Skip to content

Secure Accessfirewall Detections#3986

Open
patel-bhavin wants to merge 22 commits intodevelopfrom
secure_xcess
Open

Secure Accessfirewall Detections#3986
patel-bhavin wants to merge 22 commits intodevelopfrom
secure_xcess

Conversation

@patel-bhavin
Copy link
Copy Markdown
Contributor

@patel-bhavin patel-bhavin commented Apr 1, 2026

Update detections with Secure Access firewall attack data!

Detections :-

  • Detect Large ICMP Traffic
  • Detect Outbound SMB Traffic
  • Detect Outbound LDAP Traffic
  • Windows Remote Desktop Network Bruteforce Attempt

@patel-bhavin patel-bhavin changed the title Secure Accecess firewall detections Secure Access firewall Detections Apr 1, 2026
@patel-bhavin patel-bhavin added this to the v5.27.0 milestone Apr 15, 2026
@patel-bhavin patel-bhavin changed the title Secure Access firewall Detections Secure Access/ Umbrella firewall Detections Apr 17, 2026
@patel-bhavin patel-bhavin changed the title Secure Access/ Umbrella firewall Detections Secure Accessfirewall Detections Apr 21, 2026
@patel-bhavin patel-bhavin marked this pull request as ready for review April 23, 2026 04:47
Comment thread macros/non_public_ip_blocks.yml Outdated
"192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24",
"198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1")
description: customer specific splunk configurations to normalized Windows Event Log System 7036 to recover actual services execution.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs updating.

Comment thread macros/non_public_ip_blocks.yml Outdated
definition: ("10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10",
"127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32",
"192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24",
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we probably want to sort these in some manner? And/or mention in the description what these blocks are (beyond RFC1918)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants