External javascript libraries, decompression, ebcdic
|
8
|
January 21, 2021
|
Detection SIEM Connector Description Issue
|
9
|
January 4, 2021
|
Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability
|
1
|
November 6, 2020
|
Throttle Triggered Precision PCAP
|
3
|
October 15, 2020
|
DNS Answers in ODS feed to Splunk
|
3
|
October 9, 2020
|
Got Bots? We got an App for that!
|
2
|
September 16, 2020
|
TIMER_30SEC event
|
3
|
August 6, 2020
|
Honey Token Detection across multiple protocols
|
1
|
June 4, 2020
|
lookupByIP in L2 discovery
|
4
|
May 18, 2020
|
NDR POW (2/27): POSH Watcher
|
7
|
May 14, 2020
|
MSRPC Records
|
2
|
March 26, 2020
|
Critical Devices - EXA Connector Trigger
|
2
|
March 18, 2020
|
IP address, Port, throughput
|
1
|
March 15, 2020
|
Detection: Cloud Snooper
|
1
|
February 27, 2020
|
NDR POW (12/16) Trickbot/RYUK Variant throw-down
|
1
|
December 16, 2019
|
Debug log shows unexpected entries
|
9
|
December 14, 2019
|
NDR POW (Punkbust Of the Week): Catching Homograph Attacks (PHISH PHINDER!)
|
1
|
December 9, 2019
|
How to Optimize Trigger Code?
|
8
|
December 5, 2019
|
Hadoop DemonBot detection
|
3
|
November 13, 2019
|
NDR: Checking for 'Baby Certs" with Reveal(x)
|
2
|
November 1, 2019
|
Citrix Middle Tier Trigger
|
3
|
October 21, 2019
|
Trigger for TCP:9100 Destinations
|
3
|
June 26, 2019
|
Error : EDA-STC: Line 120: Uncaught Error: Key must be a string
|
4
|
May 29, 2019
|
Alert on an HTTP Error code
|
3
|
April 18, 2019
|
How to capture Flow/TCP Payload
|
1
|
April 12, 2019
|
Icmp pmtud
|
4
|
March 21, 2019
|
Exempt a URI in extrahop alert
|
4
|
January 17, 2019
|
Dump all Triggers to their own files by name
|
1
|
December 4, 2018
|
An existing connection was forcibly closed by the remote host
|
7
|
November 14, 2018
|
URIs not being Captured triggers
|
5
|
August 14, 2018
|