Skip to content

Improved detections based on telemetry.#3971

Merged
P4T12ICK merged 19 commits intodevelopfrom
detections_improvement
Mar 27, 2026
Merged

Improved detections based on telemetry.#3971
P4T12ICK merged 19 commits intodevelopfrom
detections_improvement

Conversation

@P4T12ICK
Copy link
Collaborator

Improved detections based on telemetry.

@nasbench nasbench added this to the v5.25.0 milestone Mar 26, 2026
Copy link
Contributor

@nasbench nasbench left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left out some comments / suggestions here and there. Overall nice changes.

I would suggest you document in the PR body the reasoning behind the change from TTP/Anomaly -> Hunting. Since this is a breaking change (they will not produce Risk/Findings anymore). Which we got customer issues about before.

P4T12ICK and others added 10 commits March 26, 2026 16:43
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
…tempt_via_rundll32.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
…exec.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Copy link
Contributor

@nasbench nasbench left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

Great work on the fixes

@P4T12ICK P4T12ICK merged commit fa45863 into develop Mar 27, 2026
6 checks passed
@P4T12ICK P4T12ICK deleted the detections_improvement branch March 27, 2026 12:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants