Comments (6)
it is definetly a more active project since we publish our active detection development there, but the tooling for it now lives on contentctl.
from security_content.
as i may understand, this is due to python 3.10.
and it is strange, why venv using 3.10, or what is wrong?
(venv) user@star:~/security_content-4.21.0$ which python
/home/user/security_content-4.21.0/venv/bin/python
(venv) user@star:~/security_content-4.21.0$ python --version
Python 3.10.12
(venv) user@star:~/security_content-4.21.0$ /home/user/security_content-4.21.0/venv/bin/python --version
Python 3.10.12
from security_content.
so, i had to update some ~20 py files with Import from collections
and changed it to Import from collections.abc
and it started to work.
but this is not expected way to solve it.
from security_content.
Hey @yaroslav-nakonechnikov I believe you might be using an old version of our tooling, we migrated all these tools over to https://github.com/splunk/contentctl .. give those a try, I will work on updating our README here so it won't mislead other users. Thank you for raising!
from security_content.
@josehelps but according to releases and timestamps for it - there is a feel, that security_content is more active project.
from security_content.
thanks!
from security_content.
Related Issues (20)
- Include `tags.atomic_guid` and `tags.required_fields` into ESCU
- Add custom annotation for versioning HOT 4
- [BUG] "Kerberos TGT Request Using RC4 Encryption" using non-CIM field "Account_Name" HOT 1
- CMD Carry Out String Command Parameter - false negatives due to trailing space before wildcard in search [BUG] HOT 2
- [BUG] ESCU - Detect Excessive Account Lockouts From Endpoint HOT 3
- [BUG] O365 Mailbox Inbox Folder Shared with All Users. Field "object" doesn't exist. HOT 1
- [BUG] sourcetype macro not consistent across Azure AD correlations HOT 2
- pre trained Deep Learning models for ESCU - Support for DSDL Version 5.1.1 HOT 1
- [BUG] - Unknown Process Using The Kerberos Protocol is too noisy HOT 3
- [BUG] Linux Service Started Or Enabled triggering on Windows events HOT 2
- Consider adding Scope for search Azure AD Tenant Wide Admin Consent Granted HOT 1
- [BUG] DNS Query Length With High Standard Deviation HOT 1
- [BUG] Datasource is set incorrectly on this detection
- [BUG] ESCU - Get ADUser with PowerShell - Rule has no Adaptive Reponse Actions HOT 3
- Scheduled Task Initiation on Remote Endpoint - Update Analytics
- Azure AD Multi-Source Failed Authentications Spike - Missing ADFSSignInLogs category
- Minor malicious_powershell_process___encoded_command search update
- [BUG] Detections with joins failed to properly translate to Sigma
- [BUG] Missing Wildcards in Splunk Rule for Detecting Known Services Killed by Ransomware
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from security_content.