows_event_log_security_4725.yml | 6 +++--- data_sources/windows_event_log_security_4726.yml | 6 +++--- data_sources/windows_event_log_security_4727.yml | 6 +++--- data_sources/windows_event_log_security_4728.yml | 6 +++--- data_sources/windows_event_log_security_4730.yml | 6 +++--- data_sources/windows_event_log_security_4731.yml | 6 +++--- data_sources/windows_event_log_security_4732.yml | 6 +++--- data_sources/windows_event_log_security_4737.yml | 6 +++--- data_sources/windows_event_log_security_4738.yml | 6 +++--- data_sources/windows_event_log_security_4739.yml | 6 +++--- data_sources/windows_event_log_security_4741.yml | 6 +++--- data_sources/windows_event_log_security_4742.yml | 6 +++--- data_sources/windows_event_log_security_4744.yml | 6 +++--- data_sources/windows_event_log_security_4749.yml | 6 +++--- data_sources/windows_event_log_security_4754.yml | 6 +++--- data_sources/windows_event_log_security_4756.yml | 6 +++--- data_sources/windows_event_log_security_4759.yml | 6 +++--- data_sources/windows_event_log_security_4768.yml | 6 +++--- data_sources/windows_event_log_security_4769.yml | 6 +++--- data_sources/windows_event_log_security_4771.yml | 6 +++--- data_sources/windows_event_log_security_4776.yml | 6 +++--- data_sources/windows_event_log_security_4781.yml | 6 +++--- data_sources/windows_event_log_security_4783.yml | 6 +++--- data_sources/windows_event_log_security_4790.yml | 6 +++--- data_sources/windows_event_log_security_4794.yml | 6 +++--- data_sources/windows_event_log_security_4798.yml | 6 +++--- data_sources/windows_event_log_security_4876.yml | 6 +++--- data_sources/windows_event_log_security_4886.yml | 6 +++--- data_sources/windows_event_log_security_4887.yml | 6 +++--- data_sources/windows_event_log_security_4946.yml | 6 +++--- data_sources/windows_event_log_security_4947.yml | 6 +++--- data_sources/windows_event_log_security_4948.yml | 6 +++--- data_sources/windows_event_log_security_5136.yml | 6 +++--- data_sources/windows_event_log_security_5137.yml | 6 +++--- data_sources/windows_event_log_security_5140.yml | 6 +++--- data_sources/windows_event_log_security_5141.yml | 6 +++--- data_sources/windows_event_log_security_5145.yml | 6 +++--- data_sources/windows_event_log_system_104.yml | 6 +++--- data_sources/windows_event_log_system_4720.yml | 6 +++--- data_sources/windows_event_log_system_4726.yml | 6 +++--- data_sources/windows_event_log_system_4728.yml | 6 +++--- data_sources/windows_event_log_system_7036.yml | 6 +++--- data_sources/windows_event_log_system_7040.yml | 6 +++--- data_sources/windows_event_log_system_7045.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_200.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_201.yml | 6 +++--- data_sources/windows_iis.yml | 6 +++--- data_sources/windows_iis_29.yml | 6 +++--- 98 files changed, 294 insertions(+), 294 deletions(-) diff --git a/data_sources/ntlm_operational_8004.yml b/data_sources/ntlm_operational_8004.yml index f021a32a67..b34e8497ae 100644 --- a/data_sources/ntlm_operational_8004.yml +++ b/data_sources/ntlm_operational_8004.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8004 id: fd08cb77-c26e-464c-a43e-2867e232127e -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8004 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8005.yml b/data_sources/ntlm_operational_8005.yml index cea1358b38..2dff87c33d 100644 --- a/data_sources/ntlm_operational_8005.yml +++ b/data_sources/ntlm_operational_8005.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8005 id: ad15a1cf-4b21-43de-81e4-6307c69172fb -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8005 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8006.yml b/data_sources/ntlm_operational_8006.yml index 357150d23c..11a3b23b93 100644 --- a/data_sources/ntlm_operational_8006.yml +++ b/data_sources/ntlm_operational_8006.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8006 id: 9f50a672-6f7d-4621-a3bd-69468c6b7a7f -version: 6 +version: 7 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8006 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index d66d449cf0..5fbb147de2 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,8 +1,8 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: @@ -18,7 +18,7 @@ separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index 0e5ebff6bd..cc0a93ca92 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -1,8 +1,8 @@ name: Windows Active Directory Admon id: 22bbf4e4-d313-43c1-98ee-808b8775519d -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ActiveDirectory supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Guid diff --git a/data_sources/windows_event_log_application_15457.yml b/data_sources/windows_event_log_application_15457.yml index 8fe42e1e7f..2a50cb0e27 100644 --- a/data_sources/windows_event_log_application_15457.yml +++ b/data_sources/windows_event_log_application_15457.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 15457 id: 4491537e-520c-46f7-9209-f56f852aa237 -version: 6 +version: 7 creation_date: '2025-02-25' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 15457 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_17135.yml b/data_sources/windows_event_log_application_17135.yml index 852fd9286b..06fb0a19ea 100644 --- a/data_sources/windows_event_log_application_17135.yml +++ b/data_sources/windows_event_log_application_17135.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 17135 id: 4491537e-520c-46f7-9209-f56f852aa231 -version: 6 +version: 7 creation_date: '2025-02-25' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 17135 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index ffab0ffddc..c2ff9fd25a 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 2282 id: 4490537e-5e0c-46f7-9209-f56f852aa237 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index 00915b2464..f07113fe44 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: @@ -17,7 +17,7 @@ separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_8128.yml b/data_sources/windows_event_log_application_8128.yml index 8fa1f13e70..3452485c5b 100644 --- a/data_sources/windows_event_log_application_8128.yml +++ b/data_sources/windows_event_log_application_8128.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 8128 id: 4491537e-5e0c-46f7-9209-f56f852aa237 -version: 6 +version: 7 creation_date: '2025-02-25' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 8128 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_400.yml b/data_sources/windows_event_log_appxdeployment_server_400.yml index f6431ed5f5..6c29b72657 100644 --- a/data_sources/windows_event_log_appxdeployment_server_400.yml +++ b/data_sources/windows_event_log_appxdeployment_server_400.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 400 id: 3e5f9d2a-b8c7-4d1e-a6f3-7b9c8d5e4f2a -version: 6 +version: 7 creation_date: '2025-08-18' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 400. These events are generated when a package deployment operation begins, providing details about the package being deployed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_854.yml b/data_sources/windows_event_log_appxdeployment_server_854.yml index 14bcf95530..38461b520a 100644 --- a/data_sources/windows_event_log_appxdeployment_server_854.yml +++ b/data_sources/windows_event_log_appxdeployment_server_854.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 854 id: 4d2e6f8a-c9b7-5a3e-8d1f-2e9c7b5a4f3d -version: 6 +version: 7 creation_date: '2025-08-18' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 854. These events are generated when an MSIX/AppX package has been successfully installed on a system. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_855.yml b/data_sources/windows_event_log_appxdeployment_server_855.yml index e495831796..0c279a5086 100644 --- a/data_sources/windows_event_log_appxdeployment_server_855.yml +++ b/data_sources/windows_event_log_appxdeployment_server_855.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 855 id: 4491537c-521c-46f7-9209-f56f852aa231 -version: 6 +version: 7 creation_date: '2025-08-18' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 855. These events are generated when a package deployment operation completes successfully, providing details about the packages that were installed or updated. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxpackaging_171.yml b/data_sources/windows_event_log_appxpackaging_171.yml index 206067ecf9..0b02870260 100644 --- a/data_sources/windows_event_log_appxpackaging_171.yml +++ b/data_sources/windows_event_log_appxpackaging_171.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXPackaging 171 id: 2d0f8e3c-a2d7-4b9e-8f1c-6a5d7e3e9f2b -version: 6 +version: 7 creation_date: '2025-08-18' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXPackaging/Operational channel, specifically focusing on EventCode 171. These events are generated when a user clicks on or attempts to interact with an MSIX package, even if the package is not fully installed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 719e16841e..435802e868 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: @@ -18,7 +18,7 @@ separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index 6dd58c7dd8..751530ae30 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 81 id: 463ff898-8135-4c0e-811e-f8629dfc5027 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index 3bffd0b680..10706daac0 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -1,8 +1,8 @@ name: Windows Event Log CertificateServicesClient 1007 id: c51444e3-479d-4c4a-b111-e8276a3acf39 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index 7d1dd00abb..a764fc2be4 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1121 id: 84a254c5-7900-4b52-a324-a176adb7c11d -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index ce5abc85a4..1428eda3fb 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1122 id: 4a2d0499-f489-4557-82f4-f357025cf3e7 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1125.yml b/data_sources/windows_event_log_defender_1125.yml index 6f83c49759..c8332bc9f8 100644 --- a/data_sources/windows_event_log_defender_1125.yml +++ b/data_sources/windows_event_log_defender_1125.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1125 id: 0cddda76-6fd8-4fb6-9026-f23a2761c95d -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1125 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time example_log: 112204000x80000000000000003701Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender Antivirus4.18.23100.2009E6DB77E5-3DF2-4CF1-B95A-636979351E5B2023-11-26T23:43:08.709Z(unknown user)C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1.401.1247.01.1.23100.2009ENT\ConsRC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x00000000 diff --git a/data_sources/windows_event_log_defender_1126.yml b/data_sources/windows_event_log_defender_1126.yml index dac1bf224f..bb2e14c048 100644 --- a/data_sources/windows_event_log_defender_1126.yml +++ b/data_sources/windows_event_log_defender_1126.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1126 id: c1c6284b-b663-4001-bdf2-c0cacee22a2a -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1126 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index c26b7bf0c0..e61c484257 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1129 id: 0572e119-a48a-4c70-bc58-90e453edacd2 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_defender_1131.yml b/data_sources/windows_event_log_defender_1131.yml index 811685381d..fe87e68050 100644 --- a/data_sources/windows_event_log_defender_1131.yml +++ b/data_sources/windows_event_log_defender_1131.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1131 id: 638f884e-439a-4328-923c-ec5a2679f450 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1131 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1132.yml b/data_sources/windows_event_log_defender_1132.yml index 4cd6e2a32e..d6ce240c1c 100644 --- a/data_sources/windows_event_log_defender_1132.yml +++ b/data_sources/windows_event_log_defender_1132.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1132 id: 18f93f60-4eca-46e8-a29d-147e6451a34c -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1132 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1133.yml b/data_sources/windows_event_log_defender_1133.yml index e8a711475e..03f7665049 100644 --- a/data_sources/windows_event_log_defender_1133.yml +++ b/data_sources/windows_event_log_defender_1133.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1133 id: 63c97a9a-cc7f-46c5-b219-8be388666637 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1133 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1134.yml b/data_sources/windows_event_log_defender_1134.yml index 4f24129663..f1345b1aac 100644 --- a/data_sources/windows_event_log_defender_1134.yml +++ b/data_sources/windows_event_log_defender_1134.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1134 id: 26abac7d-d026-44e9-b1a3-13e3e11b232d -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1134 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index 63bd60a44a..4fa5a9197f 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 5007 id: 27f18792-8d95-4871-8853-874b7faf023f -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when Windows Defender antimalware settings are modified. mitre_components: @@ -14,7 +14,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index 137e086222..29af489495 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_printservice_4909.yml b/data_sources/windows_event_log_printservice_4909.yml index c77a2c8ede..5c41132884 100644 --- a/data_sources/windows_event_log_printservice_4909.yml +++ b/data_sources/windows_event_log_printservice_4909.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 4909 id: 4c00e353-18b8-4de6-896d-83bc5817dbaa -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Printservice 4909 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time example_log: '' diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index 9567d3c63a..d9974feb95 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: @@ -16,7 +16,7 @@ separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index f02c5bb7ca..d25f2cc844 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,8 +1,8 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index cc56da8360..2acb29b989 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: @@ -15,7 +15,7 @@ separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index bb8b0045fe..b70caf0ad8 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 315f526e9c..4d5340c3a8 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index aa781065d5..444a4a4064 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4625 id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when an account fails to log on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index 33bb61a791..c7dac65547 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4627 id: e35c7b9a-b451-4084-95a5-43b7f8965cac -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index 4923f2fc2e..35debc164b 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4648 id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account mitre_components: @@ -15,7 +15,7 @@ separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index 345208a98d..3aca59ef55 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4662 id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it mitre_components: @@ -15,7 +15,7 @@ separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index f899833505..77c78d5f70 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4663 id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer mitre_components: @@ -15,7 +15,7 @@ separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 76f06e225c..89b4f40063 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index 77461e0635..c895aa32fa 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4688 id: d195eb26-a81c-45ed-aeb3-25792e8a985a -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the creation of a new process mitre_components: @@ -16,7 +16,7 @@ configuration: Enabling Windows event log process command line logging via group supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - Caller_Domain - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index 07c820e013..ddf6e75432 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4698 id: 32c06703-02d3-47ec-8856-b0dc3045866c -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a new scheduled task is created mitre_components: @@ -15,7 +15,7 @@ separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index 89cd725f48..3e8fc11a63 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4699 id: 4727dead-d063-4333-9ddd-59823a416aff -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a scheduled task is deleted from the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4700.yml b/data_sources/windows_event_log_security_4700.yml index 1e855d66a3..f5c77c2236 100644 --- a/data_sources/windows_event_log_security_4700.yml +++ b/data_sources/windows_event_log_security_4700.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4700 id: 89895c7b-2aba-41ca-ad12-8b6d290b5dde -version: 7 +version: 8 creation_date: '2025-03-11' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Steven Dick description: Data source object for Windows Event Log Security 4700 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - EventID example_log: 4700 0 0 12804 0 0x8020000000000000 344861 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin LeastPrivilege CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4702.yml b/data_sources/windows_event_log_security_4702.yml index bd331b7e49..7a21f89907 100644 --- a/data_sources/windows_event_log_security_4702.yml +++ b/data_sources/windows_event_log_security_4702.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 -version: 7 +version: 8 creation_date: '2025-03-11' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 8da3e9d9f0..1327b7bdcd 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4703 id: e256673b-16e8-4b74-b7aa-9eed6ce67072 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a token right is adjusted on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index 54cb74defe..a3a12d4994 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4719 id: 954033e6-dd05-4775-a1f2-1f19632f4420 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a system audit policy is modified on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index 54d88e8b70..9ff3acc11a 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4720 id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a new user account is created on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4723.yml b/data_sources/windows_event_log_security_4723.yml index 4f41302167..51551574f7 100644 --- a/data_sources/windows_event_log_security_4723.yml +++ b/data_sources/windows_event_log_security_4723.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4723 id: df19b271-57c8-4f31-817a-6c5566985484 -version: 5 +version: 6 creation_date: '2026-06-15' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Raven Tait, Splunk description: Logs an event when an attempt is made to change an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4723' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index fc3f1d494e..b88929472f 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4724 id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when an attempt is made to reset an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index 204a6c56e0..e84068e883 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4725 id: 31fd887d-0d14-44cc-bb64-80063a9f2968 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a user account has been disabled in Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index 66c53d1906..6da8f9f7d7 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4726 id: 0b56dcd7-0f72-4a05-9226-d6059781737b -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a user account is deleted from Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4727.yml b/data_sources/windows_event_log_security_4727.yml index 1cc19bd45f..901096f0f0 100644 --- a/data_sources/windows_event_log_security_4727.yml +++ b/data_sources/windows_event_log_security_4727.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4727 id: 4d2078ab-36f5-447e-b7e4-474890b8040b -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4727 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4728.yml b/data_sources/windows_event_log_security_4728.yml index 291b930bcf..289b61f2e3 100644 --- a/data_sources/windows_event_log_security_4728.yml +++ b/data_sources/windows_event_log_security_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4728 id: c0cb4907-d715-41f2-a98a-4f4e75f248c1 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4728 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4730.yml b/data_sources/windows_event_log_security_4730.yml index 76628f6320..f801922855 100644 --- a/data_sources/windows_event_log_security_4730.yml +++ b/data_sources/windows_event_log_security_4730.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4730 id: 126966ba-a17d-4194-882b-57d303aaf46d -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4730 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4731.yml b/data_sources/windows_event_log_security_4731.yml index 8ef95376d2..2ace30e4e2 100644 --- a/data_sources/windows_event_log_security_4731.yml +++ b/data_sources/windows_event_log_security_4731.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4731 id: 1bbc004e-a75e-4d94-a619-c5aaf5d11ed5 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4731 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index 7d337cd245..0ca78aecd0 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4732 id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a member is added to a security-enabled local group on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4737.yml b/data_sources/windows_event_log_security_4737.yml index 5eb8b5d315..cbca5c530e 100644 --- a/data_sources/windows_event_log_security_4737.yml +++ b/data_sources/windows_event_log_security_4737.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4737 id: 132fc609-17f0-4efd-8f7e-db12139c6690 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4737 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index 5727e4d47d..6a07c9d51c 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4738 id: cb85709b-101e-41a9-bb60-d2108f79dfbd -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index cb67eff56d..9c52e754b6 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4739 id: c1e0442a-8a97-405d-baf2-057c5d68cd9a -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index 93bdaaa343..615d0065d0 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4741 id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index b9f02855bc..86fd083ded 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4742 id: ea830adf-5450-489a-bcdc-fb8d2cbe674c -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4744.yml b/data_sources/windows_event_log_security_4744.yml index 88c5a61c84..ee7c86a01f 100644 --- a/data_sources/windows_event_log_security_4744.yml +++ b/data_sources/windows_event_log_security_4744.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4744 id: 244e0bd4-00b0-4091-b8b4-9d435aca6ad8 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4744 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4749.yml b/data_sources/windows_event_log_security_4749.yml index 0890cc241c..cc49946185 100644 --- a/data_sources/windows_event_log_security_4749.yml +++ b/data_sources/windows_event_log_security_4749.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4749 id: eb322056-01a3-4cd5-bc09-01140d33194a -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4749 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4754.yml b/data_sources/windows_event_log_security_4754.yml index 8712919afe..7b464c73b6 100644 --- a/data_sources/windows_event_log_security_4754.yml +++ b/data_sources/windows_event_log_security_4754.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4754 id: 501a507e-3275-4c4b-9c44-53eecfeae487 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4754 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4756.yml b/data_sources/windows_event_log_security_4756.yml index c68931342d..184f877445 100644 --- a/data_sources/windows_event_log_security_4756.yml +++ b/data_sources/windows_event_log_security_4756.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4756 id: b0093058-0cb6-4c73-a95b-fb0f3541e88c -version: 6 +version: 7 creation_date: '2026-03-30' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Nasreddine Bencherchali, Splunk description: Data source object for Windows Event Log Security 4756 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4759.yml b/data_sources/windows_event_log_security_4759.yml index 65cf71ef83..933cb169e6 100644 --- a/data_sources/windows_event_log_security_4759.yml +++ b/data_sources/windows_event_log_security_4759.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4759 id: 431e3520-505b-4ace-aced-cb51e3f7311e -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4759 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index 192d1a5467..cc6cb1490b 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4768 id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index 597e751aa4..967f48c226 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index caed5336e0..821f269a4d 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4771 id: 418debbb-adf3-48ec-9efd-59d45f8861e5 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index 797c8619ff..7e7dbf5296 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4776 id: 1da9092a-c795-4a26-ace8-d43855524e96 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index 5f3f6117d0..09dd2b9e6e 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4783.yml b/data_sources/windows_event_log_security_4783.yml index 809fd32066..8795245a65 100644 --- a/data_sources/windows_event_log_security_4783.yml +++ b/data_sources/windows_event_log_security_4783.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4783 id: 6b945150-785c-49a1-b705-56b42215630b -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4783 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4790.yml b/data_sources/windows_event_log_security_4790.yml index 9f279e858e..44538e029e 100644 --- a/data_sources/windows_event_log_security_4790.yml +++ b/data_sources/windows_event_log_security_4790.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4790 id: 1cc6ecbb-af04-432b-a224-02c65243ac88 -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4790 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index 1a37f12377..6783cec791 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4794 id: ec7da74f-274a-4bde-aa0e-15c68aca0426 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index bbe93844aa..ee5a65d0dc 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4798 id: 29e97f72-eb2e-400e-b0c9-81277547e43b -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index 0c55023bb4..3d058ba50e 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4876 id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index 22c6449735..5dd1179d89 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index 0d24f76626..438cf162b8 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4887 id: 994c7b19-a623-4231-9818-f00e453b9a75 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4946.yml b/data_sources/windows_event_log_security_4946.yml index ff6cf07f68..1c9e634be3 100644 --- a/data_sources/windows_event_log_security_4946.yml +++ b/data_sources/windows_event_log_security_4946.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4946 id: d7dafd01-a22d-4b05-b793-7571ef1fa789 -version: 7 +version: 8 creation_date: '2025-03-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4946 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4946' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4947.yml b/data_sources/windows_event_log_security_4947.yml index 43ba1a7db0..388e24744a 100644 --- a/data_sources/windows_event_log_security_4947.yml +++ b/data_sources/windows_event_log_security_4947.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4947 id: 63d4a2fa-a7dc-46d2-b702-54794e1f4d3c -version: 7 +version: 8 creation_date: '2025-03-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4947 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4947' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4948.yml b/data_sources/windows_event_log_security_4948.yml index e19cd033ff..13411a4e1e 100644 --- a/data_sources/windows_event_log_security_4948.yml +++ b/data_sources/windows_event_log_security_4948.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4948 id: 910032df-4e49-42fe-a611-d4c29557d83a -version: 7 +version: 8 creation_date: '2025-03-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4948 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4948' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index abe97668fc..5d978fbd02 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5136 id: 7ba3737e-231e-455d-824e-cd077749f835 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index 0c328521c5..32b78c9736 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AppCorrelationID diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index acf0811514..57e957cd22 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index e7514167c5..2683448397 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5141 id: eafb35fa-f034-4be3-8508-d9173a73c0a1 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 157b9712c9..5dbdd2cce9 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_system_104.yml b/data_sources/windows_event_log_system_104.yml index bac593b36a..90a19ccbf3 100644 --- a/data_sources/windows_event_log_system_104.yml +++ b/data_sources/windows_event_log_system_104.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 104 id: 577b9b41-6b37-44c4-9016-3d890b909050 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log System 104 source: XmlWinEventLog:System @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index 988e936a7d..5c9adb4679 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4720 id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 96f54036eb..05c0723985 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4726 id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index c99f13b74a..bf3431d436 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index 5e8d01067e..b80e177e6f 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7036 id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). mitre_components: @@ -17,7 +17,7 @@ separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 25161cbf0a..9dd3b673ab 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index 0482cfa5b9..73a9742ad5 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - AccountName diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index a381f769e9..ba17034a69 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ActionName diff --git a/data_sources/windows_event_log_taskscheduler_201.yml b/data_sources/windows_event_log_taskscheduler_201.yml index b257f738b5..6a7d5045b8 100644 --- a/data_sources/windows_event_log_taskscheduler_201.yml +++ b/data_sources/windows_event_log_taskscheduler_201.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 201 id: 4c09ae64-01cd-4b65-8221-20f803b0d86e -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log TaskScheduler 201 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time output_fields: diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index 07d2bc2697..7578646ccb 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -1,8 +1,8 @@ name: Windows IIS id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. mitre_components: @@ -16,4 +16,4 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index cdc858c568..f9ba107c65 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -1,8 +1,8 @@ name: Windows IIS 29 id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-24' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. mitre_components: @@ -17,7 +17,7 @@ separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.0 fields: - _time - ComputerName From 15580380e309b32acf2778449e50e59cb95ac004 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Fri, 31 Jul 2026 15:57:03 +0000 Subject: [PATCH 23/32] Update datasource TA versions --- data_sources/cisco_ai_defense_alerts.yml | 6 +++--- data_sources/cisco_asa_logs.yml | 6 +++--- data_sources/cisco_duo_activity.yml | 6 +++--- data_sources/cisco_duo_administrator.yml | 6 +++--- data_sources/cisco_isovalent_process_connect.yml | 6 +++--- data_sources/cisco_isovalent_process_exec.yml | 6 +++--- data_sources/cisco_isovalent_process_kprobe.yml | 6 +++--- ...isco_secure_firewall_threat_defense_connection_event.yml | 6 +++--- .../cisco_secure_firewall_threat_defense_file_event.yml | 6 +++--- ...cisco_secure_firewall_threat_defense_intrusion_event.yml | 6 +++--- 10 files changed, 30 insertions(+), 30 deletions(-) diff --git a/data_sources/cisco_ai_defense_alerts.yml b/data_sources/cisco_ai_defense_alerts.yml index 1a4274a4e6..c2ae92757e 100644 --- a/data_sources/cisco_ai_defense_alerts.yml +++ b/data_sources/cisco_ai_defense_alerts.yml @@ -1,8 +1,8 @@ name: Cisco AI Defense Alerts id: cbb06880-9dd9-4542-ac60-bd6e1d3c3e4e -version: 4 +version: 5 creation_date: '2025-02-14' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Bhavin Patel description: Data source object for Cisco AI Defense Alerts source: cisco_ai_defense @@ -11,5 +11,5 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: diff --git a/data_sources/cisco_asa_logs.yml b/data_sources/cisco_asa_logs.yml index 857035ae40..10623c45c0 100644 --- a/data_sources/cisco_asa_logs.yml +++ b/data_sources/cisco_asa_logs.yml @@ -1,8 +1,8 @@ name: Cisco ASA Logs id: 3f2a9b6d-1c8e-4f7b-a2d3-8b7f1c2a9d4e -version: 5 +version: 6 creation_date: '2025-09-25' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: "Data source object for Cisco ASA system logs. Cisco ASA logs provide firewall operational and security telemetry (connection events, ACL denies, VPN events, NAT translations, and device health). Deploy the Splunk Add-on for Cisco ASA (TA-cisco_asa) on indexers/heavy forwarders and the Cisco ASA App on search heads for best parsing, CIM mapping, and dashboards. This data is ingested via SYSLOG. You must be ingesting Cisco ASA syslog data into your Splunk environment. To ensure all detections work, configure your ASA and FTD devices to generate and forward both debug and informational level syslog messages before they are sent to Splunk. A few analytics are designed to be used with comprehensive logging enabled, as it relies on the presence of specific message IDs. You can find specific instructions on how to set this up here : https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/63884-config-asa-00.html#toc-hId--1451069880. \n" source: not_applicable @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - Cisco_ASA_action - Cisco_ASA_message_id diff --git a/data_sources/cisco_duo_activity.yml b/data_sources/cisco_duo_activity.yml index 80cd08546d..38c7ebb945 100644 --- a/data_sources/cisco_duo_activity.yml +++ b/data_sources/cisco_duo_activity.yml @@ -1,8 +1,8 @@ name: Cisco Duo Activity id: 83f727f6-8754-41f8-b9f7-8226886a659e -version: 4 +version: 5 creation_date: '2025-07-10' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Activity source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - access_device.browser - access_device.browser_version diff --git a/data_sources/cisco_duo_administrator.yml b/data_sources/cisco_duo_administrator.yml index 115560695e..7f71d2a9e7 100644 --- a/data_sources/cisco_duo_administrator.yml +++ b/data_sources/cisco_duo_administrator.yml @@ -1,8 +1,8 @@ name: Cisco Duo Administrator id: 38e22de6-8b6b-449c-ae26-a640c88ff7f9 -version: 4 +version: 5 creation_date: '2025-07-10' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Administrator source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - action - actionlabel diff --git a/data_sources/cisco_isovalent_process_connect.yml b/data_sources/cisco_isovalent_process_connect.yml index 98ab25136f..61f7c1e61d 100644 --- a/data_sources/cisco_isovalent_process_connect.yml +++ b/data_sources/cisco_isovalent_process_connect.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Connect id: bf8c76a1-6066-4759-ab77-d3f0a375519e -version: 4 +version: 5 creation_date: '2026-01-05' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: "Captures detailed process connection events—including source and destination process metadata, execution lineage (ancestry), and Kubernetes workload context—generated by Cisco Isovalent instrumentation. Enables technical analysis of inter-process communications, container-level activity, and workload-specific network flows in cloud-native environments." source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processConnect supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - _time - app diff --git a/data_sources/cisco_isovalent_process_exec.yml b/data_sources/cisco_isovalent_process_exec.yml index 1c1238299b..98de2a6c4a 100644 --- a/data_sources/cisco_isovalent_process_exec.yml +++ b/data_sources/cisco_isovalent_process_exec.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Exec id: 87654321-dcba-4321-00fe-0987654321ba -version: 4 +version: 5 creation_date: '2026-01-05' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Logs process execution events within Cisco Isovalent environments, providing visibility into process exec ancestry and Kubernetes workload identity. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processExec supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - _time - cluster_name diff --git a/data_sources/cisco_isovalent_process_kprobe.yml b/data_sources/cisco_isovalent_process_kprobe.yml index f6fb1902a7..4fc679241d 100644 --- a/data_sources/cisco_isovalent_process_kprobe.yml +++ b/data_sources/cisco_isovalent_process_kprobe.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Kprobe id: b2620ef2-fac6-467f-bdc8-253d65db1cb9 -version: 4 +version: 5 creation_date: '2026-01-05' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Bhavin Patel, Splunk description: Captures kernel probe (kprobe) telemetry from Cisco Isovalent Runtime Security, including function name, arguments, and process context, enabling visibility into low-level kernel interactions that may indicate container escape attempts or system tampering. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - _time - app diff --git a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml index f0a581fdee..3fc2a5d65e 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Connection Event id: 18878597-8f8a-4bca-a805-bfbe35e00032 -version: 5 +version: 6 creation_date: '2025-04-03' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Nasreddine Bencherchali, Splunk description: Data source object for raw connection events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - AC_RuleAction - action diff --git a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml index d4f5494230..cdff72aa77 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense File Event id: 19878597-8f8a-4bca-a805-bfbe35e00032 -version: 4 +version: 5 creation_date: '2025-04-09' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Nasreddine Bencherchali, Splunk description: Data source object for raw file events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - app - Application diff --git a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml index b545cd0ed5..bfccb3889d 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Intrusion Event id: d11b67ec-1cb2-4f6f-a2d8-a099c7e15b29 -version: 4 +version: 5 creation_date: '2025-04-16' -modification_date: '2026-07-28' +modification_date: '2026-07-31' author: Nasreddine Bencherchali, Splunk description: Data source object for raw intrusion events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.8 + version: 3.6.9 fields: - Application - Classification From c621138d7998b337414d163e20d279e1e4cc4738 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Mon, 3 Aug 2026 09:04:40 +0000 Subject: [PATCH 24/32] Update datasource TA versions --- data_sources/m365_copilot_graph_api.yml | 6 +++--- data_sources/o365.yml | 6 +++--- .../o365_add_app_role_assignment_grant_to_user_.yml | 6 +++--- .../o365_add_app_role_assignment_to_service_principal_.yml | 6 +++--- data_sources/o365_add_mailboxpermission.yml | 6 +++--- data_sources/o365_add_member_to_role_.yml | 6 +++--- data_sources/o365_add_owner_to_application_.yml | 6 +++--- data_sources/o365_add_service_principal_.yml | 6 +++--- data_sources/o365_change_user_license_.yml | 6 +++--- data_sources/o365_consent_to_application_.yml | 6 +++--- data_sources/o365_disable_strong_authentication_.yml | 6 +++--- data_sources/o365_mailitemsaccessed.yml | 6 +++--- data_sources/o365_modifyfolderpermissions.yml | 6 +++--- data_sources/o365_set_company_information_.yml | 6 +++--- data_sources/o365_set_mailbox.yml | 6 +++--- data_sources/o365_update_application_.yml | 6 +++--- data_sources/o365_update_authorization_policy_.yml | 6 +++--- data_sources/o365_update_user_.yml | 6 +++--- data_sources/o365_userloggedin.yml | 6 +++--- data_sources/o365_userloginfailed.yml | 6 +++--- data_sources/office_365_reporting_message_trace.yml | 6 +++--- data_sources/office_365_universal_audit_log.yml | 6 +++--- 22 files changed, 66 insertions(+), 66 deletions(-) diff --git a/data_sources/m365_copilot_graph_api.yml b/data_sources/m365_copilot_graph_api.yml index 33aec6362d..fa28d62731 100644 --- a/data_sources/m365_copilot_graph_api.yml +++ b/data_sources/m365_copilot_graph_api.yml @@ -1,8 +1,8 @@ name: M365 Copilot Graph API id: 30dd2202-869c-47fb-ad37-4f4d4c93c6b7 -version: 2 +version: 3 creation_date: '2025-10-13' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Rod Soto, Splunk description: Access Logs from M365 Copilot access via Graph API source: AuditLogs.SignIns @@ -10,7 +10,7 @@ sourcetype: o365:graph:api supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - appDisplayName - appId diff --git a/data_sources/o365.yml b/data_sources/o365.yml index a19cd4ad78..164993e13b 100644 --- a/data_sources/o365.yml +++ b/data_sources/o365.yml @@ -1,8 +1,8 @@ name: O365 id: b32de97d-0074-4cca-853c-db22c392b6c0 -version: 3 +version: 4 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs management activities in Microsoft 365, including administrative actions, user activities, and configuration changes across various services. mitre_components: @@ -17,4 +17,4 @@ separator: Operation supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 diff --git a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml index 7723ded61a..f969fb9a1e 100644 --- a/data_sources/o365_add_app_role_assignment_grant_to_user_.yml +++ b/data_sources/o365_add_app_role_assignment_grant_to_user_.yml @@ -1,8 +1,8 @@ name: O365 Add app role assignment grant to user. id: ce1d7849-a1d2-47fd-b6eb-d7ef854a860c -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs the assignment of an application role grant to a user in Microsoft 365, including details about the role, user, and application involved. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add app role assignment grant to user. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml index 8654f39dbd..23e25d521a 100644 --- a/data_sources/o365_add_app_role_assignment_to_service_principal_.yml +++ b/data_sources/o365_add_app_role_assignment_to_service_principal_.yml @@ -1,8 +1,8 @@ name: O365 Add app role assignment to service principal. id: 785ba57a-ba7b-474e-97c8-9474e6e00b3a -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs the assignment of an application role to a service principal in Microsoft 365, including details about the role, service principal, and application involved. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add app role assignment to service principal. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_add_mailboxpermission.yml b/data_sources/o365_add_mailboxpermission.yml index 39b8cabf1c..8e3ea6b19f 100644 --- a/data_sources/o365_add_mailboxpermission.yml +++ b/data_sources/o365_add_mailboxpermission.yml @@ -1,8 +1,8 @@ name: O365 Add-MailboxPermission id: 9c0babdb-bb15-449e-abba-0a9cdb3fc061 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs the addition of mailbox permissions in Microsoft 365, including details about the mailbox, granted permissions, and the user or administrator performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add-MailboxPermission supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - AccessRights diff --git a/data_sources/o365_add_member_to_role_.yml b/data_sources/o365_add_member_to_role_.yml index 203e698796..a5366a6940 100644 --- a/data_sources/o365_add_member_to_role_.yml +++ b/data_sources/o365_add_member_to_role_.yml @@ -1,8 +1,8 @@ name: O365 Add member to role. id: 8b949f7c-4b5d-404f-9694-d7403c4ec096 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs the addition of a member to a role in Microsoft 365, including details about the role, the added member, and the user or administrator performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add member to role. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_add_owner_to_application_.yml b/data_sources/o365_add_owner_to_application_.yml index 78a3be49c4..2c19e64bb7 100644 --- a/data_sources/o365_add_owner_to_application_.yml +++ b/data_sources/o365_add_owner_to_application_.yml @@ -1,8 +1,8 @@ name: O365 Add owner to application. id: da012cbf-af6e-40ee-a1ba-32a5f8da8f8a -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs the addition of an owner to an application in Microsoft 365, including details about the application, the new owner, and the user or administrator performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add owner to application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_add_service_principal_.yml b/data_sources/o365_add_service_principal_.yml index 3f55630da5..8175d52e93 100644 --- a/data_sources/o365_add_service_principal_.yml +++ b/data_sources/o365_add_service_principal_.yml @@ -1,8 +1,8 @@ name: O365 Add service principal. id: 9c1ef9f5-bc30-4a47-a1bd-cb34484ee778 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs the addition of a new service principal in Microsoft 365, including details about the associated application and the action initiator. mitre_components: @@ -17,7 +17,7 @@ separator_value: Add service principal. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_change_user_license_.yml b/data_sources/o365_change_user_license_.yml index 63af5c5dce..9fd247f3ac 100644 --- a/data_sources/o365_change_user_license_.yml +++ b/data_sources/o365_change_user_license_.yml @@ -1,8 +1,8 @@ name: O365 Change user license. id: 1029a20d-3d0d-4fb9-b5e2-22ac5380b20a -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs changes to user licenses in Microsoft 365, including additions, removals, or updates to service plans associated with a user account. mitre_components: @@ -17,7 +17,7 @@ separator_value: Change user license. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_consent_to_application_.yml b/data_sources/o365_consent_to_application_.yml index d4a327cfbe..7be70e72c5 100644 --- a/data_sources/o365_consent_to_application_.yml +++ b/data_sources/o365_consent_to_application_.yml @@ -1,8 +1,8 @@ name: O365 Consent to application. id: 0a15a464-ef51-4614-9a07-a216eb9817db -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs user or administrator consent to an application's permissions in Microsoft 365, including details about the application, granted permissions, and the consenting user or process. mitre_components: @@ -17,7 +17,7 @@ separator_value: Consent to application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_disable_strong_authentication_.yml b/data_sources/o365_disable_strong_authentication_.yml index 65923c1c80..983c04ece1 100644 --- a/data_sources/o365_disable_strong_authentication_.yml +++ b/data_sources/o365_disable_strong_authentication_.yml @@ -1,8 +1,8 @@ name: O365 Disable Strong Authentication. id: 235381c4-382a-4183-b818-a51c3ce12187 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs the disabling of strong authentication (e.g., multi-factor authentication) for a user or group in Microsoft 365, including details about the affected accounts and the action initiator. mitre_components: @@ -17,7 +17,7 @@ separator_value: Disable Strong Authentication. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_mailitemsaccessed.yml b/data_sources/o365_mailitemsaccessed.yml index 8174ccfa10..26ed219d5f 100644 --- a/data_sources/o365_mailitemsaccessed.yml +++ b/data_sources/o365_mailitemsaccessed.yml @@ -1,8 +1,8 @@ name: O365 MailItemsAccessed id: 3d5188eb-341a-4b46-9caa-aade4047d027 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs access to mailbox items in Microsoft 365, including details about the user accessing the items, the accessed content, and the method of access. mitre_components: @@ -17,7 +17,7 @@ separator_value: MailItemsAccessed supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - AppId diff --git a/data_sources/o365_modifyfolderpermissions.yml b/data_sources/o365_modifyfolderpermissions.yml index 94b626b468..ac97ad1b11 100644 --- a/data_sources/o365_modifyfolderpermissions.yml +++ b/data_sources/o365_modifyfolderpermissions.yml @@ -1,8 +1,8 @@ name: O365 ModifyFolderPermissions id: 0a8c1080-68c2-46d7-8324-2e7d97bb6e2f -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs modifications to folder permissions in Microsoft 365, including updates to access levels, user assignments, and sharing settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: ModifyFolderPermissions supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - AppId diff --git a/data_sources/o365_set_company_information_.yml b/data_sources/o365_set_company_information_.yml index b093098610..d3fc0a13e4 100644 --- a/data_sources/o365_set_company_information_.yml +++ b/data_sources/o365_set_company_information_.yml @@ -1,8 +1,8 @@ name: O365 Set Company Information. id: 06c6d576-f032-41e3-b15d-80a434ce13d8 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs updates to organizational settings and company information in Microsoft 365, including changes to contact details, branding, and configuration policies. mitre_components: @@ -17,7 +17,7 @@ separator_value: Set Company Information. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_set_mailbox.yml b/data_sources/o365_set_mailbox.yml index 96c5ad2283..9249c67cfc 100644 --- a/data_sources/o365_set_mailbox.yml +++ b/data_sources/o365_set_mailbox.yml @@ -1,8 +1,8 @@ name: O365 Set-Mailbox id: db798c5c-928c-4972-bb42-e5f90e35865f -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs changes to mailbox properties in Microsoft 365, including updates to permissions, storage quotas, and configuration settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: Set-Mailbox supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - AppId diff --git a/data_sources/o365_update_application_.yml b/data_sources/o365_update_application_.yml index 949c78147e..88f2f6708b 100644 --- a/data_sources/o365_update_application_.yml +++ b/data_sources/o365_update_application_.yml @@ -1,8 +1,8 @@ name: O365 Update application. id: 62159133-911b-4c63-9e30-a6a8c89195ca -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs updates made to applications in Microsoft 365, including changes to configurations, permissions, and role assignments. mitre_components: @@ -17,7 +17,7 @@ separator_value: Update application. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_update_authorization_policy_.yml b/data_sources/o365_update_authorization_policy_.yml index 7bae300e3d..04eed22eca 100644 --- a/data_sources/o365_update_authorization_policy_.yml +++ b/data_sources/o365_update_authorization_policy_.yml @@ -1,8 +1,8 @@ name: O365 Update authorization policy. id: d40e6a20-4d64-404c-8351-2caae8228d34 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs changes to authorization policies in Microsoft 365, including updates to access controls, permissions, and security settings. mitre_components: @@ -17,7 +17,7 @@ separator_value: Update authorization policy. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_update_user_.yml b/data_sources/o365_update_user_.yml index 16dce5cfdb..f5671cf889 100644 --- a/data_sources/o365_update_user_.yml +++ b/data_sources/o365_update_user_.yml @@ -1,8 +1,8 @@ name: O365 Update user. id: a05fd01e-34d9-4233-9089-11272416b531 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs updates to user account properties in Microsoft 365, including changes to roles, permissions, and profile information. mitre_components: @@ -17,7 +17,7 @@ separator_value: Update user. supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_userloggedin.yml b/data_sources/o365_userloggedin.yml index 8471cc627b..89971dc5a8 100644 --- a/data_sources/o365_userloggedin.yml +++ b/data_sources/o365_userloggedin.yml @@ -1,8 +1,8 @@ name: O365 UserLoggedIn id: ed29c8c4-4053-419c-b133-16abf2a1c4c9 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs successful login events by users in Microsoft 365, including details about the user account, IP address, and session metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: UserLoggedIn supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/o365_userloginfailed.yml b/data_sources/o365_userloginfailed.yml index a898d3063e..17f66d1382 100644 --- a/data_sources/o365_userloginfailed.yml +++ b/data_sources/o365_userloginfailed.yml @@ -1,8 +1,8 @@ name: O365 UserLoginFailed id: 6099b33d-d581-43ed-8401-911862590361 -version: 3 +version: 4 creation_date: '2024-05-22' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Patrick Bareiss, Splunk description: Logs failed login attempts by users in Microsoft 365, including details about the user account, IP address, and reason for failure. mitre_components: @@ -17,7 +17,7 @@ separator_value: UserLoginFailed supported_TA: - name: Splunk Add-on for Microsoft Office 365 url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time - ActorContextId diff --git a/data_sources/office_365_reporting_message_trace.yml b/data_sources/office_365_reporting_message_trace.yml index ef82a079e7..0b7c6ee83d 100644 --- a/data_sources/office_365_reporting_message_trace.yml +++ b/data_sources/office_365_reporting_message_trace.yml @@ -1,8 +1,8 @@ name: Office 365 Reporting Message Trace id: b637788e-fcf0-44fa-86ea-cab81193f939 -version: 2 +version: 3 creation_date: '2025-02-28' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Steven Dick description: Data source object for Office 365 Reporting Message Trace source: o365 @@ -11,7 +11,7 @@ separator: Organization supported_TA: - name: Splunk Microsoft Office 365 Add-on url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - FromIP - Index diff --git a/data_sources/office_365_universal_audit_log.yml b/data_sources/office_365_universal_audit_log.yml index 0e03e59a90..a4966fa4fb 100644 --- a/data_sources/office_365_universal_audit_log.yml +++ b/data_sources/office_365_universal_audit_log.yml @@ -1,8 +1,8 @@ name: Office 365 Universal Audit Log id: 86369e87-5b0b-46fe-8b96-310473dffe7f -version: 2 +version: 3 creation_date: '2025-02-21' -modification_date: '2026-05-13' +modification_date: '2026-08-03' author: Bhavin Patel, Splunk description: Data source object for Office 365 Universal Audit Log source: o365 @@ -11,7 +11,7 @@ separator: Operation supported_TA: - name: Splunk Microsoft Office 365 Add-on url: https://splunkbase.splunk.com/app/4055 - version: 6.0.2 + version: 6.1.0 fields: - _time example_log: '' From 534a314ac52d1bb03e10ab5d3af2964ceea75a03 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Wed, 5 Aug 2026 12:47:01 +0000 Subject: [PATCH 25/32] Update datasource TA versions --- data_sources/g_suite_drive.yml | 6 +++--- data_sources/g_suite_gmail.yml | 6 +++--- data_sources/google_workspace.yml | 6 +++--- data_sources/google_workspace_login_failure.yml | 6 +++--- data_sources/google_workspace_login_success.yml | 6 +++--- 5 files changed, 15 insertions(+), 15 deletions(-) diff --git a/data_sources/g_suite_drive.yml b/data_sources/g_suite_drive.yml index d8f395e74b..8eb91b63a2 100644 --- a/data_sources/g_suite_drive.yml +++ b/data_sources/g_suite_drive.yml @@ -1,8 +1,8 @@ name: G Suite Drive id: 5f79120f-a235-4468-bd0d-55203758ac22 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-06-18' +modification_date: '2026-08-05' author: Patrick Bareiss, Splunk description: Logs activities related to Google Drive in G Suite, including file creation, modification, sharing, and access details. mitre_components: @@ -16,7 +16,7 @@ sourcetype: gsuite:drive:json supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 4.0.0 + version: 5.0.0 fields: - _time - email diff --git a/data_sources/g_suite_gmail.yml b/data_sources/g_suite_gmail.yml index ba14091ca7..be65dbe287 100644 --- a/data_sources/g_suite_gmail.yml +++ b/data_sources/g_suite_gmail.yml @@ -1,8 +1,8 @@ name: G Suite Gmail id: 706c3978-41de-406b-b6e0-75bd01e12a5d -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-06-18' +modification_date: '2026-08-05' author: Patrick Bareiss, Splunk description: Logs Gmail activities in G Suite, including email sending, receiving, and access details, as well as potential security-related events. mitre_components: @@ -15,7 +15,7 @@ sourcetype: gsuite:gmail:bigquery supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 4.0.0 + version: 5.0.0 fields: - _time - action_type diff --git a/data_sources/google_workspace.yml b/data_sources/google_workspace.yml index 9a5e332fbe..9cda766641 100644 --- a/data_sources/google_workspace.yml +++ b/data_sources/google_workspace.yml @@ -1,8 +1,8 @@ name: Google Workspace id: f1a044e3-113a-4e4d-84f2-b153ade83087 -version: 3 +version: 4 creation_date: '2024-07-16' -modification_date: '2026-06-18' +modification_date: '2026-08-05' author: Bhavin Patel, Splunk description: Data source object for Google Workspace source: google_workspace @@ -10,7 +10,7 @@ sourcetype: gws:reports:login supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 4.0.0 + version: 5.0.0 fields: - action - actor.callerType diff --git a/data_sources/google_workspace_login_failure.yml b/data_sources/google_workspace_login_failure.yml index c817af96ff..7d4f0bd7e8 100644 --- a/data_sources/google_workspace_login_failure.yml +++ b/data_sources/google_workspace_login_failure.yml @@ -1,8 +1,8 @@ name: Google Workspace login_failure id: cabec7cf-4008-4899-b47e-39c34a9a1255 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-06-18' +modification_date: '2026-08-05' author: Patrick Bareiss, Splunk description: Logs failed login attempts to Google Workspace accounts, including details about the user, IP address, and reason for failure. mitre_components: @@ -17,7 +17,7 @@ separator_value: login_failure supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 4.0.0 + version: 5.0.0 fields: - _time - actor.email diff --git a/data_sources/google_workspace_login_success.yml b/data_sources/google_workspace_login_success.yml index 424a893a42..0dc18f27b4 100644 --- a/data_sources/google_workspace_login_success.yml +++ b/data_sources/google_workspace_login_success.yml @@ -1,8 +1,8 @@ name: Google Workspace login_success id: bffe8013-9cdf-4fe6-9c1b-6784391a4951 -version: 4 +version: 5 creation_date: '2024-05-22' -modification_date: '2026-06-18' +modification_date: '2026-08-05' author: Patrick Bareiss, Splunk description: Logs successful login attempts to Google Workspace accounts, including details about the user, IP address, and session metadata. mitre_components: @@ -17,7 +17,7 @@ separator_value: login_success supported_TA: - name: Splunk Add-on for Google Workspace url: https://splunkbase.splunk.com/app/5556 - version: 4.0.0 + version: 5.0.0 fields: - _time - actor.email From d806cc5f58227b10893e44af62f3ddef4cf94ca3 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Mon, 10 Aug 2026 12:41:02 +0000 Subject: [PATCH 26/32] Update datasource TA versions --- data_sources/ntlm_operational_8004.yml | 6 +++--- data_sources/ntlm_operational_8005.yml | 6 +++--- data_sources/ntlm_operational_8006.yml | 6 +++--- data_sources/powershell_script_block_logging_4104.yml | 6 +++--- data_sources/windows_active_directory_admon.yml | 6 +++--- data_sources/windows_event_log_application_15457.yml | 6 +++--- data_sources/windows_event_log_application_17135.yml | 6 +++--- data_sources/windows_event_log_application_2282.yml | 6 +++--- data_sources/windows_event_log_application_3000.yml | 6 +++--- data_sources/windows_event_log_application_8128.yml | 6 +++--- .../windows_event_log_appxdeployment_server_400.yml | 6 +++--- .../windows_event_log_appxdeployment_server_854.yml | 6 +++--- .../windows_event_log_appxdeployment_server_855.yml | 6 +++--- data_sources/windows_event_log_appxpackaging_171.yml | 6 +++--- data_sources/windows_event_log_capi2_70.yml | 6 +++--- data_sources/windows_event_log_capi2_81.yml | 6 +++--- .../windows_event_log_certificateservicesclient_1007.yml | 6 +++--- data_sources/windows_event_log_defender_1121.yml | 6 +++--- data_sources/windows_event_log_defender_1122.yml | 6 +++--- data_sources/windows_event_log_defender_1125.yml | 6 +++--- data_sources/windows_event_log_defender_1126.yml | 6 +++--- data_sources/windows_event_log_defender_1129.yml | 6 +++--- data_sources/windows_event_log_defender_1131.yml | 6 +++--- data_sources/windows_event_log_defender_1132.yml | 6 +++--- data_sources/windows_event_log_defender_1133.yml | 6 +++--- data_sources/windows_event_log_defender_1134.yml | 6 +++--- data_sources/windows_event_log_defender_5007.yml | 6 +++--- data_sources/windows_event_log_printservice_316.yml | 6 +++--- data_sources/windows_event_log_printservice_4909.yml | 6 +++--- data_sources/windows_event_log_printservice_808.yml | 6 +++--- .../windows_event_log_remoteconnectionmanager_1149.yml | 6 +++--- data_sources/windows_event_log_security_1100.yml | 6 +++--- data_sources/windows_event_log_security_1102.yml | 6 +++--- data_sources/windows_event_log_security_4624.yml | 6 +++--- data_sources/windows_event_log_security_4625.yml | 6 +++--- data_sources/windows_event_log_security_4627.yml | 6 +++--- data_sources/windows_event_log_security_4648.yml | 6 +++--- data_sources/windows_event_log_security_4662.yml | 6 +++--- data_sources/windows_event_log_security_4663.yml | 6 +++--- data_sources/windows_event_log_security_4672.yml | 6 +++--- data_sources/windows_event_log_security_4688.yml | 6 +++--- data_sources/windows_event_log_security_4698.yml | 6 +++--- data_sources/windows_event_log_security_4699.yml | 6 +++--- data_sources/windows_event_log_security_4700.yml | 6 +++--- data_sources/windows_event_log_security_4702.yml | 6 +++--- data_sources/windows_event_log_security_4703.yml | 6 +++--- data_sources/windows_event_log_security_4719.yml | 6 +++--- data_sources/windows_event_log_security_4720.yml | 6 +++--- data_sources/windows_event_log_security_4723.yml | 6 +++--- data_sources/windows_event_log_security_4724.yml | 6 +++--- data_sources/windows_event_log_security_4725.yml | 6 +++--- data_sources/windows_event_log_security_4726.yml | 6 +++--- data_sources/windows_event_log_security_4727.yml | 6 +++--- data_sources/windows_event_log_security_4728.yml | 6 +++--- data_sources/windows_event_log_security_4730.yml | 6 +++--- data_sources/windows_event_log_security_4731.yml | 6 +++--- data_sources/windows_event_log_security_4732.yml | 6 +++--- data_sources/windows_event_log_security_4737.yml | 6 +++--- data_sources/windows_event_log_security_4738.yml | 6 +++--- data_sources/windows_event_log_security_4739.yml | 6 +++--- data_sources/windows_event_log_security_4741.yml | 6 +++--- data_sources/windows_event_log_security_4742.yml | 6 +++--- data_sources/windows_event_log_security_4744.yml | 6 +++--- data_sources/windows_event_log_security_4749.yml | 6 +++--- data_sources/windows_event_log_security_4754.yml | 6 +++--- data_sources/windows_event_log_security_4756.yml | 6 +++--- data_sources/windows_event_log_security_4759.yml | 6 +++--- data_sources/windows_event_log_security_4768.yml | 6 +++--- data_sources/windows_event_log_security_4769.yml | 6 +++--- data_sources/windows_event_log_security_4771.yml | 6 +++--- data_sources/windows_event_log_security_4776.yml | 6 +++--- data_sources/windows_event_log_security_4781.yml | 6 +++--- data_sources/windows_event_log_security_4783.yml | 6 +++--- data_sources/windows_event_log_security_4790.yml | 6 +++--- data_sources/windows_event_log_security_4794.yml | 6 +++--- data_sources/windows_event_log_security_4798.yml | 6 +++--- data_sources/windows_event_log_security_4876.yml | 6 +++--- data_sources/windows_event_log_security_4886.yml | 6 +++--- data_sources/windows_event_log_security_4887.yml | 6 +++--- data_sources/windows_event_log_security_4946.yml | 6 +++--- data_sources/windows_event_log_security_4947.yml | 6 +++--- data_sources/windows_event_log_security_4948.yml | 6 +++--- data_sources/windows_event_log_security_5136.yml | 6 +++--- data_sources/windows_event_log_security_5137.yml | 6 +++--- data_sources/windows_event_log_security_5140.yml | 6 +++--- data_sources/windows_event_log_security_5141.yml | 6 +++--- data_sources/windows_event_log_security_5145.yml | 6 +++--- data_sources/windows_event_log_system_104.yml | 6 +++--- data_sources/windows_event_log_system_4720.yml | 6 +++--- data_sources/windows_event_log_system_4726.yml | 6 +++--- data_sources/windows_event_log_system_4728.yml | 6 +++--- data_sources/windows_event_log_system_7036.yml | 6 +++--- data_sources/windows_event_log_system_7040.yml | 6 +++--- data_sources/windows_event_log_system_7045.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_200.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_201.yml | 6 +++--- data_sources/windows_iis.yml | 6 +++--- data_sources/windows_iis_29.yml | 6 +++--- 98 files changed, 294 insertions(+), 294 deletions(-) diff --git a/data_sources/ntlm_operational_8004.yml b/data_sources/ntlm_operational_8004.yml index b34e8497ae..3ababb638d 100644 --- a/data_sources/ntlm_operational_8004.yml +++ b/data_sources/ntlm_operational_8004.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8004 id: fd08cb77-c26e-464c-a43e-2867e232127e -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8004 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8005.yml b/data_sources/ntlm_operational_8005.yml index 2dff87c33d..e8bbe3e510 100644 --- a/data_sources/ntlm_operational_8005.yml +++ b/data_sources/ntlm_operational_8005.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8005 id: ad15a1cf-4b21-43de-81e4-6307c69172fb -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8005 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8006.yml b/data_sources/ntlm_operational_8006.yml index 11a3b23b93..a4ee1bb451 100644 --- a/data_sources/ntlm_operational_8006.yml +++ b/data_sources/ntlm_operational_8006.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8006 id: 9f50a672-6f7d-4621-a3bd-69468c6b7a7f -version: 7 +version: 8 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8006 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index 5fbb147de2..f39936ab44 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,8 +1,8 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: @@ -18,7 +18,7 @@ separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index cc0a93ca92..a3e8ccab20 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -1,8 +1,8 @@ name: Windows Active Directory Admon id: 22bbf4e4-d313-43c1-98ee-808b8775519d -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ActiveDirectory supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Guid diff --git a/data_sources/windows_event_log_application_15457.yml b/data_sources/windows_event_log_application_15457.yml index 2a50cb0e27..731ab7922f 100644 --- a/data_sources/windows_event_log_application_15457.yml +++ b/data_sources/windows_event_log_application_15457.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 15457 id: 4491537e-520c-46f7-9209-f56f852aa237 -version: 7 +version: 8 creation_date: '2025-02-25' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 15457 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_17135.yml b/data_sources/windows_event_log_application_17135.yml index 06fb0a19ea..bcb94dac20 100644 --- a/data_sources/windows_event_log_application_17135.yml +++ b/data_sources/windows_event_log_application_17135.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 17135 id: 4491537e-520c-46f7-9209-f56f852aa231 -version: 7 +version: 8 creation_date: '2025-02-25' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 17135 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index c2ff9fd25a..4ff194ea90 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 2282 id: 4490537e-5e0c-46f7-9209-f56f852aa237 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index f07113fe44..b07b1faf3a 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: @@ -17,7 +17,7 @@ separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_8128.yml b/data_sources/windows_event_log_application_8128.yml index 3452485c5b..86ca7cf72b 100644 --- a/data_sources/windows_event_log_application_8128.yml +++ b/data_sources/windows_event_log_application_8128.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 8128 id: 4491537e-5e0c-46f7-9209-f56f852aa237 -version: 7 +version: 8 creation_date: '2025-02-25' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 8128 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_400.yml b/data_sources/windows_event_log_appxdeployment_server_400.yml index 6c29b72657..a6300ef53f 100644 --- a/data_sources/windows_event_log_appxdeployment_server_400.yml +++ b/data_sources/windows_event_log_appxdeployment_server_400.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 400 id: 3e5f9d2a-b8c7-4d1e-a6f3-7b9c8d5e4f2a -version: 7 +version: 8 creation_date: '2025-08-18' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 400. These events are generated when a package deployment operation begins, providing details about the package being deployed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_854.yml b/data_sources/windows_event_log_appxdeployment_server_854.yml index 38461b520a..0e1707c4fb 100644 --- a/data_sources/windows_event_log_appxdeployment_server_854.yml +++ b/data_sources/windows_event_log_appxdeployment_server_854.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 854 id: 4d2e6f8a-c9b7-5a3e-8d1f-2e9c7b5a4f3d -version: 7 +version: 8 creation_date: '2025-08-18' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 854. These events are generated when an MSIX/AppX package has been successfully installed on a system. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_855.yml b/data_sources/windows_event_log_appxdeployment_server_855.yml index 0c279a5086..47e7cc0645 100644 --- a/data_sources/windows_event_log_appxdeployment_server_855.yml +++ b/data_sources/windows_event_log_appxdeployment_server_855.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 855 id: 4491537c-521c-46f7-9209-f56f852aa231 -version: 7 +version: 8 creation_date: '2025-08-18' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 855. These events are generated when a package deployment operation completes successfully, providing details about the packages that were installed or updated. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxpackaging_171.yml b/data_sources/windows_event_log_appxpackaging_171.yml index 0b02870260..e4307d47b7 100644 --- a/data_sources/windows_event_log_appxpackaging_171.yml +++ b/data_sources/windows_event_log_appxpackaging_171.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXPackaging 171 id: 2d0f8e3c-a2d7-4b9e-8f1c-6a5d7e3e9f2b -version: 7 +version: 8 creation_date: '2025-08-18' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXPackaging/Operational channel, specifically focusing on EventCode 171. These events are generated when a user clicks on or attempts to interact with an MSIX package, even if the package is not fully installed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 435802e868..059d548ecd 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: @@ -18,7 +18,7 @@ separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index 751530ae30..2cb78e5ec5 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 81 id: 463ff898-8135-4c0e-811e-f8629dfc5027 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index 10706daac0..204b28e95e 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -1,8 +1,8 @@ name: Windows Event Log CertificateServicesClient 1007 id: c51444e3-479d-4c4a-b111-e8276a3acf39 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index a764fc2be4..cc49bae908 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1121 id: 84a254c5-7900-4b52-a324-a176adb7c11d -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index 1428eda3fb..3357eaa5bc 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1122 id: 4a2d0499-f489-4557-82f4-f357025cf3e7 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1125.yml b/data_sources/windows_event_log_defender_1125.yml index c8332bc9f8..763b0d3fed 100644 --- a/data_sources/windows_event_log_defender_1125.yml +++ b/data_sources/windows_event_log_defender_1125.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1125 id: 0cddda76-6fd8-4fb6-9026-f23a2761c95d -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1125 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time example_log: 112204000x80000000000000003701Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender Antivirus4.18.23100.2009E6DB77E5-3DF2-4CF1-B95A-636979351E5B2023-11-26T23:43:08.709Z(unknown user)C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1.401.1247.01.1.23100.2009ENT\ConsRC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x00000000 diff --git a/data_sources/windows_event_log_defender_1126.yml b/data_sources/windows_event_log_defender_1126.yml index bb2e14c048..14c2ff0991 100644 --- a/data_sources/windows_event_log_defender_1126.yml +++ b/data_sources/windows_event_log_defender_1126.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1126 id: c1c6284b-b663-4001-bdf2-c0cacee22a2a -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1126 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index e61c484257..74a6896f88 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1129 id: 0572e119-a48a-4c70-bc58-90e453edacd2 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_defender_1131.yml b/data_sources/windows_event_log_defender_1131.yml index fe87e68050..654a4c0242 100644 --- a/data_sources/windows_event_log_defender_1131.yml +++ b/data_sources/windows_event_log_defender_1131.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1131 id: 638f884e-439a-4328-923c-ec5a2679f450 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1131 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1132.yml b/data_sources/windows_event_log_defender_1132.yml index d6ce240c1c..ef64b19d74 100644 --- a/data_sources/windows_event_log_defender_1132.yml +++ b/data_sources/windows_event_log_defender_1132.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1132 id: 18f93f60-4eca-46e8-a29d-147e6451a34c -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1132 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1133.yml b/data_sources/windows_event_log_defender_1133.yml index 03f7665049..4e269b8457 100644 --- a/data_sources/windows_event_log_defender_1133.yml +++ b/data_sources/windows_event_log_defender_1133.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1133 id: 63c97a9a-cc7f-46c5-b219-8be388666637 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1133 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1134.yml b/data_sources/windows_event_log_defender_1134.yml index f1345b1aac..9ba1eb35fe 100644 --- a/data_sources/windows_event_log_defender_1134.yml +++ b/data_sources/windows_event_log_defender_1134.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1134 id: 26abac7d-d026-44e9-b1a3-13e3e11b232d -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1134 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index 4fa5a9197f..4fc31a5de6 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 5007 id: 27f18792-8d95-4871-8853-874b7faf023f -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when Windows Defender antimalware settings are modified. mitre_components: @@ -14,7 +14,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index 29af489495..e50f91c1dc 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_printservice_4909.yml b/data_sources/windows_event_log_printservice_4909.yml index 5c41132884..650770547a 100644 --- a/data_sources/windows_event_log_printservice_4909.yml +++ b/data_sources/windows_event_log_printservice_4909.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 4909 id: 4c00e353-18b8-4de6-896d-83bc5817dbaa -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Printservice 4909 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time example_log: '' diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index d9974feb95..a998640bf0 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: @@ -16,7 +16,7 @@ separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index d25f2cc844..92927af949 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,8 +1,8 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index 2acb29b989..1bdf653cf6 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: @@ -15,7 +15,7 @@ separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index b70caf0ad8..8411b49f17 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 4d5340c3a8..3ba3514d0a 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 444a4a4064..15cb8fcd8c 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4625 id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when an account fails to log on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index c7dac65547..f312b95c9f 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4627 id: e35c7b9a-b451-4084-95a5-43b7f8965cac -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index 35debc164b..fa303f8481 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4648 id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account mitre_components: @@ -15,7 +15,7 @@ separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index 3aca59ef55..f1904ae88e 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4662 id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it mitre_components: @@ -15,7 +15,7 @@ separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index 77c78d5f70..e900950bbb 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4663 id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer mitre_components: @@ -15,7 +15,7 @@ separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 89b4f40063..750c6684c3 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index c895aa32fa..a03ac319f2 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4688 id: d195eb26-a81c-45ed-aeb3-25792e8a985a -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the creation of a new process mitre_components: @@ -16,7 +16,7 @@ configuration: Enabling Windows event log process command line logging via group supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - Caller_Domain - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index ddf6e75432..01fc76a981 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4698 id: 32c06703-02d3-47ec-8856-b0dc3045866c -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a new scheduled task is created mitre_components: @@ -15,7 +15,7 @@ separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index 3e8fc11a63..95e35f6014 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4699 id: 4727dead-d063-4333-9ddd-59823a416aff -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a scheduled task is deleted from the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4700.yml b/data_sources/windows_event_log_security_4700.yml index f5c77c2236..d495565442 100644 --- a/data_sources/windows_event_log_security_4700.yml +++ b/data_sources/windows_event_log_security_4700.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4700 id: 89895c7b-2aba-41ca-ad12-8b6d290b5dde -version: 8 +version: 9 creation_date: '2025-03-11' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Steven Dick description: Data source object for Windows Event Log Security 4700 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - EventID example_log: 4700 0 0 12804 0 0x8020000000000000 344861 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin LeastPrivilege CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4702.yml b/data_sources/windows_event_log_security_4702.yml index 7a21f89907..a7735e1df6 100644 --- a/data_sources/windows_event_log_security_4702.yml +++ b/data_sources/windows_event_log_security_4702.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 -version: 8 +version: 9 creation_date: '2025-03-11' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 1327b7bdcd..9cdda10497 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4703 id: e256673b-16e8-4b74-b7aa-9eed6ce67072 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a token right is adjusted on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index a3a12d4994..a9b2c846f1 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4719 id: 954033e6-dd05-4775-a1f2-1f19632f4420 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a system audit policy is modified on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index 9ff3acc11a..8995e2b110 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4720 id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a new user account is created on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4723.yml b/data_sources/windows_event_log_security_4723.yml index 51551574f7..b1cc3673cb 100644 --- a/data_sources/windows_event_log_security_4723.yml +++ b/data_sources/windows_event_log_security_4723.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4723 id: df19b271-57c8-4f31-817a-6c5566985484 -version: 6 +version: 7 creation_date: '2026-06-15' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Raven Tait, Splunk description: Logs an event when an attempt is made to change an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4723' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index b88929472f..b63442b836 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4724 id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when an attempt is made to reset an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index e84068e883..c46d59c5c0 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4725 id: 31fd887d-0d14-44cc-bb64-80063a9f2968 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a user account has been disabled in Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index 6da8f9f7d7..f08bfac332 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4726 id: 0b56dcd7-0f72-4a05-9226-d6059781737b -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a user account is deleted from Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4727.yml b/data_sources/windows_event_log_security_4727.yml index 901096f0f0..8ae64cb86d 100644 --- a/data_sources/windows_event_log_security_4727.yml +++ b/data_sources/windows_event_log_security_4727.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4727 id: 4d2078ab-36f5-447e-b7e4-474890b8040b -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4727 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4728.yml b/data_sources/windows_event_log_security_4728.yml index 289b61f2e3..8ea886de95 100644 --- a/data_sources/windows_event_log_security_4728.yml +++ b/data_sources/windows_event_log_security_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4728 id: c0cb4907-d715-41f2-a98a-4f4e75f248c1 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4728 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4730.yml b/data_sources/windows_event_log_security_4730.yml index f801922855..7e2d745a44 100644 --- a/data_sources/windows_event_log_security_4730.yml +++ b/data_sources/windows_event_log_security_4730.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4730 id: 126966ba-a17d-4194-882b-57d303aaf46d -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4730 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4731.yml b/data_sources/windows_event_log_security_4731.yml index 2ace30e4e2..a210cc23fc 100644 --- a/data_sources/windows_event_log_security_4731.yml +++ b/data_sources/windows_event_log_security_4731.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4731 id: 1bbc004e-a75e-4d94-a619-c5aaf5d11ed5 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4731 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index 0ca78aecd0..6a0ca7e337 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4732 id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a member is added to a security-enabled local group on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4737.yml b/data_sources/windows_event_log_security_4737.yml index cbca5c530e..23054960be 100644 --- a/data_sources/windows_event_log_security_4737.yml +++ b/data_sources/windows_event_log_security_4737.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4737 id: 132fc609-17f0-4efd-8f7e-db12139c6690 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4737 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index 6a07c9d51c..d6620a5f23 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4738 id: cb85709b-101e-41a9-bb60-d2108f79dfbd -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index 9c52e754b6..f06047a2fd 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4739 id: c1e0442a-8a97-405d-baf2-057c5d68cd9a -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index 615d0065d0..c22bfa51e6 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4741 id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index 86fd083ded..cc3a201113 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4742 id: ea830adf-5450-489a-bcdc-fb8d2cbe674c -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4744.yml b/data_sources/windows_event_log_security_4744.yml index ee7c86a01f..fa43f12c59 100644 --- a/data_sources/windows_event_log_security_4744.yml +++ b/data_sources/windows_event_log_security_4744.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4744 id: 244e0bd4-00b0-4091-b8b4-9d435aca6ad8 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4744 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4749.yml b/data_sources/windows_event_log_security_4749.yml index cc49946185..9992abb3e3 100644 --- a/data_sources/windows_event_log_security_4749.yml +++ b/data_sources/windows_event_log_security_4749.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4749 id: eb322056-01a3-4cd5-bc09-01140d33194a -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4749 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4754.yml b/data_sources/windows_event_log_security_4754.yml index 7b464c73b6..f1ccf19ad8 100644 --- a/data_sources/windows_event_log_security_4754.yml +++ b/data_sources/windows_event_log_security_4754.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4754 id: 501a507e-3275-4c4b-9c44-53eecfeae487 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4754 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4756.yml b/data_sources/windows_event_log_security_4756.yml index 184f877445..ba51a984a7 100644 --- a/data_sources/windows_event_log_security_4756.yml +++ b/data_sources/windows_event_log_security_4756.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4756 id: b0093058-0cb6-4c73-a95b-fb0f3541e88c -version: 7 +version: 8 creation_date: '2026-03-30' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Nasreddine Bencherchali, Splunk description: Data source object for Windows Event Log Security 4756 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4759.yml b/data_sources/windows_event_log_security_4759.yml index 933cb169e6..92c45b61e2 100644 --- a/data_sources/windows_event_log_security_4759.yml +++ b/data_sources/windows_event_log_security_4759.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4759 id: 431e3520-505b-4ace-aced-cb51e3f7311e -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4759 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index cc6cb1490b..b2bd59a67d 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4768 id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index 967f48c226..426d9f3274 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index 821f269a4d..a2a4bc0f3d 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4771 id: 418debbb-adf3-48ec-9efd-59d45f8861e5 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index 7e7dbf5296..b217782c36 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4776 id: 1da9092a-c795-4a26-ace8-d43855524e96 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index 09dd2b9e6e..a9223d52ff 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4783.yml b/data_sources/windows_event_log_security_4783.yml index 8795245a65..a72ae6bd43 100644 --- a/data_sources/windows_event_log_security_4783.yml +++ b/data_sources/windows_event_log_security_4783.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4783 id: 6b945150-785c-49a1-b705-56b42215630b -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4783 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4790.yml b/data_sources/windows_event_log_security_4790.yml index 44538e029e..3825a2fa34 100644 --- a/data_sources/windows_event_log_security_4790.yml +++ b/data_sources/windows_event_log_security_4790.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4790 id: 1cc6ecbb-af04-432b-a224-02c65243ac88 -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4790 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index 6783cec791..91b6a0b4f7 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4794 id: ec7da74f-274a-4bde-aa0e-15c68aca0426 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index ee5a65d0dc..154b57b09b 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4798 id: 29e97f72-eb2e-400e-b0c9-81277547e43b -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index 3d058ba50e..bb93af9bf3 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4876 id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index 5dd1179d89..b86ea55b57 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index 438cf162b8..b38db0e33f 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4887 id: 994c7b19-a623-4231-9818-f00e453b9a75 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4946.yml b/data_sources/windows_event_log_security_4946.yml index 1c9e634be3..4c47bbcc51 100644 --- a/data_sources/windows_event_log_security_4946.yml +++ b/data_sources/windows_event_log_security_4946.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4946 id: d7dafd01-a22d-4b05-b793-7571ef1fa789 -version: 8 +version: 9 creation_date: '2025-03-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4946 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4946' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4947.yml b/data_sources/windows_event_log_security_4947.yml index 388e24744a..b12d773e0d 100644 --- a/data_sources/windows_event_log_security_4947.yml +++ b/data_sources/windows_event_log_security_4947.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4947 id: 63d4a2fa-a7dc-46d2-b702-54794e1f4d3c -version: 8 +version: 9 creation_date: '2025-03-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4947 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4947' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4948.yml b/data_sources/windows_event_log_security_4948.yml index 13411a4e1e..2f59dc291e 100644 --- a/data_sources/windows_event_log_security_4948.yml +++ b/data_sources/windows_event_log_security_4948.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4948 id: 910032df-4e49-42fe-a611-d4c29557d83a -version: 8 +version: 9 creation_date: '2025-03-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4948 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4948' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index 5d978fbd02..3f4491f8b0 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5136 id: 7ba3737e-231e-455d-824e-cd077749f835 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index 32b78c9736..c745196af0 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AppCorrelationID diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index 57e957cd22..31036dba3f 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index 2683448397..494c1932e4 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5141 id: eafb35fa-f034-4be3-8508-d9173a73c0a1 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index 5dbdd2cce9..df1ffcace4 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_system_104.yml b/data_sources/windows_event_log_system_104.yml index 90a19ccbf3..0d0dfb7e03 100644 --- a/data_sources/windows_event_log_system_104.yml +++ b/data_sources/windows_event_log_system_104.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 104 id: 577b9b41-6b37-44c4-9016-3d890b909050 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log System 104 source: XmlWinEventLog:System @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index 5c9adb4679..4dc384351b 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4720 id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 05c0723985..64d4bbe59e 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4726 id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index bf3431d436..e3dcc6c286 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index b80e177e6f..fcb8336d67 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7036 id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). mitre_components: @@ -17,7 +17,7 @@ separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 9dd3b673ab..753cdef672 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index 73a9742ad5..6333800eea 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - AccountName diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index ba17034a69..c9107f01da 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ActionName diff --git a/data_sources/windows_event_log_taskscheduler_201.yml b/data_sources/windows_event_log_taskscheduler_201.yml index 6a7d5045b8..c84db76aaa 100644 --- a/data_sources/windows_event_log_taskscheduler_201.yml +++ b/data_sources/windows_event_log_taskscheduler_201.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 201 id: 4c09ae64-01cd-4b65-8221-20f803b0d86e -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log TaskScheduler 201 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index 7578646ccb..7b88eabe2a 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -1,8 +1,8 @@ name: Windows IIS id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. mitre_components: @@ -16,4 +16,4 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index f9ba107c65..4101b2266f 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -1,8 +1,8 @@ name: Windows IIS 29 id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-31' +modification_date: '2026-08-10' author: Patrick Bareiss, Splunk description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. mitre_components: @@ -17,7 +17,7 @@ separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 11.0.0 + version: 10.0.1 fields: - _time - ComputerName From 65d095f5d89daa3344b35e9ae33617540e8dabc6 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Tue, 11 Aug 2026 09:48:54 +0000 Subject: [PATCH 27/32] Update datasource TA versions --- data_sources/github_enterprise_audit_logs.yml | 6 +++--- data_sources/github_organizations_audit_logs.yml | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/data_sources/github_enterprise_audit_logs.yml b/data_sources/github_enterprise_audit_logs.yml index 04b18f4964..76f9383192 100644 --- a/data_sources/github_enterprise_audit_logs.yml +++ b/data_sources/github_enterprise_audit_logs.yml @@ -1,8 +1,8 @@ name: GitHub Enterprise Audit Logs id: 8a4d656f-8801-4a2c-ae10-553d2696a59f -version: 4 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-06-24' +modification_date: '2026-08-11' author: Patrick Bareiss, Splunk description: Data source object for GitHub Enterprise logs using Audit log streaming as described in this documentation https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-streaming-to-splunk using a Splunk HTTP Event Collector. source: http:github @@ -10,7 +10,7 @@ sourcetype: httpevent supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.3.1 + version: 4.0.0 fields: - _document_id - action diff --git a/data_sources/github_organizations_audit_logs.yml b/data_sources/github_organizations_audit_logs.yml index e27b87cbd8..b69eb08a2d 100644 --- a/data_sources/github_organizations_audit_logs.yml +++ b/data_sources/github_organizations_audit_logs.yml @@ -1,8 +1,8 @@ name: GitHub Organizations Audit Logs id: ce520b1c-79fe-48ef-a0f9-71fbbd4837b0 -version: 4 +version: 5 creation_date: '2024-07-16' -modification_date: '2026-06-24' +modification_date: '2026-08-11' author: Patrick Bareiss, Splunk description: Data source object for GitHub Organizations logs using the Splunk Add-on for Github using a Personal Access Token. source: github @@ -10,7 +10,7 @@ sourcetype: github:cloud:audit supported_TA: - name: Splunk Add-on for Github url: https://splunkbase.splunk.com/app/6254 - version: 3.3.1 + version: 4.0.0 fields: - _document_id - action From 4a40b633a8bfb32fb834f640b582f8863bbf645f Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Tue, 11 Aug 2026 15:47:48 +0000 Subject: [PATCH 28/32] Update datasource TA versions --- data_sources/linux_auditd_add_user.yml | 6 +++--- data_sources/linux_auditd_cwd.yml | 6 +++--- data_sources/linux_auditd_daemon_abort.yml | 6 +++--- data_sources/linux_auditd_daemon_end.yml | 6 +++--- data_sources/linux_auditd_daemon_start.yml | 6 +++--- data_sources/linux_auditd_execve.yml | 6 +++--- data_sources/linux_auditd_path.yml | 6 +++--- data_sources/linux_auditd_proctitle.yml | 6 +++--- data_sources/linux_auditd_service_stop.yml | 6 +++--- data_sources/linux_auditd_syscall.yml | 6 +++--- data_sources/linux_messages_syslog.yml | 6 +++--- data_sources/linux_secure.yml | 6 +++--- 12 files changed, 36 insertions(+), 36 deletions(-) diff --git a/data_sources/linux_auditd_add_user.yml b/data_sources/linux_auditd_add_user.yml index 16d0e52b16..6dcf762b8d 100644 --- a/data_sources/linux_auditd_add_user.yml +++ b/data_sources/linux_auditd_add_user.yml @@ -1,8 +1,8 @@ name: Linux Auditd Add User id: 30f79353-e1d2-4585-8735-1e0359559f3f -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs activities related to the addition of a new user account on a Linux system, including details about the username, UID, and the process initiating the action. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - msg - type diff --git a/data_sources/linux_auditd_cwd.yml b/data_sources/linux_auditd_cwd.yml index 74f486cf02..2da3dd20e6 100644 --- a/data_sources/linux_auditd_cwd.yml +++ b/data_sources/linux_auditd_cwd.yml @@ -1,8 +1,8 @@ name: Linux Auditd Cwd id: a9ef851b-d864-478b-b1b3-76535d7ff7fc -version: 6 +version: 7 creation_date: '2025-12-02' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Nasreddine Bencherchali, Splunk description: This type is used to record the working directory from which the process that invoked the system call specified in the first record was executed. The purpose of this record is to record the current process's location in case a relative path winds up being captured in the associated PATH record. This way the absolute path can be reconstructed. source: auditd @@ -13,7 +13,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - cwd - date_hour diff --git a/data_sources/linux_auditd_daemon_abort.yml b/data_sources/linux_auditd_daemon_abort.yml index 8f72d94172..f201d6027c 100644 --- a/data_sources/linux_auditd_daemon_abort.yml +++ b/data_sources/linux_auditd_daemon_abort.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Abort id: cc8b3bb0-0fae-4236-9c61-fe2d7138bd63 -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_end.yml b/data_sources/linux_auditd_daemon_end.yml index 15f3bc7203..7b781ecbc1 100644 --- a/data_sources/linux_auditd_daemon_end.yml +++ b/data_sources/linux_auditd_daemon_end.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon End id: 15135c45-e302-4d5a-a38a-3e8279f2ebd8 -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - type - op diff --git a/data_sources/linux_auditd_daemon_start.yml b/data_sources/linux_auditd_daemon_start.yml index 5ec90785a6..280ab8ac3c 100644 --- a/data_sources/linux_auditd_daemon_start.yml +++ b/data_sources/linux_auditd_daemon_start.yml @@ -1,8 +1,8 @@ name: Linux Auditd Daemon Start id: f1b97407-ddf0-41a5-8685-ada05aae3555 -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the auditd daemon status. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - type - op diff --git a/data_sources/linux_auditd_execve.yml b/data_sources/linux_auditd_execve.yml index 9bcded1c7b..1d551b71e4 100644 --- a/data_sources/linux_auditd_execve.yml +++ b/data_sources/linux_auditd_execve.yml @@ -1,8 +1,8 @@ name: Linux Auditd Execve id: 9ef6364d-cc67-480e-8448-3306829a6a24 -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs the execution of processes on a Linux system, including details about the executed command, arguments, and the initiating process. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - msg - type diff --git a/data_sources/linux_auditd_path.yml b/data_sources/linux_auditd_path.yml index b878fc9daa..c83dd64c27 100644 --- a/data_sources/linux_auditd_path.yml +++ b/data_sources/linux_auditd_path.yml @@ -1,8 +1,8 @@ name: Linux Auditd Path id: 3d86125c-0496-4a5a-aae3-0d355a4f3d7d -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs file system access events on a Linux system, including details about file paths, permissions, and associated processes. mitre_components: @@ -19,7 +19,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - msg - type diff --git a/data_sources/linux_auditd_proctitle.yml b/data_sources/linux_auditd_proctitle.yml index 1c835ca384..cfbfff6811 100644 --- a/data_sources/linux_auditd_proctitle.yml +++ b/data_sources/linux_auditd_proctitle.yml @@ -1,8 +1,8 @@ name: Linux Auditd Proctitle id: 5a25984a-2789-400a-858b-d75c923e06b1 -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs the full command-line arguments of a process execution on a Linux system, providing visibility into the executed command and its parameters. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - proctitle - msg diff --git a/data_sources/linux_auditd_service_stop.yml b/data_sources/linux_auditd_service_stop.yml index b4078394b9..f69613d7d7 100644 --- a/data_sources/linux_auditd_service_stop.yml +++ b/data_sources/linux_auditd_service_stop.yml @@ -1,8 +1,8 @@ name: Linux Auditd Service Stop id: 0643483c-bc62-455c-8d6e-1630e5f0e00d -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs events related to the stoppage of a service on a Linux system, including details about the service name, the process initiating the stop, and associated timestamps. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - msg - type diff --git a/data_sources/linux_auditd_syscall.yml b/data_sources/linux_auditd_syscall.yml index 3cd1db7d09..488c8a134c 100644 --- a/data_sources/linux_auditd_syscall.yml +++ b/data_sources/linux_auditd_syscall.yml @@ -1,8 +1,8 @@ name: Linux Auditd Syscall id: 4dff7047-0d43-4096-bb3f-b756c889bbad -version: 7 +version: 8 creation_date: '2024-08-08' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Teoderick Contreras, Splunk description: Logs system calls made by processes on a Linux system, including details about the syscall number, arguments, return values, and associated process metadata. mitre_components: @@ -18,7 +18,7 @@ configuration: https://github.com/Neo23x0/auditd/blob/master/audit.rules supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - msg - type diff --git a/data_sources/linux_messages_syslog.yml b/data_sources/linux_messages_syslog.yml index ecf265e4ca..5c17ba9fa0 100644 --- a/data_sources/linux_messages_syslog.yml +++ b/data_sources/linux_messages_syslog.yml @@ -1,8 +1,8 @@ name: Linux Messages Syslog id: c9e3bbb5-e0a2-4bac-8457-227e71841bda -version: 5 +version: 6 creation_date: '2025-05-06' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Ravent Tait, Splunk description: Logs kernel events on a Linux system, including service starts/stops, hardware events, authentication notices, and other OS-level activity. @@ -16,7 +16,7 @@ sourcetype: linux_messages_syslog supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - _time - action diff --git a/data_sources/linux_secure.yml b/data_sources/linux_secure.yml index c5a8884d70..a36a0cc123 100644 --- a/data_sources/linux_secure.yml +++ b/data_sources/linux_secure.yml @@ -1,8 +1,8 @@ name: Linux Secure id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb -version: 7 +version: 8 creation_date: '2024-05-22' -modification_date: '2026-07-30' +modification_date: '2026-08-11' author: Patrick Bareiss, Splunk description: Logs authentication and authorization events on a Linux system, including login attempts, SSH connections, and privilege escalation activities. mitre_components: @@ -16,7 +16,7 @@ sourcetype: linux_secure supported_TA: - name: Splunk Add-on for Unix and Linux url: https://splunkbase.splunk.com/app/833 - version: 10.3.2 + version: 10.3.3 fields: - _time - action From 4da7ab40d87cec390fc053aeffc67f61a138a5aa Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Wed, 12 Aug 2026 15:51:58 +0000 Subject: [PATCH 29/32] Update datasource TA versions --- data_sources/nginx_access.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/data_sources/nginx_access.yml b/data_sources/nginx_access.yml index 8c249409e4..b0dc99cdfa 100644 --- a/data_sources/nginx_access.yml +++ b/data_sources/nginx_access.yml @@ -1,8 +1,8 @@ name: Nginx Access id: c716a418-eab3-4df5-9dff-5420174e3068 -version: 3 +version: 4 creation_date: '2024-07-16' -modification_date: '2026-05-13' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs HTTP/S access events on an Nginx server, including details such as client IP, request method, URI, response status, and user agent. mitre_components: @@ -16,7 +16,7 @@ sourcetype: nginx:plus:kv supported_TA: - name: Splunk Add-on for NGINX url: https://splunkbase.splunk.com/app/3258 - version: 3.3.0 + version: 3.3.1 fields: - _time - action From adf8ac2704733d9b2383d167a044896488efba1f Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Wed, 12 Aug 2026 17:49:25 +0000 Subject: [PATCH 30/32] Update datasource TA versions --- data_sources/ntlm_operational_8004.yml | 6 +++--- data_sources/ntlm_operational_8005.yml | 6 +++--- data_sources/ntlm_operational_8006.yml | 6 +++--- data_sources/powershell_script_block_logging_4104.yml | 6 +++--- data_sources/windows_active_directory_admon.yml | 6 +++--- data_sources/windows_event_log_application_15457.yml | 6 +++--- data_sources/windows_event_log_application_17135.yml | 6 +++--- data_sources/windows_event_log_application_2282.yml | 6 +++--- data_sources/windows_event_log_application_3000.yml | 6 +++--- data_sources/windows_event_log_application_8128.yml | 6 +++--- .../windows_event_log_appxdeployment_server_400.yml | 6 +++--- .../windows_event_log_appxdeployment_server_854.yml | 6 +++--- .../windows_event_log_appxdeployment_server_855.yml | 6 +++--- data_sources/windows_event_log_appxpackaging_171.yml | 6 +++--- data_sources/windows_event_log_capi2_70.yml | 6 +++--- data_sources/windows_event_log_capi2_81.yml | 6 +++--- .../windows_event_log_certificateservicesclient_1007.yml | 6 +++--- data_sources/windows_event_log_defender_1121.yml | 6 +++--- data_sources/windows_event_log_defender_1122.yml | 6 +++--- data_sources/windows_event_log_defender_1125.yml | 6 +++--- data_sources/windows_event_log_defender_1126.yml | 6 +++--- data_sources/windows_event_log_defender_1129.yml | 6 +++--- data_sources/windows_event_log_defender_1131.yml | 6 +++--- data_sources/windows_event_log_defender_1132.yml | 6 +++--- data_sources/windows_event_log_defender_1133.yml | 6 +++--- data_sources/windows_event_log_defender_1134.yml | 6 +++--- data_sources/windows_event_log_defender_5007.yml | 6 +++--- data_sources/windows_event_log_printservice_316.yml | 6 +++--- data_sources/windows_event_log_printservice_4909.yml | 6 +++--- data_sources/windows_event_log_printservice_808.yml | 6 +++--- .../windows_event_log_remoteconnectionmanager_1149.yml | 6 +++--- data_sources/windows_event_log_security_1100.yml | 6 +++--- data_sources/windows_event_log_security_1102.yml | 6 +++--- data_sources/windows_event_log_security_4624.yml | 6 +++--- data_sources/windows_event_log_security_4625.yml | 6 +++--- data_sources/windows_event_log_security_4627.yml | 6 +++--- data_sources/windows_event_log_security_4648.yml | 6 +++--- data_sources/windows_event_log_security_4662.yml | 6 +++--- data_sources/windows_event_log_security_4663.yml | 6 +++--- data_sources/windows_event_log_security_4672.yml | 6 +++--- data_sources/windows_event_log_security_4688.yml | 6 +++--- data_sources/windows_event_log_security_4698.yml | 6 +++--- data_sources/windows_event_log_security_4699.yml | 6 +++--- data_sources/windows_event_log_security_4700.yml | 6 +++--- data_sources/windows_event_log_security_4702.yml | 6 +++--- data_sources/windows_event_log_security_4703.yml | 6 +++--- data_sources/windows_event_log_security_4719.yml | 6 +++--- data_sources/windows_event_log_security_4720.yml | 6 +++--- data_sources/windows_event_log_security_4723.yml | 6 +++--- data_sources/windows_event_log_security_4724.yml | 6 +++--- data_sources/windows_event_log_security_4725.yml | 6 +++--- data_sources/windows_event_log_security_4726.yml | 6 +++--- data_sources/windows_event_log_security_4727.yml | 6 +++--- data_sources/windows_event_log_security_4728.yml | 6 +++--- data_sources/windows_event_log_security_4730.yml | 6 +++--- data_sources/windows_event_log_security_4731.yml | 6 +++--- data_sources/windows_event_log_security_4732.yml | 6 +++--- data_sources/windows_event_log_security_4737.yml | 6 +++--- data_sources/windows_event_log_security_4738.yml | 6 +++--- data_sources/windows_event_log_security_4739.yml | 6 +++--- data_sources/windows_event_log_security_4741.yml | 6 +++--- data_sources/windows_event_log_security_4742.yml | 6 +++--- data_sources/windows_event_log_security_4744.yml | 6 +++--- data_sources/windows_event_log_security_4749.yml | 6 +++--- data_sources/windows_event_log_security_4754.yml | 6 +++--- data_sources/windows_event_log_security_4756.yml | 6 +++--- data_sources/windows_event_log_security_4759.yml | 6 +++--- data_sources/windows_event_log_security_4768.yml | 6 +++--- data_sources/windows_event_log_security_4769.yml | 6 +++--- data_sources/windows_event_log_security_4771.yml | 6 +++--- data_sources/windows_event_log_security_4776.yml | 6 +++--- data_sources/windows_event_log_security_4781.yml | 6 +++--- data_sources/windows_event_log_security_4783.yml | 6 +++--- data_sources/windows_event_log_security_4790.yml | 6 +++--- data_sources/windows_event_log_security_4794.yml | 6 +++--- data_sources/windows_event_log_security_4798.yml | 6 +++--- data_sources/windows_event_log_security_4876.yml | 6 +++--- data_sources/windows_event_log_security_4886.yml | 6 +++--- data_sources/windows_event_log_security_4887.yml | 6 +++--- data_sources/windows_event_log_security_4946.yml | 6 +++--- data_sources/windows_event_log_security_4947.yml | 6 +++--- data_sources/windows_event_log_security_4948.yml | 6 +++--- data_sources/windows_event_log_security_5136.yml | 6 +++--- data_sources/windows_event_log_security_5137.yml | 6 +++--- data_sources/windows_event_log_security_5140.yml | 6 +++--- data_sources/windows_event_log_security_5141.yml | 6 +++--- data_sources/windows_event_log_security_5145.yml | 6 +++--- data_sources/windows_event_log_system_104.yml | 6 +++--- data_sources/windows_event_log_system_4720.yml | 6 +++--- data_sources/windows_event_log_system_4726.yml | 6 +++--- data_sources/windows_event_log_system_4728.yml | 6 +++--- data_sources/windows_event_log_system_7036.yml | 6 +++--- data_sources/windows_event_log_system_7040.yml | 6 +++--- data_sources/windows_event_log_system_7045.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_200.yml | 6 +++--- data_sources/windows_event_log_taskscheduler_201.yml | 6 +++--- data_sources/windows_iis.yml | 6 +++--- data_sources/windows_iis_29.yml | 6 +++--- 98 files changed, 294 insertions(+), 294 deletions(-) diff --git a/data_sources/ntlm_operational_8004.yml b/data_sources/ntlm_operational_8004.yml index 3ababb638d..68e2f5fa78 100644 --- a/data_sources/ntlm_operational_8004.yml +++ b/data_sources/ntlm_operational_8004.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8004 id: fd08cb77-c26e-464c-a43e-2867e232127e -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8004 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8005.yml b/data_sources/ntlm_operational_8005.yml index e8bbe3e510..2277339005 100644 --- a/data_sources/ntlm_operational_8005.yml +++ b/data_sources/ntlm_operational_8005.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8005 id: ad15a1cf-4b21-43de-81e4-6307c69172fb -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8005 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/ntlm_operational_8006.yml b/data_sources/ntlm_operational_8006.yml index a4ee1bb451..97d38afbfd 100644 --- a/data_sources/ntlm_operational_8006.yml +++ b/data_sources/ntlm_operational_8006.yml @@ -1,8 +1,8 @@ name: NTLM Operational 8006 id: 9f50a672-6f7d-4621-a3bd-69468c6b7a7f -version: 8 +version: 9 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for NTLM Operational 8006 source: XmlWinEventLog:Microsoft-Windows-NTLM/Operational @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/powershell_script_block_logging_4104.yml b/data_sources/powershell_script_block_logging_4104.yml index f39936ab44..3946d4d1a6 100644 --- a/data_sources/powershell_script_block_logging_4104.yml +++ b/data_sources/powershell_script_block_logging_4104.yml @@ -1,8 +1,8 @@ name: Powershell Script Block Logging 4104 id: 5cfd0c72-d989-47a0-92f9-6edc6f8d3564 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs detailed content of PowerShell script blocks as they are executed, including the full command text and context for the execution. mitre_components: @@ -18,7 +18,7 @@ separator_value: '4104' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_active_directory_admon.yml b/data_sources/windows_active_directory_admon.yml index a3e8ccab20..2ff7c956d2 100644 --- a/data_sources/windows_active_directory_admon.yml +++ b/data_sources/windows_active_directory_admon.yml @@ -1,8 +1,8 @@ name: Windows Active Directory Admon id: 22bbf4e4-d313-43c1-98ee-808b8775519d -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs administrative actions within Active Directory, including user and group modifications, permission changes, and policy updates. mitre_components: @@ -16,7 +16,7 @@ sourcetype: ActiveDirectory supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Guid diff --git a/data_sources/windows_event_log_application_15457.yml b/data_sources/windows_event_log_application_15457.yml index 731ab7922f..a3edf2aa0f 100644 --- a/data_sources/windows_event_log_application_15457.yml +++ b/data_sources/windows_event_log_application_15457.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 15457 id: 4491537e-520c-46f7-9209-f56f852aa237 -version: 8 +version: 9 creation_date: '2025-02-25' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 15457 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_17135.yml b/data_sources/windows_event_log_application_17135.yml index bcb94dac20..1ed630c660 100644 --- a/data_sources/windows_event_log_application_17135.yml +++ b/data_sources/windows_event_log_application_17135.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 17135 id: 4491537e-520c-46f7-9209-f56f852aa231 -version: 8 +version: 9 creation_date: '2025-02-25' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 17135 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_application_2282.yml b/data_sources/windows_event_log_application_2282.yml index 4ff194ea90..0a038aa2d1 100644 --- a/data_sources/windows_event_log_application_2282.yml +++ b/data_sources/windows_event_log_application_2282.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 2282 id: 4490537e-5e0c-46f7-9209-f56f852aa237 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event in IIS when a module DLL fails to load due to a configuration issue, including details about the module and error message. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_3000.yml b/data_sources/windows_event_log_application_3000.yml index b07b1faf3a..e011a6e9a5 100644 --- a/data_sources/windows_event_log_application_3000.yml +++ b/data_sources/windows_event_log_application_3000.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: @@ -17,7 +17,7 @@ separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_application_8128.yml b/data_sources/windows_event_log_application_8128.yml index 86ca7cf72b..d868e298aa 100644 --- a/data_sources/windows_event_log_application_8128.yml +++ b/data_sources/windows_event_log_application_8128.yml @@ -1,8 +1,8 @@ name: Windows Event Log Application 8128 id: 4491537e-5e0c-46f7-9209-f56f852aa237 -version: 8 +version: 9 creation_date: '2025-02-25' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Michael Haag, Splunk description: Data source object for Windows Event Log Application 8128 source: XmlWinEventLog:Application @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_400.yml b/data_sources/windows_event_log_appxdeployment_server_400.yml index a6300ef53f..0faf92b1db 100644 --- a/data_sources/windows_event_log_appxdeployment_server_400.yml +++ b/data_sources/windows_event_log_appxdeployment_server_400.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 400 id: 3e5f9d2a-b8c7-4d1e-a6f3-7b9c8d5e4f2a -version: 8 +version: 9 creation_date: '2025-08-18' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 400. These events are generated when a package deployment operation begins, providing details about the package being deployed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_854.yml b/data_sources/windows_event_log_appxdeployment_server_854.yml index 0e1707c4fb..15c6c87849 100644 --- a/data_sources/windows_event_log_appxdeployment_server_854.yml +++ b/data_sources/windows_event_log_appxdeployment_server_854.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 854 id: 4d2e6f8a-c9b7-5a3e-8d1f-2e9c7b5a4f3d -version: 8 +version: 9 creation_date: '2025-08-18' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 854. These events are generated when an MSIX/AppX package has been successfully installed on a system. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxdeployment_server_855.yml b/data_sources/windows_event_log_appxdeployment_server_855.yml index 47e7cc0645..379e7eb4c5 100644 --- a/data_sources/windows_event_log_appxdeployment_server_855.yml +++ b/data_sources/windows_event_log_appxdeployment_server_855.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXDeployment-Server 855 id: 4491537c-521c-46f7-9209-f56f852aa231 -version: 8 +version: 9 creation_date: '2025-08-18' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXDeploymentServer/Operational channel, specifically focusing on EventCode 855. These events are generated when a package deployment operation completes successfully, providing details about the packages that were installed or updated. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_appxpackaging_171.yml b/data_sources/windows_event_log_appxpackaging_171.yml index e4307d47b7..16f79454a6 100644 --- a/data_sources/windows_event_log_appxpackaging_171.yml +++ b/data_sources/windows_event_log_appxpackaging_171.yml @@ -1,8 +1,8 @@ name: Windows Event Log AppXPackaging 171 id: 2d0f8e3c-a2d7-4b9e-8f1c-6a5d7e3e9f2b -version: 8 +version: 9 creation_date: '2025-08-18' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Michael Haag, Splunk description: 'This data source captures Windows Event Logs from the Microsoft-Windows-AppXPackaging/Operational channel, specifically focusing on EventCode 171. These events are generated when a user clicks on or attempts to interact with an MSIX package, even if the package is not fully installed. @@ -19,7 +19,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_capi2_70.yml b/data_sources/windows_event_log_capi2_70.yml index 059d548ecd..fd85b7dcd1 100644 --- a/data_sources/windows_event_log_capi2_70.yml +++ b/data_sources/windows_event_log_capi2_70.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 70 id: 821de0a6-c5b4-491b-a27e-187552792817 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: This event log records events related to cryptographic operations, including the deletion and export of certificates. mitre_components: @@ -18,7 +18,7 @@ separator_value: '70' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_capi2_81.yml b/data_sources/windows_event_log_capi2_81.yml index 2cb78e5ec5..61c988efc1 100644 --- a/data_sources/windows_event_log_capi2_81.yml +++ b/data_sources/windows_event_log_capi2_81.yml @@ -1,8 +1,8 @@ name: Windows Event Log CAPI2 81 id: 463ff898-8135-4c0e-811e-f8629dfc5027 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an error when attempting to verify the digital signature of a file, including details about the file path, signature failure, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '81' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_certificateservicesclient_1007.yml b/data_sources/windows_event_log_certificateservicesclient_1007.yml index 204b28e95e..1004067d1b 100644 --- a/data_sources/windows_event_log_certificateservicesclient_1007.yml +++ b/data_sources/windows_event_log_certificateservicesclient_1007.yml @@ -1,8 +1,8 @@ name: Windows Event Log CertificateServicesClient 1007 id: c51444e3-479d-4c4a-b111-e8276a3acf39 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the export of a certificate from the local certificate store, including details about the certificate thumbprint, subject names, and the process involved. mitre_components: @@ -18,7 +18,7 @@ separator_value: '1007' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1121.yml b/data_sources/windows_event_log_defender_1121.yml index cc49bae908..c85bee3fd5 100644 --- a/data_sources/windows_event_log_defender_1121.yml +++ b/data_sources/windows_event_log_defender_1121.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1121 id: 84a254c5-7900-4b52-a324-a176adb7c11d -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a Windows Defender attack surface reduction rule fires in block mode. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1121' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1122.yml b/data_sources/windows_event_log_defender_1122.yml index 3357eaa5bc..f4276a2c65 100644 --- a/data_sources/windows_event_log_defender_1122.yml +++ b/data_sources/windows_event_log_defender_1122.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1122 id: 4a2d0499-f489-4557-82f4-f357025cf3e7 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a process attempts to load a DLL that is blocked by an attack surface reduction rule. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1122' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1125.yml b/data_sources/windows_event_log_defender_1125.yml index 763b0d3fed..c8dd749fb3 100644 --- a/data_sources/windows_event_log_defender_1125.yml +++ b/data_sources/windows_event_log_defender_1125.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1125 id: 0cddda76-6fd8-4fb6-9026-f23a2761c95d -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1125 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time example_log: 112204000x80000000000000003701Microsoft-Windows-Windows Defender/OperationalresearchvmhaaMicrosoft Defender Antivirus4.18.23100.2009E6DB77E5-3DF2-4CF1-B95A-636979351E5B2023-11-26T23:43:08.709Z(unknown user)C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe1.401.1247.01.1.23100.2009ENT\ConsRC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x00000000 diff --git a/data_sources/windows_event_log_defender_1126.yml b/data_sources/windows_event_log_defender_1126.yml index 14c2ff0991..b9ee7565e8 100644 --- a/data_sources/windows_event_log_defender_1126.yml +++ b/data_sources/windows_event_log_defender_1126.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1126 id: c1c6284b-b663-4001-bdf2-c0cacee22a2a -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1126 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_defender_1129.yml b/data_sources/windows_event_log_defender_1129.yml index 74a6896f88..612f88bfff 100644 --- a/data_sources/windows_event_log_defender_1129.yml +++ b/data_sources/windows_event_log_defender_1129.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1129 id: 0572e119-a48a-4c70-bc58-90e453edacd2 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a user overrides a security policy set by an Attack Surface Reduction rule in Microsoft Defender. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1129' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_defender_1131.yml b/data_sources/windows_event_log_defender_1131.yml index 654a4c0242..8dd7a08fe0 100644 --- a/data_sources/windows_event_log_defender_1131.yml +++ b/data_sources/windows_event_log_defender_1131.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1131 id: 638f884e-439a-4328-923c-ec5a2679f450 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1131 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1132.yml b/data_sources/windows_event_log_defender_1132.yml index ef64b19d74..cd7444e5ef 100644 --- a/data_sources/windows_event_log_defender_1132.yml +++ b/data_sources/windows_event_log_defender_1132.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1132 id: 18f93f60-4eca-46e8-a29d-147e6451a34c -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1132 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1133.yml b/data_sources/windows_event_log_defender_1133.yml index 4e269b8457..a1fda4e8a7 100644 --- a/data_sources/windows_event_log_defender_1133.yml +++ b/data_sources/windows_event_log_defender_1133.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1133 id: 63c97a9a-cc7f-46c5-b219-8be388666637 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1133 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_1134.yml b/data_sources/windows_event_log_defender_1134.yml index 9ba1eb35fe..fec4c50060 100644 --- a/data_sources/windows_event_log_defender_1134.yml +++ b/data_sources/windows_event_log_defender_1134.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 1134 id: 26abac7d-d026-44e9-b1a3-13e3e11b232d -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Defender 1134 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - ActivityID - CategoryString diff --git a/data_sources/windows_event_log_defender_5007.yml b/data_sources/windows_event_log_defender_5007.yml index 4fc31a5de6..1d6ff7c3ae 100644 --- a/data_sources/windows_event_log_defender_5007.yml +++ b/data_sources/windows_event_log_defender_5007.yml @@ -1,8 +1,8 @@ name: Windows Event Log Defender 5007 id: 27f18792-8d95-4871-8853-874b7faf023f -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when Windows Defender antimalware settings are modified. mitre_components: @@ -14,7 +14,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_printservice_316.yml b/data_sources/windows_event_log_printservice_316.yml index e50f91c1dc..97da9ee184 100644 --- a/data_sources/windows_event_log_printservice_316.yml +++ b/data_sources/windows_event_log_printservice_316.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 316 id: 12f0be8b-22c0-4fdf-9468-b7ccca824d1d -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when printer drivers are installed or updated on the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '316' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_printservice_4909.yml b/data_sources/windows_event_log_printservice_4909.yml index 650770547a..020ee604e3 100644 --- a/data_sources/windows_event_log_printservice_4909.yml +++ b/data_sources/windows_event_log_printservice_4909.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 4909 id: 4c00e353-18b8-4de6-896d-83bc5817dbaa -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Printservice 4909 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time example_log: '' diff --git a/data_sources/windows_event_log_printservice_808.yml b/data_sources/windows_event_log_printservice_808.yml index a998640bf0..6ef802aba3 100644 --- a/data_sources/windows_event_log_printservice_808.yml +++ b/data_sources/windows_event_log_printservice_808.yml @@ -1,8 +1,8 @@ name: Windows Event Log Printservice 808 id: e3a26785-4389-4830-8d7b-3dad4252719e -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when the print spooler service fails to load a printer plug-in module. mitre_components: @@ -16,7 +16,7 @@ separator_value: '808' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ComputerName diff --git a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml index 92927af949..e5c8b9a7d4 100644 --- a/data_sources/windows_event_log_remoteconnectionmanager_1149.yml +++ b/data_sources/windows_event_log_remoteconnectionmanager_1149.yml @@ -1,8 +1,8 @@ name: Windows Event Log RemoteConnectionManager 1149 id: 08f9edb4-f95f-40be-b1dd-bc3a1cd95aaf -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a Remote Desktop Service session is initialized. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1149' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_1100.yml b/data_sources/windows_event_log_security_1100.yml index 1bdf653cf6..17834979de 100644 --- a/data_sources/windows_event_log_security_1100.yml +++ b/data_sources/windows_event_log_security_1100.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: @@ -15,7 +15,7 @@ separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index 8411b49f17..4169bffb3a 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 11 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -16,7 +16,7 @@ separator_value: '1102' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4624.yml b/data_sources/windows_event_log_security_4624.yml index 3ba3514d0a..833de43495 100644 --- a/data_sources/windows_event_log_security_4624.yml +++ b/data_sources/windows_event_log_security_4624.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4624 id: 08682968-0366-4882-9559-fe4fe018a846 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when an account successfully logs on to a system. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4624' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4625.yml b/data_sources/windows_event_log_security_4625.yml index 15cb8fcd8c..8287889cd6 100644 --- a/data_sources/windows_event_log_security_4625.yml +++ b/data_sources/windows_event_log_security_4625.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4625 id: 365a02c2-7d18-4baf-b76e-d90c20bbe6ed -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when an account fails to log on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4625' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4627.yml b/data_sources/windows_event_log_security_4627.yml index f312b95c9f..7a52910ecf 100644 --- a/data_sources/windows_event_log_security_4627.yml +++ b/data_sources/windows_event_log_security_4627.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4627 id: e35c7b9a-b451-4084-95a5-43b7f8965cac -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a successful account logon occurs and displays the list of groups the logged-on account belongs to. mitre_components: @@ -16,7 +16,7 @@ separator_value: '4627' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4648.yml b/data_sources/windows_event_log_security_4648.yml index fa303f8481..33dd5d1e25 100644 --- a/data_sources/windows_event_log_security_4648.yml +++ b/data_sources/windows_event_log_security_4648.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4648 id: 6a367f8b-1ee0-463d-94a7-029757c6cd02 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logged when an account logon is attempted by a process by explicitly specifying the credentials of that account mitre_components: @@ -15,7 +15,7 @@ separator_value: '4648' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4662.yml b/data_sources/windows_event_log_security_4662.yml index f1904ae88e..50ac3ee70b 100644 --- a/data_sources/windows_event_log_security_4662.yml +++ b/data_sources/windows_event_log_security_4662.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4662 id: f3c2cd64-0b5f-4013-8201-35dc03828ec6 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a user accessed an object within the Active Directory, such as creating, modifying, or deleting it mitre_components: @@ -15,7 +15,7 @@ separator_value: '4662' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4663.yml b/data_sources/windows_event_log_security_4663.yml index e900950bbb..1b9a25da06 100644 --- a/data_sources/windows_event_log_security_4663.yml +++ b/data_sources/windows_event_log_security_4663.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4663 id: 5d6dca8c-dad9-494f-a321-ef2b0b92fbf4 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a user or process tried to access a file, directory, registry key, or other system object on the computer mitre_components: @@ -15,7 +15,7 @@ separator_value: '4663' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_4672.yml b/data_sources/windows_event_log_security_4672.yml index 750c6684c3..8adb6c0a97 100644 --- a/data_sources/windows_event_log_security_4672.yml +++ b/data_sources/windows_event_log_security_4672.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a user with administrative privileges logs on to a system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4672' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4688.yml b/data_sources/windows_event_log_security_4688.yml index a03ac319f2..40122826ff 100644 --- a/data_sources/windows_event_log_security_4688.yml +++ b/data_sources/windows_event_log_security_4688.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4688 id: d195eb26-a81c-45ed-aeb3-25792e8a985a -version: 11 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the creation of a new process mitre_components: @@ -16,7 +16,7 @@ configuration: Enabling Windows event log process command line logging via group supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - Caller_Domain - Caller_User_Name diff --git a/data_sources/windows_event_log_security_4698.yml b/data_sources/windows_event_log_security_4698.yml index 01fc76a981..f0cb4bbcaa 100644 --- a/data_sources/windows_event_log_security_4698.yml +++ b/data_sources/windows_event_log_security_4698.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4698 id: 32c06703-02d3-47ec-8856-b0dc3045866c -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a new scheduled task is created mitre_components: @@ -15,7 +15,7 @@ separator_value: '4698' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4699.yml b/data_sources/windows_event_log_security_4699.yml index 95e35f6014..072088740f 100644 --- a/data_sources/windows_event_log_security_4699.yml +++ b/data_sources/windows_event_log_security_4699.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4699 id: 4727dead-d063-4333-9ddd-59823a416aff -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a scheduled task is deleted from the system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4699' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4700.yml b/data_sources/windows_event_log_security_4700.yml index d495565442..427f6c92bb 100644 --- a/data_sources/windows_event_log_security_4700.yml +++ b/data_sources/windows_event_log_security_4700.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4700 id: 89895c7b-2aba-41ca-ad12-8b6d290b5dde -version: 9 +version: 10 creation_date: '2025-03-11' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Steven Dick description: Data source object for Windows Event Log Security 4700 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - EventID example_log: 4700 0 0 12804 0 0x8020000000000000 344861 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin LeastPrivilege CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4702.yml b/data_sources/windows_event_log_security_4702.yml index a7735e1df6..ec10d43f46 100644 --- a/data_sources/windows_event_log_security_4702.yml +++ b/data_sources/windows_event_log_security_4702.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 -version: 9 +version: 10 creation_date: '2025-03-11' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe diff --git a/data_sources/windows_event_log_security_4703.yml b/data_sources/windows_event_log_security_4703.yml index 9cdda10497..c37f091816 100644 --- a/data_sources/windows_event_log_security_4703.yml +++ b/data_sources/windows_event_log_security_4703.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4703 id: e256673b-16e8-4b74-b7aa-9eed6ce67072 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a token right is adjusted on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4703' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4719.yml b/data_sources/windows_event_log_security_4719.yml index a9b2c846f1..b0f7b03b89 100644 --- a/data_sources/windows_event_log_security_4719.yml +++ b/data_sources/windows_event_log_security_4719.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4719 id: 954033e6-dd05-4775-a1f2-1f19632f4420 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a system audit policy is modified on a Windows system. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4719' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4720.yml b/data_sources/windows_event_log_security_4720.yml index 8995e2b110..ad7e6772a6 100644 --- a/data_sources/windows_event_log_security_4720.yml +++ b/data_sources/windows_event_log_security_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4720 id: 7ef1c9e5-691b-48c2-811b-eba91d2d2f1d -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a new user account is created on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4723.yml b/data_sources/windows_event_log_security_4723.yml index b1cc3673cb..2069265e2c 100644 --- a/data_sources/windows_event_log_security_4723.yml +++ b/data_sources/windows_event_log_security_4723.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4723 id: df19b271-57c8-4f31-817a-6c5566985484 -version: 7 +version: 8 creation_date: '2026-06-15' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Raven Tait, Splunk description: Logs an event when an attempt is made to change an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4723' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4724.yml b/data_sources/windows_event_log_security_4724.yml index b63442b836..e3aaacac2f 100644 --- a/data_sources/windows_event_log_security_4724.yml +++ b/data_sources/windows_event_log_security_4724.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4724 id: 117fe51f-93f8-4589-8e8b-c6b7b7154c7d -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when an attempt is made to reset an account's password, whether successful or not. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4724' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4725.yml b/data_sources/windows_event_log_security_4725.yml index c46d59c5c0..e90205c227 100644 --- a/data_sources/windows_event_log_security_4725.yml +++ b/data_sources/windows_event_log_security_4725.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4725 id: 31fd887d-0d14-44cc-bb64-80063a9f2968 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a user account has been disabled in Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4725' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4726.yml b/data_sources/windows_event_log_security_4726.yml index f08bfac332..bd6c6626c9 100644 --- a/data_sources/windows_event_log_security_4726.yml +++ b/data_sources/windows_event_log_security_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4726 id: 0b56dcd7-0f72-4a05-9226-d6059781737b -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a user account is deleted from Active Directory. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4727.yml b/data_sources/windows_event_log_security_4727.yml index 8ae64cb86d..0b180fe8ca 100644 --- a/data_sources/windows_event_log_security_4727.yml +++ b/data_sources/windows_event_log_security_4727.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4727 id: 4d2078ab-36f5-447e-b7e4-474890b8040b -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4727 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4728.yml b/data_sources/windows_event_log_security_4728.yml index 8ea886de95..7459fc2716 100644 --- a/data_sources/windows_event_log_security_4728.yml +++ b/data_sources/windows_event_log_security_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4728 id: c0cb4907-d715-41f2-a98a-4f4e75f248c1 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4728 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4730.yml b/data_sources/windows_event_log_security_4730.yml index 7e2d745a44..9fd24975e1 100644 --- a/data_sources/windows_event_log_security_4730.yml +++ b/data_sources/windows_event_log_security_4730.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4730 id: 126966ba-a17d-4194-882b-57d303aaf46d -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4730 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4731.yml b/data_sources/windows_event_log_security_4731.yml index a210cc23fc..628a061e51 100644 --- a/data_sources/windows_event_log_security_4731.yml +++ b/data_sources/windows_event_log_security_4731.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4731 id: 1bbc004e-a75e-4d94-a619-c5aaf5d11ed5 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4731 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4732.yml b/data_sources/windows_event_log_security_4732.yml index 6a0ca7e337..14b1195042 100644 --- a/data_sources/windows_event_log_security_4732.yml +++ b/data_sources/windows_event_log_security_4732.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4732 id: b0d61c5d-aefe-486a-9152-de45cc10fbb4 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a member is added to a security-enabled local group on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4732' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_security_4737.yml b/data_sources/windows_event_log_security_4737.yml index 23054960be..3b1e842bfa 100644 --- a/data_sources/windows_event_log_security_4737.yml +++ b/data_sources/windows_event_log_security_4737.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4737 id: 132fc609-17f0-4efd-8f7e-db12139c6690 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4737 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - CategoryString - Channel diff --git a/data_sources/windows_event_log_security_4738.yml b/data_sources/windows_event_log_security_4738.yml index d6620a5f23..f690894245 100644 --- a/data_sources/windows_event_log_security_4738.yml +++ b/data_sources/windows_event_log_security_4738.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4738 id: cb85709b-101e-41a9-bb60-d2108f79dfbd -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a user account's properties, such as permissions or memberships, are modified on a Windows system. mitre_components: @@ -14,7 +14,7 @@ separator_value: '4738' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4739.yml b/data_sources/windows_event_log_security_4739.yml index f06047a2fd..78583da336 100644 --- a/data_sources/windows_event_log_security_4739.yml +++ b/data_sources/windows_event_log_security_4739.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4739 id: c1e0442a-8a97-405d-baf2-057c5d68cd9a -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an event when a domain policy, such as account or lockout policy, is modified in Active Directory or local security settings. mitre_components: @@ -15,7 +15,7 @@ separator_value: '4739' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Caller_Domain diff --git a/data_sources/windows_event_log_security_4741.yml b/data_sources/windows_event_log_security_4741.yml index c22bfa51e6..39ca22f8d3 100644 --- a/data_sources/windows_event_log_security_4741.yml +++ b/data_sources/windows_event_log_security_4741.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4741 id: ef87257f-e7d1-4856-abae-097b2cfdcdb4 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the creation of a new computer account in Active Directory, including details about the account name, domain, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4741' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4742.yml b/data_sources/windows_event_log_security_4742.yml index cc3a201113..5ceda0de22 100644 --- a/data_sources/windows_event_log_security_4742.yml +++ b/data_sources/windows_event_log_security_4742.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4742 id: ea830adf-5450-489a-bcdc-fb8d2cbe674c -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs changes to the properties of a computer account in Active Directory, including details about the modified attributes and the user performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AccountExpires diff --git a/data_sources/windows_event_log_security_4744.yml b/data_sources/windows_event_log_security_4744.yml index fa43f12c59..4b6ab26bb7 100644 --- a/data_sources/windows_event_log_security_4744.yml +++ b/data_sources/windows_event_log_security_4744.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4744 id: 244e0bd4-00b0-4091-b8b4-9d435aca6ad8 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4744 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4749.yml b/data_sources/windows_event_log_security_4749.yml index 9992abb3e3..c721ea16d7 100644 --- a/data_sources/windows_event_log_security_4749.yml +++ b/data_sources/windows_event_log_security_4749.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4749 id: eb322056-01a3-4cd5-bc09-01140d33194a -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4749 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4754.yml b/data_sources/windows_event_log_security_4754.yml index f1ccf19ad8..dbbfc77f66 100644 --- a/data_sources/windows_event_log_security_4754.yml +++ b/data_sources/windows_event_log_security_4754.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4754 id: 501a507e-3275-4c4b-9c44-53eecfeae487 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4754 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4756.yml b/data_sources/windows_event_log_security_4756.yml index ba51a984a7..f7620a0a8b 100644 --- a/data_sources/windows_event_log_security_4756.yml +++ b/data_sources/windows_event_log_security_4756.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4756 id: b0093058-0cb6-4c73-a95b-fb0f3541e88c -version: 8 +version: 9 creation_date: '2026-03-30' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Nasreddine Bencherchali, Splunk description: Data source object for Windows Event Log Security 4756 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4759.yml b/data_sources/windows_event_log_security_4759.yml index 92c45b61e2..ac0bbe9a40 100644 --- a/data_sources/windows_event_log_security_4759.yml +++ b/data_sources/windows_event_log_security_4759.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4759 id: 431e3520-505b-4ace-aced-cb51e3f7311e -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4759 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4768.yml b/data_sources/windows_event_log_security_4768.yml index b2bd59a67d..2fa2cfa93c 100644 --- a/data_sources/windows_event_log_security_4768.yml +++ b/data_sources/windows_event_log_security_4768.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4768 id: 4a5fd6ed-66bd-4f34-bc74-51c00c73c298 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs Kerberos pre-authentication requests, including details about the user account, authentication type, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4768' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4769.yml b/data_sources/windows_event_log_security_4769.yml index 426d9f3274..9e290407d3 100644 --- a/data_sources/windows_event_log_security_4769.yml +++ b/data_sources/windows_event_log_security_4769.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4771.yml b/data_sources/windows_event_log_security_4771.yml index a2a4bc0f3d..6d49677dbd 100644 --- a/data_sources/windows_event_log_security_4771.yml +++ b/data_sources/windows_event_log_security_4771.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4771 id: 418debbb-adf3-48ec-9efd-59d45f8861e5 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs failed Kerberos pre-authentication attempts, including details about the user account, client IP, and failure reason. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4771' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4776.yml b/data_sources/windows_event_log_security_4776.yml index b217782c36..9eb82522a6 100644 --- a/data_sources/windows_event_log_security_4776.yml +++ b/data_sources/windows_event_log_security_4776.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4776 id: 1da9092a-c795-4a26-ace8-d43855524e96 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs NTLM authentication attempts, including details about the account name, authentication status, and the originating workstation. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4776' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_security_4781.yml b/data_sources/windows_event_log_security_4781.yml index a9223d52ff..b2dc6b7ae5 100644 --- a/data_sources/windows_event_log_security_4781.yml +++ b/data_sources/windows_event_log_security_4781.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4781 id: 9732ffe7-ebce-4557-865c-1725a0f633cb -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs changes made to the name of a computer account, including the old and new names and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4781' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4783.yml b/data_sources/windows_event_log_security_4783.yml index a72ae6bd43..aaf29f3b68 100644 --- a/data_sources/windows_event_log_security_4783.yml +++ b/data_sources/windows_event_log_security_4783.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4783 id: 6b945150-785c-49a1-b705-56b42215630b -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4783 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4790.yml b/data_sources/windows_event_log_security_4790.yml index 3825a2fa34..b3bbaeb0ef 100644 --- a/data_sources/windows_event_log_security_4790.yml +++ b/data_sources/windows_event_log_security_4790.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4790 id: 1cc6ecbb-af04-432b-a224-02c65243ac88 -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log Security 4790 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_security_4794.yml b/data_sources/windows_event_log_security_4794.yml index 91b6a0b4f7..7fafb2a69d 100644 --- a/data_sources/windows_event_log_security_4794.yml +++ b/data_sources/windows_event_log_security_4794.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4794 id: ec7da74f-274a-4bde-aa0e-15c68aca0426 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs attempts to set the Directory Services Restore Mode (DSRM) administrator password, including details about the account name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4798.yml b/data_sources/windows_event_log_security_4798.yml index 154b57b09b..650012d83a 100644 --- a/data_sources/windows_event_log_security_4798.yml +++ b/data_sources/windows_event_log_security_4798.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4798 id: 29e97f72-eb2e-400e-b0c9-81277547e43b -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs an enumeration of local group membership on a system, including details about the groups queried and the account performing the action. mitre_components: @@ -16,7 +16,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4876.yml b/data_sources/windows_event_log_security_4876.yml index bb93af9bf3..6d2bc14ae0 100644 --- a/data_sources/windows_event_log_security_4876.yml +++ b/data_sources/windows_event_log_security_4876.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4876 id: 4a78722a-9cd9-44e8-b010-dffad5c7f170 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the result of a cryptographic operation, including details about the key, algorithm used, and whether the operation succeeded or failed. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4876' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4886.yml b/data_sources/windows_event_log_security_4886.yml index b86ea55b57..25df942357 100644 --- a/data_sources/windows_event_log_security_4886.yml +++ b/data_sources/windows_event_log_security_4886.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4886 id: c5abd97d-b468-451f-bd65-b4f97efa4ecc -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the deletion of a cryptographic key container, including details about the key container name and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4886' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4887.yml b/data_sources/windows_event_log_security_4887.yml index b38db0e33f..04f80f2eab 100644 --- a/data_sources/windows_event_log_security_4887.yml +++ b/data_sources/windows_event_log_security_4887.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4887 id: 994c7b19-a623-4231-9818-f00e453b9a75 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs cryptographic operations performed by a Windows system, including details about the certificate or key used and the operation type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4887' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_4946.yml b/data_sources/windows_event_log_security_4946.yml index 4c47bbcc51..c21a47d24a 100644 --- a/data_sources/windows_event_log_security_4946.yml +++ b/data_sources/windows_event_log_security_4946.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4946 id: d7dafd01-a22d-4b05-b793-7571ef1fa789 -version: 9 +version: 10 creation_date: '2025-03-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4946 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4946' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4947.yml b/data_sources/windows_event_log_security_4947.yml index b12d773e0d..49d09885bf 100644 --- a/data_sources/windows_event_log_security_4947.yml +++ b/data_sources/windows_event_log_security_4947.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4947 id: 63d4a2fa-a7dc-46d2-b702-54794e1f4d3c -version: 9 +version: 10 creation_date: '2025-03-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4947 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4947' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_4948.yml b/data_sources/windows_event_log_security_4948.yml index 2f59dc291e..a251bb2cdd 100644 --- a/data_sources/windows_event_log_security_4948.yml +++ b/data_sources/windows_event_log_security_4948.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 4948 id: 910032df-4e49-42fe-a611-d4c29557d83a -version: 9 +version: 10 creation_date: '2025-03-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Teoderick Contreras, Splunk description: Data source object for Windows Event Log Security 4948 source: XmlWinEventLog:Security @@ -12,7 +12,7 @@ separator_value: '4948' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - EventID diff --git a/data_sources/windows_event_log_security_5136.yml b/data_sources/windows_event_log_security_5136.yml index 3f4491f8b0..b2f9893a7d 100644 --- a/data_sources/windows_event_log_security_5136.yml +++ b/data_sources/windows_event_log_security_5136.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5136 id: 7ba3737e-231e-455d-824e-cd077749f835 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs modifications made to an Active Directory object, including details about the object name, type, and the changes applied. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5136' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5137.yml b/data_sources/windows_event_log_security_5137.yml index c745196af0..f8c451a6b2 100644 --- a/data_sources/windows_event_log_security_5137.yml +++ b/data_sources/windows_event_log_security_5137.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5137 id: 64ed7bb1-9c3c-4355-ac08-b506ec3b053e -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the creation of a new Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5137' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AppCorrelationID diff --git a/data_sources/windows_event_log_security_5140.yml b/data_sources/windows_event_log_security_5140.yml index 31036dba3f..b5ac0ea6f0 100644 --- a/data_sources/windows_event_log_security_5140.yml +++ b/data_sources/windows_event_log_security_5140.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5140 id: 93e0ca09-e4b8-4da6-872a-d0127c4d2b22 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs access to a network share, including details about the user, share path, and the access type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5140' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_security_5141.yml b/data_sources/windows_event_log_security_5141.yml index 494c1932e4..3d5d86bd6f 100644 --- a/data_sources/windows_event_log_security_5141.yml +++ b/data_sources/windows_event_log_security_5141.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5141 id: eafb35fa-f034-4be3-8508-d9173a73c0a1 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the deletion of an Active Directory object, including details about the object name, type, and the user performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5141' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActivityID diff --git a/data_sources/windows_event_log_security_5145.yml b/data_sources/windows_event_log_security_5145.yml index df1ffcace4..ff9ae119f9 100644 --- a/data_sources/windows_event_log_security_5145.yml +++ b/data_sources/windows_event_log_security_5145.yml @@ -1,8 +1,8 @@ name: Windows Event Log Security 5145 id: 0746479b-7b82-4d7e-8811-0b35da00f798 -version: 11 +version: 12 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs detailed information about access to a network share, including the user, share path, accessed file, and access permissions. mitre_components: @@ -17,7 +17,7 @@ separator_value: '5145' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AccessList diff --git a/data_sources/windows_event_log_system_104.yml b/data_sources/windows_event_log_system_104.yml index 0d0dfb7e03..9c9e3460b1 100644 --- a/data_sources/windows_event_log_system_104.yml +++ b/data_sources/windows_event_log_system_104.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 104 id: 577b9b41-6b37-44c4-9016-3d890b909050 -version: 10 +version: 11 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log System 104 source: XmlWinEventLog:System @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_event_log_system_4720.yml b/data_sources/windows_event_log_system_4720.yml index 4dc384351b..bc5c69152f 100644 --- a/data_sources/windows_event_log_system_4720.yml +++ b/data_sources/windows_event_log_system_4720.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4720 id: f01d4758-05c8-4ac4-a9a5-33500dd5eb6c -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the creation of a new user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4720' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4726.yml b/data_sources/windows_event_log_system_4726.yml index 64d4bbe59e..994a12c80d 100644 --- a/data_sources/windows_event_log_system_4726.yml +++ b/data_sources/windows_event_log_system_4726.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4726 id: 05e6b2df-b50e-441b-8ac8-565f2e80d62f -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the deletion of a user account, including details about the account name, associated domain, and the account performing the action. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4726' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_4728.yml b/data_sources/windows_event_log_system_4728.yml index e3dcc6c286..e5ae97a8be 100644 --- a/data_sources/windows_event_log_system_4728.yml +++ b/data_sources/windows_event_log_system_4728.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 4728 id: 4549f0ac-3df9-4bfb-bea5-1459690c8040 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the addition of a user to a security-enabled group, including details about the group name, user account, and associated domain. mitre_components: @@ -17,7 +17,7 @@ separator_value: '4728' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Account_Domain diff --git a/data_sources/windows_event_log_system_7036.yml b/data_sources/windows_event_log_system_7036.yml index fcb8336d67..25e89603c8 100644 --- a/data_sources/windows_event_log_system_7036.yml +++ b/data_sources/windows_event_log_system_7036.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7036 id: a6e9b34f-1507-4fa1-a4ba-684d1b676a34 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs state changes of a Windows service, including details about the service name and its new state (e.g., started or stopped). mitre_components: @@ -17,7 +17,7 @@ separator_value: '7036' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7040.yml b/data_sources/windows_event_log_system_7040.yml index 753cdef672..8c5e7788d4 100644 --- a/data_sources/windows_event_log_system_7040.yml +++ b/data_sources/windows_event_log_system_7040.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7040 id: 91738e9e-d112-41c9-b91b-e5868d8993d9 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs changes to the start type of a Windows service, including details about the service name, old start type, and new start type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7040' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - Channel diff --git a/data_sources/windows_event_log_system_7045.yml b/data_sources/windows_event_log_system_7045.yml index 6333800eea..70e8f7c5a1 100644 --- a/data_sources/windows_event_log_system_7045.yml +++ b/data_sources/windows_event_log_system_7045.yml @@ -1,8 +1,8 @@ name: Windows Event Log System 7045 id: 614dedc8-8a14-4393-ba9b-6f093cbcd293 -version: 10 +version: 11 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the successful installation of a new Windows service, including details about the service name, executable path, and service type. mitre_components: @@ -17,7 +17,7 @@ separator_value: '7045' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - AccountName diff --git a/data_sources/windows_event_log_taskscheduler_200.yml b/data_sources/windows_event_log_taskscheduler_200.yml index c9107f01da..2fd63ea869 100644 --- a/data_sources/windows_event_log_taskscheduler_200.yml +++ b/data_sources/windows_event_log_taskscheduler_200.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 200 id: f8c777f8-e88a-4bba-ae8a-79b250212f23 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations. mitre_components: @@ -17,7 +17,7 @@ separator_value: '200' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ActionName diff --git a/data_sources/windows_event_log_taskscheduler_201.yml b/data_sources/windows_event_log_taskscheduler_201.yml index c84db76aaa..1159b61a86 100644 --- a/data_sources/windows_event_log_taskscheduler_201.yml +++ b/data_sources/windows_event_log_taskscheduler_201.yml @@ -1,8 +1,8 @@ name: Windows Event Log TaskScheduler 201 id: 4c09ae64-01cd-4b65-8221-20f803b0d86e -version: 9 +version: 10 creation_date: '2025-02-21' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Data source object for Windows Event Log TaskScheduler 201 source: XmlWinEventLog:Security @@ -11,7 +11,7 @@ separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time output_fields: diff --git a/data_sources/windows_iis.yml b/data_sources/windows_iis.yml index 7b88eabe2a..e900b547bc 100644 --- a/data_sources/windows_iis.yml +++ b/data_sources/windows_iis.yml @@ -1,8 +1,8 @@ name: Windows IIS id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs changes to IIS server configuration, including updates to settings, modules, authentication methods, and site bindings. mitre_components: @@ -16,4 +16,4 @@ separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 diff --git a/data_sources/windows_iis_29.yml b/data_sources/windows_iis_29.yml index 4101b2266f..fa7c09ac73 100644 --- a/data_sources/windows_iis_29.yml +++ b/data_sources/windows_iis_29.yml @@ -1,8 +1,8 @@ name: Windows IIS 29 id: 1d99ddd7-7fec-4dea-bf4f-1f4906142328 -version: 9 +version: 10 creation_date: '2024-05-22' -modification_date: '2026-08-10' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Logs modifications to IIS server authentication settings, including updates to client certificate requirements and authentication methods. mitre_components: @@ -17,7 +17,7 @@ separator_value: '29' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 - version: 10.0.1 + version: 11.0.1 fields: - _time - ComputerName From 694b66cd94b65cae2560f8104906eb16b81287d3 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Wed, 12 Aug 2026 19:57:41 +0000 Subject: [PATCH 31/32] Update datasource TA versions --- data_sources/cisco_ai_defense_alerts.yml | 6 +++--- data_sources/cisco_asa_logs.yml | 6 +++--- data_sources/cisco_duo_activity.yml | 6 +++--- data_sources/cisco_duo_administrator.yml | 6 +++--- data_sources/cisco_isovalent_process_connect.yml | 6 +++--- data_sources/cisco_isovalent_process_exec.yml | 6 +++--- data_sources/cisco_isovalent_process_kprobe.yml | 6 +++--- ...isco_secure_firewall_threat_defense_connection_event.yml | 6 +++--- .../cisco_secure_firewall_threat_defense_file_event.yml | 6 +++--- ...cisco_secure_firewall_threat_defense_intrusion_event.yml | 6 +++--- 10 files changed, 30 insertions(+), 30 deletions(-) diff --git a/data_sources/cisco_ai_defense_alerts.yml b/data_sources/cisco_ai_defense_alerts.yml index c2ae92757e..db8b3d629f 100644 --- a/data_sources/cisco_ai_defense_alerts.yml +++ b/data_sources/cisco_ai_defense_alerts.yml @@ -1,8 +1,8 @@ name: Cisco AI Defense Alerts id: cbb06880-9dd9-4542-ac60-bd6e1d3c3e4e -version: 5 +version: 6 creation_date: '2025-02-14' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Bhavin Patel description: Data source object for Cisco AI Defense Alerts source: cisco_ai_defense @@ -11,5 +11,5 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: diff --git a/data_sources/cisco_asa_logs.yml b/data_sources/cisco_asa_logs.yml index 10623c45c0..b4a0c68316 100644 --- a/data_sources/cisco_asa_logs.yml +++ b/data_sources/cisco_asa_logs.yml @@ -1,8 +1,8 @@ name: Cisco ASA Logs id: 3f2a9b6d-1c8e-4f7b-a2d3-8b7f1c2a9d4e -version: 6 +version: 7 creation_date: '2025-09-25' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: "Data source object for Cisco ASA system logs. Cisco ASA logs provide firewall operational and security telemetry (connection events, ACL denies, VPN events, NAT translations, and device health). Deploy the Splunk Add-on for Cisco ASA (TA-cisco_asa) on indexers/heavy forwarders and the Cisco ASA App on search heads for best parsing, CIM mapping, and dashboards. This data is ingested via SYSLOG. You must be ingesting Cisco ASA syslog data into your Splunk environment. To ensure all detections work, configure your ASA and FTD devices to generate and forward both debug and informational level syslog messages before they are sent to Splunk. A few analytics are designed to be used with comprehensive logging enabled, as it relies on the presence of specific message IDs. You can find specific instructions on how to set this up here : https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/63884-config-asa-00.html#toc-hId--1451069880. \n" source: not_applicable @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - Cisco_ASA_action - Cisco_ASA_message_id diff --git a/data_sources/cisco_duo_activity.yml b/data_sources/cisco_duo_activity.yml index 38c7ebb945..4dd9bd3a96 100644 --- a/data_sources/cisco_duo_activity.yml +++ b/data_sources/cisco_duo_activity.yml @@ -1,8 +1,8 @@ name: Cisco Duo Activity id: 83f727f6-8754-41f8-b9f7-8226886a659e -version: 5 +version: 6 creation_date: '2025-07-10' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Activity source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - access_device.browser - access_device.browser_version diff --git a/data_sources/cisco_duo_administrator.yml b/data_sources/cisco_duo_administrator.yml index 7f71d2a9e7..749daf8e24 100644 --- a/data_sources/cisco_duo_administrator.yml +++ b/data_sources/cisco_duo_administrator.yml @@ -1,8 +1,8 @@ name: Cisco Duo Administrator id: 38e22de6-8b6b-449c-ae26-a640c88ff7f9 -version: 5 +version: 6 creation_date: '2025-07-10' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Patrick Bareiss, Splunk description: Data source object for Cisco Duo Administrator source: cisco_duo @@ -11,7 +11,7 @@ separator: supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - action - actionlabel diff --git a/data_sources/cisco_isovalent_process_connect.yml b/data_sources/cisco_isovalent_process_connect.yml index 61f7c1e61d..a1f111f913 100644 --- a/data_sources/cisco_isovalent_process_connect.yml +++ b/data_sources/cisco_isovalent_process_connect.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Connect id: bf8c76a1-6066-4759-ab77-d3f0a375519e -version: 5 +version: 6 creation_date: '2026-01-05' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: "Captures detailed process connection events—including source and destination process metadata, execution lineage (ancestry), and Kubernetes workload context—generated by Cisco Isovalent instrumentation. Enables technical analysis of inter-process communications, container-level activity, and workload-specific network flows in cloud-native environments." source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processConnect supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - _time - app diff --git a/data_sources/cisco_isovalent_process_exec.yml b/data_sources/cisco_isovalent_process_exec.yml index 98de2a6c4a..3fd87e007e 100644 --- a/data_sources/cisco_isovalent_process_exec.yml +++ b/data_sources/cisco_isovalent_process_exec.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Exec id: 87654321-dcba-4321-00fe-0987654321ba -version: 5 +version: 6 creation_date: '2026-01-05' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Logs process execution events within Cisco Isovalent environments, providing visibility into process exec ancestry and Kubernetes workload identity. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent:processExec supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - _time - cluster_name diff --git a/data_sources/cisco_isovalent_process_kprobe.yml b/data_sources/cisco_isovalent_process_kprobe.yml index 4fc679241d..6a86caf8c5 100644 --- a/data_sources/cisco_isovalent_process_kprobe.yml +++ b/data_sources/cisco_isovalent_process_kprobe.yml @@ -1,8 +1,8 @@ name: Cisco Isovalent Process Kprobe id: b2620ef2-fac6-467f-bdc8-253d65db1cb9 -version: 5 +version: 6 creation_date: '2026-01-05' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Bhavin Patel, Splunk description: Captures kernel probe (kprobe) telemetry from Cisco Isovalent Runtime Security, including function name, arguments, and process context, enabling visibility into low-level kernel interactions that may indicate container escape attempts or system tampering. source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:isovalent supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - _time - app diff --git a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml index 3fc2a5d65e..866e75d4b4 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_connection_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Connection Event id: 18878597-8f8a-4bca-a805-bfbe35e00032 -version: 6 +version: 7 creation_date: '2025-04-03' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Nasreddine Bencherchali, Splunk description: Data source object for raw connection events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - AC_RuleAction - action diff --git a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml index cdff72aa77..c053297d89 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_file_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_file_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense File Event id: 19878597-8f8a-4bca-a805-bfbe35e00032 -version: 5 +version: 6 creation_date: '2025-04-09' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Nasreddine Bencherchali, Splunk description: Data source object for raw file events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - app - Application diff --git a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml index bfccb3889d..855f16fd2b 100644 --- a/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml +++ b/data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml @@ -1,8 +1,8 @@ name: Cisco Secure Firewall Threat Defense Intrusion Event id: d11b67ec-1cb2-4f6f-a2d8-a099c7e15b29 -version: 5 +version: 6 creation_date: '2025-04-16' -modification_date: '2026-07-31' +modification_date: '2026-08-12' author: Nasreddine Bencherchali, Splunk description: Data source object for raw intrusion events from Cisco Secure Firewall Threat Defense source: not_applicable @@ -10,7 +10,7 @@ sourcetype: cisco:sfw:estreamer supported_TA: - name: Cisco Security Cloud url: https://splunkbase.splunk.com/app/7404 - version: 3.6.9 + version: 3.6.10 fields: - Application - Classification From 6ba236776bb6489bd15f3c13add713a0922b3dc8 Mon Sep 17 00:00:00 2001 From: datasource-ta-dependabot Date: Fri, 14 Aug 2026 12:37:39 +0000 Subject: [PATCH 32/32] Update datasource TA versions --- data_sources/palo_alto_network_threat.yml | 6 +++--- data_sources/palo_alto_network_traffic.yml | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/data_sources/palo_alto_network_threat.yml b/data_sources/palo_alto_network_threat.yml index f9f8d7f034..5eaa7bf10b 100644 --- a/data_sources/palo_alto_network_threat.yml +++ b/data_sources/palo_alto_network_threat.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Threat id: 375c2b0e-d216-41ad-9406-200464595209 -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-30' +modification_date: '2026-08-14' author: Patrick Bareiss, Splunk description: Logs detected threats identified by Palo Alto Networks devices, including details about malware, intrusion attempts, and malicious network activity. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:threat supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.2.2 + version: 4.0.0 fields: - _time - date_hour diff --git a/data_sources/palo_alto_network_traffic.yml b/data_sources/palo_alto_network_traffic.yml index 445f0198ed..1ed6b26abb 100644 --- a/data_sources/palo_alto_network_traffic.yml +++ b/data_sources/palo_alto_network_traffic.yml @@ -1,8 +1,8 @@ name: Palo Alto Network Traffic id: 182a83bc-c31a-4817-8c7a-263744cec52a -version: 8 +version: 9 creation_date: '2024-05-22' -modification_date: '2026-07-30' +modification_date: '2026-08-14' author: Patrick Bareiss, Splunk description: Logs network traffic events captured by Palo Alto Networks devices, including details about sessions, protocols, and source and destination IPs. mitre_components: @@ -16,7 +16,7 @@ sourcetype: pan:traffic supported_TA: - name: Palo Alto Networks Add-on url: https://splunkbase.splunk.com/app/7523 - version: 3.2.2 + version: 4.0.0 fields: - _time - date_hour