Skip to content

new o11y secure application detection#4108

Open
bpluta-splunk wants to merge 3 commits into
developfrom
secureapp
Open

new o11y secure application detection#4108
bpluta-splunk wants to merge 3 commits into
developfrom
secureapp

Conversation

@bpluta-splunk
Copy link
Copy Markdown
Collaborator

Details

We are keeping the legacy AppD Secure Application detection until we can get a TA to provide the sourcetype for both AppD and o11y.

Checklist

  • [x ] Validate name matches <platform>_<mitre att&ck technique>_<short description> nomenclature
  • [ x] CI/CD jobs passed ✔️
  • [ x] Validated SPL logic.
  • [ x] Validated tags, description, and how to implement.
  • [ x] Verified references match analytic.
  • [ x] Confirm updates to lookups are handled properly.

@bpluta-splunk
Copy link
Copy Markdown
Collaborator Author

Screenshots of search being ran against test data

Screenshot 2026-05-27 at 11 47 27 AM Screenshot 2026-05-27 at 11 47 39 AM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant