Skip to content

Cisco Secure Access - DNS and Proxy detection#4066

Open
patel-bhavin wants to merge 10 commits into
developfrom
secure_access_mahamudul
Open

Cisco Secure Access - DNS and Proxy detection#4066
patel-bhavin wants to merge 10 commits into
developfrom
secure_access_mahamudul

Conversation

@patel-bhavin
Copy link
Copy Markdown
Contributor

@patel-bhavin patel-bhavin commented May 6, 2026

@patel-bhavin patel-bhavin added this to the v6.1.0 milestone May 14, 2026
@patel-bhavin patel-bhavin marked this pull request as ready for review May 21, 2026 05:07
@patel-bhavin patel-bhavin changed the title Cisco secure access DNS detection Cisco Secure Access - DNS and Proxy detection Jun 3, 2026
Comment thread detections/network/cisco_sa___access_to_anonymizer_services.yml Outdated
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/cisco_secure_access/proxy/automated_web_recon_http_errors.log
source: cisco_cloud_security_addon
sourcetype: cisco:cloud_security:proxy
description: This test scenario covers true positive activity, simulating a high error count reconnaissance from a single src_ip against a domain. Review the filter macro to tune this detection for your environment.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not needed here

Suggested change
description: This test scenario covers true positive activity, simulating a high error count reconnaissance from a single src_ip against a domain. Review the filter macro to tune this detection for your environment.

@patel-bhavin patel-bhavin self-assigned this Jun 4, 2026
patel-bhavin and others added 3 commits June 4, 2026 17:47
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
…_http_access_errors.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
…_http_access_errors.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants