Skip to content

Conversation

@nasbench
Copy link
Contributor

@nasbench nasbench commented Jan 9, 2026

This PR introduces a couple new analytics related to Snort/ Cisco IOS and updates to output and RBA fields of old snort based detections.

New Analytics [5]

  • Cisco Privileged Account Creation with HTTP Command Execution
  • Cisco Privileged Account Creation with Suspicious SSH Activity
  • Cisco Secure Firewall - Privileged Command Execution via HTTP
  • Cisco Secure Firewall - SSH Connection to Non-Standard Port
  • Cisco Secure Firewall - SSH Connection to sshd_operns

Updated Analytics [29]

The updates mainly focused on changing the dest_ip and src_ip to dest and src respectively for ES compliance.

Updated Data Sources [3]

Updated the output fields from src_ip to src for ES compliance.

  • data_sources/cisco_secure_firewall_threat_defense_connection_event.yml
  • data_sources/cisco_secure_firewall_threat_defense_file_event.yml
  • data_sources/cisco_secure_firewall_threat_defense_intrusion_event.yml

@nasbench nasbench marked this pull request as ready for review January 10, 2026 13:28
@nasbench nasbench added this to the v5.20.0 milestone Jan 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant