Need to creatre a TRIGGER to pull TLS version and Dest Port from ExtraHop
|
|
0
|
29
|
March 23, 2023
|
Github Triggers and Bundles
|
|
2
|
2544
|
December 24, 2016
|
How to create a trigger which the client is not one, but subnet?
|
|
2
|
139
|
February 15, 2023
|
Custom Detection: Newly Discovered Asset
|
|
0
|
450
|
August 26, 2022
|
Unable to commit detection
|
|
5
|
584
|
August 3, 2022
|
Commit detection adjustment in triggers. (Identity key and lasting duration of detection)
|
|
1
|
499
|
June 22, 2022
|
Custom Detection Example - Newly created SSL certificate
|
|
0
|
545
|
May 2, 2022
|
Help in identifying data obfuscation(protocol impersonation using cookie)
|
|
9
|
1115
|
February 9, 2022
|
CVE-2021-44228 detection
|
|
2
|
1215
|
December 14, 2021
|
Handing DETECTION_UPDATE during for ExtraHop-Demisto timeout
|
|
1
|
866
|
October 12, 2021
|
Detecting Unauthorized Remote Access Trigger
|
|
0
|
972
|
October 7, 2021
|
Mapping HTTP.payload information with Src/Dst IP/Port
|
|
5
|
1213
|
September 20, 2021
|
Testing a trigger - forcing a detection?
|
|
2
|
1170
|
June 22, 2021
|
Detection: CVE-2021-22991
|
|
3
|
1491
|
March 12, 2021
|
External javascript libraries, decompression, ebcdic
|
|
7
|
3343
|
January 21, 2021
|
Detection SIEM Connector Description Issue
|
|
8
|
1470
|
January 4, 2021
|
Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability
|
|
0
|
1403
|
November 6, 2020
|
Throttle Triggered Precision PCAP
|
|
2
|
1377
|
October 15, 2020
|
DNS Answers in ODS feed to Splunk
|
|
2
|
1364
|
October 9, 2020
|
Got Bots? We got an App for that!
|
|
1
|
2650
|
September 16, 2020
|
TIMER_30SEC event
|
|
2
|
1374
|
August 6, 2020
|
Honey Token Detection across multiple protocols
|
|
0
|
1902
|
June 4, 2020
|
lookupByIP in L2 discovery
|
|
3
|
1419
|
May 18, 2020
|
NDR POW (2/27): POSH Watcher
|
|
6
|
2437
|
May 14, 2020
|
MSRPC Records
|
|
1
|
1376
|
March 26, 2020
|
Critical Devices - EXA Connector Trigger
|
|
1
|
1731
|
March 18, 2020
|
IP address, Port, throughput
|
|
0
|
1378
|
March 15, 2020
|
Detection: Cloud Snooper
|
|
0
|
2062
|
February 27, 2020
|
NDR POW (12/16) Trickbot/RYUK Variant throw-down
|
|
0
|
1943
|
December 16, 2019
|
Debug log shows unexpected entries
|
|
8
|
1694
|
December 14, 2019
|