olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.12k stars 177 forks source link

CSV Pack #33

Open billmurrin opened 5 years ago

billmurrin commented 5 years ago

Aloha Olaf,

Our team noticed that the lookup whitelist download archive does not include the new lookup files - wmi, and dns. Also, the pipe whitelist still states pipe_created.

olafhartong commented 4 years ago

Thanks for reminding me, I will make an update to the pack

billmurrin commented 4 years ago

Cool. Looks like file create also needs to be on there.

stamper197 commented 4 years ago

how goes this enhancement request?

lasdem commented 4 years ago

I found a workaround, if you open the whitelist editor in the app and click submit the whitelist will be created.